Menu

Gallery

Microsoft sheds some light on Russian email heist – and how to learn from Redmond’s mistakes
Wait, security courses aren’t a requirement to graduate with a computer science degree?
Guess the company: Takes your DNA, blames you when criminals steal it, can’t spot a cyberattack for 5 months
Akira ransomware gang says it stole passport scans from Lush in 110 GB data heist
Trickbot malware scumbag gets five years for infecting hospitals, businesses
EquiLend drags systems offline after admitting attacker broke in
HPE joins the ‘our executive email was hacked by Russia’ club
US judge rejects spyware developer NSO’s attempt to bin Apple’s spyware lawsuit
Mobb unveils vulnerability fixer for GitHub users
Major IT outage at Europe’s largest caravan and RV club makes for not-so-happy campers
Using GoAnywhere MFT for file transfers? Patch now – an exploit’s out for a critical bug
What Microsoft’s latest email breach says about this IT security heavyweight
COVID-19 test lab accused of exposing 1.3 million patient records to open internet
GCHQ’s NCSC warns of ‘realistic possibility’ AI will help state-backed malware evade detection
CISA boss swatted: ‘While my own experience was certainly harrowing, it was unfortunately not unique’
Accused PII seller faces jail for running underground fraud op
UK water giant admits attackers broke into system as gang holds it to ransom
A guide to implementing fine-grained authorization
Australia imposes cyber sanctions on Russian it says ransomwared health insurer
Atlassian Confluence Server RCE attacks underway from 600+ IPs
Slug slimes aerospace biz AerCap with ransomware, brags about 1TB theft
EFF adds Street Surveillance Hub so Americans can check who’s checking on them
Ivanti and Juniper Networks accused of bending the rules with CVE assignments
Subway’s data torpedoed by LockBit, ransomware gang claims
ICO fines spam slinging financial services biz
Safeguarding against the global ransomware threat
BreachForums admin ‘Pompourin’ sentenced to 20 years of supervised release
Russians invade Microsoft exec mail while China jabs at VMware vCenter Server
Five ripped off IT giant with $7M+ in bogus work expenses, prosecutors claim
Thieves steal 35.5M customers’ data from Vans sneakers maker
IT consultant fined for daring to expose shoddy security
US agencies warn made-in-China drones might help Beijing snoop on the world
JPMorgan exec claims bank repels ’45 billion’ cyberattack attempts per day
Future of America’s Cyber Safety Review Board hangs in balance amid calls for rethink
Ransomware attacks hospitalizing security pros, as one admits suicidal feelings
Two more Citrix NetScaler bugs exploited in the wild
Google TAG: Kremlin cyber spies move into malware with a custom backdoor
Vast botnet hijacks smart TVs for prime-time cybercrime
Enter the era of platform-based cloud security
Insurance website’s buggy API leaked Office 365 password and a giant email trove
Apple, AMD, Qualcomm GPU security hole lets miscreants snoop on AI training and chats
What’s worse than paying an extortion bot that auto-pwned your database?
JFrog, AWS team up for machine learning in the cloud
Windows Server 2022 patch is breaking apps for some users
Home improvement marketers dial up trouble from regulator
Combination of cheap .cloud domains and fake Shark Tank news fuel unhealthy wellness scams
Nokia walks the walk about its RAN to play on Uncle Sam’s China fears
FBI: Beware of thieves building Androxgh0st botnets using stolen creds
Double trouble for VMware and Atlassian admins – critical flaws to fix
More than 178,000 SonicWall firewalls are exposed to old denial of service bugs
Ivanti zero-day exploits explode as bevy of attackers get in on the act
China’s gambling crackdown spawned wave of illegal online casinos and crypto-crime in Asia
Thousands of Juniper Networks devices vulnerable to critical RCE bug
Patch time: Critical GitLab vulnerability exposes 2FA-less users to account takeovers
FTC secures first databroker settlement banning sale of sensitive location data
Ransomware protection deconstructed
China loathes AirDrop so much it’s publicized an old flaw in Apple’s P2P protocol
Number of orgs compromised via Ivanti VPN zero-days grows as Mandiant weighs in
Why we update… Data-thief malware exploits SmartScreen on unpatched Windows PCs
Exploit for under-siege SharePoint vuln reportedly in hands of ransomware crew
Secret multimillion-dollar cryptojacker snared by Ukrainian police
Secure network operations for hybrid working
So, are we going to talk about how GitHub is an absolute boon for malware, or nah?
Data regulator fines HelloFresh £140K for sending 80M+ spams
How finops can make the cloud more secure
While we fire the boss, can you lock him out of the network?
Drivers: We’ll take that plain dumb car over a flashy data-spilling internet one, thanks
eBay to cough up $3M after cyber-stalking couple who dared criticize the souk
Mandiant’s brute-forced X account exposes perils of skimping on 2FA
Infoseccers think attackers backed by China are behind Ivanti zero-day exploits
Fidelity National now says 1.3M customers had data stolen by cyber-crooks
Uncle Sam tells hospitals: Meet security standards or no federal dollars for you
Be honest. Would you pay off a ransomware crew?
US Navy sailor swaps sea for cell after accepting bribes from Chinese snoops
Cybercrooks play dress-up as ‘helpful’ researchers in latest ransomware ruse
ShinyHunters chief phisherman gets 3 years, must cough up $5M
New year, new updates for security holes in Windows, Adobe, Android and more
SEC Twitter hijacked to push fake news of hotly anticipated Bitcoin ETF approval
And that’s a wrap for Babuk Tortilla ransomware as free decryptor released
Apache OFBiz zero-day pummeled by exploit attempts after disclosure
British Library: Finances remain healthy as ransomware recovery continues
Facebook, Instagram now mine web links you visit to fuel targeted ads
Ransomware payment ban: Wrong idea at the wrong time
After injecting cancer hospital with ransomware, crims threaten to swat patients
BreachForums boss busted for bond blunders – including using a VPN
Sandworm’s Kyivstar attack should serve as a reminder of the Kremlin crew’s ‘global reach’
X-ploited: Mandiant restores hijacked Twitter account after attempted crypto heist
Infosec experts divided over 23andMe’s ‘victim-blaming’ stance on data breach
Infostealer malware, weak password leaves Orange Spain RIPE for plucking
As lawmakers mull outlawing poor security, what can they really do to tackle online gangs?
Three Chinese balloons float near Taiwanese airbase
Microsoft kills off Windows app installation from the web, again
Freight giant Estes refuses to deliver ransom, says personal data opened and stolen
Atos confirms talks with Airbus over cybersecurity wing sale
Copy that? Xerox confirms ‘security incident’ at subsidiary
Formal ban on ransomware payments? Asking orgs nicely to not cough up ain’t working
Google password resets not enough to stop these info-stealing malware strains
Court hearings become ransomware concern after justice system breach
4 key devsecops skills for the generative AI era
CEO arranged his own cybersecurity, with predictable results