Menu

Link

TikTok Launches Bug Bounty Program Amid Security Snafus
News Wrap: Barnes & Noble Hack, DDoS Extortion Threats and More
Critical Magento Holes Open Online Shops to Code Execution
FIFA 21 Blockbuster Release Gives Fraudsters an Open Field for Theft
Zoom Rolls Out End-to-End Encryption After Setbacks
Broadvoice Leak Exposes 350M Records, Personal Voicemail Transcripts
Barnes & Noble Hack: A Reading List for Phishers and Crooks
Beware COVID-19 charity fraudsters, warns the FBI
Carnival Corp. Ransomware Attack Affects Three Cruise Lines
Barnes & Noble warns customers it has been hacked, customer data may have been accessed
Elite security intelligence for zero cost. Meet the Recorded Future Express browser extension
Smashing Security podcast #200: Two flipping hundred
Hackney Council’s cyber attack update is more interesting for what it doesn’t say than what it does
Travelex, Other Orgs Face DDoS Threats as Extortion Campaign Rages On
BEC Attacks: Nigeria No Longer the Epicenter as Losses Top $26B
Critical SonicWall VPN Portal Bug Allows DoS, Worming RCE
Silent Librarian Goes Back to School with Global Research-Stealing Effort
FIN11 Cybercrime Gang Shifts Tactics to Double-Extortion Ransomware
Intel Adds Memory Encryption, Firmware Security to Ice Lake Chips
Google, Intel Warn on ‘Zero-Click’ Kernel Bug in Linux-Based IoT Devices
Cybercriminals Steal Nearly 1TB of Data from Miami-Based International Tech Firm
October Patch Tuesday: Microsoft Patches Critical, Wormable RCE Bug
Lemon Duck Cryptocurrency-Mining Botnet Activity Spikes
Software AG Data Released After Clop Ransomware Strike – Report
Critical Flash Player Flaw Opens Adobe Users to RCE
Election Systems Under Attack via Microsoft Zerologon Exploits
Authentication Bug Opens Android Smart-TV Box to Data Theft
TrickBot Takedown Disrupts Major Crimeware Apparatus
Hackney hacked. Council hit by “serious cyber attack”, data breached
Office 365: A Favorite for Cyberattack Persistence
Home security cams hacked in Singapore, and stolen footage sold on adult websites
Android ransomware learns new tricks to lock devices
Ransomware Attackers Buy Network Access in Cyberattack Shortcut
Taking a screwdriver to unlock your IoT sex toy is nuts
Fitbit Spyware Steals Personal Data via Watch Face
Sophisticated Android Ransomware Executes with the Home Button
Twitter closing my account for copyright violation? No, it’s a phishing attack
Facebook Debuts Bug-Bounty ‘Loyalty Program’
Amazon Prime Day Spurs Spike in Phishing, Fraud Attacks
MontysThree APT Takes Unusual Aim at Industrial Targets
Feds Sound Alarm Over Emotet Attacks on State, Local Govs
Google Rolls Out Fixes for High-Severity Android System Flaws
BAHAMUT Spies-for-Hire Linked to Extensive Nation-State Activity
Wormable Apple iCloud Bug Allows Automatic Photo Theft
RAINBOWMIX Apps in Google Play Serve Up Millions of Ad Fraud Victims
Cisco Fixes High-Severity Webex, Security Camera Flaws
HEH P2P Botnet Sports Dangerous Wiper Function
Microsoft Azure Flaws Open Admin Servers to Takeover
Hackers disguise malware attack as new details on Donald Trump’s COVID-19 illness
Smashing Security podcast #199: A few tech cock-ups, and one cock lock-up
Recorded Future Express gives you elite security intelligence at zero cost
PoetRAT Resurfaces in Attacks in Azerbaijan Amid Escalating Conflict
IRS COVID-19 Relief Payment Deadlines Anchor Convincing Phish
Comcast TV Remote Hack Opens Homes to Snooping
Grindr’s Bug Bounty Pledge Doesn’t Translate to Security
Male Chastity Device Comes with Massive Security Flaws
Boom! Mobile Customer Data Lost to Fullz House/Magecart Attack
Microsoft Zerologon Flaw Under Attack By Iranian Nation-State Actors
COVID-19 Clinical Trials Slowed After Ransomware Attack
APT Attack Injects Malware into Windows Error Reporting
Unpatched Apple T2 Chip Flaw Plagues Macs
John McAfee arrested on US tax evasion charges
Post Grid WordPress Plugin Flaws Allow Site Takeovers
Black-T Malware Emerges From Cryptojacker Group TeamTNT
Malware Families Turn to Legit Pastebin-Like Service
Rare Bootkit Malware Targets North Korea-Linked Diplomats
Tenda Router Zero-Days Emerge in Spyware Botnet Campaign
See me keynote at the (ISC)² Security Congress in November 2020
Video-Game Piracy Group ‘Team Xecuter’ Leaders in Custody
UK loses 16,000 COVID-19 cases due to Excel spreadsheet snafu
Google warns of security holes in other vendors’ Android phones
Grindr security hole made it easy to hijack accounts
Egregor Ransomware Threatens ‘Mass-Media’ Release of Corporate Data
Voter Registration ‘Error’ Phish Hits During U.S. Election Frenzy
Account Takeover Fraud Losses Total Billions Across Online Retailers
Researchers Mixed on Sanctions for Ransomware Negotiators
LatAm Banking Trojans Collaborate in Never-Before-Seen Effort
Years-Long ‘SilentFade’ Attack Drained Facebook Victims of $4M
305 CVEs and Counting: Bug-Hunting Stories From a Security Engineer
Malware campaign poses as Team Blue Take Action email
Emotet Emails Strike Thousands of DNC Volunteers
QR Codes: A Sneaky Security Threat
Microsoft Office 365 Phishing Attack Uses Multiple CAPTCHAs
NFL, NBA Players Hacked in Would-Be Cyber-Slam-Dunk
Spammers Smuggle LokiBot Via URL Obfuscation Tactic
What to do first when your company suffers a ransomware attack
A complete stranger controlled this woman’s home security system, but they’re not the one she’s angry with
InterPlanetary Storm Botnet Infects 13K Mac, Android Devices
Smashing Security podcast #198: Chucky the coffee maker
OAuth Consent Phishing Ramps Up with Microsoft Office 365 Attacks
Android Spyware Variant Snoops on WhatsApp, Telegram Messages
Facebook Small Business Grants Spark Identity-Theft Scam
Microsoft Exchange Servers Still Open to Actively Exploited Flaw
Why Web Browser Padlocks Shouldn’t Be Trusted
Zerologon Attacks Against Microsoft DCs Snowball in a Week
The Network Perimeter: This Time, It’s Personal
When your every keystroke, mouse click, and website visit is monitored by your boss…
Las Vegas Students’ Personal Data Leaked, Post-Ransomware Attack
Telehealth Poll: How Risky Are Remote Doctor Visits?
Windows 7 ‘Upgrade’ Emails Steal Outlook Credentials