Cybersecurity Month A simple AI prompt saved a developer from this job interview scam Plus: Ransomware posing as Teams installer, Cisco 0-day exploit to drop rootkit, and European cops bust SIM-box service
Cybersecurity Month Leak suggests US government is fibbing over FEMA security failings Plus, PAN under attack, IT whistleblowers get a payout, and China kills online scammers
Security Dutch teen duo arrested over alleged 'Wi-Fi sniffing' for Russia PLUS: Interpol recoups $439M from crims; CISA criticizes Feds security; FIFA World Cup nets dodgy domain deluge
Security Ransomware attack linked to museum break-in and theft of golden exhibits PLUS: Luxury brands under fire; FBI warns crims are spoofing it again; ICE buys phone cracking software
Security CISA sounds alarm over TP-Link wireless routers under attack Plus: Google clears up Gmail concerns, NSA drops SBOM bomb, Texas sues PowerSchool, and more
Security WhatsApp warns of 'attack against specific targeted users' PLUS: Microsoft ends no-MFA Azure access; WorkDay attack diverts payments; FreePBX warns of CVSS 10 flaw; and more
Security AWS, Cloudflare, Digital Ocean, and Google helped Feds investigate alleged Rapper Bot DDoS perp Comet AI browser fooled; Microsoft sets sail for quantum safety; Sailor sent down for espionage
Security US spy satellite agency breached, but insists no classified secrets spilled Plus, leak site for BlackSuit seized, Tea spilt, and avoid crime if you've got a famous dad
Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Security 23andMe settles class-action breach lawsuit for $30 million Also: Apple to end NSO Group lawsuit; Malicious Python dev job offers; Dark web kingpins busted; and more
Security Predator spyware updated with dangerous new features, also now harder to track Plus: Trump family X accounts hijacked to promote crypto scam; Fog ransomware spreads; Hijacked PyPI packages; and more
Security Check your IP cameras: There's a new Mirai botnet on the rise Also, US offering $2.5M for Belarusian hacker, Backpage kingpins jailed, additional MOVEit victims, and more
Security Alleged Karakut ransomware scumbag charged in US Plus: Microsoft issues workaround for dual-boot crashes; ARRL cops to ransom payment, and more
Security RansomHub-linked EDR-killing malware spotted in the wild Also: Your external-facing NetSuite sites need a review; five popular malware varieties for Q2, and more
Security The UN unanimously agrees that cybercrime is bad, mkay? Also: British nuke subs get code from Russia; and BlackSuit begs for $500M
Security Google gamed into advertising a malicious version of Authenticator Plus: CISA's AI hire; and claimed Canuck SIM swappers busted
Security Secure Boot useless on hundreds of PCs from major vendors after key leak Plus: More stalkerware exposure; a $16M TracFone fine; Ransomware victims don't use MFA, and more
Security Cellebrite got into Trump shooter's Samsung device in just 40 minutes Also: Second-string Russian hackers sanctioned; Senators demand answers from Snowflake, and more
Security I spy another mSpy breach: Millions more stalkerware buyers exposed Also: Velops routers love plaintext; everything is a dark pattern; Internet Explorer rises from the grave, and more
Security Microsoft tells yet more customers their emails have been stolen Plus: US auto dealers still offline; Conti coders sanction; Rabbit R1 hardcoded API keys; and more
Security Snowflake breach snowballs as more victims, perps, come forward Also: The leaked Apple internal tools that weren't; TV pirate pirates convicted; and some critical vulns, too
Security That didn't take long: Replacement for SORBS spam blacklist arises ... sort of Also: Online adoption cyberstalker nabbed; Tesla trade secrets thief pleads guilty; and a critical ASUS Wi-Fi vuln
Security Snowflake tells customers to enable MFA as investigations continue Also, industry begs Uncle Sam for infosec reg harmony, dueling container-compromise campaigns, and crit vulns
Security Check Point warns customers to patch VPN vulnerability under active exploitation Also, free pianos are the latest internet scam bait, Cooler Master gets pwned, and some critical vulnerabilities
Security Bayer and 12 other major drug companies caught up in Cencora data loss Plus: US water systems fail at cyber security
Security Nissan infosec in the spotlight again after breach affecting more than 50K US employees PLUS: Connected automakers put on notice; Cisco Talos develops macOS fuzzing technique; Last week's critical vulns
Security Encrypted mail service Proton hands suspect's personal info to local cops Plus: Google patches another Chrome security hole, and more
Security Germany points finger at Fancy Bear for widespread 2023 hacks, DDoS attacks Also: Microsoft promises to git gud on cybersecurity; unqualified attackers are targeting your water systems, and more
Security Discord dismantles Spy.pet site that snooped on millions of users ALSO: Infostealer spotted hiding in CDN cache, antivirus update hijacked to deliver virus, and some critical vulns
Security MITRE admits 'nation state' attackers touched its NERVE R&D operation PLUS: Akira ransomware resurgent; Telehealth outfit fined for data-sharing; This week's nastiest vulns
Security US House approves FISA renewal – warrantless surveillance and all PLUS: Chinese chipmaker Nexperia attacked; A Microsoft-signed backdoor; CISA starts scanning your malware; and more
Security Head of Israeli cyber spy unit exposed ... by his own privacy mistake Plus: Another local government hobbled by ransomware; Huge rise in infostealing malware; and critical vulns
Security Nearly 3M people hit in Harvard Pilgrim healthcare data theft Also, TheMoon botnet back for EoL SOHO routers, Sellafield to be prosecuted for 'infosec failures', plus critical vulns
Security Microsoft confirms memory leak in March Windows Server security update ALSO: Viasat hack wiper malware is back, users are the number one cause of data loss, and critical vulns
Security ChatGPT side-channel attack has easy fix: Token obfuscation Also: Roblox-themed infostealer on the prowl, telco insider pleads guilty to swapping SIMs, and some crit vulns
Security Microsoft waited 6 months to patch actively exploited admin-to-kernel vulnerability PLUS: NSA shares cloud security tips; Infosec training for Jordanian women; Critical vulnerabilities
Security LockBit's contested claim of fresh ransom payment suggests it's been well hobbled ALSO: CISA warns Ivanti vuln mitigations might not work, SAML hijack doesn't need ADFS, and crit vulns
Security Fox News 'hacker' turns out to be journalist whose lawyers say was doing his job Also, another fake iOS app slips into the store, un-cybersafe EV chargers leave UK shelves, and critical vulns
Security Feds post $15 million bounty for info on ALPHV/Blackcat ransomware crew ALSO: EncroChat crims still getting busted; ransomware takes down CO public defenders office; and crit vulns
Security Mon Dieu! Nearly half the French population have data nabbed in massive breach PLUS: Juniper's support portal leaks customer info; Canada moves to ban Flipper Zero; Critical vulns
Security SBF likely off the hook for misplaced FTX funds after cops bust SIM swap ring PLUS: more glibc vulns discovered; DraftKings hacker sentenced; and a hefty dose of critical vulnerabilities
Security Tesla hacks make big bank at Pwn2Own's first automotive-focused event ALSO: SEC admits to X account negligence; New macOS malware family appears; and some critical vulns
Security BreachForums admin 'Pompourin' sentenced to 20 years of supervised release Also: Another UEFI flaw found; Kaspersky discovers iOS log files actually work; and a few critical vulnerabilities
Security FTC secures first databroker settlement banning sale of sensitive location data Also, iOS spyware abused Apple's own ECC, breach victim says it can't figure out what hackers took, and some critical vulns
Patches Facebook, Instagram now mine web links you visit to fuel targeted ads Also: Twitter hijackings, BEC arrest, and critical vulnerabilities
Cyber-crime Iranian cyberspies target US defense orgs with a brand new backdoor Also: International cops crackdown on credit card stealers and patch these critical vulns
Security MongoDB warns breach of internal systems exposed customer contact info PLUS: Cancer patients get ransom notes for Christmas, Delta Dental is the latest MOVEit victim, and critical vulns
Security EU lawmakers finalize cyber security rules that panicked open source devs PLUS: Montana TikTok ban ruled unconstitutional; Dollar Tree employee data stolen; critical vulnerabilities
Security Leader of pro-Russia DDoS crew Killnet 'unmasked' by Russian state media Also: NXP China attack, Australia can't deliver on ransom payment ban (yet), and Justin Sun's very bad month
Security Your password hygiene remains atrocious, says NordPass ALSO: FCC cracks down on SIM-swap scams, old ZeroLogon targeted by new ransomware, and critical vulnerabilities
Security Royal Mail cybersecurity still a bit of a mess, infosec bods claim Also: Most Mainers are MOVEit victims, NY radiology firm fined for not updating kit, and some critical vulnerabilities
Security Okta October breach affected 134 orgs, biz admits Plus: CVSS 4.0 is here, this week's critical vulns, and 'incident' hit loan broker promises no late fees. Generous
AI + ML SEC boss warns it's 'nearly unavoidable' that AI will cause financial crash Plus Meta gets physical, moves bots in the house...
Security Regulator, insurers and customers all coming for Progress after MOVEit breach Also, CISA cataloging new ransomware data points, 17k WP sites hijacked by malware in Sept., and more critical vulns
AI + ML UK data watchdog warns Snap over My AI chatbot privacy issues Plus: 4channers are making troll memes with Bing AI, and more
Security Chinese smart TV boxes infected with malware in PEACHPIT ad fraud campaign PLUS: Sony admits to MoveITbreach; Blackbaud fined again, Qakbot's sorta back from the dead; and more
AI + ML OpenAI warns folks over GPT-4 Vision's limits and flaws Plus: Mistral emits uncensored model, Meta expands Llama 2's context window, Alexa drills into your voice
Patches Now MOVEit maker Progress patches holes in WS_FTP Plus: Johnson Controls hit by IT 'incident', Exim and Chrome security updates, and more
Security T-Mobile US exposes some customer data – but don't call it a breach PLUS: Trojan hidden in PoC; cyber insurance surge; pig butchering's new cuts; and the week's critical vulns
Security California passes bill to set up one-stop data deletion shop Also, LockBit gets a new second stringer, AirTag owners find yet another illicit use, and this week's critical vulns
Security Google warns infoseccers: Beware of North Korean spies sliding into your DMs ALSO: Verizon turns self in for reduced fine, malvertising comes to macOS, and this week's critical vulnerabilities
Security Apple opens annual applications for free hackable iPhones ALSO: Brazilian stalkerware database ripped by the short hairs, a fast fashion breach, and this week's critical vulns
Security Whiffy malware stinks after tracking location via Wi-FI ALSO: Euro chip maker breached, crims plan to undermine cyber insurance, and this week's critical vulnerabilities
Security Microsoft DNS boo-boo breaks Hotmail for users around the globe ALSO: NYC says kthxbye to TikTok, slain Microsoft exec's wife indicted, and some ASAP patch warnings
Security US government to investigate China's Microsoft email breach PLUS: Phishing campaign targets the C-suite; Cybercrime arrests in EU and Africa; and more
Security Five Eyes nations detail dirty dozen most exploited vulnerabilities PLUS: FBI admits buying NSO spyware; "IT" company busted for drugs 'n guns biz; this week's critical vulns
Security US senator victim-blames Microsoft for Chinese hack ALSO: China says US hacked it right back, BreachForums users have been pwned, and this week's critical vulns
Security Google Cloud shores up log permissions for builder bot ALSO: Amazon's child-sized COPPA fine, smart tech security labels coming to the US, and this week's critical vulns
Security Boris Johnson pleads ignorance, which just might work Also: More high-profile MOVEit victims; CVSS 4.0 coming soon; and a long list of critical vulnerabilities
AI + ML Sarah Silverman, novelists sue OpenAI for scraping their books to train ChatGPT Plus: Adobe is limiting how staff can use external generative AI tools, and the Pentagon is testing different large language models
Security Liberté, Égalité, Spyware: France okays cops snooping on phones ALSO: Shell fails to learn from past leaks; hundreds of solar plants found open to Mirai; and this week's crit vulns
Systems Russian military satellite comms provider offline after hack ALSO: Ransomware hit on Mancunian Uni spills NHS patient deets, USPTO leaks inventor info, and this week's crit vulns
CSO Ex-FBI employee jailed for taking classified material home Also: a PII harvest at Dole's server farm, military members mailed mystery smartwatches, and this week's critical vulns
Patches Guess what happened to this US agency using outdated software? Also: Hackers target security researchers, MaaS model flourishing, and this week's vulnerabilities
Cyber-crime Hold it – another vulnerability found in MOVEit file transfer software Also, the FBI's $180k investment in AN0M keeps paying off, and this week's critical vulnerabilities
Security Toyota admits to yet another cloud leak Also, hackers publish RaidForum user data, Google's $180k Chrome bug bounty, and this week's vulnerabilities
Security T-Mobile US suffers second data theft within months Also, Capita's buckets are leaking, ransomware attackers deliver demands via emergency alert, and this week's critical vulns
Cyber-crime 40% of IT security pros say they've been told not to report a data leak Plus: KFC, Pizza Hut owner spills more beans on ransomware hit... latest critical flaws... and more
Research Gone in 120 seconds: Tesla Model 3 child's play for hackers Plus OIG finds Uncle Sam fibbed over Login.gov
AI + ML Alphabet reshuffles to meet ChatGPT threat Plus: ArtStation cracks down on rebellious creators and lame-duck AI laws in the US on the cards
Security Back to work, Linux admins: You may have a CVSS 10 kernel bug to address Also, script kiddies are coming for your gift cards, and Meta's Cambridge Analytica pathetic payout
AI + ML OpenAI predicts biz can break a billion in revs by 2024 Plus: Suomi security warnings and artists rebel against AI on Artstation
AI + ML Hey, GitHub, can you create an array compare function without breaking the GPL? Plus: Amazon debuts AI warehouse robot, Midjourney releases latest ML art generator
AI + ML OpenAI, Microsoft, GitHub hit with lawsuit over Copilot Plus: City of Edinburgh promises to scrap Chinese AI Hikvision cameras, and more
AI + ML Bumble open sources AI code to automatically blur NSFW photos Plus: Why some manga and anime fans hate AI-generated art, and ex-Google boss funds AI students
Security Apple patches actively exploited iPhone, iPad kernel vulns Plus: Misconfigured server leaks Thomson Reuters data; VMware patches critical flaw in retired software; MalwareBytes apologies for a hoodie
AI + ML Weird robot breaks down in middle of House of Lords hearing on AI art Plus: Listen to Fake Joe Rogan interviewing Bogus Steve Jobs in bizarre podcast episode
Security Biden's Privacy Shield 2.0 order may not satisfy Europe Also, Albania almost called in NATO over cyber attacks, and Facebook warns of account-stealing mobile apps
Security BlackCat malware lashes out at US defense IT contractor Also, Amazon's Ring footage TV shows draws criticism, US v Soviet spying docs found, and more
AI + ML Text-to-image models are so last month, text-to-video is here Plus: Did Bruce Willis sell his image rights to AI biz creating deepfakes? And more
AI + ML Creatives up in arms over claim that AI is killing human art Plus: Cruise expanding self-driving robotaxi operations, and more
Security GPT-3 'prompt injection' attack causes bad bot manners Also, EA goes kernel-deep to stop cheaters, PuTTY gets hijacked by North Korea, and more.
Security Brewdog might make an OK pint but its security sucks: Flaw opened door to free beers for anyone
AI + ML Clearview CEO doubles down, claims biz has now scraped over ten billion social media selfies for surveillance
AI + ML Report: Microsoft and AWS scored $50m in contracts after Google pulled out of Pentagon's AI drone plan
Security Black Hat security conference returns to Las Vegas – complete with hacks to quiet the hotel guest from hell
Security With a straight face, Putin agrees to do something about ransomware coming out of Russia, apparently
AI + ML Graphcore's AI chips may not be as powerful as Nvidia's GPUs, but may provide good bang for your buck
AI + ML Mayflower, the AI ship sent to sail from the UK to the US with no humans, made it three days before breaking down
Security Uncle Sam wants 'ethical hackers' to crack its planetary defenses, but don't expect a pay-day from this bug bounty
Security Apple patches iOS, macOS, iPadOS, watchOS, kitchen-sinkOS bugs said to be exploited in the wild
Security Homebrew fixes Cask repo GitHub Actions bug that would have let anyone sneak malicious code onto machines
Security Sysadmin for FIN7 criminal cracking group gets 10 years in US prison for managing card slurping malware scam
AI + ML Machine learning devs, rejoice: You can now rent up to 16 Nvidia A100 GPUs on a single machine via Google
Security Exchange flaws could be much worse than thought: Six hacking groups suspected of using the zero days pre-patch
AI + ML How Facebook uses public videos to train, deploy machine-learning models and harvest those eyeballs
Security Brave browser leaks visited Tor .onion addresses in DNS traffic, fix released after bug hunter raises alarm
Security Let's Encrypt completes huge upgrade, can now rip and replace 200 million security certs in 'worst case scenario'
Security Countless emails wrongly blocked as spam after Cisco's SpamCop failed to renew domain name at the weekend
Security Hallowed Bugtraq infosec list killed then resurrected over the weekend: We heard your feedback, says Accenture
Security SolarWinds takes a leaf out of Zoom's book, hires A-Team of Stamos and Krebs to sort out its security woes
Security SolarWinds releases known attack timeline, new data suggests hackers may have done a dummy run last year
Security Rogue ex-Cisco employee who crippled WebEx conferences and cost Cisco millions gets two years in US prison
Security It's not just the economy and bad management messing with Kmart - ransomware crews are there too
Security Google's home security package flies the Nest, Chocolate Factory pledges software support – for now
Security First, Patch Tuesday. Now, Oh Hell, Monday: Microsoft emits bonus fixes for Visual Studio, Windows 10 security bugs
AI + ML Remember OpenAI's GPT model that was too dangerous for mere mortals? Well, it's now for sale on Azure
AI + ML Whoops, our bad, we may have 'accidentally' let Google Home devices record your every word, sound – oops
AI + ML US drugstore chain installed anti-shoplifter facial-recognition cameras in 200 locations – for eight years
AI + ML Is that croaky voicemail of your CEO just a Fakey McFake Fake – or does he normally ask you to wire him $1m?
AI + ML Detroit Police make second wrongful facial-recog arrest when another man is misidentified by software
Security Better get Grandpa off Windows 7 because zero-day bug in Zoom allows remote code execution on vintage OS