04 Nov Discord will switch to temporary file links to block malware delivery Discord will switch to temporary file links for all users by the end of the year to block attackers from using its CDN (content delivery network) for hosting and pushing malware. […]
04 Nov Apple ‘Find My’ network can be abused to steal keylogged passwords Apple’s “Find My” location network can be abused by malicious actors to stealthily transmit sensitive information captured by keyloggers installed in keyboards. […]
03 Nov The Week in Ransomware – November 3rd 2023 – Hive’s Back Over the past couple of months, ransomware attacks have been escalating as new operations launch, old ones return, and existing operations continue to target the enterprise. […]
03 Nov Dutch hacker jailed for extortion, selling stolen data on RaidForums A former Dutch cybersecurity professional was sentenced to four years in prison after being found guilty of hacking and blackmailing more than a dozen companies in the Netherlands and worldwide. […]
03 Nov American Airlines pilot union hit by ransomware attack Allied Pilots Association (APA), a labor union representing 15,000 American Airlines pilots, disclosed a ransomware attack that hit its systems on Monday. […]
03 Nov Google Play adds security audit badges for Android VPN apps Google Play, Android’s official app store, is now tagging VPN apps with an ‘independent security reviews’ badge if they conducted an independent security audit of their software and platform. […]
03 Nov New Microsoft Exchange zero-days allow RCE, data theft attacks Microsoft Exchange is impacted by four zero-day vulnerabilities that attackers can exploit remotely to execute arbitrary code or disclose sensitive information on affected installations. […]
03 Nov Okta breach: 134 customers exposed in October support system hack Okta says attackers who breached its customer support system last month gained access to files belonging to 134 customers, five of them later being targeted in session hijacking attacks with the help of stolen session tokens. […]
02 Nov Atlassian warns of exploit for Confluence data wiping bug, get patching Atlassian warned admins that a public exploit is now available for a critical Confluence security flaw that can be used in data destruction attacks targeting Internet-exposed and unpatched instances. […]
02 Nov Ace Hardware says 1,202 devices were hit during cyberattack Ace Hardware confirmed that a cyberattack is preventing local stores and customers from placing orders as the company works to restore 196 servers. […]