Final call: TechCrunch Disrupt 2025 ticket savings end tonight

TechCrunch Disrupt 2025 marks 20 years of shaping the startup world — and tonight’s your last chance to save up to $675 on your ticket. From October 27–29, Disrupt returns to Moscone West in San Francisco. Join 10,000+ tech innovators, founders, VCs, and ecosystem builders for three days of high-impact programming, networking, and startup energy. […]

Continue ReadingFinal call: TechCrunch Disrupt 2025 ticket savings end tonight

Google says hackers stole its customers’ data by breaching its Salesforce database

Google confirmed that one of its cloud-stored Salesforce databases was breached, exposing its customer data. Google attributed the breach to a hacking group, ShinyHunters, known for breaking into Salesforce databases.

Continue ReadingGoogle says hackers stole its customers’ data by breaching its Salesforce database

Hacker used a voice phishing attack to steal Cisco customers’ personal information

Cisco disclosed a data breach including customer names, organization names, addresses, email addresses, and phone numbers of Cisco.com users.

Continue ReadingHacker used a voice phishing attack to steal Cisco customers’ personal information

SonicWall urges customers to disable SSLVPN amid reports of ransomware attacks

Security researchers say they have evidence that ransomware gangs are hacking into large companies that rely on fully-patched SonicWall firewalls. The researchers say it's likely the flaw is a "zero-day" bug currently unknown to SonicWall.

Continue ReadingSonicWall urges customers to disable SSLVPN amid reports of ransomware attacks

Perplexity accused of scraping websites that explicitly blocked AI scraping

Internet giant Cloudflare says it detected Perplexity crawling and scraping websites, even after customers had added technical blocks telling Perplexity not to scrape their pages.

Continue ReadingPerplexity accused of scraping websites that explicitly blocked AI scraping

North Korean spies posing as remote workers have infiltrated hundreds of companies, says CrowdStrike

North Korean IT workers are increasingly using generative AI to draft resumes and "deepfake" their appearances to make money for North Korea's sanctioned nuclear weapons program.

Continue ReadingNorth Korean spies posing as remote workers have infiltrated hundreds of companies, says CrowdStrike

A backlog at the Commerce Department is reportedly stalling Nvidia’s H20 chip licenses

News of a backlog at the U.S. federal department comes less than a week after national security experts urged the Trump administration to reverse its decision that allows Nvidia to export H20 chips to China.

Continue ReadingA backlog at the Commerce Department is reportedly stalling Nvidia’s H20 chip licenses

Sex toy maker Lovense threatens legal action after fixing security flaws that exposed users’ data

The internet-connected sex toy maker said it fixed the vulnerabilities that exposed users' private email addresses and accounts to takeovers, but said it was also planning to take legal action following the disclosure.

Continue ReadingSex toy maker Lovense threatens legal action after fixing security flaws that exposed users’ data

Minnesota activates National Guard as cyberattack on Saint Paul disrupts public services

Gov. Tim Walz activated the state military's cyber forces to help ensure public services continue to run as the city of Saint Paul battles an ongoing cyberattack.

Continue ReadingMinnesota activates National Guard as cyberattack on Saint Paul disrupts public services

Google won’t say if UK secretly demanded a backdoor for user data

Google said it has "never built a backdoor" for its services, but refused to rule out that it had received a secret U.K. surveillance order demanding access to encrypted data.

Continue ReadingGoogle won’t say if UK secretly demanded a backdoor for user data

Sex toy maker Lovense caught leaking users’ email addresses and exposing accounts to takeovers

A security researcher went public after the sex toy maker asked for more than a year to fix the vulnerabilities, which leak users' private email addresses and allow for accounts to be hijacked.

Continue ReadingSex toy maker Lovense caught leaking users’ email addresses and exposing accounts to takeovers

New York state cyber chief calls out Trump for cybersecurity cuts

The top cybersecurity official in New York told TechCrunch in an interview that Trump's budget cuts are going to put the government at risk from cyberattacks, and will put more pressure on states to secure themselves.

Continue ReadingNew York state cyber chief calls out Trump for cybersecurity cuts

Allianz Life says ‘majority’ of customers’ personal data stolen in cyberattack

Exclusive: Allianz Life said the "majority" of its customers and employees had data stolen in the July cyberattack. The company said it has notified the FBI.

Continue ReadingAllianz Life says ‘majority’ of customers’ personal data stolen in cyberattack

Google took a month to shut down Catwatchful, a phone spyware operation hosted on its servers

Google has suspended the Firebase account of Catwatchful following a TechCrunch investigation. The spyware operation was caught using Google's own servers to host and run its surveillance app, which was stealthily monitoring thousands of people's phones.

Continue ReadingGoogle took a month to shut down Catwatchful, a phone spyware operation hosted on its servers

A Premium Luggage Service’s Web Bugs Exposed the Travel Plans of Every User—Including Diplomats

Security flaws in Airportr, a door-to-door luggage checking service used by 10 airlines, let hackers access user data and even gain privileges that would have let them redirect or steal luggage.

Continue ReadingA Premium Luggage Service’s Web Bugs Exposed the Travel Plans of Every User—Including Diplomats

AI slop and fake reports are exhausting some security bug bounties

"We're getting a lot of stuff that looks like gold, but it's actually just crap,” said the founder of one security testing firm. AI-generated security vulnerability reports are already having an effect on bug hunting, for better and worse.

Continue ReadingAI slop and fake reports are exhausting some security bug bounties

European authorities arrest alleged admin of notorious Russian crime forum XSS

French authorities say they wiretapped a server used by the administrator to access their private messages, which revealed activities relating to cybercrime and ransomware attacks.

Continue ReadingEuropean authorities arrest alleged admin of notorious Russian crime forum XSS

Hundreds of organizations breached by SharePoint mass-hacks

One of the hacked organizations reportedly includes the U.S. agency responsible for maintaining the country's stockpile of nuclear weapons. China-backed hackers have been observed carrying out the hacks targeting SharePoint servers.

Continue ReadingHundreds of organizations breached by SharePoint mass-hacks

Apple alerted Iranians to iPhone spyware attacks, say researchers

Researchers say Apple sent out threat notifications to several Iranians in recent months, saying their iPhones had been hacked. Iran is likely behind the attacks.

Continue ReadingApple alerted Iranians to iPhone spyware attacks, say researchers

UK government wants ransomware victims to report cyberattacks so it can disrupt the hackers

Experts applauded the proposed change, which would require ransomware victims to notify authorities when paying a hacker's ransom, arguing that this information can help catch cybercriminals and stop their activities.

Continue ReadingUK government wants ransomware victims to report cyberattacks so it can disrupt the hackers

National security meets next-gen tech at TechCrunch Disrupt 2025’s AI Defense panel

TechCrunch Disrupt 2025 is where breakthrough ideas meet the real-world challenges that define the future — and with over 10,000 startup and VC leaders converging, there’s no better place to have the hard conversations. One of the most urgent? How artificial intelligence is reshaping national defense, security, and critical infrastructure in real time. Enter AI […]

Continue ReadingNational security meets next-gen tech at TechCrunch Disrupt 2025’s AI Defense panel

Google, Microsoft say Chinese hackers are exploiting SharePoint zero-day

The tech giants have evidence that Chinese hackers are exploiting the new bug, but warned "multiple actors" are also hacking into affected SharePoint systems.

Continue ReadingGoogle, Microsoft say Chinese hackers are exploiting SharePoint zero-day

Serial spyware founder Scott Zuckerman wants the FTC to unban him from the surveillance industry

The spyware maker was banned from the surveillance industry in 2021, but was caught flouting the ban less than a year later. Now the founder wants the ban lifted altogether.

Continue ReadingSerial spyware founder Scott Zuckerman wants the FTC to unban him from the surveillance industry

Don’t miss your chance to exhibit at TechCrunch Disrupt 2025

TechCrunch Disrupt 2025 is just around the corner, and with more than 10,000 startup and VC leaders heading to Moscone West in San Francisco this October 27 to 29, the Expo Hall is where connections get made and business gets done. If you’ve been thinking about showcasing your company, consider this your nudge — exhibitor […]

Continue ReadingDon’t miss your chance to exhibit at TechCrunch Disrupt 2025

A surveillance vendor was caught exploiting a new SS7 attack to track people’s phone locations

The new SS7 bypass-attack tricks phone operators into disclosing a cell subscriber's location, in some cases down to a few hundred meters.

Continue ReadingA surveillance vendor was caught exploiting a new SS7 attack to track people’s phone locations

Can an ‘ethical’ spyware maker justify providing its tech to ICE?

Analysis: In calling itself an ethical spyware vendor, Paragon has opened itself up to scrutiny of its government customers.

Continue ReadingCan an ‘ethical’ spyware maker justify providing its tech to ICE?

CISA warns hackers are actively exploiting critical ‘Citrix Bleed 2’ security flaw

The U.S. cybersecurity agency gave federal agencies just one day to patch a security bug in Citrix Netscaler, which can be exploited to break into corporate and government networks.

Continue ReadingCISA warns hackers are actively exploiting critical ‘Citrix Bleed 2’ security flaw

AI chatbot’s simple ‘123456’ password risked exposing personal data of millions of McDonald’s job applicants

Security researchers found two flaws in an AI-powered chatbot used by McDonald’s to interact with job applicants.

Continue ReadingAI chatbot’s simple ‘123456’ password risked exposing personal data of millions of McDonald’s job applicants

Knox lands $6.5M to compete with Palantir in the federal compliance market

While highly sought after, federal software contracts frequently come with a hidden cost: Achieving government SaaS security compliance, known as FedRAMP, can take years and require substantial resources. Achieving this certification typically takes up to three years and costs more than $3 million, covering everything from security operations engineer salaries to security audits, according to […]

Continue ReadingKnox lands $6.5M to compete with Palantir in the federal compliance market

Get your exhibit table at TechCrunch Disrupt 2025

Time is running out to secure your exhibit table at TechCrunch Disrupt 2025, October 27-29, at Moscone West in San Francisco. This is your chance to get your startup in front of 10,000+ startup pioneers, VC leaders, and tech enthusiasts. Learn more and grab your table here before your competitor does. Maximum exposure for your […]

Continue ReadingGet your exhibit table at TechCrunch Disrupt 2025

US government confirms arrest of Chinese national accused of stealing COVID research and mass-hacking email servers

Accused hacker and Chinese national Xu Zewei was arrested in Italy at the request of U.S. prosecutors.

Continue ReadingUS government confirms arrest of Chinese national accused of stealing COVID research and mass-hacking email servers

US government takes down major North Korean ‘remote IT workers’ operation 

US prosecutors indicated a total of 13 people involved in the fraudulent scheme to steal and launder money for North Korea’s nuclear weapons program.

Continue ReadingUS government takes down major North Korean ‘remote IT workers’ operationÂ