Menu

Latest articles

Believing they would be paid a fortune for having sex with women, hundreds of Indian men scammed out of cash
Security firm Mandiant says it didn’t have 2FA enabled on its hacked Twitter account
Twitter says it’s not its fault the SEC’s account got hacked
Smashing Security podcast #354: Chuck Norris and the fake CEO, artificial KYC, and an Airbnb scam
Fidelity National now says 1.3M customers had data stolen by cyber-crooks
Uncle Sam tells hospitals: Meet security standards or no federal dollars for you
Be honest. Would you pay off a ransomware crew?
US Navy sailor swaps sea for cell after accepting bribes from Chinese snoops
Cybercrooks play dress-up as ‘helpful’ researchers in latest ransomware ruse
Love is in the AI: Finding love online takes on a whole new meaning

Is AI companionship the future of not-so-human connection – and even the cure for loneliness?

SEC’s Twitter account hacked to say Bitcoin ETFs approved. Politicians and lawyers demand investigation into security breach
ShinyHunters chief phisherman gets 3 years, must cough up $5M
Jeffrey Epstein email scams rear their ugly head
New year, new updates for security holes in Windows, Adobe, Android and more
SEC Twitter hijacked to push fake news of hotly anticipated Bitcoin ETF approval
And that’s a wrap for Babuk Tortilla ransomware as free decryptor released
Midwives clinic takes nine months to deliver news of data breach
Sexual assault in the metaverse investigated by British police
Apache OFBiz zero-day pummeled by exploit attempts after disclosure
Hackers hijack Beirut airport departure and arrival boards
Stuxnet: The malware that cost a billion dollars to develop?
British Library: Finances remain healthy as ransomware recovery continues
Facebook, Instagram now mine web links you visit to fuel targeted ads
Cybersecurity trends and challenges to watch out for in 2024 – Week in security with Tony Anscombe

What are some of the key cybersecurity trends that people and organizations should have on their radars this year?

Ransomware payment ban: Wrong idea at the wrong time
After injecting cancer hospital with ransomware, crims threaten to swat patients

https://security-tracker.debian.org/tracker/DSA-5597-1

https://security-tracker.debian.org/tracker/DSA-5596-1

Lost and found: How to locate your missing devices and more

Losing your keys, your wallet – or anything else, really – can be a pain, but there is a wide world of trackers that can help you locate your missing things – with awesome accuracy

BreachForums boss busted for bond blunders – including using a VPN
Sandworm’s Kyivstar attack should serve as a reminder of the Kremlin crew’s ‘global reach’
X-ploited: Mandiant restores hijacked Twitter account after attempted crypto heist
Infosec experts divided over 23andMe’s ‘victim-blaming’ stance on data breach
Cryptocurrency wallet CEO loses $125,000 in wallet-draining scam
Infostealer malware, weak password leaves Orange Spain RIPE for plucking
As lawmakers mull outlawing poor security, what can they really do to tackle online gangs?
Three Chinese balloons float near Taiwanese airbase
Microsoft kills off Windows app installation from the web, again

https://security-tracker.debian.org/tracker/DSA-5595-1

Freight giant Estes refuses to deliver ransom, says personal data opened and stolen

https://security-tracker.debian.org/tracker/DSA-5594-1

Atos confirms talks with Airbus over cybersecurity wing sale
Copy that? Xerox confirms ‘security incident’ at subsidiary
Courts service “PWNED” in Australia, as hackers steal sensitive recordings of hearings
Formal ban on ransomware payments? Asking orgs nicely to not cough up ain’t working
Google password resets not enough to stop these info-stealing malware strains
Court hearings become ransomware concern after justice system breach
4 key devsecops skills for the generative AI era

https://security-tracker.debian.org/tracker/DSA-5593-1

https://security-tracker.debian.org/tracker/DSA-5592-1

CEO arranged his own cybersecurity, with predictable results

https://security-tracker.debian.org/tracker/DSA-5589-1

A tale of 2 casino ransomware attacks: One paid out, one did not
Kaspersky reveals previously unknown hardware ‘feature’ used in iPhone attacks

https://security-tracker.debian.org/tracker/DSA-5591-1

https://security-tracker.debian.org/tracker/DSA-5590-1

How software engineering will evolve in 2024
You should be worried about cloud squatting

https://security-tracker.debian.org/tracker/DSA-5588-1

Key findings from ESET Threat Report H2 2023 – Week in security with Tony Anscombe

How cybercriminals take advantage of the popularity of ChatGPT and other tools of its ilk to direct people to sketchy sites, plus other interesting findings from ESET’s latest Threat Report

Iranian cyberspies target US defense orgs with a brand new backdoor

https://security-tracker.debian.org/tracker/DSA-5587-1

https://security-tracker.debian.org/tracker/DSA-5585-1

https://security-tracker.debian.org/tracker/DSA-5584-1

https://security-tracker.debian.org/tracker/DSA-5583-1

https://security-tracker.debian.org/tracker/DSA-5582-1

Safeguard the joy: 10 tips for securing your shiny new device

Unwrapping a new gadget this holiday season will put a big smile on your face but things may quickly turn sour if the device and data on it aren’t secured properly

Cyber sleuths reveal how they infiltrate the biggest ransomware gangs

https://security-tracker.debian.org/tracker/DSA-5586-1

Lapsus$ teen sentenced to indefinite detention in hospital after Nvidia, GTA cyberattacks

https://security-tracker.debian.org/tracker/DSA-5581-1

Four in five Apache Struts 2 downloads are for versions featuring critical flaw
Mozilla decides Trusted Types is a worthy security feature
Data loss prevention isn’t rocket science, but NASA hasn’t made it work in Microsoft 365
Smashing Security podcast #353: Phone hacking, Piers Morgan, and Carole’s Christmas cockup
Something nasty injected login-stealing JavaScript into 50K online banking sessions
Cybercrooks book a stay in hotel email inboxes to trick staff into spilling credentials
ALPHV/BlackCat ransomware operation disrupted, but criminals threaten more attacks
Manchester’s finest drowning in paperwork as Freedom of Information requests pile up
SSH shaken, not stirred by Terrapin vulnerability
Philippines, South Korea, Interpol cuff 3,500 suspected cyber scammers, seize $300M
Millions of Xfinity customers’ info, hashed passwords feared stolen in cyberattack

https://security-tracker.debian.org/tracker/DSA-5580-1

Before you go away for Xmas: You’ve patched that critical Perforce Server hole, right?
AlphV/BlackCat hits back as Feds offer decryptor to ransomware victims
Sharing stories on the CyberTuesday podcast
Qakbot’s backbot: FBI-led takedown keeps crims at bay for just 3 months
Hacktivists boast: We shut down Iran’s gas pumps today
Mr Cooper cyberattack laid bare: 14.7M people’s info stolen, costs hit $25M

https://security-tracker.debian.org/tracker/DSA-5579-1

Cyber-crooks slip into Vans, trample over operations
National Grid latest UK org to zap Chinese kit from critical infrastructure
3 ways to reduce stress on the DevSecOps team
MongoDB warns breach of internal systems exposed customer contact info
Pro-China campaign targeted YouTube with AI avatars
New iOS feature to thwart eavesdropping – Week in security with Tony Anscombe

Your iPhone has just received a new feature called iMessage Contact Key Verification that is designed to help protect your messages from prying eyes

https://security-tracker.debian.org/tracker/DSA-5576-2

https://security-tracker.debian.org/tracker/DSA-5578-1

Hundreds of thousands of dollars in crypto stolen after Ledger code poisoned
Kraft Heinz suggests we simmer down about Snatch ransomware attack claims