Security

International cyber coalition releases advisory on Chinese APT threats, Salt Typhoon tops list

A new joint cybersecurity advisory released on Wednesday by over a dozen international law enforcement organizations exposes the inner workings of Beijing-backed threat groups, with Salt Typhoon topping the list.
Read more about International cyber coalition releases advisory on Chinese APT threats, Salt Typhoon tops list

PR behemoth Singer Associates claimed by ransomware gang

A ransomware cartel has claimed the renowned crisis communications firm Singer Associates. The group shared snippets of data supposedly taken from the company.
Read more about PR behemoth Singer Associates claimed by ransomware gang

Critical security flaw in Chrome discovered by Google's own AI

Google has released an urgent Chrome update for all major platforms, fixing a critical security vulnerability.
Read more about Critical security flaw in Chrome discovered by Google's own AI

Massive attack hits Salesforce users: hackers exfiltrating data with stolen third-party app credentials

Hackers raided numerous corporate Salesforce instances by abusing compromised access tokens from Salesloft Drift integrations, a premium AI-powered conversational marketing platform. Cyber pros warn that OAuth tokens are becoming one of the biggest risks: unlike user sessions, they don’t expire.
Read more about Massive attack hits Salesforce users: hackers exfiltrating data with stolen third-party app credentials

Tencent sites leak sensitive credentials, expose backend to hackers

Cybernews researchers have discovered severe misconfigurations affecting two Tencent sites, exposing sensitive credentials and internal source code. The critical flaws could potentially grant full access to internal services and backend infrastructure within Tencent Cloud. Tencent explained after the publication that no data was exposed and that the findings relate to a honeypot deployed as a security test.
Read more about Tencent sites leak sensitive credentials, expose backend to hackers

Chinese apps are the most “data-hungry” out there, study finds

A study by Incogni, a company that offers information removal services from data brokers, shows that six out of the ten most popular apps in the United States are owned by Chinese tech companies. These apps aggressively collect Americans’ personal data to offer personalized ads and create user profiles, and often share it with other companies.
Read more about Chinese apps are the most “data-hungry” out there, study finds

DOGE whistleblower: entire Social Security database uploaded to open cloud, security experts speak out

A DOGE whistleblower reveals that staffers at the Trump-created agency uploaded an entire Social Security database to an insecure cloud server – compromising the records of hundreds of millions of Americans.
Read more about DOGE whistleblower: entire Social Security database uploaded to open cloud, security experts speak out

FCC cracks down on robocalls: 1,200 voice service providers axed

The Federal Communications Commission (FCC) has axed 1,200 voice service providers from the US phone network for failing to meet the rules protecting users from malicious and illegal calls, known as robocalls.
Read more about FCC cracks down on robocalls: 1,200 voice service providers axed

Fallout from MATLAB maker data breach: 10K+ users exposed

A ransomware attack on the Massachusetts-based mathematical software maker MathWorks exposed the personal details of thousands of users.
Read more about Fallout from MATLAB maker data breach: 10K+ users exposed

Massive Docker Desktop flaw grants hackers full Windows control

Docker Desktop contains a critical flaw that allows hackers to take over control of Windows computers running the software using just a few HTML requests.
Read more about Massive Docker Desktop flaw grants hackers full Windows control

New type of attack tricks AI summaries into pushing malware onto victims

Threat actors have found a new way to deliver ransomware by hiding malicious instructions in AI-generated content summaries. The target then executes a self-sabotaging command and is infected.
Read more about New type of attack tricks AI summaries into pushing malware onto victims

Discord message-scraping service claims access to 1.8 billion messages

Discord-focused online tool makers claim they have access to billions of user messages and a trove of voice sessions, files, and user profiles.
Read more about Discord message-scraping service claims access to 1.8 billion messages

Google ends anonymous sideloading on Android: developers will have to register

Google is closing the door on unrestricted sideloading on Android. Starting September 2026, only apps from verified developers will be allowed on Google-certified Android devices.
Read more about Google ends anonymous sideloading on Android: developers will have to register

FTC warns US tech companies: “Be aware of weakening data security by foreign powers”

The Federal Trade Commission (FTC) has reminded American tech companies of their obligations to protect the privacy of American consumers despite pressure from foreign governments to weaken security safeguards.
Read more about FTC warns US tech companies: “Be aware of weakening data security by foreign powers”

Hack of Michigan health system exposes patients’ lab results

Cybercriminals penetrated Aspire Rural Health Systems’ network and infected it for months. The exposed patient details range from payment card details to medical records, with over 100,000 individuals impacted.
Read more about Hack of Michigan health system exposes patients’ lab results

Why Palantir's success story is also a warning about government surveillance

Palantir Technologies is having a moment. Its stock has surged over 2,500% since early 2021. It recently posted its first $1 billion quarter. It's being talked about in the same breath as Nvidia and Microsoft.
Read more about Why Palantir's success story is also a warning about government surveillance

Phishing is out of control: Microsoft recommends disabling Run dialog box and PowerShell

Microsoft is urging system admins to disable the Run dialog box and restrict command-line tools in response to waves of ClickFix phishing attacks. The technique relies on users copy pasting malware themselves as part of fake CATCHA checks or other social engineering.
Read more about Phishing is out of control: Microsoft recommends disabling Run dialog box and PowerShell

Coinbase CEO reveals how firm sniffs out North Korean “IT workers”

By now, it’s no secret that North Korean hackers pretending to be IT workers run rampant in the crypto world. Brian Armstrong, CEO of cryptocurrency exchange Coinbase, says the firm has been finding ways to deal with the issue effectively.
Read more about Coinbase CEO reveals how firm sniffs out North Korean “IT workers”

FTC warns big tech: don’t cave to EU and UK pressure on encryption and privacy

The Federal Trade Commission (FTC) has warned big tech companies to resist pressure “to censor and weaken data security protections for Americans” from foreign laws such as the EU’s Digital Services Act and the UK’s Online Safety Act.
Read more about FTC warns big tech: don’t cave to EU and UK pressure on encryption and privacy

Mexico City is in the race to become the most surveilled city in the Americas

Mexico City is about to launch the "Eyes That Look After You" plan – a government’s attempt to decrease crime rates by expanding the city's surveillance camera network.
Read more about Mexico City is in the race to become the most surveilled city in the Americas