FreshRSS

🔒
☐ ☆ ✇ The Hacker News

Chinese Hackers Exploited New Zero-Day in Barracuda's ESG Appliances

By Newsroom — December 27th 2023 at 12:35
Barracuda has revealed that Chinese threat actors exploited a new zero-day in its Email Security Gateway (ESG) appliances to deploy backdoors on a "limited number" of devices. Tracked as CVE-2023-7102, the issue relates to a case of arbitrary code execution that resides within a third-party and open-source library named Spreadsheet::ParseExcel that's used by the Amavis scanner
☐ ☆ ✇ WIRED

Facebook Marketplace Is Being Ruined by Zelle Scammers

By Amanda Hoover — December 22nd 2023 at 12:00
I tried to sell a futon on Facebook Marketplace and nearly all I got were scammers.
☐ ☆ ✇ WIRED

A Major Ransomware Takedown Suffers a Strange Setback

By Lily Hay Newman — December 19th 2023 at 19:34
After an 18-month rampage, global law enforcement finally moved against the notorious Alphv/BlackCat ransomware group. Within hours, the operation faced obstacles.
☐ ☆ ✇ The Hacker News

MongoDB Suffers Security Breach, Exposing Customer Data

By Newsroom — December 17th 2023 at 04:48
MongoDB on Saturday disclosed it's actively investigating a security incident that has led to unauthorized access to "certain" corporate systems, resulting in the exposure of customer account metadata and contact information. The American database software company said it first detected anomalous activity on December 13, 2023, and that it immediately activated its incident response
☐ ☆ ✇ WIRED

Google Just Denied Cops a Key Surveillance Tool

By Andy Greenberg, Lily Hay Newman — December 16th 2023 at 14:00
Plus: Apple tightens anti-theft protections, Chinese hackers penetrate US critical infrastructure, and the long-running rumor of eavesdropping phones crystallizes into more than an urban legend.
☐ ☆ ✇ WIRED

McDonald’s Ice Cream Machine Hackers Say They Found the ‘Smoking Gun’ That Killed Their Startup

By Andy Greenberg — December 14th 2023 at 22:59
Kytch, the company that tried to fix McDonald’s broken ice cream machines, has unearthed a 3-year-old email it says proves claims of an alleged plot to undermine their business.
☐ ☆ ✇ WIRED

Microsoft’s Digital Crime Unit Goes Deep on How It Disrupts Cybercrime

By Lily Hay Newman — December 14th 2023 at 17:22
Ten years in, Microsoft’s DCU has honed its strategy of using both unique legal tactics and the company’s technical reach to disrupt global cybercrime and state-backed actors.
☐ ☆ ✇ WIRED

Hacker Group Linked to Russian Military Claims Credit for Cyberattack on Kyivstar

By Andy Greenberg — December 13th 2023 at 15:56
A hacker group calling itself Solntsepek—previously linked to Russia’s notorious Sandworm hackers—says it carried out a disruptive breach of Kyivstar, a major Ukrainian mobile and internet provider.
☐ ☆ ✇ The Hacker News

New MrAnon Stealer Malware Targeting German Users via Booking-Themed Scam

By Newsroom — December 12th 2023 at 09:55
A phishing campaign has been observed delivering an information stealer malware called MrAnon Stealer to unsuspecting victims via seemingly benign booking-themed PDF lures. "This malware is a Python-based information stealer compressed with cx-Freeze to evade detection," Fortinet FortiGuard Labs researcher Cara Lin said. "MrAnon Stealer steals its victims' credentials, system
☐ ☆ ✇ The Hacker News

Researchers Unveil GuLoader Malware's Latest Anti-Analysis Techniques

By Newsroom — December 9th 2023 at 07:16
Threat hunters have unmasked the latest tricks adopted by a malware strain called GuLoader in an effort to make analysis more challenging. "While GuLoader's core functionality hasn't changed drastically over the past few years, these constant updates in their obfuscation techniques make analyzing GuLoader a time-consuming and resource-intensive process," Elastic Security Labs
☐ ☆ ✇ The Hacker News

Qualcomm Releases Details on Chip Vulnerabilities Exploited in Targeted Attacks

By Newsroom — December 6th 2023 at 05:23
Chipmaker Qualcomm has released more information about three high-severity security flaws that it said came under "limited, targeted exploitation" back in October 2023. The vulnerabilities are as follows - CVE-2023-33063 (CVSS score: 7.8) - Memory corruption in DSP Services during a remote call from HLOS to DSP. CVE-2023-33106 (CVSS score: 8.4) - Memory corruption in
☐ ☆ ✇ WIRED

The 23andMe Data Breach Keeps Spiraling

By Lily Hay Newman — December 5th 2023 at 23:54
23andMe has provided more information about the scope and scale of its recent breach, but with these details come more unanswered questions.
☐ ☆ ✇ WIRED

A New Trick Uses AI to Jailbreak AI Models—Including GPT-4

By Will Knight — December 5th 2023 at 11:00
Adversarial algorithms can systematically probe large language models like OpenAI’s GPT-4 for weaknesses that can make them misbehave.
☐ ☆ ✇ WIRED

ChatGPT Spit Out Sensitive Data When Told to Repeat ‘Poem’ Forever

By Lily Hay Newman, Andy Greenberg — December 2nd 2023 at 14:00
Plus: A major ransomware crackdown, the arrest of Ukraine’s cybersecurity chief, and a hack-for-hire entrepreneur charged with attempted murder.
☐ ☆ ✇ The Hacker News

Agent Racoon Backdoor Targets Organizations in Middle East, Africa, and U.S.

By Newsroom — December 2nd 2023 at 08:29
Organizations in the Middle East, Africa, and the U.S. have been targeted by an unknown threat actor to distribute a new backdoor called Agent Racoon. "This malware family is written using the .NET framework and leverages the domain name service (DNS) protocol to create a covert channel and provide different backdoor functionalities," Palo Alto Networks Unit 42 researcher Chema Garcia 
☐ ☆ ✇ WIRED

Google Fixes a Seventh Zero-Day Flaw in Chrome—Update Now

By Kate O'Flaherty — November 30th 2023 at 15:42
Plus: Major security patches from Microsoft, Mozilla, Atlassian, Cisco, and more.
☐ ☆ ✇ The Hacker News

North Korea's Lazarus Group Rakes in $3 Billion from Cryptocurrency Hacks

By Newsroom — November 30th 2023 at 11:55
Threat actors from the Democratic People's Republic of Korea (DPRK) are increasingly targeting the cryptocurrency sector as a major revenue generation mechanism since at least 2017 to get around sanctions imposed against the country. "Even though movement in and out of and within the country is heavily restricted, and its general population is isolated from the rest of the world, the
☐ ☆ ✇ WIRED

Okta Breach Impacted All Customer Support Users—Not 1 Percent

By Lily Hay Newman — November 29th 2023 at 15:53
Okta upped its original estimate of customer support users affected by a recent breach from 1 percent to 100 percent, citing a “discrepancy.”
☐ ☆ ✇ WIRED

OpenAI’s Custom Chatbots Are Leaking Their Secrets

By Matt Burgess — November 29th 2023 at 12:00
Released earlier this month, OpenAI’s GPTs let anyone create custom chatbots. But some of the data they’re built on is easily exposed.
☐ ☆ ✇ WIRED

Cybersecurity Industry Baffled by FBI’s Lack of Action on Ransomware Gang

By Andy Greenberg, Andrew Couts — December 17th 2023 at 01:02
Plus: Hackers reveal flaws in crypto wallets holding $1 billion, a massive breach of Danish electric utilities, and more.
☐ ☆ ✇ WIRED

Inside the Race to Secure the F1 Las Vegas Grand Prix

By Lily Hay Newman — November 18th 2023 at 12:00
Beyond the blinding speeds and sharp turns on new terrain, the teams at this weekend’s big F1 race are preparing for another kind of danger.
☐ ☆ ✇ The Hacker News

27 Malicious PyPI Packages with Thousands of Downloads Found Targeting IT Experts

By Newsroom — November 17th 2023 at 09:56
An unknown threat actor has been observed publishing typosquat packages to the Python Package Index (PyPI) repository for nearly six months with an aim to deliver malware capable of gaining persistence, stealing sensitive data, and accessing cryptocurrency wallets for financial gain. The 27 packages, which masqueraded as popular legitimate Python libraries, attracted thousands of downloads,
☐ ☆ ✇ WIRED

A Spy Agency Leaked People's Data Online—Then the Data Was Stolen

By Matt Burgess — November 16th 2023 at 11:00
The National Telecommunication Monitoring Center in Bangladesh exposed a database to the open web. The types of data leaked online are extensive.
☐ ☆ ✇ WIRED

Google’s New Titan Security Key Adds Another Piece to the Password-Killing Puzzle

By Lily Hay Newman — November 15th 2023 at 18:15
The new generation of hardware authentication key includes support for cryptographic passkeys as Google pushes adoption of the more secure login alternative.
☐ ☆ ✇ WIRED

CISA Has a New Road Map for Handling Weaponized AI

By Lily Hay Newman — November 14th 2023 at 15:51
In its plans to implement a White House executive order, CISA aims to strike a balance between promoting AI adoption for national security and defending against its malicious use.
☐ ☆ ✇ WIRED

The Mirai Confessions: Three Young Hackers Who Built a Web-Killing Monster Finally Tell Their Story

By Andy Greenberg — November 14th 2023 at 11:00
Netflix, Spotify, Twitter, PayPal, Slack. All down for millions of people. How a group of teen friends plunged into an underworld of cybercrime and broke the internet—then went to work for the FBI.
☐ ☆ ✇ WIRED

Sandworm Hackers Caused Another Blackout in Ukraine—During a Missile Strike

By Andy Greenberg — November 9th 2023 at 08:00
Russia's most notorious military hackers successfully sabotaged Ukraine's power grid for the third time last year. And in this case, the blackout coincided with a physical attack.
☐ ☆ ✇ WIRED

This Cheap Hacking Device Can Crash Your iPhone With Pop-Ups

By Matt Burgess — November 4th 2023 at 13:00
Plus: SolarWinds is charged with fraud, New Orleans police face recognition has flaws, and new details about Okta’s October data breach emerge.
☐ ☆ ✇ WIRED

Microsoft Does Damage Control With Its New 'Secure Future Initiative'

By Lily Hay Newman — November 2nd 2023 at 15:00
Following a string of serious security incidents, Microsoft says it has a plan to deal with escalating threats from cybercriminals and state-backed hackers.
☐ ☆ ✇ WIRED

This Cryptomining Tool Is Stealing Secrets

By Lily Hay Newman — October 28th 2023 at 13:00
Plus: Details emerge of a US government social media-scanning tool that flags “derogatory” speech, and researchers find vulnerabilities in the global mobile communications network.
☐ ☆ ✇ WIRED

Okta's Latest Security Breach Is Haunted by the Ghost of Incidents Past

By Lily Hay Newman — October 25th 2023 at 17:40
A recent breach of authentication giant Okta has impacted nearly 200 of its clients. But repeated incidents and the company’s delayed disclosure have security experts calling foul.
☐ ☆ ✇ WIRED

They Cracked the Code to a Locked USB Drive Worth $235 Million in Bitcoin. Then It Got Weird

By Andy Greenberg — October 24th 2023 at 10:00
Stefan Thomas lost the password to an encrypted USB drive holding 7,002 bitcoins. One team of hackers believes they can unlock it—if they can get Thomas to let them.
☐ ☆ ✇ The Hacker News

Quasar RAT Leverages DLL Side-Loading to Fly Under the Radar

By Newsroom — October 23rd 2023 at 07:58
The open-source remote access trojan known as Quasar RAT has been observed leveraging DLL side-loading to fly under the radar and stealthily siphon data from compromised Windows hosts. "This technique capitalizes on the inherent trust these files command within the Windows environment," Uptycs researchers Tejaswini Sandapolla and Karthickkumar Kathiresan said in a report published last week,
☐ ☆ ✇ WIRED

The 23andMe User Data Leak May Be Far Worse Than Believed

By Andrew Couts — October 21st 2023 at 13:00
Plus: IT workers secretly funnel money to North Korea, a court in the US upholds keyword search warrants, and WhatsApp gets a passwordless upgrade on Android
☐ ☆ ✇ WIRED

HTTP/2 Rapid Reset: A New Protocol Vulnerability Will Haunt the Web for Years

By Lily Hay Newman — October 13th 2023 at 11:00
Dubbed “HTTP/2 Rapid Reset,” the flaw requires issuing patches to virtually every web server around the world before the problem can be eradicated.
☐ ☆ ✇ WIRED

New Clues Suggest Stolen FTX Funds Went to Russia-Linked Money Launderers

By Andy Greenberg — October 12th 2023 at 12:00
Whoever looted FTX on the day of its bankruptcy has now moved the stolen money through a long string of intermediaries—and eventually some that look Russian in origin.
☐ ☆ ✇ WIRED

Activist Hackers Are Racing Into the Israel-Hamas War—for Both Sides

By Lily Hay Newman, Matt Burgess — October 9th 2023 at 22:21
Since the conflict escalated, hackers have targeted dozens of government websites and media outlets with defacements and DDoS attacks, and attempted to overload targets with junk traffic to bring them down.
☐ ☆ ✇ WIRED

Inside FTX’s All-Night Race to Stop a $1 Billion Crypto Heist

By Andy Greenberg — October 9th 2023 at 10:00
The same chaotic day FTX declared bankruptcy, someone began stealing hundreds of millions of dollars from its coffers. A WIRED investigation reveals the company’s “very crazy night” trying to stop them.
☐ ☆ ✇ WIRED

Apple's Encryption Is Under Attack by a Mysterious Group

By Andrew Couts — October 7th 2023 at 13:00
Plus: Sony confirms a breach of its networks, US federal agents get caught illegally using phone location data, and more.
☐ ☆ ✇ WIRED

23andMe User Data Stolen in Targeted Attack on Ashkenazi Jews

By Lily Hay Newman — October 6th 2023 at 21:53
At least a million data points from 23andMe accounts appear to have been exposed on BreachForums. While the scale of the campaign is unknown, 23andMe says it's working to verify the data.
☐ ☆ ✇ WIRED

Your Cheap Android TV Streaming Box May Have a Dangerous Backdoor

By Matt Burgess — October 4th 2023 at 10:00
New research has found that some streaming devices and dozens of Android and iOS apps are secretly being used for fraud and other cybercrime.
☐ ☆ ✇ WIRED

The Biggest Hack of 2023 Keeps Getting Bigger

By Lily Hay Newman, Matt Burgess — October 2nd 2023 at 15:07
Victims of the MOVEit breach continue to come forward. But the full scale of the attack is still unknown.
☐ ☆ ✇ WIRED

Chinese Hackers Are Hiding in Routers in the US and Japan

By Lily Hay Newman, Matt Burgess — September 30th 2023 at 13:00
Plus: Stolen US State Department emails, $20 million zero-day flaws, and controversy over the EU’s message-scanning law.
☐ ☆ ✇ WIRED

Apple, Microsoft, and Google Just Fixed Multiple Zero-Day Flaws

By Kate O'Flaherty — September 30th 2023 at 11:00
Plus: Mozilla patches 10 Firefox bugs, Cisco fixes a vulnerability with a rare maximum severity score, and SAP releases updates to stamp out three highly critical flaws.
☐ ☆ ✇ WIRED

A Tricky New Way to Sneak Past Repressive Internet Censorship

By Justin Ling — September 25th 2023 at 11:00
With the number of internet blackouts on the rise, cybersecurity firm eQualitie figured out how to hide censored online news in satellite TV signals.
☐ ☆ ✇ WIRED

The Shocking Data on Kia and Hyundai Thefts in the US

By Lily Hay Newman — September 23rd 2023 at 13:00
Plus: MGM hackers hit more than just casinos, Microsoft researchers accidentally leak terabytes of data, and China goes on the PR offensive over cyberespionage.
☐ ☆ ✇ WIRED

Chinese Spies Infected Dozens of Networks With Thumb Drive Malware

By Andy Greenberg — September 19th 2023 at 14:00
Security researchers found USB-based Sogu espionage malware spreading within African operations of European and US firms.
☐ ☆ ✇ WIRED

You Need to Update Google Chrome or Whatever Browser You Use

By Andrew Couts — September 16th 2023 at 13:00
Plus: Spyware-packing ads, TikTok GDPR violations, Elon Musk investigations, and more.
☐ ☆ ✇ WIRED

Massive MGM and Caesars Hacks Epitomize a Vicious Ransomware Cycle

By Lily Hay Newman — September 16th 2023 at 11:00
Cyberattacks on casinos grab attention, but a steady stream of less publicized attacks leave vulnerable victims struggling to recover.
☐ ☆ ✇ WIRED

China-Linked Hackers Breached a Power Grid—Again

By Andy Greenberg — September 12th 2023 at 10:00
Signs suggest the culprits worked within a notorious Chinese hacker group that may have also hacked Indian electric utilities years earlier.
☐ ☆ ✇ WIRED

Mozilla: Your New Car Is a Data Privacy Nightmare

By Dhruv Mehrotra, Andrew Couts — September 9th 2023 at 13:00
Plus: Apple patches newly discovered flaws exploited by NSO Group spyware, North Korean hackers target security researchers, and more.
☐ ☆ ✇ WIRED

US and UK Mount Aggressive Crackdown on Trickbot and Conti Ransomware Gangs

By Lily Hay Newman — September 7th 2023 at 18:38
Authorities have sanctioned 11 alleged members of the cybercriminal groups, while the US Justice Department unsealed three federal indictments against nine people accused of being members.
☐ ☆ ✇ WIRED

The International Criminal Court Will Now Prosecute Cyberwar Crimes

By Andy Greenberg — September 7th 2023 at 16:19
And the first case on the docket may well be Russia’s cyberattacks against civilian critical infrastructure in Ukraine.
☐ ☆ ✇ WIRED

The Comedy of Errors That Let China-Backed Hackers Steal Microsoft’s Signing Key

By Lily Hay Newman — September 7th 2023 at 00:01
After leaving many questions unanswered, Microsoft explains in a new postmortem the series of slipups that allowed attackers to steal and abuse a valuable cryptographic key.
☐ ☆ ✇ WIRED

How China Demands Tech Firms Reveal Hackable Flaws in Their Products

By Andy Greenberg — September 6th 2023 at 13:00
Some foreign companies may be complying—potentially offering China’s spies hints for hacking their customers.
☐ ☆ ✇ WIRED

Generative AI’s Biggest Security Flaw Is Not Easy to Fix

By Matt Burgess — September 6th 2023 at 11:00
Chatbots like OpenAI’s ChatGPT and Google’s Bard are vulnerable to indirect prompt injection attacks. Security researchers say the holes can be plugged—sort of.
☐ ☆ ✇ The Hacker News

Ukraine's CERT Thwarts APT28's Cyberattack on Critical Energy Infrastructure

By THN — September 6th 2023 at 08:02
The Computer Emergency Response Team of Ukraine (CERT-UA) on Tuesday said it thwarted a cyber attack against an unnamed critical energy infrastructure facility in the country. The intrusion, per the agency, started with a phishing email containing a link to a malicious ZIP archive that activates the infection chain. “Visiting the link will download a ZIP archive containing three JPG images (
☐ ☆ ✇ WIRED

2 Polish Men Arrested for Radio Hack That Disrupted Trains

By Andy Greenberg, Andrew Couts — September 2nd 2023 at 13:00
Plus: A major FBI botnet takedown, new Sandworm malware, a cyberattack on two major scientific telescopes—and more.
☐ ☆ ✇ WIRED

Google Fixes Serious Security Flaws in Chrome and Android

By Kate O'Flaherty — August 31st 2023 at 11:00
Plus: Mozilla patches more than a dozen vulnerabilities in Firefox, and enterprise companies Ivanti, Cisco, and SAP roll out a slew of updates to get rid of some high-severity bugs.
☐ ☆ ✇ WIRED

Unmasking Trickbot, One of the World’s Top Cybercrime Gangs

By Matt Burgess, Lily Hay Newman — August 30th 2023 at 17:37
A WIRED investigation into a cache of documents posted by an unknown figure lays bare the Trickbot ransomware gang’s secrets, including the identity of a central member.
❌