FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ The Register - Security

Zendesk users targeted as Scattered Lapsus$ Hunters spin up fake support sites

β€” November 27th 2025 at 16:30

ReliaQuest finds fresh crop of phishing domains and toxic tickets

Scattered Lapsus$ Hunters may be circling Zendesk users for its latest extortion campaign, with new phishing domains and weaponized helpdesk tickets uncovered by ReliaQuest.…

☐ β˜† βœ‡ ZDNet | security RSS

How I turned this 98-inch TV an immersive home theater system (and it's over half off)

β€” November 27th 2025 at 15:58
Some fine-tuning and adjustments have transformed the TCL S5 TV into a formidable home entertainment system, and this Black Friday price makes it even more appealing.
☐ β˜† βœ‡ ZDNet | security RSS

This large-screen tablet gave me zero iPad Pro envy (and it's $400 off)

β€” November 27th 2025 at 15:49
The latest Samsung Galaxy Tab S10 Ultra has a large AMOLED 2X screen that creatives and professionals will likely gravitate toward.
☐ β˜† βœ‡ The Register - Security

OpenAI cuts off Mixpanel after analytics leak exposes API users

β€” November 27th 2025 at 15:45

ChatGPT maker places other vendors under review following breach

OpenAI says API users may be affected by a recent breach at its former data analytics provider, Mixpanel.…

☐ β˜† βœ‡ ZDNet | security RSS

My go-to USB-C accessory ever has a magnetic feature that protects your devices

β€” November 27th 2025 at 15:42
While USB-C ports can be fragile, this affordable breakaway accessory offers solid protection.
☐ β˜† βœ‡ The Hacker News

Microsoft to Block Unauthorized Scripts in Entra ID Logins with 2026 CSP Update

By: Ravie Lakshmanan β€” November 27th 2025 at 15:37
Microsoft has announced plans to improve the security of Entra ID authentication by blocking unauthorized script injection attacks starting a year from now. The update to its Content Security Policy (CSP) aims to enhance the Entra ID sign-in experience at "login.microsoftonline[.]com" by only letting scripts from trusted Microsoft domains run. "This update strengthens security and adds an extra
☐ β˜† βœ‡ ZDNet | security RSS

ExpressVPN is now at its lowest price ever in a rare Black Friday deal

β€” November 27th 2025 at 14:30
One of our favorite VPNs, ExpressVPN is now only a few dollars a month, making it cheaper than its closest rival, NordVPN.
☐ β˜† βœ‡ The Register - Security

FCC sounds alarm after emergency tones turned into potty-mouthed radio takeover

β€” November 27th 2025 at 14:00

Agency flags hijacks of insecure studio-to-transmitter gear after attackers pipe in fake alerts and vulgar audio

Malicious intruders have hijacked US radio gear to turn emergency broadcast tones into a profanity-laced alarm system.…

☐ β˜† βœ‡ The Register - Security

Asahi admits ransomware gang may have spilled almost 2M people's data

β€” November 27th 2025 at 13:15

Brewer finally tallies fallout from September attack as it pushes earnings into 2026

Asahi has finally done the sums on September's ransomware attack in Japan, conceding the crooks may have helped themselves to personal data tied to almost 2 million people.…

☐ β˜† βœ‡ The Register - Security

Scottish council still rebuilding systems two years after ransomware attack

β€” November 27th 2025 at 12:15

Audit sympathetic toward Comhairle nan Eilean Siar as staff stretched to capacity trying to recover

Auditors remain concerned about the cyber resilience of a Scottish council as some systems are yet to be fully rebuilt following a ransomware attack in November 2023.…

☐ β˜† βœ‡ ZDNet | security RSS

6 MagSafe chargers, wallets, and phone stands I'd buy if I didn't already own them (all are on sale)

β€” November 27th 2025 at 10:45
Black Friday is coming, and it's the perfect time to grab my favorite magnetic gadgets for your phone.
☐ β˜† βœ‡ The Hacker News

ThreatsDay Bulletin: AI Malware, Voice Bot Flaws, Crypto Laundering, IoT Attacks β€” and 20 More Stories

By: Ravie Lakshmanan β€” November 27th 2025 at 10:03
Hackers have been busy again this week. From fake voice calls and AI-powered malware to huge money-laundering busts and new scams, there’s a lot happening in the cyber world. Criminals are getting creative β€” using smart tricks to steal data, sound real, and hide in plain sight. But they’re not the only ones moving fast. Governments and security teams are fighting back, shutting down fake
☐ β˜† βœ‡ ZDNet | security RSS

I cut cable to save $1,200 a year. Here's what helped me do it

β€” November 27th 2025 at 10:00
These devices and streaming services helped me cut the cord and save some money - and they're all on sale for Black Friday.
☐ β˜† βœ‡ ZDNet | security RSS

The GoPro Max 2 is the most convenient 360 travel camera, and it's $100 off

β€” November 27th 2025 at 10:00
The GoPro Max 2 is a massive upgrade over the original Max, and this Black Friday deal makes it easy to recommend.
☐ β˜† βœ‡ The Hacker News

Gainsight Expands Impacted Customer List Following Salesforce Security Alert

By: Ravie Lakshmanan β€” November 27th 2025 at 07:03
Gainsight has disclosed that the recent suspicious activity targeting its applications has affected more customers than previously thought. The company said Salesforce initially provided a list of 3 impacted customers and that it has "expanded to a larger list" as of November 21, 2025. It did not reveal the exact number of customers who were impacted, but its CEO, Chuck Ganapathi, said "we
☐ β˜† βœ‡ /r/netsec - Information Security News & Discussion

Zero the Hero (0tH) – Mach-O structural analysis tool (Rust) with full CodeSignature/SuperBlob parsing

By: /u/gabriele70 β€” November 27th 2025 at 06:34

Author here.

Zero the Hero (0tH) is a Mach-O structural analysis tool written in Rust.

It parses FAT binaries, load commands, slices, CodeSignature/SuperBlob, DER entitlements, requirements bytecode, and CodeDirectory versions.

The binary is universal (Intel + ARM64), notarized and stapled.

Motivation: existing tools lack full coverage of modern Mach-O signature internals.

Docs: https://zero-the-hero.run/docs

Happy to discuss signature internals or Mach-O specifics.

submitted by /u/gabriele70
[link] [comments]
☐ β˜† βœ‡ ZDNet | security RSS

The Even Realities G2 smartglasses are bundled with the ring in this Black Friday deal

β€” November 27th 2025 at 03:47
Customers who buy the Even Realities G2 smartglasses will receive the Even R1 Smart Ring and additional accessories for 50% off.
☐ β˜† βœ‡ ZDNet | security RSS

Verizon is giving away free iPhones, iPads, and Apple Watches - here's how you can get them

β€” November 27th 2025 at 02:18
Save over $2,000 on Apple tech during Black Friday with this bundle offer from Verizon when you sign up for new lines. Here's what to know.
☐ β˜† βœ‡ ZDNet | security RSS

Looking for an Apple Watch alternative? I recommend this Garmin (and it's on sale)

β€” November 27th 2025 at 01:38
Garmin's Instict 3 Solar offers a smart selection of flagship features, down to $349 at Amazon for Black Friday.
☐ β˜† βœ‡ ZDNet | security RSS

The only noise-canceling earbuds I can wear all day are on sale for $129

β€” November 26th 2025 at 23:09
Bose's midrange QuietComfort Earbuds have impressive noise cancellation, a 30-hour battery life, and bass-forward audio. They're $50 off for Black Friday.
☐ β˜† βœ‡ ZDNet | security RSS

This MagSafe power bank plays nice with my Android and has a cool superpower

β€” November 26th 2025 at 22:47
The Sharge Icemag 2 lives up to its name as a cool MagSafe charger that's Android-friendly. It's currently $20 off for Black Friday.
☐ β˜† βœ‡ ZDNet | security RSS

Samsung's S25 Ultra is $400 off - the Android phone I recommend most for Black Friday

β€” November 26th 2025 at 22:22
The slim design, enhanced processor, and Galaxy AI features make this year's Ultra flagship better than ever. Right now, it's $899 for Black Friday.
☐ β˜† βœ‡ ZDNet | security RSS

I've tested every iPad model - here's why I still recommend the Mini (especially for $100 off)

β€” November 26th 2025 at 22:00
There are tons of iPads out there, but the Mini reigns supreme for portability over screen size, particularly while on sale for Black Friday.
☐ β˜† βœ‡ ZDNet | security RSS

I found one of the best stick vacuum cleaners ever and it's not a Dyson

β€” November 26th 2025 at 21:47
The Roborock H60 Hub Ultra is simply outstanding (and on sale through Black Friday), if not for one detail.
☐ β˜† βœ‡ /r/netsec - Information Security News & Discussion

Prepared Statements? Prepared to Be Vulnerable.

By: /u/eqarmada2 β€” November 26th 2025 at 21:40

Think prepared statements automatically make your Node.js apps secure? Think again.

In my latest blog post, I explore a surprising edge case in the mysql and mysql2 packages that can turn β€œsafe” prepared statements into exploitable SQL injection vulnerabilities.

If you use Node.js and rely on prepared statements (as you should be!), this is a must-read: https://blog.mantrainfosec.com/blog/18/prepared-statements-prepared-to-be-vulnerable

submitted by /u/eqarmada2
[link] [comments]
☐ β˜† βœ‡ ZDNet | security RSS

I tested the ReMarkable Paper Pro, and can't go back to 'real' paper - especially at this price

β€” November 26th 2025 at 21:37
The ReMarkable Paper Pro delivers a premium pen-and-paper experience on a color display. Despite the purity of its mission, however, it remains an exclusive product.
☐ β˜† βœ‡ ZDNet | security RSS

Does the new Flux.2 beat Nano Banana Pro? You can try it for yourself - for free

β€” November 26th 2025 at 21:08
Here's what Black Forest Labs' latest image model can do.
☐ β˜† βœ‡ ZDNet | security RSS

These OnePlus earbuds effectively drowned out my noisy commute - but the price is more wild

β€” November 26th 2025 at 21:03
The OnePlus Buds 4 offer flagship-level active noise cancellation for a budget-friendly price - just $90 for Black Friday.
☐ β˜† βœ‡ The Register - Security

Gainsight CEO downplays breach, says only a 'handful' of customers had data stolen

β€” November 26th 2025 at 20:37

Maybe if your hand has 200+ fingers...

Gainsight CEO Chuck Ganapathi downplayed the victim count related to his company's recent breach, saying he's only aware of "a handful of customers" who had their data affected after Salesforce flagged unusual activity involving Gainsight's connected app.…

☐ β˜† βœ‡ ZDNet | security RSS

This Anker USB-C charger bundle is the impulse buy you won't regret (especially at this price)

β€” November 26th 2025 at 19:27
My favorite Black Friday deal right now is Anker's USB-C charger 2-pack for $11. Here's why.
☐ β˜† βœ‡ ZDNet | security RSS

Stop saying AI 'hallucinates' - it doesn't. And the mischaracterization is dangerous

β€” November 26th 2025 at 19:12
The language we use to describe AI is pivotal to how humans see AI - so we'd better get it right.
☐ β˜† βœ‡ /r/netsec - Information Security News & Discussion

TROOPERS25: Revisiting Cross Session Activation attacks

By: /u/S3cur3Th1sSh1t β€” November 26th 2025 at 18:55

My talk about Lateral Movement in the context of logged in user sessions πŸ™Œ

submitted by /u/S3cur3Th1sSh1t
[link] [comments]
☐ β˜† βœ‡ The Register - Security

Botnet takes advantage of AWS outage to smack 28 countries

β€” November 26th 2025 at 18:44

Even worse, it might have been a 'test run' for future attacks

A Mirai-based botnet named ShadowV2 emerged during last October's widespread AWS outage, infecting IoT devices across industries and continents, likely serving as a "test run" for future attacks, according to Fortinet's FortiGuard Labs.…

☐ β˜† βœ‡ /r/netsec - Information Security News & Discussion

Desktop Application Security Verification Standard - DASVS

By: /u/bajk β€” November 26th 2025 at 18:30

Curious what frameworks people use for desktop application testing. I run a pentesting firm that does thick clients for enterprise, and we couldn't find anything comprehensive for this.

Ended up building DASVS over the past 5 years - basically ASVS but for desktop applications. Covers desktop-specific stuff like local data storage, IPC security, update mechanisms, and memory handling that web testing frameworks miss. Been using it internally for thick client testing, but you can only see so much from one angle. Just open-sourced it because it could be useful beyond just us.

The goal is to get it to where ASVS is: community-driven, comprehensive, and actually used.

To people who do desktop application testing, what is wrong or missing? Where do you see gaps that should be addressed? In the pipeline, we have testing guides per OS and an automated assessment tool inspired by MobSF. What do you use now for desktop application testing? And what would make a framework like this actually useful?

submitted by /u/bajk
[link] [comments]
☐ β˜† βœ‡ ZDNet | security RSS

Is the Samsung Frame Pro a viable TV alternative at home? My advice after weeks of testing

β€” November 26th 2025 at 18:29
The Frame Pro TV improves on its predecessor by seamlessly integrating entertainment and home dΓ©cor. Plus, it's on sale for Black Friday.
☐ β˜† βœ‡ ZDNet | security RSS

Google Pixel Watch 4 is my favorite smartwatch - and it's selling at an all-time low price

β€” November 26th 2025 at 18:26
Google's Pixel Watch 4 is one of the best deals I've found this Black Friday.
☐ β˜† βœ‡ The Hacker News

Shai-Hulud v2 Spreads From npm to Maven, as Campaign Exposes Thousands of Secrets

By: Ravie Lakshmanan β€” November 26th 2025 at 18:08
The second wave of the Shai-Hulud supply chain attack has spilled over to the Maven ecosystem after compromising more than 830 packages in the npm registry. The Socket Research Team said it identified a Maven Central package named org.mvnpm:posthog-node:4.18.1 that embeds the same two components associated with Sha1-Hulud: the "setup_bun.js" loader and the main payload "bun_environment.js." The
☐ β˜† βœ‡ ZDNet | security RSS

How Microsoft Entra aims to keep your AI agents from running wild

β€” November 26th 2025 at 18:04
AI agents amok could cause real problems - Entra takes a shot at reining them in
☐ β˜† βœ‡ ZDNet | security RSS

I use this smart plug for anything from fans to holiday lights, and it's only $12

β€” November 26th 2025 at 17:58
The Amazon Smart Plug is up to 52% off this Black Friday, with a two-pack deal available for $24.
☐ β˜† βœ‡ ZDNet | security RSS

Yes, your AirPods are dirty. Grab this $6 tool to keep them clean

β€” November 26th 2025 at 17:52
If you're upgrading your AirPods or gifting a pair to someone else, consider this cheap little tool that prevents nasty buildup.
☐ β˜† βœ‡ Krebs on Security

Meet Rey, the Admin of β€˜Scattered Lapsus$ Hunters’

By: BrianKrebs β€” November 26th 2025 at 17:22

A prolific cybercriminal group that calls itself β€œScattered LAPSUS$ Hunters” has dominated headlines this year by regularly stealing data from and publicly mass extorting dozens of major corporations. But the tables seem to have turned somewhat for β€œRey,” the moniker chosen by the technical operator and public face of the hacker group: Earlier this week, Rey confirmed his real life identity and agreed to an interview after KrebsOnSecurity tracked him down and contacted his father.

Scattered LAPSUS$ Hunters (SLSH) is thought to be an amalgamation of three hacking groups β€” Scattered Spider, LAPSUS$ and ShinyHunters. Members of these gangs hail from many of the same chat channels on the Com, a mostly English-language cybercriminal community that operates across an ocean of Telegram and Discord servers.

In May 2025, SLSH members launched a social engineering campaign that used voice phishing to trick targets into connecting a malicious app to their organization’s Salesforce portal. The group later launched a data leak portal that threatened to publish the internal data of three dozen companies that allegedly had Salesforce data stolen, including Toyota,Β FedEx,Β Disney/Hulu, andΒ UPS.

The new extortion website tied to ShinyHunters, which threatens to publish stolen data unless Salesforce or individual victim companies agree to pay a ransom.

Last week, the SLSH Telegram channel featured an offer to recruit and reward β€œinsiders,” employees at large companies who agree to share internal access to their employer’s network for a share of whatever ransom payment is ultimately paid by the victim company.

SLSH has solicited insider access previously, but their latest call for disgruntled employees started making the rounds on social media at the same time news broke that the cybersecurity firm Crowdstrike had fired an employee for allegedly sharing screenshots of internal systems with the hacker group (Crowdstrike said their systems were never compromised and that it has turned the matter over to law enforcement agencies).

The Telegram server for the Scattered LAPSUS$ Hunters has been attempting to recruit insiders at large companies.

Members of SLSH have traditionally used other ransomware gangs’ encryptors in attacks, including malware from ransomware affiliate programs like ALPHV/BlackCat, Qilin, RansomHub, and DragonForce. But last week, SLSH announced on its Telegram channel the release of their own ransomware-as-a-service operation called ShinySp1d3r.

The individual responsible for releasing the ShinySp1d3r ransomware offering is a core SLSH member who goes by the handle β€œRey” and who is currently one of just three administrators of the SLSH Telegram channel. Previously, Rey was an administrator of the data leak website for Hellcat, a ransomware group that surfaced in late 2024 and was involved in attacks on companies including Schneider Electric, Telefonica, and Orange Romania.

A recent, slightly redacted screenshot of the Scattered LAPSUS$ Hunters Telegram channel description, showing Rey as one of three administrators.

Also in 2024, Rey would take over as administrator of the most recent incarnation of BreachForums, an English-language cybercrime forum whose domain names have been seized on multiple occasions by the FBI and/or by international authorities. In April 2025, Rey posted on Twitter/X about another FBI seizure of BreachForums.

On October 5, 2025, the FBI announced it had once again seized the domains associated with BreachForums, which it described as a major criminal marketplace used by ShinyHunters and others to traffic in stolen data and facilitate extortion.

β€œThis takedown removes access to a key hub used by these actors to monetize intrusions, recruit collaborators, and target victims across multiple sectors,” the FBI said.

Incredibly, Rey would make a series of critical operational security mistakes last year that provided multiple avenues to ascertain and confirm his real-life identity and location. Read on to learn how it all unraveled for Rey.

WHO IS REY?

According to the cyber intelligence firm Intel 471, Rey was an active user on various BreachForums reincarnations over the past two years, authoring more than 200 posts between February 2024 and July 2025. Intel 471 says Rey previously used the handle β€œHikki-Chan” on BreachForums, where their first post shared data allegedly stolen from the U.S. Centers for Disease Control and Prevention (CDC).

In that February 2024 post about the CDC, Hikki-Chan says they could be reached at the Telegram username @wristmug. In May 2024, @wristmug posted in a Telegram group chat called β€œPantifan” a copy of an extortion email they said they received that included their email address and password.

The message that @wristmug cut and pasted appears to have been part of an automated email scam that claims it was sent by a hacker who has compromised your computer and used your webcam to record a video of you while you were watching porn. These missives threaten to release the video to all your contacts unless you pay a Bitcoin ransom, and they typically reference a real password the recipient has used previously.

β€œNoooooo,” the @wristmug account wrote in mock horror after posting a screenshot of the scam message. β€œI must be done guys.”

A message posted to Telegram by Rey/@wristmug.

In posting their screenshot, @wristmug redacted the username portion of the email address referenced in the body of the scam message. However, they did not redact their previously-used password, and they left the domain portion of their email address (@proton.me) visible in the screenshot.

O5TDEV

Searching on @wristmug’s rather unique 15-character password in the breach tracking service Spycloud finds it is known to have been used by just one email address: cybero5tdev@proton.me. According to Spycloud, those credentials were exposed at least twice in early 2024 when this user’s device was infected with an infostealer trojan that siphoned all of its stored usernames, passwords and authentication cookies (a finding that was initially revealed in March 2025 by the cyber intelligence firm KELA).

Intel 471 shows the email address cybero5tdev@proton.me belonged to a BreachForums member who went by the username o5tdev. Searching on this nickname in Google brings up at least two website defacement archives showing that a user named o5tdev was previously involved in defacing sites with pro-Palestinian messages. The screenshot below, for example, shows that 05tdev was part of a group called Cyb3r Drag0nz Team.

Rey/o5tdev’s defacement pages. Image: archive.org.

A 2023 report from SentinelOne described Cyb3r Drag0nz Team as a hacktivist group with a history of launching DDoS attacks and cyber defacements as well as engaging in data leak activity.

β€œCyb3r Drag0nz Team claims to have leaked data on over a million of Israeli citizens spread across multiple leaks,” SentinelOne reported. β€œTo date, the group has released multiple .RAR archives of purported personal information on citizens across Israel.”

The cyber intelligence firm Flashpoint finds the Telegram user @05tdev was active in 2023 and early 2024, posting in Arabic on anti-Israel channels like β€œGhost of Palestine” [full disclosure: Flashpoint is currently an advertiser on this blog].

β€˜I’M A GINTY’

Flashpoint shows that Rey’s Telegram account (ID7047194296) was particularly active in a cybercrime-focused channel called Jacuzzi, where this user shared several personal details, including that their father was an airline pilot. Rey claimed in 2024 to be 15 years old, and to have family connections to Ireland.

Specifically, Rey mentioned in several Telegram chats that he had Irish heritage, even posting a graphic that shows the prevalence of the surname β€œGinty.”

Rey, on Telegram claiming to have association to the surname β€œGinty.” Image: Flashpoint.

Spycloud indexed hundreds of credentials stolen from cybero5dev@proton.me, and those details indicate that Rey’s computer is a shared Microsoft Windows device located in Amman, Jordan. The credential data stolen from Rey in early 2024 show there are multiple users of the infected PC, but that all shared the same last name of Khader and an address in Amman, Jordan.

The β€œautofill” data lifted from Rey’s family PC contains an entry for a 46-year-old Zaid Khader that says his mother’s maiden name was Ginty. The infostealer data also shows Zaid Khader frequently accessed internal websites for employees of Royal Jordanian Airlines.

MEET SAIF

The infostealer data makes clear that Rey’s full name is Saif Al-Din Khader. Having no luck contacting Saif directly, KrebsOnSecurity sent an email to his father Zaid. The message invited the father to respond via email, phone or Signal, explaining that his son appeared to be deeply enmeshed in a serious cybercrime conspiracy.

Less than two hours later, I received a Signal message from Saif, who said his dad suspected the email was a scam and had forwarded it to him.

β€œI saw your email, unfortunately I don’t think my dad would respond to this because they think its some β€˜scam email,'” said Saif, who told me he turns 16 years old next month. β€œSo I decided to talk to you directly.”

Saif explained that he’d already heard from European law enforcement officials, and had been trying to extricate himself from SLSH. When asked why then he was involved in releasing SLSH’s new ShinySp1d3r ransomware-as-a-service offering, Saif said he couldn’t just suddenly quit the group.

β€œWell I cant just dip like that, I’m trying to clean up everything I’m associated with and move on,” he said.

The former Hellcat ransomware site. Image: Kelacyber.com

He also shared that ShinySp1d3r is just a rehash of Hellcat ransomware, except modified with AI tools. β€œI gave the source code of Hellcat ransomware out basically.”

Saif claims he reached out on his own recently to the Telegram account for Operation Endgame, the codename for an ongoing law enforcement operation targeting cybercrime services, vendors and their customers.

β€œI’m already cooperating with law enforcement,” Saif said. β€œIn fact, I have been talking to them since at least June. I have told them nearly everything. I haven’t really done anything like breaching into a corp or extortion related since September.”

Saif suggested that a story about him right now could endanger any further cooperation he may be able to provide. He also said he wasn’t sure if the U.S. or European authorities had been in contact with the Jordanian government about his involvement with the hacking group.

β€œA story would bring so much unwanted heat and would make things very difficult if I’m going to cooperate,” Saif said. β€œI’m unsure whats going to happen they said they’re in contact with multiple countries regarding my request but its been like an entire week and I got no updates from them.”

Saif shared a screenshot that indicated he’d contacted Europol authorities late last month. But he couldn’t name any law enforcement officials he said were responding to his inquiries, and KrebsOnSecurity was unable to verify his claims.

β€œI don’t really care I just want to move on from all this stuff even if its going to be prison time or whatever they gonna say,” Saif said.

☐ β˜† βœ‡ ZDNet | security RSS

My 5 must-have gadgets for office commuters (especially at these prices)

β€” November 26th 2025 at 17:20
These five devices couldn't be easier to carry, but bring next-level comfort and productivity wherever you're working. Right now, they're all on sale for Black Friday.
☐ β˜† βœ‡ The Register - Security

Mobile industry warns patchwork cyber regs are driving up costs

β€” November 26th 2025 at 17:12

GSMA says fragmented, poorly designed laws add burdens without making networks any safer

Mobile operators' core cybersecurity spending is projected to more than double by 2030 as threats evolve, while poorly designed and fragmented policy frameworks add extra compliance costs, according to industry group the GSMA.…

☐ β˜† βœ‡ ZDNet | security RSS

This 3-in-1 charger for Apple users is a fan favorite, and it's 30% off right now

β€” November 26th 2025 at 17:06
The Nomad Base One Max is one of my go-to picks for charging my favorite Apple devices, and it's currently on sale for Black Friday.
☐ β˜† βœ‡ ZDNet | security RSS

Is that Black Friday deal legit? Find out with ZDNET's deal tracker

β€” November 26th 2025 at 16:56
We compared the price histories of the products ZDNET readers bought most this year to help you find the best deals this Black Friday weekend. Here's what's worth it (and what's not).
☐ β˜† βœ‡ ZDNet | security RSS

5 Linux desktop environments that make ditching Windows 10 easy - including my top pick

β€” November 26th 2025 at 16:42
If you're looking to migrate from Windows 10 or 11 and Linux is in your sights, you might want to try one of these desktop environments to ease the transition.
☐ β˜† βœ‡ WIRED

The Destruction of a Notorious Myanmar Scam Compound Appears to Have Been β€˜Performative’

By: Matt Burgess β€” November 26th 2025 at 16:33
Myanmar’s military has been blowing up parts of the KK Park scam compound. Experts say the actions are likely for show.
☐ β˜† βœ‡ ZDNet | security RSS

5 Kindle accessories every reader should have (and are all on sale for Black Friday)

β€” November 26th 2025 at 15:48
The right accessories for your Kindle e-reader can help you cross more books off your to-read list -- especially with these Black Friday deals.
☐ β˜† βœ‡ ZDNet | security RSS

Does the CEO doubt your AI savvy? CIOs must upskill in these 3 critical areas

β€” November 26th 2025 at 15:14
AI implementation is up 282% in a year, and it's reshaping how CIOs and CEOs work together, Salesforce says.
☐ β˜† βœ‡ ZDNet | security RSS

I used AI to summarize boring ToS agreements, and these two tools did it best

β€” November 26th 2025 at 15:08
AI can explain what you're agreeing to before you hit accept. But can you trust it? Here's what happened when I tested it.
☐ β˜† βœ‡ The Register - Security

CodeRED emergency alert system CodeDEAD after INC ransomware attack

β€” November 26th 2025 at 14:33

Regions across US affected, and one tore up its contract for the product

Towns and cities across the US are without access to their CodeRED emergency alert system following a cyberattack on vendor Crisis24.…

☐ β˜† βœ‡ ZDNet | security RSS

This ChatGPT upgrade just fixed my biggest annoyance with voice mode - for free

β€” November 26th 2025 at 14:32
If ChatGPT's voice mode always felt clunky to use before, the new update will be a welcomed change.
☐ β˜† βœ‡ The Hacker News

Qilin Ransomware Turns South Korean MSP Breach Into 28-Victim 'Korean Leaks' Data Heist

By: Ravie Lakshmanan β€” November 26th 2025 at 14:31
South Korea's financial sector has been targeted by what has been described as a sophisticated supply chain attack that led to the deployment of Qilin ransomware. "This operation combined the capabilities of a major Ransomware-as-a-Service (RaaS) group, Qilin, with potential involvement from North Korean state-affiliated actors (Moonstone Sleet), leveraging Managed Service Provider (MSP)
☐ β˜† βœ‡ The Register - Security

US Navy scuttles Constellation frigate program for being too slow for tomorrow's threats

β€” November 26th 2025 at 14:10

Service limits 20-ship line to two hulls after redesigns and delays torpedo schedule

The US Navy is scrapping an entire shipbuilding program in an effort to find alternatives that can be delivered faster to counter expected threats.…

☐ β˜† βœ‡ ZDNet | security RSS

Vibe coding feels magical, but it can sink your business fast - here's how

β€” November 26th 2025 at 13:23
What may start as 'move fast and break things' too often becomes move fast and break everything, then spend a fortune rebuilding it.'
☐ β˜† βœ‡ The Hacker News

When Your $2M Security Detection Fails: Can your SOC Save You?

By: Unknown β€” November 26th 2025 at 11:55
Enterprises today are expected to have at least 6-8 detection tools, as detection is considered a standard investment and the first line of defense. Yet security leaders struggle to justify dedicating resources further down the alert lifecycle to their superiors. As a result, most organizations' security investments are asymmetrical, robust detection tools paired with an under-resourced SOC,
☐ β˜† βœ‡ The Hacker News

Chrome Extension Caught Injecting Hidden Solana Transfer Fees Into Raydium Swaps

By: Ravie Lakshmanan β€” November 26th 2025 at 11:10
Cybersecurity researchers have discovered a new malicious extension on the Chrome Web Store that's capable of injecting a stealthy Solana transfer into a swap transaction and transferring the funds to an attacker-controlled cryptocurrency wallet. The extension, named Crypto Copilot, was first published by a user named "sjclark76" on May 7, 2024. The developer describes the browser add-on as
☐ β˜† βœ‡ The Hacker News

Webinar: Learn to Spot Risks and Patch Safely with Community-Maintained Tools

By: Unknown β€” November 26th 2025 at 11:10
If you're using community tools like Chocolatey or Winget to keep systems updated, you're not alone. These platforms are fast, flexible, and easy to work withβ€”making them favorites for IT teams. But there’s a catch... The very tools that make your job easier might also be the reason your systems are at risk. These tools are run by the community. That means anyone can add or update packages. Some
☐ β˜† βœ‡ The Register - Security

London councils probe cyber incident as shared IT systems knocked offline

β€” November 26th 2025 at 11:04

Three boroughs confirm investigation amid service outages, disrupted phone lines, and limited online access

Two London councils are scrambling for answers after declaring a cybersecurity issue that began on Monday.…

❌