Security

252M identities dumped online in massive leak affecting 7 countries

Over 250 million identity records have been exposed across seven countries in a massive data leak.
Read more about 252M identities dumped online in massive leak affecting 7 countries

Popular marketing chatbot abused by hackers to breach Google, Cloudflare taken offline

Amid a wave of significant data breach disclosures from some of the world’s largest firms, Salesloft has announced that it’s pulling its Drift AI chatbot service offline. Hackers abused compromised Drift access tokens to infiltrate Salesforce instances.
Read more about Popular marketing chatbot abused by hackers to breach Google, Cloudflare taken offline

Production process of Jaguar Land Rover disrupted by cyberattack

A cyberattack has “severely disrupted” Jaguar Land Rover’s production activities. The good news is that there’s no evidence that customer data has been stolen.
Read more about Production process of Jaguar Land Rover disrupted by cyberattack

Google accused of “partisan” spam filters in Gmail

Federal Trade Commission (FTC) Chairman Andrew Ferguson has sent a letter to Sundar Pichai, CEO of Google’s parent company Alphabet, warning the company of potential FTC Act violations related to Gmail’s alleged “partisan” spam filters.
Read more about Google accused of “partisan” spam filters in Gmail

Zscaler discloses data breach after cyberattack on third party

The data of an unknown number of customers at Zscaler has been leaked due to a cyberattack on Salesforce. The American cloud security company is now warning affected customers of phishing attacks and social engineering attempts.
Read more about Zscaler discloses data breach after cyberattack on third party

Cloudflare joins list of Salesforce attack victims, provides detailed timeline

Cloudflare announces it has officially joined the list of hundreds of companies impacted by a continuing rash of third-party attacks on its Salesforce instance, following in the footsteps of Palo Alto Networks, which also made a similar admission on Tuesday.
Read more about Cloudflare joins list of Salesforce attack victims, provides detailed timeline

Palo Alto Networks also targeted during Salesforce data heist

Palo Alto Networks (PAN), the largest cybersecurity company by market capitalization, will be disclosing a data breach that exposed customer data and support cases, BleepingComputer reports.
Read more about Palo Alto Networks also targeted during Salesforce data heist

“This is personal now:” Man fired after cyberattack wants Lapsus$ hackers to pay

Fired after a supposed cyberattack on his company, a former employee has declared war on the ransomware gang. The company says there was no cyberattack.
Read more about “This is personal now:” Man fired after cyberattack wants Lapsus$ hackers to pay

Santa Fe County hack likely full of hot air

Attackers claim to have stolen source code from the Santa Fe County government website. However, the Cybernews research team believes that they’re peddling outdated information.
Read more about Santa Fe County hack likely full of hot air

Everyone can find your car, phone or other WiFi: what can you do about it?

You might not like it, but your WiFi devices are already mapped and used in vast, public location tracking systems without giving you anything in return. This means that attackers can accurately pinpoint where you are from a couch on another continent.
Read more about Everyone can find your car, phone or other WiFi: what can you do about it?

“Invincible” hackers threaten Google, FBI over Salesforce attack investigations

Three teen cybercrime gangs, previously decimated by arrests, are now acting as one and again feeling invincible. After claiming responsibility for major breaches tied to Salesforce instances, the group is now demanding that Google and the FBI halt their investigations and fire specific employees.
Read more about “Invincible” hackers threaten Google, FBI over Salesforce attack investigations

Don’t worry, your Gmail accounts might be secure after all

Google has denied claims that it informed Gmail users of a major security issue that supposedly affected 2.5 million users.
Read more about Don’t worry, your Gmail accounts might be secure after all

Orange Belgium adds an additional check to number transfer process to prevent SIM swapping

After recently suffering a data breach, Orange Belgium has decided to implement an additional check against SIM swapping.
Read more about Orange Belgium adds an additional check to number transfer process to prevent SIM swapping

Fresh AT&T data breach could impact 24M users, hackers claim

Attackers claim to have live access to AT&T infrastructure, which essentially allows them to bypass two-factor authentication tied to a specific phone number.
Read more about Fresh AT&T data breach could impact 24M users, hackers claim

The whole world depends on one overworked, underpaid developer, who might be from Moscow

A critical piece of code used by the Department of Defence and millions of others is being maintained by a single Russian developer. So what, some argue: half the internet runs on someone’s side project. The stir in the cybersecurity community highlights concerns over the influence nation-states can exert on individual maintainers.
Read more about The whole world depends on one overworked, underpaid developer, who might be from Moscow

NCSC stumbles upon new malware campaign involving PDF editors and manual finders

The National Cyber Security Centre (NCSC) from the Netherlands has warned of a global campaign in which criminals are distributing seemingly innocent tools, such as a PDF editor or manual finder, to infect systems with malware.
Read more about NCSC stumbles upon new malware campaign involving PDF editors and manual finders

AI chatbots crawl website hundreds of times before sending a single actual visitor

Millions of crawls but just a few clicks – new data shows that AI chatbots are leeching attention away from publishers and site owners, harvesting their content but giving back very little traffic in return.
Read more about AI chatbots crawl website hundreds of times before sending a single actual visitor

433K US doctors’ data leaked online, hackers claim

Attackers claim the leaked details include everything from medical practitioners' names to home addresses. The Cybernews research team believes that the data could have come from a third-party service provider breach.
Read more about 433K US doctors’ data leaked online, hackers claim

Tea app says only 0.1% of users affected by breach – is it just the tip of the iceberg?

Tea Dating Advice, the “secure” platform for women to share sensitive information about their dates, has started sending breach notification letters a month after its much-publicized leak
Read more about Tea app says only 0.1% of users affected by breach – is it just the tip of the iceberg?

4chan and Kiwi Farms sue British regulator Ofcom over age verification

American internet forums 4chan and Kiwi Farms have sued the United Kingdom’s communication services regulator Ofcom over the recently adopted Online Safety Act.
Read more about 4chan and Kiwi Farms sue British regulator Ofcom over age verification