09 Jun

Cybercriminals: the ‘auditors’ you never hired

There’s one cognitive bias that we humans are prone to, and it lies at the centre of some of the challenges that cybersecurity professionals face

Author rabih
08 Jun

Norks blast 250+ fake job offers to developers over 6 weeks to try and snarf creds and crypto

There’s another likely North Korean-linked scam hitting developers and their employers, while snarfing up credentials and cryptocurrency – and this one doesn’t even involve embedding

Author rabih
08 Jun

Ransomware crims got a month-long head start on Check Point VPN 0-day that now has a fix

cyber-crime Scumbags, including a Qilin ransomware affiliate, began hitting this hole May 7 Check Point released an emergency fix on Monday for a critical authentication

Author rabih
08 Jun

Ransomware sends Illinois high school on an early summer vacation

Cyber-crime Meanwhile, 13 schools in Wales affected by separate attack An Illinois high school won’t reopen until Wednesday at the earliest after suffering a ransomware

Author rabih
08 Jun

GitHub nukes 70+ Microsoft repos, breaks CI/CD pipelines, following suspected worm infections

security Miasma worm shapeshifts, but cloud secret-scouting remains the goal Microsoft’s GitHub has disabled over 70 repositories after they were reportedly compromised by a worm

Author rabih
08 Jun

NSO Group back in Meta’s crosshairs after alleged WhatsApp targeting

security Zuckercorp says surveillance-for-hire vendor was still running phishing operations after federal court told it to knock it off Meta has asked a federal judge

Author rabih
06 Jun

Oxford Uni student data pwned yet again – this time via career platform breach

security Totally different attack from the break-in last month. Oh so that’s OK then  Oxford University students seeking work will be dismayed to learn that

Author rabih
05 Jun

If you don’t fall for these extortionists’ calls, they’ll show up with USB sticks

If they don’t get you online, they’ll try in person. A data-theft and extortion gang has targeted “dozens” of banks, law firms, and other professional

Author rabih
05 Jun

Yet another Cisco SD-WAN 0-day under attack, and no patch in sight

security Good luck, sys admins The threat is real. Unknown miscreants are exploiting a high-severity, zero-day bug in Cisco’s SD-WAN management software, and the networking

Author rabih
05 Jun

World Food Programme breach exposes data of 600k vulnerable Gazan families

security Those receiving aid in the famine-threatened, war-torn territory told support will remain Humanitarian organization World Food Programme (WFP) says one of its systems was

Author rabih
05 Jun

Council in UK’s City of York outs hundreds of disabled residents with a single email blunder

Security Blue Badge holders exposed to each other after BCC function proves too complex A City of York Council email mishap exposed the email addresses

Author rabih
04 Jun

Pink is the latest goon squad to use fake helpdesk calls to steal creds

CYBER-CRIME A familiar tactic popularized by chaotic crime crew Lapsus$ A new extortion brand called Pink uses voice phishing and fake help-desk calls to gain

Author rabih
04 Jun

OpenAI’s agent chained decade-old DoS attacks to crash web servers in seconds

Security Codex drops an HTTP/2 Bomb The next threat your server faces may have been helped along by a bot. OpenAI’s Codex agent helped uncover a

Author rabih
04 Jun

Five Eyes: Watch out for odd LinkedIn connection requests, China’s back on the hunt for state secrets

Security Cash-for-intel tradecraft continues to concern intelligence officials years after it was first spotted MI5 and its international allies are once again warning that China

Author rabih
04 Jun

Duo who sold car crash victims’ data must repay £118k

cyber-crime Fresh penalties secured after initial prison, community service sentences for RAC double act Two former RAC workers in the UK have three months to

Author rabih
04 Jun

Nobody needs Mythos or 0-days to build a chaos-causing computer worm – free open source models work just fine

There’s a lot of fear surrounding the bug-finding capabilities of super-advanced AI models like Anthropic’s Mythos and OpenAI’s GPT 5.5-Cyber. But attackers are already using

Author rabih
04 Jun

All the passwords were stored in Active Directory description fields

SECURITY It was far too easy for a hacker to get the information PWNED Welcome back to PWNED, the weekly column where we talk about

Author rabih
03 Jun

Commvault says it’s time to rethink resiliency as AI crooks leave victims in a ‘dark, dead’ state

AI-enabled cybercriminals have better tools and are inflicting more pain on their victims, wiping out virtual machines and hypervisors and leaving infrastructure in a “dark,

Author rabih
Load moreLoadingAll items loaded