Cybersecurity

12 readers
13 users here now

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Rules

Community Rules

founded 2 years ago
MODERATORS
176
 
 

#Sensata Technologies says personal data stolen by #ransomware gang

https://www.bleepingcomputer.com/news/security/sensata-technologies-says-personal-data-stolen-by-ransomware-gang/

#cybersecurity #privacy #DataBreach

177
 
 

#Grocery wholesale giant #UnitedNaturalFoods hit by #cyberattack

https://www.bleepingcomputer.com/news/security/grocery-wholesale-giant-united-natural-foods-hit-by-cyberattack/

#UNFI #food #cybersecurity #WholeFoods #Amazon

178
 
 

"In a victory for personal privacy, a New York federal district court judge today granted a preliminary injunction in a lawsuit challenging the U.S. Office of Personnel Management’s (OPM) disclosure of records to DOGE and its agents.

Judge Denise L. Cote of the U.S. District Court for the Southern District of New York found that OPM violated the Privacy Act and bypassed its established cybersecurity practices under the Administrative Procedures Act. The court will decide the scope of the injunction later this week. The plaintiffs have asked the court to halt DOGE agents’ access to OPM records and for DOGE and its agents to delete any records that have already been disclosed. OPM’s databases hold highly sensitive personal information about tens of millions of federal employees, retirees, and job applicants.

“The plaintiffs have shown that the defendants disclosed OPM records to individuals who had no legal right of access to those records,” Cote found. “In doing so, the defendants violated the Privacy Act and departed from cybersecurity standards that they are obligated to follow. This was a breach of law and of trust. Tens of millions of Americans depend on the Government to safeguard records that reveal their most private and sensitive affairs.”"

https://www.eff.org/press/releases/privacy-victory-judge-grants-preliminary-injunction-opmdoge-lawsuit

#USA #Trump #Musk #DOGE #OPM #CyberSecurity #Privacy #DataProtection

179
 
 

New #Mirai #botnet infect #TBK #DVR devices via command injection flaw

https://www.bleepingcomputer.com/news/security/new-mirai-botnet-infect-tbk-dvr-devices-via-command-injection-flaw/

#cybersecurity

180
 
 

Threat Actor Claims #TikTok Breach, Puts 428 Million Records Up for Sale

https://hackread.com/threat-actor-tiktok-breach-428-million-records-sale/

#cybersecurity #DataBreach #privacy

181
 
 

#Trump administration takes aim at #Biden and #Obama #cybersecurity rules

https://techcrunch.com/2025/06/07/trump-administration-takes-aim-at-biden-and-obama-cybersecurity-rules/

#politics

182
 
 
183
 
 

Malicious #npm packages posing as utilities delete project directories

https://www.bleepingcomputer.com/news/security/malicious-npm-packages-posing-as-utilities-delete-project-directories/

#cybersecurity

184
 
 

#Apple warns #Australia against joining #EU in mandating #iPhone app #sideloading

https://www.neowin.net/news/apple-warns-australia-against-joining-eu-in-mandating-iphone-app-sideloading/

#cybersecurity #privacy

185
 
 

After its data was wiped, #KiranaPro’s co-founder cannot rule out an external hack

https://techcrunch.com/2025/06/06/after-its-data-was-wiped-kiranapros-co-founder-cannot-rule-out-an-external-hack/

#cybersecurity #India #groceries

186
 
 

A cybersecurity issue left phone numbers linked to Google accounts completely vulnerable, according to a researcher. It would take an hour to obtain a U.S. number, eight minutes for a U.K. one and less than a minute for some other countries.

"Phone numbers are a goldmine for SIM swappers. A researcher found how to get this precious piece of information from any Google account," writes @josephcox@infosec.exchange for @404media.

https://flip.it/zBdlAw

#Google #Cybersecurity #OnlinePrivacy #Tech #TechNews

187
 
 

New laws. More hacks. Rising global tension.

Open source is under pressure — from regulators, enterprises, and geopolitics.

💡 How do we protect trust in open source and AI?

#OpenSource #CyberSecurity #AI #CNAI #OSS #TechPolicy

video/mp4

188
 
 

#Citibank emailed me an alert. The same bank that constantly warns me about email scams. And, yet, they misconfigured their email so it comes as a spoofed email. My email provider delivered it anyway because Citi has a "relaxed" policy in their DNS that says that EMAIL FROM A SPOOFING SERVER CAN BE DELIVERED so long as the signature passes. Yep, servers spoofing them are not a major red flag and the email should be delivered to the inbox anyway. The email provider is not to blame here.

A major bank should not do it this way.

The spoofing SMTP server check failed because the sending IP address is not authorized by Citibank's SPF record for info6.citi.com to send their email. This has been going on for years. Do you want Citibank email from a server not authorized by them to send it?

This relaxed attitude by corporations is why people get scammed.

Authentication-Results: mail.protonmail.ch; spf=fail smtp.mailfrom=info6.citi.com
Authentication-Results: mail.protonmail.ch; arc=none smtp.remote-ip=173.213.5.122

#citi #CyberSecurity #EmailSecurity

189
 
 

#NewYork state lawmakers vote to stop #NYPD’s attempt to block radio communications from public

https://nypost.com/2025/06/05/us-news/new-york-state-lawmakers-vote-to-stop-nypds-attempt-to-block-radio-communications-from-public/

#cybersecurity

190
 
 

Cybercriminals Are Hiding Malicious Web Traffic in Plain Sight

https://www.wired.com/story/cybercriminals-are-hiding-malicious-web-traffic-in-plain-sight/

#cybercrime #cybersecurity

191
 
 

Report on the Malicious Uses of #AI

https://www.schneier.com/blog/archives/2025/06/report-on-the-malicious-uses-of-ai.html

#OpenAI #ChatGPT #cybersecurity

192
 
 

New #PathWiper data wiper #malware hits critical infrastructure in #Ukraine

https://www.bleepingcomputer.com/news/security/new-pathwiper-data-wiper-malware-hits-critical-infrastructure-in-ukraine/

#cybersecurity

193
 
 

Critical #Fortinet flaws now exploited in #Qilin #ransomware attacks

https://www.bleepingcomputer.com/news/security/critical-fortinet-flaws-now-exploited-in-qilin-ransomware-attacks/

#cybersecurity

194
 
 

"We disclose a novel tracking method by Meta and Yandex potentially affecting billions of Android users. We found that native Android apps—including Facebook, Instagram, and several Yandex apps including Maps and Browser—silently listen on fixed local ports for tracking purposes.

These native Android apps receive browsers' metadata, cookies and commands from the Meta Pixel and Yandex Metrica scripts embedded on thousands of web sites. These JavaScripts load on users' mobile browsers and silently connect with native apps running on the same device through localhost sockets. As native apps access programatically device identifiers like the Android Advertising ID (AAID) or handle user identities as in the case of Meta apps, this method effectively allows these organizations to link mobile browsing sessions and web cookies to user identities, hence de-anonymizing users' visiting sites embedding their scripts.

This web-to-app ID sharing method bypasses typical privacy protections such as clearing cookies, Incognito Mode and Android's permission controls. Worse, it opens the door for potentially malicious apps eavesdropping on users’ web activity."

https://localmess.github.io/

#CyberSecurity #Android #Meta #Yandex #Surveillance #Privacy #DataProtection #GDPR #MobileApps

195
 
 

"On Thursday, the findings of the parliamentary committee investigating Italy's usage of the spyware were published, in a rare incident of a Western state shedding light into a usually secretive world of intelligence agencies and covert surveillance.
The committee confirmed that Paragon provided Graphite to two Italian agencies, including the country's external intelligence service, starting in 2023. The version of Graphite provided did not include the ability to activate the phone's microphone or camera, the report said.

Instead, it only enabled its operators access to encrypted communications on the hacked devices. The report also confirmed that Graphite exploited a vulnerability in WhatsApp that Meta identified and patched in December 2024, one month before the spyware's activity was publicly disclosed.

The vulnerability's discovery also caused "panic" at Israel's military intelligence Unit 8200, according to the recent Israeli television report.

The Italian committee also confirmed Meta's claim that several activists involved in migrant rights in Italy had their phones hacked, including Luca Casarini, Giuseppe Caccia, and David Yambio – though in Yambio's case, the hack was carried out not by Graphite but by another unnamed spyware."

https://www.haaretz.com/israel-news/security-aviation/2025-06-05/ty-article/.premium/italy-admits-activists-were-hacked-with-israeli-spyware-but-not-journalists/00000197-3ff4-d079-ab97-7ff5bd8a0000

#EU #Italy #CyberSecurity #Surveillance #Privacy #Spyware #Paragon #Graphite #Israel

196
 
 

#Proxy Services Feast on #Ukraine’s IP Address Exodus

https://krebsonsecurity.com/2025/06/proxy-services-feast-on-ukraines-ip-address-exodus/

#cybercrime #cybersecurity #Russia #politics

197
 
 

#Italy Admits Hacking Activists With Israeli #Spyware #Paragon

https://archive.ph/Ocm8S

#cybersecurity #privacy #politics

198
 
 

Hacker selling critical #Roundcube #webmail exploit as tech info disclosed

https://www.bleepingcomputer.com/news/security/hacker-selling-critical-roundcube-webmail-exploit-as-tech-info-disclosed/

#cybersecurity

199
 
 

What Really Happened in the Aftermath of the #LizardSquad Hacks

https://www.wired.com/story/ctrl-alt-chaos-joe-tidy-book-excerpt/

#cybercrime #cybersecurity #gaming #PSN #PlayStation #PlayStationNetwork

200
 
 

#ViLE gang members sentenced for #DEA portal breach, extortion

https://www.bleepingcomputer.com/news/security/vile-gang-members-sentenced-for-breaching-law-enforcement-portal/

#cybercrime #cybersecurity

view more: ‹ prev next ›