Menu

Link

Brute-Force Attacks Target Inboxes for Gift Card Data
NFT Collector Tricked into Buying Fake Banksy 
SpyFone & CEO Banned From Stalkerware Biz
Bluetooth Bugs Open Billions of Devices to DoS, Code Execution
Google Play Sign-Ins Allow Covert Location-Tracking
Cisco Patches Critical Authentication Bug With Public Exploit
“Attackers don’t take the weekends off, and neither should your cybersecurity”
7 Ways to Defend Mobile Apps, APIs from Cyberattacks
WhatsApp Photo Filter Bug Allows Sensitive Info to Be Lifted
Digital State IDs Start Rollouts Despite Privacy Concerns
Comcast RF Attack Leveraged Remotes for Surveillance
How a Bumble dating app vulnerability revealed any user’s exact location
Build a culture of security security and productivity in your business with 1Password
Smashing Security podcast #241: Flipping dating apps, and crypto rewards for criminals
Gutenberg Template Library & Redux Framework Bugs Plague WordPress Sites
LockBit Jumps Its Own Countdown, Publishes Bangkok Air Files
BEC Scammers Seek Native English Speakers on Underground
Feds Warn of Ransomware Attacks Ahead of Labor Day
Fortress Home Security Open to Remote Disarmament
Cream Finance DeFi Platform Rooked For $29M
Proxyware Services Open Orgs to Abuse – Report
Ragnarok ransomware gang shuts down, universal decryption key released
WooCommerce Pricing Plugin Allows Malicious Code-Injection
QNAP Is Latest to Get Dinged by OpenSSL Bugs Fallout
Top 3 APIs Vulnerabilities: Why Apps are Owned by Cyberattackers
LockFile Ransomware Uses Never-Before Seen Encryption to Avoid Detection
HPE Warns Sudo Bug Gives Attackers Root Privileges to Aruba Platform
Army Testing Facial Recognition in Child-Care Centers
The Underground Economy: Recon, Weaponization & Delivery for Account Takeovers
Microsoft Exchange ‘ProxyToken’ Bug Allows Email Snooping
LockBit Gang to Publish 103GB of Bangkok Air Customer Data
T-Mobile’s Security Is ‘Awful,’ Says Purported Thief
Parallels Offers ‘Inconvenient’ Fix for High-Severity Bug
Experts: WH Cybersecurity Summit Should Be Followed by Regulation, Enforcement
Winning the Cyber-Defense Race: Understand the Finish Line
FIN8 Targets US Bank With New ‘Sardonic’ Backdoor
Critical Azure Cosmos DB Bug Allows Full Cloud Account Takeover
Ragnarok Ransomware Gang Bites the Dust, Releases Decryptor
Top Strategies That Define the Success of a Modern Vulnerability Management Program
‘Pay Ransom’ Screen? Too Late, Humpty Dumpty – Podcast
Man Sues Parents of Teens Who Hijacked Nearly $1M in Bitcoin
F5 Bug Could Lead to Complete System Takeover
Podcast: Ransomware Up x10: Disrupting Cybercrime Suppy Chains an Opportunity
Microsoft Breaks Silence on Barrage of ProxyShell Attacks
FBI warns of OnePercent ransomware gang – what you need to know
Smashing Security podcast #240: 3D printer hijacks, crypto fails, and a tech billionaire’s revenge
Cisco Issues Critical Fixes for High-End Nexus Gear
Man admits impersonating Apple support staff to steal 620,000 photos from iCloud accounts
Win10 Admin Rights Tossed Off by Yet Another Plug-In
Build and improve your company’s culture of security with 1Password
US Media, Retailers Targeted by New SparklingGoblin APT
California Man Hacked iCloud Accounts to Steal Nude Photos
Poly Network Recoups $610M Stolen from DeFi Platform
Pegasus Spyware Uses iPhone Zero-Click iMessage Zero-Day
Custom WhatsApp Build Delivers Triada Malware
Effective Threat-Hunting Queries in a Redacted World
Microsoft Spills 38 Million Sensitive Data Records Via Careless Power App Configs
ProxyShell Attacks Pummel Unpatched Exchange Servers
Windows 10 Admin Rights Gobbled by Razer Devices
Managing Privileged Access to Secure the Post-COVID Perimeter
Attackers Actively Exploiting Realtek SDK Flaws
T-Mobile confirms fifth data breach in three years
Web Censorship Systems Can Facilitate Massive DDoS Attacks
Nigerian Threat Actors Solicit Employees to Deploy Ransomware for Cut of Profits
What’s Next for T-Mobile and Its Customers? – Podcast
How Ready Are You for a Ransomware Attack?
Critical Cisco Bug in Small Business Routers to Remain Unpatched
InkySquid State Actor Exploiting Known IE Bugs
Windows EoP Bug Detailed by Google Project Zero
COVID-19 Contact-Tracing Data Exposed, Fake Vax Cards Circulate
Postmortem on U.S. Census Hack Exposes Cybersecurity Failures
Want to ban someone from Instagram? That’ll cost you just $60
Smashing Security podcast #239: TikTok vigilantes, sloppy IoT, and Wikipedia woe
Bogus Cryptomining Apps Infest Google Play
T-Mobile: >40 Million Customers’ Data Stolen
Learn how a culture of security can improve security and productivity across your business with 1Password
Memory Bugs in BlackBerry’s QNX Embedded OS Open Devices to Attacks
Kerberos Authentication Spoofing: Don’t Bypass the Spec
Unpatched Fortinet Bug Allows Firewall Takeovers
HolesWarm Malware Exploits Unpatched Windows, Linux Servers   
The Overlooked Security Risks of The Cloud
LockBit 2.0 Ransomware Proliferates Globally
Bug in Millions of Flawed IoT Devices Lets Attackers Eavesdrop
Terrorist Watchlist Exposed Online with Nearly 1.9M Records
Apple: CSAM Image-Detection Backdoor ‘Narrow’ in Scope
How to Reduce Exchange Server Downtime in Case of a Disaster?
Survey finds vast majority of people reusing personal passwords in the workplace, despite security training
Phishing Costs Nearly Quadrupled Over 6 Years
Critical Valve Bug Lets Gamers Add Unlimited Funds to Steam Wallets
XSS Bug in SEOPress WordPress Plugin Allows Site Takeover
100m T-Mobile Customer Records Purportedly Up for Sale
Indra hacking group blamed for attack on Iranian railway system that trolled country’s supreme leader
T-Mobile USA investigates possible breach after hacker offers to sell customer data
Amazon’s Plan to Track Worker Keystrokes: A Sign of Controls to Come?
Cyberattackers Embrace CAPTCHAs to Hide Phishing, Malware
SolarWinds 2.0 Could Ignite Financial Crisis – Podcast
Exchange Servers Under Active Attack via ProxyShell Bugs
WordPress Sites Abused in Aggah Spear-Phishing Campaign
Rogue Marketplace AlphaBay Reboots
Black Hat: Novel DNS Hack Spills Confidential Corp Data