Security

This is what you should include in your password to make it uncrackable

Think your password is safe because it’s eight characters long and mixes in a number or two? According to new analysis from Specops, nearly 99% of breached passwords are so weak they could be cracked in minutes.
Read more about This is what you should include in your password to make it uncrackable

Marks & Spencer hackers hit US retailer Belk

Belk, the popular US department store chain, has allegedly been targeted by the DragonForce hacker group. This is the same group that struck UK retailer Marks & Spencer with a cyberattack, costing the company hundreds of millions of dollars.
Read more about Marks & Spencer hackers hit US retailer Belk

Serious Google Gemini flaw: it obeys hidden prompts in malicious emails

If hackers hide malicious commands in an email, Google Gemini for Workspace will “faithfully obey” them when interacting with the content. Researchers tricked Gemini into alerting users about account compromise and directing them to call scammers.
Read more about Serious Google Gemini flaw: it obeys hidden prompts in malicious emails

UnitedHealth subsidiary Episource hit with data breach, millions affected

Over five million patients were affected after a massive data breach at Episource that exposed sensitive medical and personal information.
Read more about UnitedHealth subsidiary Episource hit with data breach, millions affected

S&P 500’s AI adoption may invite data breaches, new research shows

Researchers have identified hundreds of potential issues ranging from insecure AI output to critical infrastructure attack vectors across sectors such as infrastructure, finance, and healthcare.
Read more about S&P 500’s AI adoption may invite data breaches, new research shows

Shopify plugin exposes hundreds of websites to attacks

A trusted Shopify plugin designed to enforce privacy compliance ended up quietly exposing hundreds of online stores to serious security threats.
Read more about Shopify plugin exposes hundreds of websites to attacks

Massive investment fraud campaign leverages 17,000 fraudulent news sites

Scam sites are impersonating legitimate news websites, using native languages, major brands, and regional public figures to promote fake investment opportunities.
Read more about Massive investment fraud campaign leverages 17,000 fraudulent news sites

Your eSIM might not be as safe as you think: researchers hack and clone numbers

Researchers have successfully hacked a widely used chip that stores eSIM (embedded SIM) profiles, leaving billions of users vulnerable to SIM cloning, spoofing, spying on them, and related security implications.
Read more about Your eSIM might not be as safe as you think: researchers hack and clone numbers

Saudi industrial services group breached, hackers claim

Rezayat Group, a multibillion-dollar industrial services provider based in Saudi Arabia, has been posted on a dark web leak site. Hackers claim they’ve obtained several gigabytes of data from the company.
Read more about Saudi industrial services group breached, hackers claim

Estimating age with augmented cameras in tobacco shops is a no-go, CNIL says

The use of augmented cameras that can estimate the age of tobacco shop customers to prohibit the sale of cigarettes and other tobacco products to minors is neither necessary nor proportionate and, therefore, not allowed according to data protection and privacy laws.
Read more about Estimating age with augmented cameras in tobacco shops is a no-go, CNIL says

PewDiePie is driving self-hosting craze: how to protect your home server experiments?

Do you have an old laptop without a screen and other missing parts? That’s more than enough for a decent home server. Some folks even use Legos to build theirs. A recent shoutout from PewDiePie sent thousands of beginners diving into self-hosting for the first time. But beware of potential security disasters waiting to happen: don’t expose yourself to bots constantly scanning your IP.
Read more about PewDiePie is driving self-hosting craze: how to protect your home server experiments?

A simple radio hack can emergency stop any train in North America, researchers warn

End-of-train devices, installed on the rear of freight trains in North America to sense and control braking, are outdated and simplistic. Hackers can easily target them with plain text radio signals to send emergency braking commands.
Read more about A simple radio hack can emergency stop any train in North America, researchers warn

Hacker exploits Elmo’s X account, calls President Trump a “child f**ker,” and tells the world to “kill all Jews”

The iconic character from Sesame Street was hacked by an antisemitic attacker who used Elmo’s X account to rant about Jeffrey Epstein files and tell all Jews to die.
Read more about Hacker exploits Elmo’s X account, calls President Trump a “child f**ker,” and tells the world to “kill all Jews”

TikTok under new Irish investigation after admitting EU user data reached China

The Data Protection Commission (DPC) has announced that it will launch a new investigation into TikTok’s transfer of European users’ personal data to servers in China.
Read more about TikTok under new Irish investigation after admitting EU user data reached China

Hackers use GitHub to spread malware disguised as a free VPN

Attackers are weaponizing GitHub to deliver powerful infostealing malware under the guise of a free VPN.
Read more about Hackers use GitHub to spread malware disguised as a free VPN

Tech YouTuber visited by the FBI over KVMs: tiny devices become a security headache

IP-KVM (keyboard, video, and mouse over IP) devices are cheap and abundant, and hackers are finding it easier than ever to gain complete remote control of servers without raising alarms.
Read more about Tech YouTuber visited by the FBI over KVMs: tiny devices become a security headache

Alabama city hack exposed financial data and citizens, hackers claim

The City of Gardendale has appeared on a dark web forum that hackers use to showcase their latest victims. The threat actors claim to have obtained tens of gigabytes of sensitive data.
Read more about Alabama city hack exposed financial data and citizens, hackers claim

Major security flaws found in Adobe PDF reader and ASUS system controller

Your RGB controller and PDF reader almost became cyberattack launchpads, thanks to critical flaws just uncovered.
Read more about Major security flaws found in Adobe PDF reader and ASUS system controller

Hackers hide dangerous trojan in legitimate Mac apps, targeting developers

Hackers are bundling legitimate Mac tools with a ZuRu trojan, poisoning search results to advertise compromised packages and infecting unsuspecting users, SentinelOne warns.
Read more about Hackers hide dangerous trojan in legitimate Mac apps, targeting developers

Security pros run a 36-hour war room to close a critical DeFi backdoor, likely installed by North Korean hackers

Security researchers said they've closed a critical backdoor on "thousands" of smart contracts before a threat actor managed to hit a large target.
Read more about Security pros run a 36-hour war room to close a critical DeFi backdoor, likely installed by North Korean hackers