News
-
"AI Voice Generator App Used to Drop Gipy Malware"A new infostealer malware campaign called "Gipy" targets users in Germany, Russia, Spain, and Taiwan with phishing lures regarding an Artificial Intelligence (AI) voice changer.
-
"Hyundai App Exposed Vehicles to High-Tech Thieves: Researchers"According to the cybersecurity company Rapid7, software vulnerabilities in a Hyundai Motor app that lets cars be started remotely made them vulnerable to hackers for three months before the company fixed the bug in March.
-
"US Retailers Under Attack by Gift Card-Thieving Cyber Gang""Storm-0539," also known as "Atlas Lion," is a Moroccan cybercriminal group that compromises retailers and creates fake gift cards.
-
"Courtroom Recording Software Compromised With Backdoor Installer"Hackers have compromised a popular brand of recording software used in courtrooms, jails, and prisons, allowing them to gain complete control of a system via a backdoor implanted in an update to the tool.
-
"Spyware Found on US Hotel Check-in Computers"A consumer-grade spyware app called "pcTattletale" has been discovered on the check-in systems of at least three US Wyndham hotels. The app secretly took screenshots of the hotel booking systems containing guest and customer information.
-
"Health Information Published Online After MediSecure Ransomware Attack"Australian patients' health and personal information has reportedly been published online following the ransomware attack on medical prescriptions provider MediSecure.
-
"Cencora Data Breach Exposes US Patient Info From 8 Drug Companies"Some of the largest drug companies in the world have disclosed data breaches due to a February 2024 cyberattack at Cencora, whom they partner with for pharmaceutical and business services.
-
"High-Severity GitLab Flaw Lets Attackers Take over Accounts"GitLab fixed a high-severity vulnerability that enables unauthenticated attackers to hijack user accounts in Cross-Site Scripting (XSS) attacks. The vulnerability is an XSS flaw in the VS code editor (Web IDE) that allows threat ac
-
"Critical Flaw in AI Platform Exposes Proprietary Data"Through the exploitation of a critical vulnerability in the Replicate Artificial Intelligence (AI) platform, attackers could have executed a malicious AI model within the platform for a cross-tenant attack.
-
"NSA Releases Guidance on Zero Trust Maturity Throughout the Application and Workload Pillar"The new Cybersecurity Information Sheet (CSI), "Advancing Zero Trust Maturity Throughout the Application and Workload Pillar," from the National Security Agency (NSA) helps organizations secure applications from unauthorized users
-
"NVD Leaves Exploited Vulnerabilities Unchecked"A new VulnCheck report found that the US National Vulnerability Database (NVD) lacks most currently exploited software vulnerabilities. In its May 23 report, the software security provider revealed that the NVD team has n