Security
How the Salesforce breaches unfolded: root causes identified
New details have emerged regarding the massive Salesforce compromise campaign, which impacted hundreds of companies, including major tech and cybersecurity firms.
Read more about How the Salesforce breaches unfolded: root causes identified
The dumbest employee tech hacks that nearly broke companies
From medical data being shared on Dropbox to an industrial control system connected to a food truck’s hotspot, what are the dumbest employee IT decisions?
Read more about The dumbest employee tech hacks that nearly broke companies
Data breach at American credit union exposes financial data
Not only did hackers penetrate Carter Credit Union’s network, but they also got their hands on virtually every possible data point the financial institution had on its customers.
Read more about Data breach at American credit union exposes financial data
Fake recruiters from North Korea plot attacks on Slack, abuse Western cyber intelligence
Hundreds of people were hacked between March and June this year by North Korean hackers posing as recruiters or job seekers, cybersecurity researchers warn. They abuse Western cyber intelligence platforms and other commercial tools when carrying out cyberattacks.
Read more about Fake recruiters from North Korea plot attacks on Slack, abuse Western cyber intelligence
Major airline inflight service providers' hack exposes Starlink users
Anuvu, an in-flight entertainment and connectivity (IFEC) service provider, has allegedly fallen victim to a hacker attack.
Read more about Major airline inflight service providers' hack exposes Starlink users
Instagram exposes teens to gruesome content despite pledges to protect them
Let’s say a 15-year-old boy creates a new Instagram account and follows celebrities recommended by the platform. He searches for the word “fight” and ultimately ends up scrolling through an array of violent and gory videos, despite Meta’s pledges to restrict unsafe content.
Read more about Instagram exposes teens to gruesome content despite pledges to protect them
Bridgestone hacked same day as Jaguar Land Rover, also disrupting operations
Bridgestone Americas on Thursday confirms the company has suffered what it calls a “limited cyber incident” – ironically, on the same day luxury carmaker Jaguar Land Rover was breached by the publicity-hungry Scattered Spider-led trio of ransomware gangs.
Read more about Bridgestone hacked same day as Jaguar Land Rover, also disrupting operations
Surge in malicious scans for outdated routers: hackers hunting for old Cisco, Linksys gear
Researchers are warning of a surge in malicious scans for old, outdated, and vulnerable network equipment. Hackers are likely succeeding because these probes often come from compromised end-of-life Cisco, Linksys, and Araknis Networks devices.
Read more about Surge in malicious scans for outdated routers: hackers hunting for old Cisco, Linksys gear
Online chess players’ data leaked in third-party breach
The most popular platform for chess players, Chess.com, has informed thousands of users that their personal details were exposed after hackers breached the company’s data storage vendor.
Read more about Online chess players’ data leaked in third-party breach
AI blockade: websites are putting up fences to protect their content
Website owners, from global banks to prestigious universities and leading law firms, are cracking down on AI bots pillaging their online content. Firms are increasingly blocking AI crawlers using various methods, from including them in robots.txt files to implementing server-side anti-bot protections.
Read more about AI blockade: websites are putting up fences to protect their content
Jaguar Land Rover cyberattack claimed by Salesforce, M&S hacking gangs
The hacking group said to be behind the devastating rash of Salesforce supply chain attacks is claiming responsibility for this week's cyberattack on luxury automaker Jaguar Land Rover.
Read more about Jaguar Land Rover cyberattack claimed by Salesforce, M&S hacking gangs
Cybercrime revolutionized with an AI “brain” that unleashes automated cyberattack mayhem
Instead of hacking themselves, attackers are increasingly deploying a free AI weapon that hacks for them. Twelve autonomous AI agents juggle 150 highly specialized security tools, from reconnaissance to zero-day exploitation, and it seems to be working.
Read more about Cybercrime revolutionized with an AI “brain” that unleashes automated cyberattack mayhem
PayPal users targeted by stealthy phishing scam
A polished and sophisticated scam is targeting PayPal users. Like most scams, it has telltale signs of deception, which can be easily spotted if you look hard enough.
Read more about PayPal users targeted by stealthy phishing scam
Hackers exploiting popular TP-Link WiFi device, WhatsApp also affected
The US Cybersecurity and Infrastructure Security Agency (CISA) has warned that hackers are actively exploiting two vulnerabilities: one affects very popular TP-Link WiFI extenders, and another is a recent WhatsApp flaw exploited by highly sophisticated attackers.
Read more about Hackers exploiting popular TP-Link WiFi device, WhatsApp also affected
252M identities dumped online in massive leak affecting 7 countries
Over 250 million identity records have been exposed across seven countries in a massive data leak.
Read more about 252M identities dumped online in massive leak affecting 7 countries
Popular marketing chatbot abused by hackers to breach Google, Cloudflare taken offline
Amid a wave of significant data breach disclosures from some of the world’s largest firms, Salesloft has announced that it’s pulling its Drift AI chatbot service offline. Hackers abused compromised Drift access tokens to infiltrate Salesforce instances.
Read more about Popular marketing chatbot abused by hackers to breach Google, Cloudflare taken offline
Production process of Jaguar Land Rover disrupted by cyberattack
A cyberattack has “severely disrupted” Jaguar Land Rover’s production activities. The good news is that there’s no evidence that customer data has been stolen.
Read more about Production process of Jaguar Land Rover disrupted by cyberattack
Google accused of “partisan” spam filters in Gmail
Federal Trade Commission (FTC) Chairman Andrew Ferguson has sent a letter to Sundar Pichai, CEO of Google’s parent company Alphabet, warning the company of potential FTC Act violations related to Gmail’s alleged “partisan” spam filters.
Read more about Google accused of “partisan” spam filters in Gmail
Zscaler discloses data breach after cyberattack on third party
The data of an unknown number of customers at Zscaler has been leaked due to a cyberattack on Salesforce. The American cloud security company is now warning affected customers of phishing attacks and social engineering attempts.
Read more about Zscaler discloses data breach after cyberattack on third party
Cloudflare joins list of Salesforce attack victims, provides detailed timeline
Cloudflare announces it has officially joined the list of hundreds of companies impacted by a continuing rash of third-party attacks on its Salesforce instance, following in the footsteps of Palo Alto Networks, which also made a similar admission on Tuesday.
Read more about Cloudflare joins list of Salesforce attack victims, provides detailed timeline