Latest Tweets

Latest Ransomware and Zero Day

The Big Feed

  • ⚡ TL;DR | Go Straight to the Google Chrome 124 Vulnerability Audit Report

  • Epic glow-up: Cyberpunk 2077, the open-world action RPG that launched to a storm of negativity back in 2020, has incredibly turned things around and is now basking in “Overwhelmingly Positive” reviews on Steam. This redemption story is nothing short of remarkable in the gaming world.

  • Europol is investigating a cybercriminal’s claims that they stole confidential data from a number of the agency’s sources.

  • Londoners were met with a rather unusual sight this week as part of a thought-provoking marketing campaign by virtual private network (VPN) provider Surfshark. A truck carrying a fully functional, transparent toilet roamed the streets, sparking conversations about online privacy and the data we share.

  • Palo Alto Networks and Accenture announced an expansion of their long-standing strategic alliance. New offerings will combine Precision AI technology from Palo Alto Networks and Accenture’s secure generative AI services to help organizations embrace the potential of AI with unparalleled cybersecurity.

  • Black Basta, one of the most prolific ransomware-as-a-service operators, is trying out a combination of email DDoS and vishing to get employees to download remote access tools.

  • The incoming phone call flashes on a victim’s phone. It may only last a few seconds, but can end with the victim handing over codes that give cybercriminals the ability to hijack their online accounts or drain their crypto and digital wallets.

  • Booking.com has been designated a gatekeeper under the bloc’s Digital Markets Act (DMA), meaning the online travel agency will face regulation under the bloc’s market fairness and contestability framework — with the risk of major fines (of up to 10% or even 20%) for non-compliance.

  • May 13, 2024The Hacker NewsBrowser Security / Data Protection

  • Listen to the article 11 min This audio is auto-generated. Please let us know if you have feedback. The first quarter of 2024 was dominated by two events for health insurers: turbulence in Medicare Advantage and the cyberattack on claims clearinghouse giant Change Healthcare. Both created significant uncertainty coming into the quarter, with investors braced for…

  • The breach has brought back into focus an earlier Europol security incident reported in March which involved the disappearance of physical personal records belonging to Catherine De Bolle, Europol’s executive director, and other senior officials before September 2023.

  • FIDO2 is a modern authentication group term for passwordless authentication. The Fast Identity Online (FIDO) Alliance developed it to replace the use of legacy known passwords and provide a secure method to authenticate using a physical or embedded key.  

  • As the Central Board of Secondary Education (CBSE) in India released the CBSE results 2024 for its class 10th and 12th examinations, a significant cybersecurity flaw was discovered on the official website. This vulnerability, identified by The Cyber Express, could potentially allow unauthorized individuals to view and alter students’ examination results.

  • A threatening scenario has been in the making in the region: Iran’s calculated expansion into Latin America. Experts have warned about Tehran’s efforts to establish a foothold in the Western Hemisphere, cozying up to like-minded regimes with the objective of threatening democracy and stability. The region is starting to take note.

  • tuuid Collects anonymous data related to the user’s visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded. tuuid_last_update Collects anonymous data related to the user’s visits to the website, such as the number of visits, average time spent on the website and…

  • LLMs’ Data-Control Path Insecurity Back in the 1960s, if you played a 2,600Hz tone into an AT&T pay phone, you could make calls without paying. A phone hacker named John Draper noticed that the plastic whistle that came free in a box of Captain Crunch cereal worked to make the right sound. That became his…

  • In this first-ever in-person recording of Shared Security, Tom and Kevin, along with special guest Matt Johansen from Reddit, discuss their experience at the RSA conference in San Francisco, including their walk-through of ‘enhanced security’ and the humorous misunderstanding that ensued. The conversation moves to the ubiquity of AI and machine learning buzzwords at the…

  • When a company intends to acquire another organization through a merger or purchase, it is important to know what security risks could accompany the acquisition. Without this, organizations could open themselves to significant financial and legal challenges. 

  • Recently, HPE Aruba Networking, formerly known as Aruba Networks, has encountered significant security challenges. Vulnerabilities in their ArubaOS, the proprietary network operating system, have been identified, posing serious risks, including remote code execution (RCE). In this article, we delve into the details of these HPE Aruba vulnerabilities, their implications, and the recommended actions to mitigate…

  • In August of last year, I examined several CPU bugs that posed serious security threats. The mitigations for these vulnerabilities generally involved either incorporating additional instructions or opting for alternative CPU instructions – strategies that lead to diminished system performance overall. My argument was that such vulnerabilities effectively revert your infrastructure to the technological level…