Menu

Link

Uber’s ex-CSO avoids prison after data breach cover up
WordPress plugin vulnerability puts two million websites at risk
PSA. Don’t share your password in your app’s release notes
Patch now! The Mirai IoT botnet is exploiting TP-Link routers
Apple and Google join forces to combat AirTag stalking
Smashing Security podcast #320: City Jerks, AI animals, and is the BBC hacking again?
Fortify your Mac with Intego – the award-winning Mac antivirus
Medusa ransomware gang leaks students’ psychological reports and abuse allegations
Minecraft clones stealthily load ads on millions of Android devices
“Ashamed” LockBit ransomware gang apologises to hacked school, offers free decryption tool
Israel’s Prime Minister has his Facebook account hijacked, website knocked offline
Charming Kitten targets critical infrastructure in US and elsewhere with BellaCiao malware
Smashing Security podcast #319: The CEO who also ran IT, Strava strife, and TikTok tall tales
Pro-Russia hackers attack European air traffic control website, but don’t panic! Flights continue as normal
US Facebook users can now claim their share of $725 million Cambridge Analytica settlement
MacStealer – newly-discovered malware steals passwords and exfiltrates data from infected Macs
US charges three men with six million dollar business email compromise plot
LockBit ransomware for Mac – coming soon?
Ex-CEO of hacked therapy clinic sentenced for failing to protect patients’ session notes
FTC accuses payments firm of knowingly assisting tech support scammers
Smashing Security podcast #318: Tesla workers spy on drivers, and Operation Fox Hunt scams
Army helicopter crash blamed on skipped software patch
As Tax Day approaches, Microsoft warns accounting firms of targeted attacks
Pentagon leak suspect Jack Teixeira arrested at gunpoint
Smashing Security podcast #317: Another Uber SNAFU, an AI chatbot quiz, and is juice-jacking genuine?
Plenty of juice-jacking scare stories, but precious little juice-jacking
Ukrainian hackers spend $25,000 of pro-Russian blogger’s money on sex toys
A fireside chat with four CISOs about how they secure their cybersecurity firms from attack
Own a Nexx “smart” alarm or garage door opener? Get rid of it, or regret it
Smashing Security podcast #316: Of Musk and Afroman
Hack the Pentagon website promotes the benefits of bug bounties to US Military
Clipboard-injecting malware disguises itself as Tor browser, steals cryptocurrency
US sends million-dollar scammer to prison for four years
Smashing Security podcast #315: Crypto hacker hijinks, government spyware, and Utah social media shocker
UK police reveal they are running fake DDoS-for-hire sites to collect details on cybercriminals
Can zero trust be saved?
Danger USB! Journalists sent exploding flash drives
Europe’s transport sector terrorised by ransomware, data theft, and denial-of-service attacks
Fake GPT Chrome extension steals Facebook session cookies, breaks into accounts
Smashing Security podcast #314: Photo cropping bombshell, TikTok debates, and real estate scams
The hidden danger to zero trust: Excessive cloud permissions
aCropalypse now! Cropped and redacted images suffer privacy fail on Google Pixel smartphones
Free decryptor released for Conti-based ransomware following data leak
Android phones can be hacked just by someone knowing your phone number
Smashing Security podcast #313: Tesla twins and deepfake dramas
Microsoft has another go at closing security hole exploited by Magniber ransomware
Software supply chain attacks are on the rise — are you at risk?
STALKER 2 hacker demands Ukrainian game developer reinstates Russian language support, or else…
FBI reveals that more money is lost to investment fraud than ransomware and business email compromise combined
WhatsApp and UK government on collision course, as app vows not to remove end-to-end encryption
Pirated copies of Final Cut Pro infect Macs with cryptojacking malware
TSA tells US aviation industry to boost its cybersecurity
Smashing Security podcast #312: Rule 34, Twitter scams, and Facebook fails
Study reveals companies are wasting millions on unused Kubernetes resources
Vice Society publishes data stolen during Vesuvius ransomware attack
Trezor crypto wallets under attack in SMS phishing campaign
WH Smith investigates hacking attack after employee data stolen
Indigo Books & Music refuses to pay ransom after hackers stole employee information
Smashing Security podcast #311: TikTok, wiretapping, and your deepfake voice is your password
“Ethical hacker” amongst those arrested in Dutch ransomware investigation
The cloud’s worst kept secret? Vulnerabilities
That ticking noise is your end users’ laptops
Fake ChatGPT apps spread Windows and Android malware
Food giant Dole hit by ransomware, halts North American production temporarily
Smashing Security podcast #310: Verified blue ticks and horny AI chatbots
Hackers blamed after Russian radio stations play warnings of missile strikes and air raids
HardBit ransomware tells corporate victims to share their cyber insurance details
As Twitter forces users to remove text message 2FA, it’s in danger of decreasing security
Smashing Security podcast #309: Synthetic voices, ChatGPT reflections, and social skirmishes
Gulp! Pepsi hack sees personal information stolen by data-stealing malware
Ransomware attackers steal over 3 million patients’ medical records
Dallas Central Appraisal District paid $170,000 to ransomware attackers
Hard drugs actively sold on Twitter in plain sight. Twitter says it doesn’t breach its safety policies
Bungling Optus scammer was no criminal mastermind
Smashing Security podcast #308: Jail after VPN fail, criminal messaging apps, and wolf-crying watches
How to remove yourself from the internet and from people search sites
Ex-Ubiquiti worker pleads guilty to data theft, extortion, and smear plot
Hackers hit Vesuvius, UK engineering company shuts down affected systems
Romance fraud losses rose 91% during the pandemic, claims UK’s TSB bank
Smashing Security podcast #307: ChatGPT and the Minister for Foreign Affairs
Take a tour of the Edgescan Cybersecurity Platform
Planet Ice hacked! 240,000 skating fans’ details stolen
Latvia says Russian hackers tried to phish its Ministry of Defence
If a locked filing cabinet is stolen along with its key, can you still say it’s locked? GoTo thinks you can
Hackers steal 10 million customer details from JD Sports
Hive ransomware leak site and decryption keys seized in police sting
ShinyHunters suspect extradited to United States from Morocco, could face 116 years in jail if convicted
Smashing Security podcast #306: No Fly lists, cell phones, and the end of ransomware riches?
After data breach put their lives at risk, US releases 3000 immigrants seeking asylum
FanDuel gamblers warned of phishing threat after data breach at Mailchimp
Kolide – Endpoint security for people, not paper clips
Ransomware attack hit KFC and Pizza Hut stores in the UK
T-Mobile has been hacked… again. 37 million customers’ data stolen
LockBit ransomware – what you need to know
Mailchimp slips up again, suffers security breach after falling on social engineering banana skin
Bitzlato cryptocurrency exchange shut down by authorities, accused of cybercriminal links
Smashing Security podcast #305: Norton unlocked, and police leaks
Does your MFA solution secure access to your on-premise apps as well as those in the cloud?
Ugh! Norton LifeLock password manager accounts accessed by hackers
Hackers disrupt 24 Hours of Le Mans Virtual esports event