Google says hackers stole its customers’ data by breaching its Salesforce database

Google confirmed that one of its cloud-stored Salesforce databases was breached, exposing its customer data. Google attributed the breach to a hacking group, ShinyHunters, known for breaking into Salesforce databases.

Continue ReadingGoogle says hackers stole its customers’ data by breaching its Salesforce database

Hacker used a voice phishing attack to steal Cisco customers’ personal information

Cisco disclosed a data breach including customer names, organization names, addresses, email addresses, and phone numbers of Cisco.com users.

Continue ReadingHacker used a voice phishing attack to steal Cisco customers’ personal information

SonicWall urges customers to disable SSLVPN amid reports of ransomware attacks

Security researchers say they have evidence that ransomware gangs are hacking into large companies that rely on fully-patched SonicWall firewalls. The researchers say it's likely the flaw is a "zero-day" bug currently unknown to SonicWall.

Continue ReadingSonicWall urges customers to disable SSLVPN amid reports of ransomware attacks

North Korean spies posing as remote workers have infiltrated hundreds of companies, says CrowdStrike

North Korean IT workers are increasingly using generative AI to draft resumes and "deepfake" their appearances to make money for North Korea's sanctioned nuclear weapons program.

Continue ReadingNorth Korean spies posing as remote workers have infiltrated hundreds of companies, says CrowdStrike

Sex toy maker Lovense threatens legal action after fixing security flaws that exposed users’ data

The internet-connected sex toy maker said it fixed the vulnerabilities that exposed users' private email addresses and accounts to takeovers, but said it was also planning to take legal action following the disclosure.

Continue ReadingSex toy maker Lovense threatens legal action after fixing security flaws that exposed users’ data

Minnesota activates National Guard as cyberattack on Saint Paul disrupts public services

Gov. Tim Walz activated the state military's cyber forces to help ensure public services continue to run as the city of Saint Paul battles an ongoing cyberattack.

Continue ReadingMinnesota activates National Guard as cyberattack on Saint Paul disrupts public services

Google won’t say if UK secretly demanded a backdoor for user data

Google said it has "never built a backdoor" for its services, but refused to rule out that it had received a secret U.K. surveillance order demanding access to encrypted data.

Continue ReadingGoogle won’t say if UK secretly demanded a backdoor for user data

Sex toy maker Lovense caught leaking users’ email addresses and exposing accounts to takeovers

A security researcher went public after the sex toy maker asked for more than a year to fix the vulnerabilities, which leak users' private email addresses and allow for accounts to be hijacked.

Continue ReadingSex toy maker Lovense caught leaking users’ email addresses and exposing accounts to takeovers

New York state cyber chief calls out Trump for cybersecurity cuts

The top cybersecurity official in New York told TechCrunch in an interview that Trump's budget cuts are going to put the government at risk from cyberattacks, and will put more pressure on states to secure themselves.

Continue ReadingNew York state cyber chief calls out Trump for cybersecurity cuts

Allianz Life says ‘majority’ of customers’ personal data stolen in cyberattack

Exclusive: Allianz Life said the "majority" of its customers and employees had data stolen in the July cyberattack. The company said it has notified the FBI.

Continue ReadingAllianz Life says ‘majority’ of customers’ personal data stolen in cyberattack

Google took a month to shut down Catwatchful, a phone spyware operation hosted on its servers

Google has suspended the Firebase account of Catwatchful following a TechCrunch investigation. The spyware operation was caught using Google's own servers to host and run its surveillance app, which was stealthily monitoring thousands of people's phones.

Continue ReadingGoogle took a month to shut down Catwatchful, a phone spyware operation hosted on its servers

AI slop and fake reports are exhausting some security bug bounties

"We're getting a lot of stuff that looks like gold, but it's actually just crap,” said the founder of one security testing firm. AI-generated security vulnerability reports are already having an effect on bug hunting, for better and worse.

Continue ReadingAI slop and fake reports are exhausting some security bug bounties

Hundreds of organizations breached by SharePoint mass-hacks

One of the hacked organizations reportedly includes the U.S. agency responsible for maintaining the country's stockpile of nuclear weapons. China-backed hackers have been observed carrying out the hacks targeting SharePoint servers.

Continue ReadingHundreds of organizations breached by SharePoint mass-hacks

Apple alerted Iranians to iPhone spyware attacks, say researchers

Researchers say Apple sent out threat notifications to several Iranians in recent months, saying their iPhones had been hacked. Iran is likely behind the attacks.

Continue ReadingApple alerted Iranians to iPhone spyware attacks, say researchers

UK government wants ransomware victims to report cyberattacks so it can disrupt the hackers

Experts applauded the proposed change, which would require ransomware victims to notify authorities when paying a hacker's ransom, arguing that this information can help catch cybercriminals and stop their activities.

Continue ReadingUK government wants ransomware victims to report cyberattacks so it can disrupt the hackers

Google, Microsoft say Chinese hackers are exploiting SharePoint zero-day

The tech giants have evidence that Chinese hackers are exploiting the new bug, but warned "multiple actors" are also hacking into affected SharePoint systems.

Continue ReadingGoogle, Microsoft say Chinese hackers are exploiting SharePoint zero-day

Serial spyware founder Scott Zuckerman wants the FTC to unban him from the surveillance industry

The spyware maker was banned from the surveillance industry in 2021, but was caught flouting the ban less than a year later. Now the founder wants the ban lifted altogether.

Continue ReadingSerial spyware founder Scott Zuckerman wants the FTC to unban him from the surveillance industry

A surveillance vendor was caught exploiting a new SS7 attack to track people’s phone locations

The new SS7 bypass-attack tricks phone operators into disclosing a cell subscriber's location, in some cases down to a few hundred meters.

Continue ReadingA surveillance vendor was caught exploiting a new SS7 attack to track people’s phone locations

CISA warns hackers are actively exploiting critical ‘Citrix Bleed 2’ security flaw

The U.S. cybersecurity agency gave federal agencies just one day to patch a security bug in Citrix Netscaler, which can be exploited to break into corporate and government networks.

Continue ReadingCISA warns hackers are actively exploiting critical ‘Citrix Bleed 2’ security flaw

AI chatbot’s simple ‘123456’ password risked exposing personal data of millions of McDonald’s job applicants

Security researchers found two flaws in an AI-powered chatbot used by McDonald’s to interact with job applicants.

Continue ReadingAI chatbot’s simple ‘123456’ password risked exposing personal data of millions of McDonald’s job applicants

US government confirms arrest of Chinese national accused of stealing COVID research and mass-hacking email servers

Accused hacker and Chinese national Xu Zewei was arrested in Italy at the request of U.S. prosecutors.

Continue ReadingUS government confirms arrest of Chinese national accused of stealing COVID research and mass-hacking email servers

US government takes down major North Korean ‘remote IT workers’ operation 

US prosecutors indicated a total of 13 people involved in the fraudulent scheme to steal and launder money for North Korea’s nuclear weapons program.

Continue ReadingUS government takes down major North Korean ‘remote IT workers’ operation 

Iran’s government says it shut down internet to protect against cyberattacks

The government cited the recent hacks on Bank Sepah and cryptocurrency exchange Nobite as reasons to shut down internet access to virtually all Iranians.

Continue ReadingIran’s government says it shut down internet to protect against cyberattacks