25 Apr

M&S stops online orders as ‘cyber incident’ issues worsen

Marks & Spencer has paused online orders for customers via its website and app as the UK retailer continues to wrestle with an ongoing “cyber

Author rabih
25 Apr

Emergency patch for potential SAP zero-day that could grant full system control

SAP’s latest out-of-band patch is for a perfect 10/10 bug in NetWeaver that experts suspect could have already been exploited as a zero-day. However, we

Author rabih
25 Apr

Claims assistance firm fined for cold-calling people who put themselves on opt-out list

Britain’s data privacy watchdog has slapped a fine of £90k ($120k) on a business that targeted people with intrusive marketing phone calls, despite them being

Author rabih
25 Apr

Deepfake ‘doctors’ take to TikTok to peddle bogus cures

Social Media Look out for AI-generated ‘TikDocs’ who exploit the public’s trust in the medical profession to drive sales of sketchy supplements 25 Apr 2025

Author rabih
25 Apr

Darcula adds AI to its DIY phishing kits to help would-be vampires bleed victims dry

Darcula, a cybercrime outfit that offers a phishing-as-a-service kit to other criminals, this week added AI capabilities to its kit that help would-be vampires spin

Author rabih
24 Apr

SSNs and more on 5.5M+ patients feared stolen from Yale Health

Yale New Haven Health has notified more than 5.5 million people that their private details were likely stolen by miscreants who broke into the healthcare

Author rabih
24 Apr

Microsoft mystery folder fix might need a fix of its own

Turns out Microsoft’s latest patch job might need a patch of its own, again. This time, the culprit is a mysterious inetpub folder quietly deployed

Author rabih
24 Apr

Assassin’s Creed maker faces GDPR complaint for forcing single-player gamers online

For anyone who’s ever been frustrated by the need to go online to play a single-player video game, the European privacy specialists at noyb have

Author rabih
24 Apr

M&S takes systems offline as ‘cyber incident’ lingers

UK high street retailer Marks & Spencer says contactless payments are still down following its “cyber incident” and order delays are likely to continue. The

Author rabih
24 Apr

Your vendor may be the weakest link: Percentage of third-party breaches doubled in a year

The percentage of confirmed data breaches involving third-party relationships doubled last year as cybercriminals increasingly exploited weak links in supply chains and partner ecosystems. That’s

Author rabih
24 Apr

Booby-trapped Alpine Quest Android app geolocates Russian soldiers

Russian soldiers are being targeted with an Android app specially altered to pinpoint their location and scan their phones for files, with the ability to

Author rabih
24 Apr

Ransomware scum and other crims bilked victims out of a ‘staggering’ $16.6B last year, says FBI

Digital scammers and extortionists bilked businesses and individuals in the US out of a “staggering” $16.6 billion last year, according to the FBI — the

Author rabih
23 Apr

Blue Shield says it shared health info on up to 4.7M patients with Google Ads

US health insurance giant Blue Shield of California handed sensitive health information belonging to as many as 4.7 million members to Google’s advertising empire, likely

Author rabih
23 Apr

Ripple NPM supply chain attack hunts for private keys

Many versions of the Ripple ledger (XRPL) official NPM package are compromised with malware injected to steal cryptocurrency. The NPM package, xrpl, is a JavaScript/TypeScript

Author rabih
23 Apr

We’re calling it now: Agentic AI will win RSAC buzzword Bingo

The security industry loves its buzzwords, and this is always on full display at the annual RSA Conference event in San Francisco. Don’t believe us?

Author rabih
23 Apr

Who needs phishing when your login’s already in the wild?

Criminals used stolen credentials more frequently than email phishing to gain access into their victims’ IT systems last year, marking the first time that compromised

Author rabih
23 Apr

Ex-NSA chief warns AI devs: Don’t repeat infosec’s early-day screwups

AI engineers should take a lesson from the early days of cybersecurity and bake safety and security into their models during development, rather than trying

Author rabih
23 Apr

How fraudsters abuse Google Forms to spread scams

The form and quiz-building tool is a popular vector for social engineering and malware. Here’s how to stay safe. Phil Muncaster 23 Apr 2025  • 

Author rabih
Load moreLoadingAll items loaded