AT&T Paid a Hacker $370,000 to Delete Stolen Phone Records post, juli 14, 2024juli 15, 2024 A security researcher who assisted with the deal says he believes the only copy of the complete dataset of call and text records of “nearly all” AT&T customers has been wiped—but some risks may remain. US telecom giant AT&T, which disclosed Friday that hackers had stolen the call records for tens… Continue Reading
Japanese space agency spotted zero-day attacks while cleaning up attack on M365 post, juli 11, 2024juli 12, 2024 The Japanese Space Exploration Agency (JAXA) discovered it was under attack using zero-day exploits while working with Microsoft to probe a 2023 cyberattack on its systems. But the space org’s statement also revealed the discovery of malware found and removed by an actor other than Microsoft. And then there’s the… Continue Reading
Google Is Adding Passkey Support for Its Most Vulnerable Users post, juli 10, 2024juli 15, 2024 Google is bringing the password-killing “passkey” tech to its Advanced Protection Program users more than a year after rolling them out broadly. The password killers known as “passkeys” are now available to users of Google’s Advanced Protection Program, which works to add an additional layer of account protection for people… Continue Reading
State-Sponsored Russian Media LeveragesMeliorator Software for Foreign MalignInfluence Activity post, juli 9, 2024juni 13, 2025 The U.S. Federal Bureau of Investigation (FBI) and Cyber National Mission Force (CNMF), in partnershipwith the Netherlands General Intelligence and Security Service (AIVD), Netherlands Military Intelligence and Security Service (MIVD), the Netherlands Police (DNP), and the Canadian Centre for Cyber Security (CCCS), (hereinafter referred to as the authoring organizations) are… Continue Reading
Cybersecurity Agencies Warn of China-linked APT40’s Rapid Exploit Adaptation post, juli 9, 2024juli 3, 2025 Cybersecurity agencies from Australia, Canada, Germany, Japan, New Zealand, South Korea, the U.K., and the U.S. have released a joint advisory about a China-linked cyber espionage group called APT40, warning about its ability to co-opt exploits for newly disclosed security flaws within hours or days of public release. “APT40 has previously… Continue Reading
Apple Geolocation API Exposes Wi-Fi Access Points Worldwide post, juli 8, 2024juli 10, 2024 Apple’s Wi-Fi Positioning System (WPS) can be used to map and track Wi-Fi access points (APs) around the globe. But in a presentation at Black Hat 2024, University of Maryland researcher Erik Rye will demonstrate how he mapped hundreds of millions of APs in a matter of days, without even needing… Continue Reading
CISA and Partners join ASD’S ACSC to Release Advisory on PRC State-Sponsored Group, APT 40 post, juli 8, 2024juli 3, 2025 CISA has collaborated with the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) to release an advisory, People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action outlining a PRC state-sponsored cyber group’s activity. APT 40 has previously targeted organizations in various countries, including Australia and the United… Continue Reading
Ransomware scum who hit Indonesian government apologizes, hands over encryption key post, juli 4, 2024juli 5, 2024 Brain Cipher, the group responsible for hacking into Indonesia’s Temporary National Data Center (PDNS) and disrupting the country’s services, has seemingly apologized for its actions and released an encryption key to the government. That key was in the form of an 54 kb ESXi file. Its efficacy has not yet… Continue Reading
Hackers of Indonesian government apologize and give key post, juli 3, 2024juli 5, 2024 Attackers clear logs before exploitation and use “no caller ID” numbers to negotiate ransoms, complicating detection and forensics efforts. A double-extortion ransomware player has exploded onto the scene with several attacks in two weeks, wielding innovative locker malware and a slew of evasion tactics for covering its tracks and making it difficult… Continue Reading
New OpenSSH Vulnerability Could Lead to RCE as Root on Linux Systems post, juli 1, 2024 OpenSSH maintainers have released security updates to contain a critical security flaw that could result in unauthenticated remote code execution with root privileges in glibc-based Linux systems. The vulnerability has been assigned the CVE identifier CVE-2024-6387. It resides in the OpenSSH server component, also known as sshd, which is designed to… Continue Reading