ClickFix may be the biggest security threat your family has never heard of
Relatively new technique can bypass many endpoint protections.
Commercial spyware “Landfall” ran rampant on Samsung phones for almost a year
Targeted attack could steal all of a phone’s data and activate camera or mic.
How to trade your $214,000 cybersecurity job for a jail cell
Ransomware doesn’t pay what it used to.
Wipers from Russia’s most cut-throat hackers rain destruction on Ukraine
Sandworm and other Russian-state hackers unleash data-destroying payloads on their neighbors.
Musk and Trump both went to Penn—now hacked by someone sympathetic to their cause
Social engineering strikes again.
5 AI-developed malware families analyzed by Google fail to work and are easily detected
You wouldn’t know it from the hype, but the results fail to impress.
Two Windows vulnerabilities, one a 0-day, are under active exploitation
Both vulnerabilities are being exploited in wide-scale operations.
FCC to rescind ruling that said ISPs are required to secure their networks
FCC chair to rely on ISPs’ voluntary commitments instead of Biden-era ruling.
NPM flooded with malicious packages downloaded more than 86,000 times
Packages downloaded from NPM can fetch dependencies from untrusted sites.
New physical attacks are quickly diluting secure enclave defenses from Nvidia, AMD, and Intel
On-chip TEEs withstand rooted OSes but fall instantly to cheap physical attacks.
This browser claims “perfect privacies protection,” but it acts like malware
Researchers note links to Asia’s booming cybercrime and illegal gambling networks.
Cache poisoning vulnerabilities found in 2 DNS resolving apps
At least one CVE could weaken defenses put in place following 2008 disclosure.
Jaguar Land Rover looking at $2.5 billion price tag from crippling cyberattack
Incident was likely the most economically damaging cyber event in UK history.
NSO permanently barred from targeting WhatsApp users with Pegasus spyware
Ruling holds that defeating end-to-end encryption in WhatsApp harms Meta’s business.
Nation-state hackers deliver malware from “bulletproof” blockchains
Malicious payloads stored on Ethereum and BNB blockchains are immune to takedowns.
Thousands of customers imperiled after nation-state ransacks F5’s network
Risks to BIG-IP users include supply-chain attacks, credential loss, and vulnerability exploits.
NATO boss mocks Russian navy, which is on the hunt for Red October “the nearest mechanic”
A Russian sub surfaces off of Western Europe. Is it damaged?
Hackers can steal 2FA codes and private messages from Android phones
Malicious app required to make “Pixnapping” attack work requires no permissions.
Why Signal’s post-quantum makeover is an amazing engineering achievement
New design sets a high standard for post-quantum readiness.
Apple ups the reward for finding major exploits to $2 million
With bonuses, maximum rewards can be as high as $5 million.
Microsoft warns of new “Payroll Pirate” scam stealing employees’ direct deposits
Among other things, the scammers bypass multi-factor authentication.
Discord says hackers stole government IDs of 70,000 users
As more sites require IDs for user age verification, expect more such breaches to come.
Salesforce says it won’t pay extortion demand in 1 billion records breach
Scattered LAPSUS$ Hunters gave Salesforce until Friday to pay or else.
ICE wants to build a 24/7 social media surveillance team
ICE plans to hire contractors to scan platforms to target people for deportation.
Japan is running out of its favorite beer after ransomware attack
Asahi Super Dry production at Japanese breweries halted after cyberattack.
That annoying SMS phish you just got may have come from a box like this
Smishers looking for new infrastructure are getting creative.
Intel and AMD trusted enclaves, a foundation for network security, fall to physical attacks
The chipmakers say physical attacks aren’t in the threat model. Many users didn’t get the memo.
Rocket Report: Keeping up with Kuiper; New Glenn’s second flight slips
Amazon plans to conduct two launches of Kuiper broadband satellites just days apart.
As many as 2 million Cisco devices affected by actively exploited 0-day
Search shows 2 million vulnerable Cisco SNMP interfaces exposed to the Internet.
Supermicro server motherboards can be infected with unremovable malware
Baseboard management controller vulnerabilities make remote attacks possible.
US uncovers 100,000 SIM cards that could have “shut down” NYC cell network
A “nation-state” is said to be involved.
Here’s how potent Atomic credential stealer is finding its way onto Macs
LastPass warns it’s one of the latest to see its well-known brand impersonated.
Microsoft’s Entra ID vulnerabilities could have been catastrophic
They could’ve allowed attacker to gain access to virtually all Azure customer accounts.
Two of the Kremlin’s most active hack groups are collaborating, ESET says
Turla is getting a helping hand from Gamaredon. Both are units of Russia’s FSB.
Two UK teens charged in connection to Scattered Spider ransomware attacks
Ransomware group is one of the world’s most prolific.
New attack on ChatGPT research agent pilfers secrets from Gmail inboxes
Unlike most prompt injections, ShadowLeak executes on OpenAI’s cloud-based infrastructure.