FreshRSS

🔒
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayYour RSS feeds

An Apple Malware-Flagging Tool Is ‘Trivially’ Easy to Bypass

By Lily Hay Newman
The macOS Background Task Manager tool is supposed to spot potentially malicious software on your machine. But a researcher says it has troubling flaws.

GitHub’s Hardcore Plan to Roll Out Two-Factor Authentication (2FA)

By Lily Hay Newman
GitHub has spent two years researching and slowly rolling out its multifactor authentication system. Soon it will be mandatory for all 100 million users—with no opt-out.

Teens Hacked Boston Subway’s CharlieCard to Get Infinite Free Rides—and This Time Nobody Got Sued

By Andy Greenberg
In 2008, Boston’s transit authority sued to stop MIT hackers from presenting at the Defcon hacker conference on how to get free subway rides. Today, four teens picked up where they left off.

Panasonic Warns That IoT Malware Attack Cycles Are Accelerating

By Lily Hay Newman
The legacy electronics manufacturer is creating IoT honeypots with its products to catch real-world threats and patch vulnerabilities in-house.

Hackers Rig Casino Card-Shuffling Machines for ‘Full Control’ Cheating

By Andy Greenberg
Security researchers accessed an internal camera inside the Deckmate 2 shuffler to learn the exact deck order—and the hand of every player at a poker table.

A Clever Honeypot Tricked Hackers Into Revealing Their Secrets

By Matt Burgess
Security researchers set up a remote machine and recorded every move cybercriminals made—including their login details.

New ‘Downfall’ Flaw Exposes Valuable Data in Generations of Intel Chips

By Lily Hay Newman
The vulnerability could allow attackers to take advantage of an information leak to steal sensitive details like private messages, passwords, and encryption keys.

Microsoft’s AI Red Team Has Already Made the Case for Itself

By Lily Hay Newman
Since 2018, a dedicated team within Microsoft has attacked machine learning systems to make them safer. But with the public release of new generative AI tools, the field is already evolving.

Criminals Have Created Their Own ChatGPT Clones

By Matt Burgess
Cybercriminals are touting large language models that could help them with phishing or creating malware. But the AI chatbots could just be their own kind of scam.

Security News This Week: The Cloud Company at the Center of a Global Hacking Spree

By Andrew Couts
Plus: A framework for encrypting social media, Russia-backed hacking through Microsoft Teams, and the Bitfinex Crypto Couple pleads guilty.

Free Airline Miles, Hotel Points, and User Data Put at Risk by Flaws in Points Platform

By Lily Hay Newman
Flaws in the Points.com platform, which is used to manage dozens of major travel rewards programs, exposed user data—and could have let an attacker snag some extra perks.

A New Attack Impacts ChatGPT—and No One Knows How to Stop It

By Will Knight
Researchers found a simple way to make ChatGPT, Bard, and other chatbots misbehave, proving that AI is hard to tame.

Twitter Scammers Stole $1,000 From My Friend—So I Hunted Them Down

By Selena Larson
After scammers duped a friend with a hacked Twitter account and a “deal” on a MacBook, I enlisted the help of a fellow threat researcher to trace the criminals’ offline identities.

TETRA Radio Code Encryption Has a Flaw: A Backdoor

By Kim Zetter
A secret encryption cipher baked into radio systems used by critical infrastructure workers, police, and others around the world is finally seeing sunlight. Researchers say it isn’t pretty.

China’s Breach of Microsoft Cloud Email May Expose Deeper Problems

By Matt Burgess, Lily Hay Newman
Plus: Microsoft expands access to premium security features, AI child sexual abuse material is on the rise, and Netflix’s password crackdown has its intended effect.

Satellites Are Rife With Basic Security Flaws

By Matt Burgess
German researchers gained rare access to three satellites and found that they're years behind normal cybersecurity standards.

How a Cloud Flaw Gave Chinese Spies a Key to Microsoft’s Kingdom

By Andy Greenberg
Microsoft says hackers somehow stole a cryptographic key, perhaps from its own network, that let them forge user identities and slip past cloud defenses.

Ransomware Attacks Are on the Rise, Again

By Lily Hay Newman, Matt Burgess
Ransomware attacks tumbled in 2022, offering hope that the tide was turning against the criminal gangs behind them. Then things got a whole lot worse.

Silk Road’s Second-in-Command, Variety Jones, Gets 20 Years in Prison

By Andy Greenberg
Roger Thomas Clark, also known as Variety Jones, will spend much of the rest of his life in prison for his key role in building the world’s first dark-web drug market.

Russia’s Notorious Troll Farm Disbands

By Andy Greenberg, Andrew Couts
Plus: A French bill would allow spying via phone cameras, ATM skimmers target welfare families, and Japan’s largest cargo port gets hit with ransomware.

EV Charger Hacking Poses a ‘Catastrophic’ Risk

By Tik Root
Vulnerabilities in electric vehicle charging stations and a lack of broad standards threaten drivers—and the power grid.

US Supreme Court Hands Cyberstalkers a First Amendment Victory

By Lily Hay Newman
Plus: Hackers knock out Russian military satellite communications, a spyware maker gets breached, and the SEC targets a victim company's CISO.

Apple, Google, and MOVEit Just Patched Serious Security Flaws

By Kate O'Flaherty
Plus: Microsoft fixes 78 vulnerabilities, VMWare plugs a flaw already used in attacks, and more critical updates from June.

How Your Real Flight Reservation Can Be Used to Scam You

By Ax Sharma
Scammers use a booking technicality, traveler confusion, and promises of dirt-cheap tickets to offer hot deals that are anything but.

Update Your iPhone Right Now to Fix 2 Apple Zero Days

By Dhruv Mehrotra, Andrew Couts
Plus: Discord has a child predator problem, fears rise of China spying from Cuba, and hackers try to blackmail Reddit.

A Newly Named Group of GRU Hackers is Wreaking Havoc in Ukraine

By Andy Greenberg, Andrew Couts
Plus: The arrest of an alleged Lockbit ransomware hacker, the wild tale of a problematic FBI informant, and one of North Korea’s biggest crypto heists.

Clop Hacking Rampage Hits US Agencies and Exposes Data of Millions

By Lily Hay Newman
The ransomware gang Clop exploited a vulnerability in a file transfer service. The flaw is now patched, but the damage is still coming into focus.

The US Navy, NATO, and NASA Are Using a Shady Chinese Company’s Encryption Chips

By Andy Greenberg
The US government warns encryption chipmaker Hualan has suspicious ties to China’s military. Yet US agencies still use one of its subsidiary’s chips, raising fears of a backdoor.

A Massive Vaccine Database Leak Exposes IDs of Millions of Indians

By Varsha Bansal
Personal information, including ID documents and phone numbers, have been released on Telegram.

9 Years After the Mt. Gox Hack, Feds Indict Alleged Culprits

By Lily Hay Newman, Andy Greenberg
Plus: Instagram’s CSAM network gets exposed, Clop hackers claim credit for MOVEit Transfer exploit, and a $35 million crypto heist has North Korean ties.

The Bold Plan to Create Cyber 311 Hotlines

By Eric Geller
UT-Austin will join a growing movement to launch cybersecurity clinics for cities and small businesses that often fall through the cracks.

Hacks Against Ukraine's Emergency Response Services Rise During Bombings

By Lily Hay Newman
Data from Cloudflare's free digital defense service, Project Galileo, illuminates new links between online and offline attacks.

AI Is Being Used to ‘Turbocharge’ Scams

By Matt Burgess
Plus: Amazon’s Ring was ordered to delete algorithms, North Korea’s failed spy satellite, and a rogue drone “attack” isn’t what it seems.

How AI Protects (and Attacks) Your Inbox

By Reece Rogers
Criminals may use artificial intelligence to scam you. Companies, like Google, are looking for ways AI and machine learning can help prevent phishing.

Kaspersky Says New Zero-Day Malware Hit iPhones—Including Its Own

By Lily Hay Newman, Andy Greenberg
On the same day, Russia’s FSB intelligence service launched wild claims of NSA and Apple hacking thousands of Russians.

Apple's iOS 16.5 Fixes 3 Security Bugs Already Used in Attacks

By Kate O'Flaherty
Plus: Microsoft patches two zero-day flaws, Google’s Android and Chrome get some much-needed updates, and more.

Millions of Gigabyte Motherboards Were Sold With a Firmware Backdoor

By Andy Greenberg
Hidden code in hundreds of models of Gigabyte motherboards invisibly and insecurely downloads programs—a feature ripe for abuse, researchers say.

Bcrypt, a Popular Password Hashing Algorithm, Starts Its Long Goodbye

By Lily Hay Newman
The coinventor of “bcrypt” is reflecting on the ubiquitous function’s 25 years and channeling cybersecurity’s core themes into electronic dance music.

The Security Hole at the Heart of ChatGPT and Bing

By Matt Burgess
Indirect prompt-injection attacks can leave people vulnerable to scams and data theft when they use the AI chatbots.

China Hacks US Critical Networks in Guam, Raising Cyberwar Fears

By Andy Greenberg, Lily Hay Newman
Researchers say the state-sponsored espionage operation may also lay the groundwork for disruptive cyberattacks.

There’s Finally a Way to Improve Cloud Container Registry Security

By Lily Hay Newman
“Container registries” are ubiquitous software clearinghouses, but they’ve been exposed for years. Chainguard says it now has a solution.

The Real Risks in Google’s New .Zip and .Mov Domains

By Lily Hay Newman
While the company’s new top-level domains could be used in phishing attacks, security researchers are divided on how big of a problem they really pose.

A TikTok ‘Car Theft’ Challenge Is Costing Hyundai $200 Million

By Andrew Couts
Plus: The FBI gets busted abusing a spy tool, an ex-Apple engineer is charged with corporate espionage, and collection of airborne DNA raises new privacy risks.

The Underground History of Turla, Russia's Most Ingenious Hacker Group

By Andy Greenberg
From USB worms to satellite-based hacking, Russia’s FSB hackers, known as Turla, have spent 25 years distinguishing themselves as “adversary number one.”

A Mysterious Group Has Ties to 15 Years of Ukraine-Russia Hacks

By Lily Hay Newman
Kaspersky researchers have uncovered clues that further illuminate the hackers’ activities, which appear to have begun far earlier than originally believed.

ChatGPT Scams Are Infiltrating Apple's App Store and Google Play

By Lily Hay Newman
An explosion of interest in OpenAI’s sophisticated chatbot means a proliferation of “fleeceware” apps that trick users with sneaky in-app subscriptions.

Toyota Leaked Vehicle Data of 2 Million Customers

By Dhruv Mehrotra, Andrew Couts
The FBI disables notorious Russia-linked malware, the EU edges toward a facial recognition ban, and security firm Dragos has an intrusion of its own.

A Republican-Led Lawsuit Threatens Critical US Cyber Protections

By Eric Geller
Three states are suing to block security rules for water facilities. If they win, it may open the floodgates for challenges to other cyber rules.

A Mysterious New Hacker Group, Red Stinger, Is Lurking in Ukraine’s Cyberspace

By Lily Hay Newman
The unidentified attackers have targeted people on both sides of Russia’s war against Ukraine, carrying out espionage operations that suggest state funding.

The Team of Sleuths Quietly Hunting Cyberattack-for-Hire Services

By Andy Greenberg
For a decade, a group called Big Pipes has worked behind the scenes with the FBI to target the worst cybercriminal “booter” services plaguing the internet.

Russian ‘Ghost Ships’ Identified Near the Nord Stream Blasts

By Matt Burgess
Plus: Apple and Google plan to stop AirTag stalking, Meta violated the FTC’s privacy order, and how to tell if your car is tracking you.

Meta Moves to Counter New Malware and Repeat Account Takeovers

By Lily Hay Newman
The company is adding new tools as bad actors use ChatGPT-themed lures and mask their infrastructure in an attempt to trick victims and elude defenders.

Doctors Behind Mifepristone Ban Called ‘Christians’ a Top Threat

By Dell Cameron, Dhruv Mehrotra
Leaked documents reveal that the American College of Pediatricians viewed “mainstream medicine” and “nominal Christians” as its opposition.

American College of Pediatricians Leak Exposes 10,000 Confidential Files

By Dell Cameron, Dhruv Mehrotra
A Google Drive left public on the American College of Pediatricians’ website exposed detailed financial records, sensitive member details, and more.

Cops Just Revealed a Record-Breaking Dark Web Dragnet

By Andy Greenberg
Operation SpecTor likely drew on leads from multiple dark web market busts, including the secret takedown of Monopoly Market in 2021.

SolarWinds: The Untold Story of the Boldest Supply-Chain Hack

By Kim Zetter
The attackers were in thousands of corporate and government networks. They might still be there now. Behind the scenes of the SolarWinds investigation.

Apple, Google, and Microsoft Just Fixed Zero-Day Security Flaws

By Kate O'Flaherty
Firefox gets a needed tune-up, SolarWinds squashes two high-severity bugs, Oracle patches 433 vulnerabilities, and more updates you should make now.

DOJ Detected SolarWinds Breach Months Before Public Disclosure

By Kim Zetter
In May 2020, the US Department of Justice noticed Russian hackers in its network but did not realize the significance of what it had found for six months.

NSA Cybersecurity Director Says ‘Buckle Up’ for Generative AI

By Lily Hay Newman
The security issues raised by ChatGPT and similar tech are just beginning to emerge, but Rob Joyce says it’s time to prepare for what comes next.
❌