Security

Talentsconnect data leak: 5M+ job listings, including Fortune 500 companies, exposed

The exposed data includes references to Siemens, Deutsche Bank, Vodafone, BASF, and EY.
Read more about Talentsconnect data leak: 5M+ job listings, including Fortune 500 companies, exposed

Microsoft Patch Tuesday curse: vengeful researcher drops Defender exploit granting SYSTEM privileges

Hundreds of bug fixes in Microsoft’s latest Patch Tuesday were undermined hours later by a new Windows Defender exploit.
Read more about Microsoft Patch Tuesday curse: vengeful researcher drops Defender exploit granting SYSTEM privileges

OpenAI's new cyber AI finds hundreds of bugs before launch


North Korean IT worker spent months at US federal agency

Has a North Korean IT worker managed to fool the FBI?
Read more about North Korean IT worker spent months at US federal agency

Simian data breach exposes customer data and credit card details

Attackers got hold of personal data and credit card information.
Read more about Simian data breach exposes customer data and credit card details

ShinyHunters claims Metabase breach days after zero-day exposes 100K+ organizations

One successful exploit could open the door to credentials and databases across thousands of connected organizations.
Read more about ShinyHunters claims Metabase breach days after zero-day exposes 100K+ organizations

Dozens of new botnets are rising from the ashes of Kimwolf and Aisuru

Your old router might have already changed several operators.
Read more about Dozens of new botnets are rising from the ashes of Kimwolf and Aisuru

UK Ministry of Defence found Chinese tech in Naval sea drones


This open-source VPN manager is secretly owned by an attacker, researchers warn


Security hole in HP thin client disk encryption: key available with a single script

Tricking a TPM into handing over its sealed disk encryption key is alarmingly easy on HP thin client devices.
Read more about Security hole in HP thin client disk encryption: key available with a single script

Hackers hit Levi Strauss in cyberattack, corporate data stolen

The attackers used social engineering techniques on 3 employees to breach Levi Strauss.
Read more about Hackers hit Levi Strauss in cyberattack, corporate data stolen

Steam hardware purchasers in Europe exposed: data breach hits Valve’s logistics partner

Scammers are expected to use leaked details in attempts to extort money through fraudulent requests for delivery or customs fees.
Read more about Steam hardware purchasers in Europe exposed: data breach hits Valve’s logistics partner

Romance scams get a new twist: fake girls invading DMs to promote OnlyFans accounts

Phishers are finding OnlyFans subscription upsells profitable enough to fuel massive bot campaigns.
Read more about Romance scams get a new twist: fake girls invading DMs to promote OnlyFans accounts

Hackers phish their way into US defense manufacturer’s Microsoft 365 account

Exposed details may include highly sensitive export-controlled technical info.
Read more about Hackers phish their way into US defense manufacturer’s Microsoft 365 account

ING and Ace & Tate report security incident at logistics partner

De Bijenkorf, bol, and Ajax have fallen victim to a breach at a logistics partner. ING and Ace & Tate now join the list of victims.
Read more about ING and Ace & Tate report security incident at logistics partner

Ajax caught in CEVA hack fallout, fans left waiting

Ajax is the latest victim of the data breach at CEVA Logistics.
Read more about Ajax caught in CEVA hack fallout, fans left waiting

Out of control? Meta says its AI model hacked another organization

Could Meta just be trying to at least look like it’s keeping up with rival labs?
Read more about Out of control? Meta says its AI model hacked another organization

Logistics partner hack disrupts Dutch retailer’s business operations, customer information possibly exposed


Germany calls on administrators to implement security.txt on their websites

Security.txt would boost responsible vulnerability disclosure and improve Germany’s cyber resilience.
Read more about Germany calls on administrators to implement security.txt on their websites

Token theft now is an industry: platforms reselling access to LLM using stolen API keys

AI token chop shops pool stolen accounts, resell cut-rate access to Claude, GPT, and Gemini, and covertly harvest every prompt for more sensitive details.
Read more about Token theft now is an industry: platforms reselling access to LLM using stolen API keys