Menu

Link

Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
LastPass hackers steal source code, no evidence of users’ passwords compromised
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Hackers demand $10 million from Paris hospital after ransomware attack
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
Mac users urged to update Zoom, after security patch released for previously-flawed security patch
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
APT Lazarus Targets Engineers with macOS Malware
U.K. Water Supplier Hit with Clop Ransomware Attack
Xiaomi Phone Bug Allowed Payment Forgery
Black Hat and DEF CON Roundup
Feds: Zeppelin Ransomware Resurfaces with New Compromise, Encryption Tactics
Facebook’s In-app Browser on iOS Tracks ‘Anything You Do on Any Website’
Ransomware attack blamed for closure of all 7-Eleven stores in Denmark
Chinese criminals scam kids desperate to play games for more than three hours a week
Starlink Successfully Hacked Using $25 Modchip
New Hacker Forum Takes Pro-Ukraine Stance
Years after claiming DogWalk wasn’t a vulnerability, Microsoft confirms flaw is being exploited and issues patch
Cisco Confirms Network Breach Via Hacked Employee Google Account
Podcast: Inside the Hackers’ Toolkit
Microsoft Patches ‘Dogwalk’ Zero-Day and 17 Critical Flaws
Virtual Currency Platform ‘Tornado Cash’ Accused of Aiding APTs
Phishers Swim Around 2FA in Coinbase Account Heists
Open Redirect Flaw Snags Amex, Snapchat User Data
Kaspersky blames “misconfiguration” after customers receive “dear and lovely” email
Smashing Security podcast #286: Hackers doxxed, Pornhub probs, and Co-op security measures
VMWare Urges Users to Patch Critical Authentication Bypass Bug
Universities Put Email Users at Cyber Risk
Imran Khan’s Instagram account hacked to promote phoney Elon Musk $100 million crypto giveaway
Securing Your Move to the Hybrid Cloud
Malicious Npm Packages Tapped Again to Target Discord Users
Romance scammers jailed after tricking Irish OAP out of €250k
Threat Actors Pivot Around Microsoft’s Macro-Blocking in Office
$10 million reward offered for information on North Korean hackers
Smashing Security podcast #285: Uber’s hidden hack, tips for travel, and AI accent fixes
Uber’s former head of security faces fraud charges after allegedly covering up data breach
Messaging Apps Tapped as Platform for Cybercriminal Activity
Novel Malware Hijacks Facebook Business Accounts
Testing times for AV-Test as Twitter account hijacked by NFT spammers
Phishing Attacks Skyrocket with Microsoft and Facebook as Most Abused Brands
IoT Botnets Fuels DDoS Attacks – Are You Prepared?
Why Physical Security Maintenance Should Never Be an Afterthought
Hackers for Hire: Adversaries Employ ‘Cyber Mercenaries’
Smashing Security podcast #284: The Most Wanted Missing CryptoQueen
More malware-infested apps, downloaded millions of times, found in the Google Play store
Clunk flush! Bexplus cryptocurrency exchange closes suddenly, giving its users only 24 hours to withdraw funds
Conti’s Reign of Chaos: Costa Rica in the Crosshairs
Magecart Serves Up Card Skimmers on Restaurant-Ordering Systems
Authentication Risks Discovered in Okta Platform
FBI Warns Fake Crypto Apps are Bilking Investors of Millions
Who on earth would be trying to promote EC-Council University via comment spam on my website?
Hacker hijacks NFT artist DeeKay’s Twitter account, steals $150,000 worth of NFTs from fans
Google Boots Multiple Malware-laced Android Apps from Marketplace
CISA Urges Patch of Exploited Windows 11 Bug by Aug. 2
Emerging H0lyGh0st Ransomware Tied to North Korea
Smashing Security podcast #283: Disney’s social dumpster fire, Anom phones, and TikTok tragedies
Windows 8.1 displays full-screen warning as it nears its last day of support
Journalists Emerge as Favored Attack Target for APTs
10,000 organisations targeted by phishing attack that bypasses multi-factor authentication
Large-Scale Phishing Campaign Bypasses MFA
How War Impacts Cyber Insurance
‘Callback’ Phishing Campaign Impersonates Security Firms
Rethinking Vulnerability Management in a Heightened Threat Landscape
Popular NFT Marketplace Phished for $540M
Disneyland social media accounts hacked, offensive messages posted
Microsoft rolls back plan to block macros by default
Sneaky Orbit Malware Backdoors Linux Devices
U.S. Healthcare Orgs Targeted with Maui Ransomware
Lockdown Mode: Apple to protect users from targeted spyware attacks
Hack Allows Drone Takeover Via ‘ExpressLRS’ Protocol
Smashing Security podcast #282: Raising money through ransomware, China’s mega-leak, and hackers for hire
Comprehensive risk-based API protection with AppTrana
Human Error Blamed for Leak of 1 Billion Records of Chinese Citizens
Latest Cyberattack Against Iran Part of Ongoing Campaign
Google Patches Actively Exploited Chrome Bug
Official British Army Twitter and YouTube accounts hijacked by NFT scammers
FTC warns LGBTQ+ community of extortion scams targeting them on dating apps
AMD held to ransom by gang that claims 450GB of data has been stolen
ZuoRAT Can Take Over Widely Used SOHO Routers
Black Basta ransomware – what you need to know
A Guide to Surviving a Ransomware Attack
Leaky Access Tokens Exposed Amazon Photos of Users
Patchable and Preventable Security Issues Lead Causes of Q1 Attacks
Carnival Cruises bruised by $6.25 million fine after series of cyberattacks
Top Six Security Bad Habits, and How to Break Them
Mitel VoIP Bug Exploited in Ransomware Attacks
‘Killnet’ Adversary Pummels Lithuania with DDoS Attacks Over Blockade
Log4Shell Vulnerability Targeted in VMware Servers to Exfiltrate Data
Drunk worker loses USB stick containing details of every resident of his city
Google Warns Spyware Being Deployed Against Android, iOS Users
Amazon thinks it’s really cool that Alexa can mimic your dead grandma’s voice
NHS warns of scam COVID-19 text messages
Smashing Security podcast #280: Hot tub hijinx, and a sentient AI
Fancy Bear Uses Nuke Threat Lure to Exploit 1-Click Bug
Gamification of Ethical Hacking and Hacking Esports
Discovery of 56 OT Device Flaws Blamed on Lackluster Security Culture