Category: Cyber-Crime
US Homeland Security Reveals Guide to Enhance Cyber Incident Reporting
The US Department of Homeland Security (DHS) has introduced new recommendations to streamline the reporting of cyber incidents across the Department of Defense and 32 other federal agencies. The guide is expected to further protect the country’s vital infrastructure, reduce the burden on cybersecurity partners, and decrease the downtime of associated operations in each sector covered. The recommendations will also…
TransUnion denies it was hacked, links leaked data to 3rd party
Credit reporting firm TransUnion has denied claims of a security breach after a threat actor known as USDoD leaked data allegedly stolen from the company’s network. The Chicago-based company’s over 10,000 employees provide their services to millions of consumers and more than 65,000 businesses from 30 countries. “Immediately upon discovering these assertions, we partnered with outside cybersecurity and forensic experts…
War crimes tribunal ICC says it has been hacked
The International Criminal Court (ICC) said on Tuesday its computer system had been hacked, a breach at one of the world’s most high-profile international institutions and one that handles highly sensitive information about war crimes. The ICC said it had detected unusual activity on its computer network at the end of last week, prompting a response that was still ongoing….
Microsoft leaks 38TB of private data via unsecured Azure storage
The Microsoft AI research division accidentally leaked dozens of terabytes of sensitive data starting in July 2020 while contributing open-source AI learning models to a public GitHub repository. Almost three years later, this was discovered by cloud security firm Wiz whose security researchers found that a Microsoft employee inadvertently shared the URL for a misconfigured Azure Blob storage bucket containing the…
University of Sydney data breach impacts recent applicants
The University of Sydney (USYD) announced that a breach at a third-party service provider exposed personal information of recently applied and enrolled international applicants. The public university started operations in 1850 and has nearly 70,000 students and about 8,500 academic and administrative personnel. It is considered one of Australia’s most important educational institutes. In the data breach announcement, the…
Scraped data of 2.6 million Duolingo users released on hacking forum
The scraped data of 2.6 million DuoLingo users was leaked on a hacking forum, allowing threat actors to conduct targeted phishing attacks using the exposed information. Duolingo is one of the largest language learning sites in the world, with over 74 million monthly users worldwide. In January 2023, someone was selling the scraped data of 2.6 million DuoLingo users on…
Interpol takes down 16shop phishing-as-a-service platform
A joint operation between Interpol and cybersecurity firms has led to an arrest and shutdown of the notorious 16shop phishing-as-a-service (PhaaS) platform. Phishing-as-a-service platforms offer cybercriminals a one-stop-shop to conduct phishing attacks. These platforms typically include everything you need, including email distribution, ready-made phishing kits for well-known brands, hosting, data proxying, victim overview dashboards, and other tools that help increase…
Canadian publishers want Meta investigated for blocking news, following the impending Canadian law that demands tech firms pay for news
Canadian news industry groups have asked the country’s antitrust regulator to investigate Meta Platforms’ decision to block news on its platforms in the country, accusing the Facebook parent of abusing its dominant position. Meta started blocking news on its Facebook and Instagram platforms for all users in Canada last week in response to a law requiring internet giants to pay…
Tennessee teen sues school for suspending him after he posted memes mocking principal
Students rights are limited on school grounds. But they don’t cease to exist. And what they do off-campus is subject to even fewer limitations. These are long-held facts backed by years of court precedent, the most famous of which is the Supreme Court’s 1969 Tinker decision. This is the baseline for school-student interactions when it comes to constitutional rights, as…
New Inception attack leaks sensitive data from all AMD Zen CPUs
Researchers have discovered a new and powerful transient execution attack called ‘Inception’ that can leak privileged secrets and data using unprivileged processes on all AMD Zen CPUs, including the latest models. Transient execution attacks exploit a feature present on all modern processors named speculative execution, which dramatically increases the performance of CPUs by guessing what will be executed next before…
Europe confirms in-depth probe for Adobe’s $20B Figma acquisition
The European Commission (EC) has confirmed that it’s opening an in-depth investigation into Adobe’s proposed $20 billion bid for digital design software rival Figma. The Commission said that the acquisition “may reduce competition in the global markets for the supply of interactive product design software and for digital asset creation tools.” First announced last September, Adobe’s megabucks bid for one…
China’s draft measures demand ‘individual consent’ for facial recognition use
The pervasive use of facial recognition technology across all facets of life in China has elicited both praise for its convenience and backlash around privacy concerns. The widespread adoption has also fueled the exponential growth of valuations in companies specializing in the field, such as AI giants SenseTime and Megvii. Now the industry is facing some potentially significant changes as…
Colorado Department of Higher Education warns of massive data breach
The Colorado Department of Higher Education (CDHE) discloses a massive data breach impacting students, past students, and teachers after suffering a ransomware attack in June. In a ‘Notice of Data Incident’ published on the CDHE website, the Department says they suffered a ransomware attack on June 19th, 2023. “On June 19, 2023, CDHE became aware it was the victim of…
FBI Investigation Into Mysterious NSO Spyware Purchase Reveals It Was The FBI Doing The Mysterious Purchasing
As information started to leak out from the… everywhere about NSO Group’s secondhand contribution to surveillance abuses all over the world, the world (except for the worst of NSO’s customers) began taking action. Even the government that facilitated many of NSO’s sales to human rights violators decided it might be time to toss a few restrictions on the Israel-based malware…
U.S. Blacklists Israeli-owned Cyber Arms Firms: Intellexa and Cytrox
Intellexa (AKA Intellexa Anonymi Etaireia), an alliance of digital intelligence firms in Greece run by an ex-Israeli intel officer, and Cytrox AD (AKA Sytrox), which produces their Predator spyware, added to U.S. ‘entity list’ which already includes Israel’s NSO and Candiru. Late last year, Citizen Lab uncovered the hacking of an Egyptian dissident’s phone. The affected device was host to two forms…
Almost 40% of Ubuntu users vulnerable to new privilege elevation flaws
Two Linux vulnerabilities introduced recently into the Ubuntu kernel create the potential for unprivileged local users to gain elevated privileges on a massive number of devices. Ubuntu is one of the most widely used Linux distributions, especially popular in the U.S., having an approximate user base of over 40 million. Two recent flaws tracked as CVE-2023-32629 and CVE-2023-2640 discovered by Wiz’s…