27 Mar

Security shop pwns ransomware gang, passes insider info to authorities

Here’s one you don’t see every day: A cybersecurity vendor is admitting to breaking into a notorious ransomware crew’s infrastructure and gathering data it relayed

Author rabih
27 Mar

CrushFTP CEO’s feisty response to VulnCheck’s CVE for critical make-me-admin bug

CrushFTP’s CEO is not happy with VulnCheck after the CVE numbering authority (CNA) released an unofficial ID for the critical vulnerability in its file transfer

Author rabih
27 Mar

RansomHub affiliates linked to rival RaaS gangs

ESET researchers also examine the growing threat posed by tools that ransomware affiliates deploy in an attempt to disrupt EDR security solutions 27 Mar 2025

Author rabih
27 Mar

FamousSparrow resurfaces to spy on targets in the US, Latin America

Once thought to be dormant, the China-aligned group has also been observed using the privately-sold ShadowPad backdoor for the first time 27 Mar 2025 The

Author rabih
27 Mar

UK’s first permanent facial recognition cameras installed in South London

The Metropolitan Police has confirmed its first permanent installation of live facial recognition (LFR) cameras is coming this summer and the lucky location will be

Author rabih
27 Mar

Ransomwared NHS software supplier nabs £3M discount from ICO for good behavior

The UK’s data protection watchdog is dishing out a £3.07 million ($3.95 million) fine to Advanced Computer Software Group, whose subsidiary’s security failings led to

Author rabih
26 Mar

Signalgate storm intensifies as journalist releases full secret Houthi airstrike chat

The Atlantic’s editor-in-chief who was inadvertently added to a Signal group in which the US Secretary of Defense, Vice President, and others discussed secret military

Author rabih
26 Mar

US defense contractor cops to sloppy security, settles after infosec lead blows whistle

A US defense contractor will cough up $4.6 million to settle complaints it failed to meet cybersecurity requirements on military contracts and knowingly submitted false

Author rabih
26 Mar

Files stolen from NSW court system, including restraining orders for violence

Australian police are currently investigating the theft of “sensitive” data from a New South Wales court system after they confirmed approximately 9,000 files were stolen.

Author rabih
26 Mar

Credible nerd says stop using atop, doesn’t say why, everyone panics

Veteran sysadmin and tech blogger Rachel Kroll posted a cryptic warning yesterday about a popular Linux system monitoring tool. Maybe it’s better to be safe

Author rabih
26 Mar

Shifting the sands of RansomHub’s EDRKillShifter

ESET researchers take a look back at the significant changes in the ransomware ecosystem in 2024 and focus on the newly emerged and currently dominating

Author rabih
26 Mar

You will always remember this as the day you finally caught FamousSparrow

In July 2024, ESET Research noticed suspicious activity on the system of a trade group in the United States that operates in the financial sector.

Author rabih
26 Mar

NCSC taps influencers to make 2FA go viral

The world’s biggest brands have benefited from influencer marketing for years – now the UK’s National Cyber Security Centre (NCSC) has hopped on the bandwagon

Author rabih
25 Mar

Top Trump officials text secret Yemen airstrike plans to journo in Signal SNAFU

Updated Senior Trump administration officials used the messaging app Signal to discuss detailed plans to attack Houthi rebels in Yemen – and accidentally added a

Author rabih
25 Mar

OTF, which backs Tor, Let’s Encrypt and more, sues to save its funding from Trump cuts

An organization that bankrolls various internet security projects has asked a Washington DC court to prevent the Trump administration from cancelling its federal funding –

Author rabih
25 Mar

There are perhaps 10,000 reasons to doubt Oracle Cloud’s security breach denial

Oracle Cloud’s denial of a digital break-in is now in clear dispute. A infosec researcher working on validating claims that the cloud provider’s login servers

Author rabih
25 Mar

Infosec pro Troy Hunt HasBeenPwned in Mailchimp phish

Infosec veteran Troy Hunt of HaveIBeenPwned fame is notifying thousands of people after phishers scooped up his Mailchimp mailing list. He said the list comprises

Author rabih
25 Mar

You know that generative AI browser assistant extension is probably beaming everything to the cloud, right?

Generative AI assistants packaged up as browser extensions harvest personal data with minimal safeguards, researchers warn. Some of these extensions may violate their own privacy

Author rabih
Load moreLoadingAll items loaded