Menu

Gallery

Chromium’s WebRTC zero-day fix arrives in Microsoft Edge
S3 Ep90: Chrome 0-day again, True Cybercrime, and a 2FA bypass [Podcast + Transcript]
IT reseller giant SHI International knocked offline by cyberattack
Tech world may face huge fines if it doesn’t scrub CSAM from encrypted chats
FBI and MI5 bosses: China cheats and steals at massive scale
SANS Institute spells out security in multiple languages
Here today, gone to Maui: That’s your data captured by North Korean ransomware
Hive ransomware gang rapidly evolves with complex encryption, Rust code
OpenSSL fixes two “one-liner” crypto bugs – what you need to know
Being hit with a cyber-attack is bad. Not having a recovery plan is worse
Typo-squatting NPM software supply chain attack uncovered
Marriott Hotels admits to third data breach in 4 years
Multi-cloud doesn’t have to mean multi problems for data protection
Near-undetectable malware linked to Russia’s Cozy Bear
AstraLocker ransomware reportedly closes doors to pursue cryptojacking
Actual quantum computers don’t exist yet. The cryptography to defeat them may already be here
Pentagon: We’ll pay you if you can find a way to hack us
Calls for bans on Chinese CCTV makers Hikvision, Dahua expand
Google patches “in-the-wild” Chrome zero-day – update now!
How to spot your biggest security threat? Just look out for the humans
Germany unveils plan to tackle cyberattacks on satellites
Alibaba’s finance arm open sources its privacy software and a ‘Secure Processing Unit’
Dutch University retrieves Bitcoin ransomware payment and makes a profit
Billion-record stolen Chinese database for sale on breach forum
Google updates Chrome to squash actively exploited WebRTC Zero Day
Canadian cybercriminal pleads guilty to “NetWalker” attacks in US
Identity, trust, and their role in modern applications
British Army Twitter and YouTube feeds hijacked by crypto-promos
What to do about inherent security flaws in critical infrastructure?
Google location tracking to forget you were ever at that medical clinic
Cyberattack shuts down unemployment, labor websites across the US
Facebook 2FA phish arrives just 28 minutes after scam domain created
Crypto sleuths pin $100 million Harmony theft on Lazarus Group
“Missing Cryptoqueen” hits the FBI’s Ten Most Wanted list
Microsoft gives its partners power to change AD privileges on customer systems – without permission
OpenSea phishing threat after rogue insider leaks customer email addresses
Jenkins warns of security holes in these 25 plugins
California state’s gun control websites expose personal data
Google battles bots, puts Workspace admins on alert
S3 Ep89: Sextortion, blockchain blunder, and an OpenSSL bugfix [Podcast + Transcript]
Israel plans ‘Cyber-Dome’ to defeat digital attacks from Iran and others
Start using Modern Auth now for Exchange Online
Sysdig Secure update adds ability to stop container attacks at runtime
‘Prolific’ NetWalker extortionist pleads guilty to ransomware charges
Firefox 102 fixes address bar spoofing security hole (and helps with Follina!)
Microsoft postpones shift to New Commerce Experience subscriptions
FBI warning: Crooks are using deepfake videos in interviews for remote gigs
Trio accused of selling $88m of pirated Avaya licenses
Walmart accused of turning blind eye to transfer fraud totaling millions of dollars
Customized malware coded to target OT systems
AMD targeted by RansomHouse, cybercrims claim to have ‘450Gb’ in stolen data
Have you modelled the attack paths into your organization? Because an attacker already has
Cloud security risks remain very human
Tencent admits to poisoned QR code attack on QQ chat platform
Carnival Cruises torpedoed by US states, agrees to pay $6m after wave of cyberattacks
India extends deadline for compliance with infosec logging rules by 90 days
OpenSSL 3.0.5 awaits release to fix potential worse-than-Heartbleed flaw
LGBTQ+ folks warned of dating app extortion scams
Harmony blockchain loses nearly $100M due to hacked private keys
FTC warns of LGBTQ+ extortion scams – be aware before you share!
Contractor loses entire Japanese city’s personal data in USB fail
7 devops practices to improve application performance
Security survives the budget axe
Beijing probes security at academic journal database
Singapore promises ‘brutal and unrelentingly hard’ action on dodgy crypto players
We’re now truly in the era of ransomware as pure extortion without the encryption
More than $100m in cryptocurrency stolen from blockchain biz
OpenSSL issues a bugfix for the previous bugfix
Google: How we tackled this iPhone, Android spyware
Beijing-backed attackers use ransomware as a decoy while they conduct espionage
NSO claims ‘more than 5’ EU states use Pegasus spyware
$6b mega contract electronics vendor Sanmina jumps into zero trust
S3 Ep88: Phone scammers, hacking bust, and data breach fines [Podcast + Transcript]
Halfords suffers a puncture in the customer details department
Don’t ditch PowerShell to improve security, say infosec agencies from UK, US, and NZ
Europol arrests nine suspected of stealing ‘several million’ euros via phishing
Mega’s unbreakable encryption proves to be anything but
Cisco warns of security holes in its security appliances
Israeli air raid sirens triggered in possible cyberattack
DARPA study challenges assumptions about distributed ledger (and Bitcoin) security
Yodel becomes the latest victim of a cyber ‘incident’
Okta says Lapsus$ incident was actually a brilliant zero trust demonstration
Info on 1.5m people stolen from US bank in cyberattack
Don’t react, prevent
Capital One identity theft hacker finally gets convicted
1Password’s Insights tool to help admins monitor users’ security practices
A great day for non-robots: iOS 16 will bypass CAPTCHAs
Legacy systems are the new attack vectors for hackers
How refactoring code in Safari’s WebKit resurrected ‘zombie’ security bug
CISA and friends raise alarm on critical flaws in industrial equipment, infrastructure
Voicemail phishing emails steal Microsoft credentials
Interpol busts 2000 suspects in phone scamming takedown
Capital One: Convicted techie got in via ‘misconfigured’ AWS buckets
There are 24.6 billion sets of credentials up for sale on the dark web
Are you ready to automate continuous deployment in CI/CD?
You don’t need another hero…you need an automated incident response process
Indian government issues confidential infosec guidance to staff – who leak it
DeadBolt ransomware takes another shot at QNAP storage
Inverse Finance stung for $1.2 million via flash loan attack
US senators seek ban on sale of health location data