22 Sep Nigerian man pleads guilty to attempted $6 million BEC email heist Kosi Goodness Simon-Ebo, a 29-year-old Nigerian national extradited from Canada to the United States last April, pleaded guilty to wire fraud and money laundering through business email compromise (BEC). […]
22 Sep Recently patched Apple, Chrome zero-days exploited in spyware attacks Security researchers with the Citizen Lab and Google’s Threat Analysis Group (TAG) revealed today that three zero-days patched by Apple on Thursday were abused as part of an exploit chain to install Cytrox’s Predator spyware. […]
22 Sep Government of Bermuda links cyberattack to Russian hackers The Government of British overseas territory Bermuda has linked a cyberattack affecting all its departments’ IT systems since Thursday to hackers based out of Russia. […]
22 Sep Crypto firm Nansen asks users to reset passwords after vendor breach Ethereum blockchain analytics firm Nansen asks a subset of its users to reset passwords following a recent data breach at its authentication provider. […]
22 Sep T-Mobile denies new data breach rumors, points to authorized retailer T-Mobile has denied suffering another data breach following Thursday night reports that a threat actor leaked a large database allegedly containing T-Mobile employees’ data. […]
22 Sep Hotel hackers redirect guests to fake Booking.com to steal cards Security researchers discovered a multi-step information stealing campaign where hackers breach the systems of hotels, booking sites, and travel agencies and then use their access to go after financial data belonging to customers. […]
21 Sep ‘Sandman’ hackers backdoor telcos with new LuaDream malware A previously unknown threat actor dubbed ‘Sandman’ targets telecommunication service providers in the Middle East, Western Europe, and South Asia, using a modular info-stealing malware named ‘LuaDream.’ […]
21 Sep GitHub passkeys generally available for passwordless sign-ins GitHub has made passkeys generally available across the platform today to secure accounts against phishing and allow passwordless logins for all users. […]
21 Sep Apple emergency updates fix 3 new zero-days exploited in attacks Apple released emergency security updates to patch three new zero-day vulnerabilities exploited in attacks targeting iPhone and Mac users, for a total of 16 zero-days patched this year. […]
21 Sep Pizza Hut Australia warns 193,000 customers of a data breach Pizza Hut Australia is sending data breach notifications to customers, warning that a cyberattack allowed hackers to access their personal information. […]