FreshRSS

🔒
☐ ☆ ✇ WIRED

What It’s Like to Use Apple’s Lockdown Mode

By Lily Hay Newman — January 2nd 2024 at 12:00
If you're at high risk of being targeted by mercenary spyware, or just don't mind losing iOS features for extra security, the company's restricted mode is surprisingly usable.
☐ ☆ ✇ WIRED

Google Fixes Nearly 100 Android Security Issues

By Kate O'Flaherty — December 31st 2023 at 12:00
Plus: Apple shuts down a Flipper Zero Attack, Microsoft patches more than 30 vulnerabilities, and more critical updates for the last month of 2023.
☐ ☆ ✇ WIRED

The Worst Hacks of 2023

By Lily Hay Newman — December 29th 2023 at 12:00
It was a year of devastating cyberattacks around the globe, from ransomware attacks on casinos to state-sponsored breaches of critical infrastructure.
☐ ☆ ✇ WIRED

The Most Dangerous People on the Internet in 2023

By WIRED Staff — December 28th 2023 at 12:00
From Sam Altman and Elon Musk to ransomware gangs and state-backed hackers, these are the individuals and groups that spent this year disrupting the world we know it.
☐ ☆ ✇ WIRED

Facebook Marketplace Is Being Ruined by Zelle Scammers

By Amanda Hoover — December 22nd 2023 at 12:00
I tried to sell a futon on Facebook Marketplace and nearly all I got were scammers.
☐ ☆ ✇ WIRED

A Major Ransomware Takedown Suffers a Strange Setback

By Lily Hay Newman — December 19th 2023 at 19:34
After an 18-month rampage, global law enforcement finally moved against the notorious Alphv/BlackCat ransomware group. Within hours, the operation faced obstacles.
☐ ☆ ✇ WIRED

Google Just Denied Cops a Key Surveillance Tool

By Andy Greenberg, Lily Hay Newman — December 16th 2023 at 14:00
Plus: Apple tightens anti-theft protections, Chinese hackers penetrate US critical infrastructure, and the long-running rumor of eavesdropping phones crystallizes into more than an urban legend.
☐ ☆ ✇ WIRED

McDonald’s Ice Cream Machine Hackers Say They Found the ‘Smoking Gun’ That Killed Their Startup

By Andy Greenberg — December 14th 2023 at 22:59
Kytch, the company that tried to fix McDonald’s broken ice cream machines, has unearthed a 3-year-old email it says proves claims of an alleged plot to undermine their business.
☐ ☆ ✇ WIRED

Microsoft’s Digital Crime Unit Goes Deep on How It Disrupts Cybercrime

By Lily Hay Newman — December 14th 2023 at 17:22
Ten years in, Microsoft’s DCU has honed its strategy of using both unique legal tactics and the company’s technical reach to disrupt global cybercrime and state-backed actors.
☐ ☆ ✇ WIRED

Hacker Group Linked to Russian Military Claims Credit for Cyberattack on Kyivstar

By Andy Greenberg — December 13th 2023 at 15:56
A hacker group calling itself Solntsepek—previously linked to Russia’s notorious Sandworm hackers—says it carried out a disruptive breach of Kyivstar, a major Ukrainian mobile and internet provider.
☐ ☆ ✇ The Hacker News

SLAM Attack: New Spectre-based Vulnerability Impacts Intel, AMD, and Arm CPUs

By Newsroom — December 9th 2023 at 11:52
Researchers from the Vrije Universiteit Amsterdam have disclosed a new side-channel attack called SLAM that could be exploited to leak sensitive information from kernel memory on current and upcoming CPUs from Intel, AMD, and Arm. The attack is an end-to-end exploit for Spectre based on a new feature in Intel CPUs called Linear Address Masking (LAM) as well as its analogous
☐ ☆ ✇ WIRED

The 23andMe Data Breach Keeps Spiraling

By Lily Hay Newman — December 5th 2023 at 23:54
23andMe has provided more information about the scope and scale of its recent breach, but with these details come more unanswered questions.
☐ ☆ ✇ WIRED

A New Trick Uses AI to Jailbreak AI Models—Including GPT-4

By Will Knight — December 5th 2023 at 11:00
Adversarial algorithms can systematically probe large language models like OpenAI’s GPT-4 for weaknesses that can make them misbehave.
☐ ☆ ✇ The Hacker News

15,000 Go Module Repositories on GitHub Vulnerable to Repojacking Attack

By Newsroom — December 5th 2023 at 10:14
New research has found that over 15,000 Go module repositories on GitHub are vulnerable to an attack called repojacking. "More than 9,000 repositories are vulnerable to repojacking due to GitHub username changes," Jacob Baines, chief technology officer at VulnCheck, said in a report shared with The Hacker News. "More than 6,000 repositories were vulnerable to repojacking due to account
☐ ☆ ✇ WIRED

ChatGPT Spit Out Sensitive Data When Told to Repeat ‘Poem’ Forever

By Lily Hay Newman, Andy Greenberg — December 2nd 2023 at 14:00
Plus: A major ransomware crackdown, the arrest of Ukraine’s cybersecurity chief, and a hack-for-hire entrepreneur charged with attempted murder.
☐ ☆ ✇ The Hacker News

Discover How Gcore Thwarted Powerful 1.1Tbps and 1.6Tbps DDoS Attacks

By The Hacker News — December 1st 2023 at 10:26
The most recent Gcore Radar report and its aftermath have highlighted a dramatic increase in DDoS attacks across multiple industries. At the beginning of 2023, the average strength of attacks reached 800 Gbps, but now, even a peak as high as 1.5+ Tbps is unsurprising. To try and break through Gcore’s defenses, perpetrators made two attempts with two different strategies.
☐ ☆ ✇ WIRED

Google Fixes a Seventh Zero-Day Flaw in Chrome—Update Now

By Kate O'Flaherty — November 30th 2023 at 15:42
Plus: Major security patches from Microsoft, Mozilla, Atlassian, Cisco, and more.
☐ ☆ ✇ The Hacker News

North Korea's Lazarus Group Rakes in $3 Billion from Cryptocurrency Hacks

By Newsroom — November 30th 2023 at 11:55
Threat actors from the Democratic People's Republic of Korea (DPRK) are increasingly targeting the cryptocurrency sector as a major revenue generation mechanism since at least 2017 to get around sanctions imposed against the country. "Even though movement in and out of and within the country is heavily restricted, and its general population is isolated from the rest of the world, the
☐ ☆ ✇ WIRED

Okta Breach Impacted All Customer Support Users—Not 1 Percent

By Lily Hay Newman — November 29th 2023 at 15:53
Okta upped its original estimate of customer support users affected by a recent breach from 1 percent to 100 percent, citing a “discrepancy.”
☐ ☆ ✇ WIRED

OpenAI’s Custom Chatbots Are Leaking Their Secrets

By Matt Burgess — November 29th 2023 at 12:00
Released earlier this month, OpenAI’s GPTs let anyone create custom chatbots. But some of the data they’re built on is easily exposed.
☐ ☆ ✇ The Hacker News

Key Cybercriminals Behind Notorious Ransomware Families Arrested in Ukraine

By Newsroom — November 28th 2023 at 10:33
A coordinated law enforcement operation has led to the arrest of key individuals in Ukraine who are alleged to be a part of several ransomware schemes. "On 21 November, 30 properties were searched in the regions of Kyiv, Cherkasy, Rivne, and Vinnytsia, resulting in the arrest of the 32-year-old ringleader," Europol said in a statement today. "Four of the ringleader's most active
☐ ☆ ✇ The Hacker News

North Korean Hackers Pose as Job Recruiters and Seekers in Malware Campaigns

By Newsroom — November 22nd 2023 at 12:14
North Korean threat actors have been linked to two campaigns in which they masquerade as both job recruiters and seekers to distribute malware and obtain unauthorized employment with organizations based in the U.S. and other parts of the world. The activity clusters have been codenamed Contagious Interview and Wagemole, respectively, by Palo Alto Networks Unit 42. While the first set of attacks
☐ ☆ ✇ The Hacker News

Indian Hack-for-Hire Group Targeted U.S., China, and More for Over 10 Years

By Newsroom — November 20th 2023 at 06:42
An Indian hack-for-hire group targeted the U.S., China, Myanmar, Pakistan, Kuwait, and other countries as part of a wide-ranging espionage, surveillance, and disruptive operation for over a decade. The Appin Software Security (aka Appin Security Group), according to an in-depth analysis from SentinelOne, began as an educational startup offering offensive security training programs, while
☐ ☆ ✇ WIRED

Cybersecurity Industry Baffled by FBI’s Lack of Action on Ransomware Gang

By Andy Greenberg, Andrew Couts — December 17th 2023 at 01:02
Plus: Hackers reveal flaws in crypto wallets holding $1 billion, a massive breach of Danish electric utilities, and more.
☐ ☆ ✇ WIRED

Inside the Race to Secure the F1 Las Vegas Grand Prix

By Lily Hay Newman — November 18th 2023 at 12:00
Beyond the blinding speeds and sharp turns on new terrain, the teams at this weekend’s big F1 race are preparing for another kind of danger.
☐ ☆ ✇ The Hacker News

CISA and FBI Issue Warning About Rhysida Ransomware Double Extortion Attacks

By Newsroom — November 16th 2023 at 12:03
The threat actors behind the Rhysida ransomware engage in opportunistic attacks targeting organizations spanning various industry sectors. The advisory comes courtesy of the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Multi-State Information Sharing and Analysis Center (MS-ISAC). "Observed as a ransomware-as-a-service (RaaS)
☐ ☆ ✇ WIRED

A Spy Agency Leaked People's Data Online—Then the Data Was Stolen

By Matt Burgess — November 16th 2023 at 11:00
The National Telecommunication Monitoring Center in Bangladesh exposed a database to the open web. The types of data leaked online are extensive.
☐ ☆ ✇ WIRED

Google’s New Titan Security Key Adds Another Piece to the Password-Killing Puzzle

By Lily Hay Newman — November 15th 2023 at 18:15
The new generation of hardware authentication key includes support for cryptographic passkeys as Google pushes adoption of the more secure login alternative.
☐ ☆ ✇ WIRED

CISA Has a New Road Map for Handling Weaponized AI

By Lily Hay Newman — November 14th 2023 at 15:51
In its plans to implement a White House executive order, CISA aims to strike a balance between promoting AI adoption for national security and defending against its malicious use.
☐ ☆ ✇ WIRED

The Mirai Confessions: Three Young Hackers Who Built a Web-Killing Monster Finally Tell Their Story

By Andy Greenberg — November 14th 2023 at 11:00
Netflix, Spotify, Twitter, PayPal, Slack. All down for millions of people. How a group of teen friends plunged into an underworld of cybercrime and broke the internet—then went to work for the FBI.
☐ ☆ ✇ WIRED

Sandworm Hackers Caused Another Blackout in Ukraine—During a Missile Strike

By Andy Greenberg — November 9th 2023 at 08:00
Russia's most notorious military hackers successfully sabotaged Ukraine's power grid for the third time last year. And in this case, the blackout coincided with a physical attack.
☐ ☆ ✇ WIRED

This Cheap Hacking Device Can Crash Your iPhone With Pop-Ups

By Matt Burgess — November 4th 2023 at 13:00
Plus: SolarWinds is charged with fraud, New Orleans police face recognition has flaws, and new details about Okta’s October data breach emerge.
☐ ☆ ✇ WIRED

Microsoft Does Damage Control With Its New 'Secure Future Initiative'

By Lily Hay Newman — November 2nd 2023 at 15:00
Following a string of serious security incidents, Microsoft says it has a plan to deal with escalating threats from cybercriminals and state-backed hackers.
☐ ☆ ✇ WIRED

This Cryptomining Tool Is Stealing Secrets

By Lily Hay Newman — October 28th 2023 at 13:00
Plus: Details emerge of a US government social media-scanning tool that flags “derogatory” speech, and researchers find vulnerabilities in the global mobile communications network.
☐ ☆ ✇ The Hacker News

iLeakage: New Safari Exploit Impacts Apple iPhones and Macs with A- and M-Series CPUs

By Newsroom — October 26th 2023 at 16:49
A group of academics has devised a novel side-channel attack dubbed iLeakage that exploits a weakness in the A- and M-series CPUs running on Apple iOS, iPadOS, and macOS devices, enabling the extraction of sensitive information from the Safari web browser. "An attacker can induce Safari to render an arbitrary webpage, subsequently recovering sensitive information present within it using
☐ ☆ ✇ The Hacker News

Record-Breaking 100 Million RPS DDoS Attack Exploits HTTP/2 Rapid Reset Flaw

By Newsroom — October 26th 2023 at 13:00
Cloudflare on Thursday said it mitigated thousands of hyper-volumetric HTTP distributed denial-of-service (DDoS) attacks that exploited a recently disclosed flaw called HTTP/2 Rapid Reset, 89 of which exceeded 100 million requests per second (RPS). "The campaign contributed to an overall increase of 65% in HTTP DDoS attack traffic in Q3 compared to the previous quarter," the web infrastructure
☐ ☆ ✇ The Hacker News

Iranian Group Tortoiseshell Launches New Wave of IMAPLoader Malware Attacks

By Newsroom — October 26th 2023 at 07:24
The Iranian threat actor known as Tortoiseshell has been attributed to a new wave of watering hole attacks that are designed to deploy a malware dubbed IMAPLoader. "IMAPLoader is a .NET malware that has the ability to fingerprint victim systems using native Windows utilities and acts as a downloader for further payloads," the PwC Threat Intelligence team said in a Wednesday analysis. "It uses
☐ ☆ ✇ WIRED

Okta's Latest Security Breach Is Haunted by the Ghost of Incidents Past

By Lily Hay Newman — October 25th 2023 at 17:40
A recent breach of authentication giant Okta has impacted nearly 200 of its clients. But repeated incidents and the company’s delayed disclosure have security experts calling foul.
☐ ☆ ✇ The Hacker News

Nation State Hackers Exploiting Zero-Day in Roundcube Webmail Software

By Newsroom — October 25th 2023 at 13:20
The threat actor known as Winter Vivern has been observed exploiting a zero-day flaw in Roundcube webmail software on October 11, 2023, to harvest email messages from victims' accounts. "Winter Vivern has stepped up its operations by using a zero-day vulnerability in Roundcube," ESET security researcher Matthieu Faou said in a new report published today. Previously, it was using known
☐ ☆ ✇ WIRED

They Cracked the Code to a Locked USB Drive Worth $235 Million in Bitcoin. Then It Got Weird

By Andy Greenberg — October 24th 2023 at 10:00
Stefan Thomas lost the password to an encrypted USB drive holding 7,002 bitcoins. One team of hackers believes they can unlock it—if they can get Thomas to let them.
☐ ☆ ✇ WIRED

The 23andMe User Data Leak May Be Far Worse Than Believed

By Andrew Couts — October 21st 2023 at 13:00
Plus: IT workers secretly funnel money to North Korea, a court in the US upholds keyword search warrants, and WhatsApp gets a passwordless upgrade on Android
☐ ☆ ✇ WIRED

HTTP/2 Rapid Reset: A New Protocol Vulnerability Will Haunt the Web for Years

By Lily Hay Newman — October 13th 2023 at 11:00
Dubbed “HTTP/2 Rapid Reset,” the flaw requires issuing patches to virtually every web server around the world before the problem can be eradicated.
☐ ☆ ✇ WIRED

New Clues Suggest Stolen FTX Funds Went to Russia-Linked Money Launderers

By Andy Greenberg — October 12th 2023 at 12:00
Whoever looted FTX on the day of its bankruptcy has now moved the stolen money through a long string of intermediaries—and eventually some that look Russian in origin.
☐ ☆ ✇ WIRED

Activist Hackers Are Racing Into the Israel-Hamas War—for Both Sides

By Lily Hay Newman, Matt Burgess — October 9th 2023 at 22:21
Since the conflict escalated, hackers have targeted dozens of government websites and media outlets with defacements and DDoS attacks, and attempted to overload targets with junk traffic to bring them down.
☐ ☆ ✇ WIRED

Inside FTX’s All-Night Race to Stop a $1 Billion Crypto Heist

By Andy Greenberg — October 9th 2023 at 10:00
The same chaotic day FTX declared bankruptcy, someone began stealing hundreds of millions of dollars from its coffers. A WIRED investigation reveals the company’s “very crazy night” trying to stop them.
☐ ☆ ✇ WIRED

Apple's Encryption Is Under Attack by a Mysterious Group

By Andrew Couts — October 7th 2023 at 13:00
Plus: Sony confirms a breach of its networks, US federal agents get caught illegally using phone location data, and more.
☐ ☆ ✇ WIRED

23andMe User Data Stolen in Targeted Attack on Ashkenazi Jews

By Lily Hay Newman — October 6th 2023 at 21:53
At least a million data points from 23andMe accounts appear to have been exposed on BreachForums. While the scale of the campaign is unknown, 23andMe says it's working to verify the data.
☐ ☆ ✇ WIRED

Your Cheap Android TV Streaming Box May Have a Dangerous Backdoor

By Matt Burgess — October 4th 2023 at 10:00
New research has found that some streaming devices and dozens of Android and iOS apps are secretly being used for fraud and other cybercrime.
☐ ☆ ✇ WIRED

The Biggest Hack of 2023 Keeps Getting Bigger

By Lily Hay Newman, Matt Burgess — October 2nd 2023 at 15:07
Victims of the MOVEit breach continue to come forward. But the full scale of the attack is still unknown.
☐ ☆ ✇ WIRED

Chinese Hackers Are Hiding in Routers in the US and Japan

By Lily Hay Newman, Matt Burgess — September 30th 2023 at 13:00
Plus: Stolen US State Department emails, $20 million zero-day flaws, and controversy over the EU’s message-scanning law.
☐ ☆ ✇ WIRED

Apple, Microsoft, and Google Just Fixed Multiple Zero-Day Flaws

By Kate O'Flaherty — September 30th 2023 at 11:00
Plus: Mozilla patches 10 Firefox bugs, Cisco fixes a vulnerability with a rare maximum severity score, and SAP releases updates to stamp out three highly critical flaws.
☐ ☆ ✇ WIRED

A Tricky New Way to Sneak Past Repressive Internet Censorship

By Justin Ling — September 25th 2023 at 11:00
With the number of internet blackouts on the rise, cybersecurity firm eQualitie figured out how to hide censored online news in satellite TV signals.
☐ ☆ ✇ WIRED

The Shocking Data on Kia and Hyundai Thefts in the US

By Lily Hay Newman — September 23rd 2023 at 13:00
Plus: MGM hackers hit more than just casinos, Microsoft researchers accidentally leak terabytes of data, and China goes on the PR offensive over cyberespionage.
☐ ☆ ✇ WIRED

Chinese Spies Infected Dozens of Networks With Thumb Drive Malware

By Andy Greenberg — September 19th 2023 at 14:00
Security researchers found USB-based Sogu espionage malware spreading within African operations of European and US firms.
☐ ☆ ✇ WIRED

You Need to Update Google Chrome or Whatever Browser You Use

By Andrew Couts — September 16th 2023 at 13:00
Plus: Spyware-packing ads, TikTok GDPR violations, Elon Musk investigations, and more.
☐ ☆ ✇ WIRED

Massive MGM and Caesars Hacks Epitomize a Vicious Ransomware Cycle

By Lily Hay Newman — September 16th 2023 at 11:00
Cyberattacks on casinos grab attention, but a steady stream of less publicized attacks leave vulnerable victims struggling to recover.
☐ ☆ ✇ WIRED

China-Linked Hackers Breached a Power Grid—Again

By Andy Greenberg — September 12th 2023 at 10:00
Signs suggest the culprits worked within a notorious Chinese hacker group that may have also hacked Indian electric utilities years earlier.
☐ ☆ ✇ WIRED

Mozilla: Your New Car Is a Data Privacy Nightmare

By Dhruv Mehrotra, Andrew Couts — September 9th 2023 at 13:00
Plus: Apple patches newly discovered flaws exploited by NSO Group spyware, North Korean hackers target security researchers, and more.
☐ ☆ ✇ WIRED

US and UK Mount Aggressive Crackdown on Trickbot and Conti Ransomware Gangs

By Lily Hay Newman — September 7th 2023 at 18:38
Authorities have sanctioned 11 alleged members of the cybercriminal groups, while the US Justice Department unsealed three federal indictments against nine people accused of being members.
☐ ☆ ✇ WIRED

The International Criminal Court Will Now Prosecute Cyberwar Crimes

By Andy Greenberg — September 7th 2023 at 16:19
And the first case on the docket may well be Russia’s cyberattacks against civilian critical infrastructure in Ukraine.
❌