FreshRSS

🔒
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ ☆ ✇ The Hacker News

Alert: GhostSec and Stormous Launch Joint Ransomware Attacks in Over 15 Countries

By: Newsroom — March 6th 2024 at 07:11
The cybercrime group called GhostSec has been linked to a Golang variant of a ransomware family called GhostLocker. “TheGhostSec and Stormous ransomware groups are jointly conducting double extortion ransomware attacks on various business verticals in multiple countries,” Cisco Talos researcher Chetan Raghuprasad said in a report shared with The Hacker News. “GhostLocker and
☐ ☆ ✇ The Hacker News

New APT Group 'Lotus Bane' Behind Recent Attacks on Vietnam's Financial Entities

By: Newsroom — March 6th 2024 at 07:01
A financial entity in Vietnam was the target of a previously undocumented threat actor called Lotus Bane as part of a cyber attack that was first detected in March 2023. Singapore-headquartered Group-IB described the hacking outfit as an advanced persistent threat group that's believed to have been active since at least 2022. The exact specifics of the infection chain remain unknown
☐ ☆ ✇ The Hacker News

Hackers Exploit ConnectWise ScreenConnect Flaws to Deploy TODDLERSHARK Malware

By: Newsroom — March 5th 2024 at 16:18
North Korean threat actors have exploited the recently disclosed security flaws in ConnectWise ScreenConnect to deploy a new malware called TODDLERSHARK. According to a report shared by Kroll with The Hacker News, TODDLERSHARK overlaps with known Kimsuky malware such as BabyShark and ReconShark. “The threat actor gained access to the victim workstation by exploiting the exposed setup wizard
☐ ☆ ✇ The Hacker News

Critical JetBrains TeamCity On-Premises Flaws Could Lead to Server Takeovers

By: Newsroom — March 5th 2024 at 03:34
A new pair of security vulnerabilities have been disclosed in JetBrains TeamCity On-Premises software that could be exploited by a threat actor to take control of affected systems. The flaws, tracked as CVE-2024-27198 (CVSS score: 9.8) and CVE-2024-27199 (CVSS score: 7.3), have been addressed in version 2023.11.4. They impact all TeamCity On-Premises versions through 2023.11.3. “The
☐ ☆ ✇ WIRED

Hackers Behind the Change Healthcare Ransomware Attack Just Received a $22 Million Payment

By: Andy Greenberg — March 4th 2024 at 17:41
The transaction, visible on Bitcoin's blockchain, suggests the victim of one of the worst ransomware attacks in years may have paid a very large ransom.
☐ ☆ ✇ WIRED

The Privacy Danger Lurking in Push Notifications

By: Andy Greenberg, Andrew Couts, Matt Burgess — March 2nd 2024 at 14:00
Plus: Apple warns about sideloading apps, a court orders NSO group to turn over the code of its Pegasus spyware, and an investigation finds widely available security cams are wildly insecure.
☐ ☆ ✇ WIRED

Here Come the AI Worms

By: Matt Burgess — March 1st 2024 at 09:00
Security researchers created an AI worm in a test environment that can automatically spread between generative AI agents—potentially stealing data and sending spam emails along the way.
☐ ☆ ✇ WIRED

The Mysterious Case of the Missing Trump Trial Ransomware Leak

By: Andy Greenberg — February 29th 2024 at 18:24
The notorious LockBit gang promised a Georgia court leak "that could affect the upcoming US election.” It didn't materialize—but the story may not be over yet.
☐ ☆ ✇ WIRED

Here Are the Google and Microsoft Security Updates You Need Right Now

By: Kate O'Flaherty — February 29th 2024 at 16:30
Plus: Mozilla patches 12 flaws in Firefox, Zoom fixes seven vulnerabilities, and more critical updates from February.
☐ ☆ ✇ WIRED

Change Healthcare Ransomware Attack: BlackCat Hackers Quickly Returned After FBI Bust

By: Andy Greenberg — February 27th 2024 at 22:35
Two months ago, the FBI “disrupted” the BlackCat ransomware group. They're already back—and their latest attack is causing delays at pharmacies across the US.
☐ ☆ ✇ WIRED

How a Right-Wing Controversy Could Sabotage US Election Security

By: Eric Geller — February 26th 2024 at 13:00
Republicans who run elections are split over whether to keep working with the Cybersecurity and Infrastructure Security Agency to fight hackers, online falsehoods, and polling-place threats.
☐ ☆ ✇ WIRED

A Mysterious Leak Exposed Chinese Hacking Secrets

By: Matt Burgess — February 24th 2024 at 14:00
Plus: Scammers try to dupe Apple with 5,000 fake iPhones, Avast gets fined for selling browsing data, and researchers figure out how to clone fingerprints from your phone screen.
☐ ☆ ✇ WIRED

Apple iOS 17.4: iMessage Gets Post-Quantum Encryption in New Update

By: Matt Burgess — February 21st 2024 at 14:00
Useful quantum computers aren’t a reality—yet. But in one of the biggest deployments of post-quantum encryption so far, Apple is bringing the technology to iMessage.
☐ ☆ ✇ WIRED

Anne Neuberger, a Top White House Cyber Official, Sees the 'Promise and Peril' in AI

By: Garrett M. Graff — February 21st 2024 at 12:00
Anne Neuberger, the Biden administration’s deputy national security adviser for cyber, tells WIRED about emerging cybersecurity threats—and what the US plans to do about them.
☐ ☆ ✇ WIRED

How to Not Get Scammed Out of $50,000

By: Andrew Couts — February 17th 2024 at 14:00
Plus: State-backed hackers test out generative AI, the US takes down a major Russian military botnet, and 100 hospitals in Romania go offline amid a major ransomware attack.
☐ ☆ ✇ WIRED

The Hidden Injustice of Cyberattacks

By: Nicole Tisdale — February 12th 2024 at 13:00
Cyberattacks and criminal scams can impact anyone. But communities of color and other marginalized groups are often disproportionately impacted and lack the support to better protect themselves.
☐ ☆ ✇ WIRED

How 3 Million ‘Hacked’ Toothbrushes Became a Cyber Urban Legend

By: Andy Greenberg, Dhruv Mehrotra — February 10th 2024 at 14:00
Plus: China’s Volt Typhoon hackers lurked in US systems for years, the Biden administration’s crackdown on spyware vendors ramps up, and a new pro-Beijing disinformation campaign gets exposed.
☐ ☆ ✇ WIRED

I Stopped Using Passwords. It's Great—and a Total Mess

By: Matt Burgess — February 8th 2024 at 12:00
Passkeys are here to replace passwords. When they work, it’s a seamless vision of the future. But don’t ditch your old logins just yet.
☐ ☆ ✇ WIRED

Ransomware Payments Hit a Record $1.1 Billion in 2023

By: Andy Greenberg — February 7th 2024 at 14:00
After a slowdown in payments to ransomware gangs in 2022, last year saw total ransom payouts jump to their highest level yet, according to a new report from crypto-tracing firm Chainalysis.
☐ ☆ ✇ WIRED

The Mystery of the $400 Million FTX Heist May Have Been Solved

By: Andy Greenberg — February 1st 2024 at 21:48
An indictment against three Americans suggests that at least some of the culprits behind the theft of an FTX crypto fortune may be in custody.
☐ ☆ ✇ WIRED

A Startup Allegedly ‘Hacked the World.’ Then Came the Censorship—and Now the Backlash

By: Andy Greenberg — February 1st 2024 at 17:30
A loose coalition of anti-censorship voices is working to highlight reports of one Indian company’s hacker-for-hire past—and the legal threats aimed at making them disappear.
☐ ☆ ✇ WIRED

Apple and Google Just Patched Their First Zero-Day Flaws of the Year

By: Kate O'Flaherty — January 31st 2024 at 12:00
Plus: Google fixes dozens of Android bugs, Microsoft rolls out nearly 50 patches, Mozilla squashes 15 Firefox flaws, and more.
☐ ☆ ✇ WIRED

Big-Name Targets Push Midnight Blizzard Hacking Spree Back Into the Limelight

By: Lily Hay Newman — January 25th 2024 at 21:30
Newly disclosed breaches of Microsoft and Hewlett-Packard Enterprise highlight the persistent threat posed by Midnight Blizzard, a notorious Russian cyber-espionage group.
☐ ☆ ✇ WIRED

How a Group of Israel-Linked Hackers Has Pushed the Limits of Cyberwar

By: Andy Greenberg — January 25th 2024 at 12:00
From repeatedly crippling thousands of gas stations to setting a steel mill on fire, Predatory Sparrow’s offensive hacking has now targeted Iranians with some of history's most aggressive cyberattacks.
☐ ☆ ✇ WIRED

Notorious Spyware Maker NSO Group Is Quietly Plotting a Comeback

By: Vas Panagiotopoulos — January 24th 2024 at 12:00
NSO Group, creator of the infamous Pegasus spyware, is spending millions on lobbying in Washington while taking advantage of the crisis in Gaza to paint itself as essential for global security.
☐ ☆ ✇ WIRED

US Agencies Urged to Patch Ivanti VPNs That Are Actively Being Hacked

By: Lily Hay Newman — January 20th 2024 at 14:00
Plus: Microsoft says attackers accessed employee emails, Walmart fails to stop gift card fraud, “pig butchering” scams fuel violence in Myanmar, and more.
☐ ☆ ✇ The Hacker News

Experts Warn of macOS Backdoor Hidden in Pirated Versions of Popular Software

By: Newsroom — January 19th 2024 at 12:48
Pirated applications targeting Apple macOS users have been observed containing a backdoor capable of granting attackers remote control to infected machines. "These applications are being hosted on Chinese pirating websites in order to gain victims," Jamf Threat Labs researchers Ferdous Saljooki and Jaron Bradley said. "Once detonated, the malware will download and execute multiple payloads
☐ ☆ ✇ The Hacker News

TensorFlow CI/CD Flaw Exposed Supply Chain to Poisoning Attacks

By: Newsroom — January 18th 2024 at 12:34
Continuous integration and continuous delivery (CI/CD) misconfigurations discovered in the open-source TensorFlow machine learning framework could have been exploited to orchestrate supply chain attacks. The misconfigurations could be abused by an attacker to "conduct a supply chain compromise of TensorFlow releases on GitHub and PyPi by compromising TensorFlow's build agents via
☐ ☆ ✇ The Hacker News

MFA Spamming and Fatigue: When Security Measures Go Wrong

By: The Hacker News — January 18th 2024 at 12:02
In today's digital landscape, traditional password-only authentication systems have proven to be vulnerable to a wide range of cyberattacks. To safeguard critical business resources, organizations are increasingly turning to multi-factor authentication (MFA) as a more robust security measure. MFA requires users to provide multiple authentication factors to verify their identity, providing an
☐ ☆ ✇ WIRED

A Flaw in Millions of Apple, AMD, and Qualcomm GPUs Could Expose AI Data

By: Lily Hay Newman, Matt Burgess — January 16th 2024 at 17:00
Patching every device affected by the LeftoverLocals vulnerability—which includes some iPhones, iPads, and Macs—may prove difficult.
☐ ☆ ✇ WIRED

A Bloody Pig Mask Is Just Part of a Wild New Criminal Charge Against eBay

By: Lily Hay Newman, Matt Burgess — January 13th 2024 at 14:00
Plus: Chinese officials tracked people using AirDrop, Stuxnet mole’s identity revealed, AI chatbot hacking, and more.
☐ ☆ ✇ WIRED

How to Stop Your X Account From Getting Hacked Like the SEC's

By: Lily Hay Newman — January 12th 2024 at 17:30
The US Securities and Exchange Commission and security firm Mandiant both had their X accounts breached, possibly due to changes to X’s two-factor authentication settings. Here’s how to fix yours.
☐ ☆ ✇ WIRED

The SEC’s Official X Account Was ‘Compromised’ and Used to Post Fake Bitcoin News

By: Andrew Couts, Andy Greenberg — January 9th 2024 at 22:05
The US financial regulator says its official @SECGov account was “compromised,” resulting in an “unauthorized” post about the status of Bitcoin ETFs.
☐ ☆ ✇ WIRED

23andMe Blames Users for Recent Data Breach as It's Hit With Dozens of Lawsuits

By: Lily Hay Newman, Andy Greenberg — January 6th 2024 at 14:00
Plus: Russia hacks surveillance cameras as new details emerge of its attack on a Ukrainian telecom, a Google contractor pays for videos of kids to train AI, and more.
☐ ☆ ✇ WIRED

What It’s Like to Use Apple’s Lockdown Mode

By: Lily Hay Newman — January 2nd 2024 at 12:00
If you're at high risk of being targeted by mercenary spyware, or just don't mind losing iOS features for extra security, the company's restricted mode is surprisingly usable.
☐ ☆ ✇ WIRED

Google Fixes Nearly 100 Android Security Issues

By: Kate O'Flaherty — December 31st 2023 at 12:00
Plus: Apple shuts down a Flipper Zero Attack, Microsoft patches more than 30 vulnerabilities, and more critical updates for the last month of 2023.
☐ ☆ ✇ WIRED

The Worst Hacks of 2023

By: Lily Hay Newman — December 29th 2023 at 12:00
It was a year of devastating cyberattacks around the globe, from ransomware attacks on casinos to state-sponsored breaches of critical infrastructure.
☐ ☆ ✇ WIRED

The Most Dangerous People on the Internet in 2023

By: WIRED Staff — December 28th 2023 at 12:00
From Sam Altman and Elon Musk to ransomware gangs and state-backed hackers, these are the individuals and groups that spent this year disrupting the world we know it.
☐ ☆ ✇ The Hacker News

Chinese Hackers Exploited New Zero-Day in Barracuda's ESG Appliances

By: Newsroom — December 27th 2023 at 12:35
Barracuda has revealed that Chinese threat actors exploited a new zero-day in its Email Security Gateway (ESG) appliances to deploy backdoors on a "limited number" of devices. Tracked as CVE-2023-7102, the issue relates to a case of arbitrary code execution that resides within a third-party and open-source library named Spreadsheet::ParseExcel that's used by the Amavis scanner
☐ ☆ ✇ WIRED

Facebook Marketplace Is Being Ruined by Zelle Scammers

By: Amanda Hoover — December 22nd 2023 at 12:00
I tried to sell a futon on Facebook Marketplace and nearly all I got were scammers.
☐ ☆ ✇ WIRED

A Major Ransomware Takedown Suffers a Strange Setback

By: Lily Hay Newman — December 19th 2023 at 19:34
After an 18-month rampage, global law enforcement finally moved against the notorious Alphv/BlackCat ransomware group. Within hours, the operation faced obstacles.
☐ ☆ ✇ The Hacker News

MongoDB Suffers Security Breach, Exposing Customer Data

By: Newsroom — December 17th 2023 at 04:48
MongoDB on Saturday disclosed it's actively investigating a security incident that has led to unauthorized access to "certain" corporate systems, resulting in the exposure of customer account metadata and contact information. The American database software company said it first detected anomalous activity on December 13, 2023, and that it immediately activated its incident response
☐ ☆ ✇ WIRED

Google Just Denied Cops a Key Surveillance Tool

By: Andy Greenberg, Lily Hay Newman — December 16th 2023 at 14:00
Plus: Apple tightens anti-theft protections, Chinese hackers penetrate US critical infrastructure, and the long-running rumor of eavesdropping phones crystallizes into more than an urban legend.
☐ ☆ ✇ WIRED

McDonald’s Ice Cream Machine Hackers Say They Found the ‘Smoking Gun’ That Killed Their Startup

By: Andy Greenberg — December 14th 2023 at 22:59
Kytch, the company that tried to fix McDonald’s broken ice cream machines, has unearthed a 3-year-old email it says proves claims of an alleged plot to undermine their business.
☐ ☆ ✇ WIRED

Microsoft’s Digital Crime Unit Goes Deep on How It Disrupts Cybercrime

By: Lily Hay Newman — December 14th 2023 at 17:22
Ten years in, Microsoft’s DCU has honed its strategy of using both unique legal tactics and the company’s technical reach to disrupt global cybercrime and state-backed actors.
☐ ☆ ✇ WIRED

Hacker Group Linked to Russian Military Claims Credit for Cyberattack on Kyivstar

By: Andy Greenberg — December 13th 2023 at 15:56
A hacker group calling itself Solntsepek—previously linked to Russia’s notorious Sandworm hackers—says it carried out a disruptive breach of Kyivstar, a major Ukrainian mobile and internet provider.
☐ ☆ ✇ The Hacker News

New MrAnon Stealer Malware Targeting German Users via Booking-Themed Scam

By: Newsroom — December 12th 2023 at 09:55
A phishing campaign has been observed delivering an information stealer malware called MrAnon Stealer to unsuspecting victims via seemingly benign booking-themed PDF lures. "This malware is a Python-based information stealer compressed with cx-Freeze to evade detection," Fortinet FortiGuard Labs researcher Cara Lin said. "MrAnon Stealer steals its victims' credentials, system
☐ ☆ ✇ The Hacker News

Researchers Unveil GuLoader Malware's Latest Anti-Analysis Techniques

By: Newsroom — December 9th 2023 at 07:16
Threat hunters have unmasked the latest tricks adopted by a malware strain called GuLoader in an effort to make analysis more challenging. "While GuLoader's core functionality hasn't changed drastically over the past few years, these constant updates in their obfuscation techniques make analyzing GuLoader a time-consuming and resource-intensive process," Elastic Security Labs
☐ ☆ ✇ The Hacker News

Qualcomm Releases Details on Chip Vulnerabilities Exploited in Targeted Attacks

By: Newsroom — December 6th 2023 at 05:23
Chipmaker Qualcomm has released more information about three high-severity security flaws that it said came under "limited, targeted exploitation" back in October 2023. The vulnerabilities are as follows - CVE-2023-33063 (CVSS score: 7.8) - Memory corruption in DSP Services during a remote call from HLOS to DSP. CVE-2023-33106 (CVSS score: 8.4) - Memory corruption in
☐ ☆ ✇ WIRED

The 23andMe Data Breach Keeps Spiraling

By: Lily Hay Newman — December 5th 2023 at 23:54
23andMe has provided more information about the scope and scale of its recent breach, but with these details come more unanswered questions.
☐ ☆ ✇ WIRED

A New Trick Uses AI to Jailbreak AI Models—Including GPT-4

By: Will Knight — December 5th 2023 at 11:00
Adversarial algorithms can systematically probe large language models like OpenAI’s GPT-4 for weaknesses that can make them misbehave.
☐ ☆ ✇ WIRED

ChatGPT Spit Out Sensitive Data When Told to Repeat ‘Poem’ Forever

By: Lily Hay Newman, Andy Greenberg — December 2nd 2023 at 14:00
Plus: A major ransomware crackdown, the arrest of Ukraine’s cybersecurity chief, and a hack-for-hire entrepreneur charged with attempted murder.
☐ ☆ ✇ The Hacker News

Agent Racoon Backdoor Targets Organizations in Middle East, Africa, and U.S.

By: Newsroom — December 2nd 2023 at 08:29
Organizations in the Middle East, Africa, and the U.S. have been targeted by an unknown threat actor to distribute a new backdoor called Agent Racoon. "This malware family is written using the .NET framework and leverages the domain name service (DNS) protocol to create a covert channel and provide different backdoor functionalities," Palo Alto Networks Unit 42 researcher Chema Garcia 
☐ ☆ ✇ WIRED

Google Fixes a Seventh Zero-Day Flaw in Chrome—Update Now

By: Kate O'Flaherty — November 30th 2023 at 15:42
Plus: Major security patches from Microsoft, Mozilla, Atlassian, Cisco, and more.
☐ ☆ ✇ The Hacker News

North Korea's Lazarus Group Rakes in $3 Billion from Cryptocurrency Hacks

By: Newsroom — November 30th 2023 at 11:55
Threat actors from the Democratic People's Republic of Korea (DPRK) are increasingly targeting the cryptocurrency sector as a major revenue generation mechanism since at least 2017 to get around sanctions imposed against the country. "Even though movement in and out of and within the country is heavily restricted, and its general population is isolated from the rest of the world, the
☐ ☆ ✇ WIRED

Okta Breach Impacted All Customer Support Users—Not 1 Percent

By: Lily Hay Newman — November 29th 2023 at 15:53
Okta upped its original estimate of customer support users affected by a recent breach from 1 percent to 100 percent, citing a “discrepancy.”
☐ ☆ ✇ WIRED

OpenAI’s Custom Chatbots Are Leaking Their Secrets

By: Matt Burgess — November 29th 2023 at 12:00
Released earlier this month, OpenAI’s GPTs let anyone create custom chatbots. But some of the data they’re built on is easily exposed.
☐ ☆ ✇ WIRED

Cybersecurity Industry Baffled by FBI’s Lack of Action on Ransomware Gang

By: Andy Greenberg, Andrew Couts — December 17th 2023 at 01:02
Plus: Hackers reveal flaws in crypto wallets holding $1 billion, a massive breach of Danish electric utilities, and more.
☐ ☆ ✇ WIRED

Inside the Race to Secure the F1 Las Vegas Grand Prix

By: Lily Hay Newman — November 18th 2023 at 12:00
Beyond the blinding speeds and sharp turns on new terrain, the teams at this weekend’s big F1 race are preparing for another kind of danger.
☐ ☆ ✇ The Hacker News

27 Malicious PyPI Packages with Thousands of Downloads Found Targeting IT Experts

By: Newsroom — November 17th 2023 at 09:56
An unknown threat actor has been observed publishing typosquat packages to the Python Package Index (PyPI) repository for nearly six months with an aim to deliver malware capable of gaining persistence, stealing sensitive data, and accessing cryptocurrency wallets for financial gain. The 27 packages, which masqueraded as popular legitimate Python libraries, attracted thousands of downloads,
❌