Security

Mexico City is in the race to become the most surveilled city in the Americas

Mexico City is about to launch the "Eyes That Look After You" plan – a government’s attempt to decrease crime rates by expanding the city's surveillance camera network.
Read more about Mexico City is in the race to become the most surveilled city in the Americas

Windows lets anyone on your WiFi hijack your connection with IPv6

A dormant IPv6 feature is a backdoor for Windows attackers, security researchers warn. Enabled by default, if unused and left unchecked, it can lead to a complete domain compromise.
Read more about Windows lets anyone on your WiFi hijack your connection with IPv6

Major flaw affecting password managers: they autofill credentials for attackers

A major flaw is affecting major password managers – attackers can steal credit card details and credentials from tens of millions of users with just “a single click anywhere.” 1Password, Bitwarden, Dashlane, Enpass, iCloud Passwords, Keeper, LastPass, LogMeOnce, NordPass, ProtonPass, and RoboForm – all failed, and many remain vulnerable.
Read more about Major flaw affecting password managers: they autofill credentials for attackers

Russian state hackers using unsecured Cisco devices for cyber espionage

Static Tundra, a Russian state-sponsored cyber espionage gang, has been actively exploiting a seven-year-old security flaw in Cisco software. Both the company and the FBI have now disclosed details of malicious activity.
Read more about Russian state hackers using unsecured Cisco devices for cyber espionage

Google updates terms for Play Store following EU pressure

Good news for app developers: Google will make it easier to direct users outside of its Android ecosystem to make purchases and transactions.
Read more about Google updates terms for Play Store following EU pressure

FBI, Cisco warn Russia’s FSB hackers exploited old software flaw

Hackers associated with some of Russia’s most prolific cyber espionage units have over the last year been leveraging a vulnerability in older Cisco software to target thousands of networking devices associated with critical infrastructure IT systems, the FBI and Cisco said on Wednesday.
Read more about FBI, Cisco warn Russia’s FSB hackers exploited old software flaw

Microsoft restricts Chinese firms’ access after SharePoint hacks

Microsoft said on Wednesday it has scaled back some Chinese companies' access to its early warning system for cybersecurity vulnerabilities following speculation that Beijing was involved in a hacking campaign against the company's widely used SharePoint servers.
Read more about Microsoft restricts Chinese firms’ access after SharePoint hacks

Quantum insiders warn PQC changeover could take 12 years: "This is not Y2K all over again"

Warning: the upcoming post-quantum encryption (PQC) changeover (to prevent a dreaded Q-Day apocalypse) could take as long as twelve years, say those who witnessed Y2K from the IT trenches. Should we be frightened? Probably, quantum insiders tell Cybernews.
Read more about Quantum insiders warn PQC changeover could take 12 years: "This is not Y2K all over again"

Cybersecurity training doesn’t work: time wasted with no impact, study finds

One employee out of 19,500 fell for a simulated phishing email every time during an eight-month research period, despite all the cybersecurity training efforts.
Read more about Cybersecurity training doesn’t work: time wasted with no impact, study finds

Millions at risk after Turkey’s top finance apps spill sensitive data

Millions of Turks using popular finance apps may have had their private data leaked.
Read more about Millions at risk after Turkey’s top finance apps spill sensitive data

Free Chrome VPN extension capturing screenshots of all 100K users

FreeVPN.One, a featured Chrome extension with a verified badge and over 100,000 installs, which was previously considered “safe,” is secretly spying on its users by grabbing their screens and sending data to a remote server, security researchers warn.
Read more about Free Chrome VPN extension capturing screenshots of all 100K users

Court rules that “Pay or Okay” model by Austrian newspaper violates GDPR

The Austrian Federal Administrative Court (BVwG) has ruled that the “Pay or Okay” model that was implemented by Austrian newspaper Der Standard violates the GDPR, confirming an earlier decision by the Austrian data protection authority, the DSB.
Read more about Court rules that “Pay or Okay” model by Austrian newspaper violates GDPR

Attackers use GenAI to create even harder-to-detect phishing threats

The GenAI web is evolving, and so are the cybercriminals who are using it to create more realistic and harder-to-detect phishing attacks, new research by Palo Alto's Unit 42 shows.
Read more about Attackers use GenAI to create even harder-to-detect phishing threats

How old HDDs end up on e-shops: counterfeit hard drive workshop busted in Malaysia

Malaysian authorities have raided a workshop converting used hard drives into counterfeit new ones, which are later resold on major marketplaces.
Read more about How old HDDs end up on e-shops: counterfeit hard drive workshop busted in Malaysia

Massive Intel data exposure: hacker harvests 270K employee data, gets a “thanks” for disclosure

A whitehat hacker broke into four of Intel’s internal systems and discovered that the sensitive data of 270K Intel employees’ was exposed. Then, he spent months helping the company plug the leaks, only to receive one automated thank-you note.
Read more about Massive Intel data exposure: hacker harvests 270K employee data, gets a “thanks” for disclosure

Shadow library Anna’s Archive reappears online despite attacks on its “mission”

After a period of disruption, the shadow library Anna’s Archive has resurfaced online. Its operators say they’re hardening their security and urge supporters to “keep fighting” to preserve humanity’s legacy.
Read more about Shadow library Anna’s Archive reappears online despite attacks on its “mission”

UK withdraws Apple backdoor order after US opposition

Director of National Intelligence Tulsi Gabbard said on Monday the UK had agreed to drop its mandate for iPhone maker Apple to provide a "backdoor" that would have enabled access to the protected encrypted data of American citizens.
Read more about UK withdraws Apple backdoor order after US opposition

Workday CRM platform hit by hackers, suspected link to Salesforce attackers

HR solutions company Workday reveals unknown threat actors have successfully breached its third-party CRM platform using advanced social engineering tactics, echoing a recent wave of Salesforce-related attacks.
Read more about Workday CRM platform hit by hackers, suspected link to Salesforce attackers

Jane Smorodnikova, Welltory: “health data should empower every person, not just the experts”

For years, health data has remained fragmented and hard to interpret, often leaving everyday people feeling lost in numbers and...
Read more about Jane Smorodnikova, Welltory: “health data should empower every person, not just the experts”

Alex Capecelatro, Josh.ai: “AI should make the smart home seamless, secure, and truly personal”

For many homeowners, smart home technology has long promised convenience, security, and comfort – but also brought complexity and concerns...
Read more about Alex Capecelatro, Josh.ai: “AI should make the smart home seamless, secure, and truly personal”