27 Dec Hackers steal $8 million from users running trojanized BitKeep apps Multiple BitKeep crypto wallet users reported that their wallets were emptied during Christmas after hackers triggered transactions that didn’t require verification. […]
27 Dec EarSpy attack eavesdrops on Android phones via motion sensors A team of researchers has developed an eavesdropping attack for Android devices that can, to various degrees, recognize the caller’s gender and identity, and even discern private speech. […]
26 Dec Hacker claims to be selling Twitter data of 400 million users A threat actor claims to be selling public and private data of 400 million Twitter users scraped in 2021 using a now-fixed API vulnerability. They’re asking $200,000 for an exclusive sale. […]
24 Dec New info-stealer malware infects software pirates via fake cracks sites A new information-stealing malware named ‘RisePro’ is being distributed through fake cracks sites operated by the PrivateLoader pay-per-install (PPI) malware distribution service. […]
23 Dec The Week in Ransomware – December 23rd 2022 – Targeting Microsoft Exchange Reports this week illustrate how threat actors consider Microsoft Exchange as a prime target for gaining initial access to corporate networks to steal data and deploy ransomware. […]
23 Dec Hackers exploit bug in WordPress gift card plugin with 50K installs Hackers are actively targeting a critical flaw in YITH WooCommerce Gift Cards Premium, a WordPress plugin used on over 50,000 websites. […]
23 Dec Massive Twitter data leak investigated by EU privacy watchdog The Irish Data Protection Commission (DPC) has launched an inquiry following last month’s news reports of a massive Twitter data leak. […]
23 Dec Ghost CMS vulnerable to critical authentication bypass flaw A critical vulnerability in the Ghost CMS newsletter subscription system could allow external users to create newsletters or modify existing ones so that they contain malicious JavaScript. […]
22 Dec Leading sports betting firm BetMGM discloses data breach Leading sports betting company BetMGM disclosed a data breach after a threat actor stole personal information belonging to an undisclosed number of customers. […]
22 Dec Lastpass: Hackers stole customer vault data in cloud storage breach LastPass revealed today that attackers stole customer vault data after breaching its cloud storage earlier this year using information stolen during an August 2022 incident. […]