Category: x.tech

Genetics firm 23andMe says user data stolen in credential stuffing attack

23andMe has confirmed to BleepingComputer that it is aware of user data from its platform circulating on hacker forums and attributes the leak to a credential-stuffing attack. 23andMe is a U.S. biotechnology and genomics firm offering genetic testing services to customers who send a saliva sample to its labs and get back an ancestry and genetic predispositions report. Recently, a threat…

MGM Resorts ransomware attack led to $100 million loss, data theft

MGM Resorts reveals that last month’s cyberattack cost the company $100 million and allowed the hackers to steal customers’ personal information. The hospitality and entertainment giant disclosed a cybersecurity issue on September 11, 2023, which impacted its main website, online reservations systems, and in-casino services like slot machines, credit card terminals, and ATMs. A few days later, it was revealed that the…

Popular “AI Hub” Discord Taken Down Following Copyright Complaints

In just a few months, “AI Hub” became a massively popular Discord server with over half a million members. While copyright infringement was strictly forbidden, not all users stuck to the rules. This previously raised the attention of the RIAA, and now appears to have caused the server’s downfall after it was suddenly shut down. Artificial intelligence is booming. Dozens…

Warning: 100,000 industrial control systems exposed online

About 100,000 industrial control systems (ICS) were found on the public web, exposed to attackers probing them for vulnerabilities and at risk of unauthorized access. Among them are power grids, traffic light systems, security and water systems. Exposed ICSs include units (sensors, actuators, switches, building management systems, and automatic tank gauges) for critical infrastructure systems. Cybersecurity company BitSight alerted of the…

Google Accused Of Secretly Altering Search Queries To Drive More Ads And Sales

I know many of you have heard this before, but Cory Doctorow’s “enshittification” concept is such a useful framework to think about things: first, companies are good to their users; then they abuse their users to make things better for their business customers; finally, they abuse those business customers to claw back all the value for themselves. As I’ve highlighted,…

Philippines Pirate Site Blocking Scheme Comes to Fruition

This month, the Philippines celebrates its creative industries by dedicating a special month to their work. On top of that, the Government presented a long-awaited ‘gift’. The Intellectual Property Office of the Philippines (IPOPHL) announced that local site-blocking plans are about to come to fruition. IPOPHL Director General Rowel Barba signed a memorandum that will go into effect in late…

Disclosure of Pirates’ Identities “Compatible With EU Privacy Laws”

Following the creation of its Hadopi anti-piracy agency over 13 years ago, France monitored and stored data on millions of users suspected of infringing copyrights. The majority were BitTorrent users and the plan was to use evidence of their piracy activities as a basis for escalating actions including warnings, fines, and ultimately, internet disconnections. Operating the program for a decade…

The Group Claiming To Have Hacked Sony Is Using GDPR As A Weapon For Demanding Ransoms

Unintended Consequences We’ve spilled a great deal of ink discussing the GDPR and its failures and unintended consequences. The European data privacy law that was ostensibly built to protect the data of private citizens, but which was also expected to result in heavy fines for primarily American internet companies, has mostly failed to do either. While the larger American internet…

Microsoft breach led to theft of 60,000 US State Dept emails

Chinese hackers reportedly stole tens of thousands of emails from U.S. State Department accounts after breaching Microsoft’s cloud-based Exchange email platform in May. During a recent Senate staff briefing, U.S. State Department officials disclosed that the attackers stole at least 60,000 emails from Outlook accounts belonging to State Department officials stationed in East Asia, the Pacific, and Europe, as Reuters first…

Air Canada discloses data breach of employee and ‘certain records’

Air Canada, the flag carrier and the largest airline of Canada, disclosed a cyber security incident this week in which hackers “briefly” obtained limited access to its internal systems. According to the airline, the incident resulted in the theft of a limited amount of personal information of some of its employees and “certain records.” Customer data was not affected. Hackers “briefly”…

TransUnion denies it was hacked, links leaked data to 3rd party

Credit reporting firm TransUnion has denied claims of a security breach after a threat actor known as USDoD leaked data allegedly stolen from the company’s network. The Chicago-based company’s over 10,000 employees provide their services to millions of consumers and more than 65,000 businesses from 30 countries. “Immediately upon discovering these assertions, we partnered with outside cybersecurity and forensic experts…

Microsoft leaks 38TB of private data via unsecured Azure storage

The Microsoft AI research division accidentally leaked dozens of terabytes of sensitive data starting in July 2020 while contributing open-source AI learning models to a public GitHub repository. Almost three years later, this was discovered by cloud security firm Wiz whose security researchers found that a Microsoft employee inadvertently shared the URL for a misconfigured Azure Blob storage bucket containing the…

University of Sydney data breach impacts recent applicants

  The University of Sydney (USYD) announced that a breach at a third-party service provider exposed personal information of recently applied and enrolled international applicants. The public university started operations in 1850 and has nearly 70,000 students and about 8,500 academic and administrative personnel. It is considered one of Australia’s most important educational institutes. In the data breach announcement, the…

Push To Strip Fox’s Broadcast License Over Election Lies Gains New Momentum

  Last July, we noted how media reform activists had petitioned the FCC to revoke Fox News’ local broadcast license in Philadelphia. More specifically, the group argued that Fox News’ rampant election fraud propaganda technically violated the “character clause” embedded in the Communications Act the FCC is supposed to use to determine whether an organization should hold a broadcast license. To be…

Two founders behind Russian crypto mixer Tornado Cash charged by U.S. federal courts

The two founders behind Tornado Cash, a Russian cryptocurrency mixing service, have been charged by the U.S. Attorney’s Office for the Southern District of New York, according to a statement on Wednesday. Roman Storm and Roman Semenov were officially charged with conspiracy to commit money laundering, conspiracy to commit sanctions violations and conspiracy to operate an unlicensed money transmitting business,…

Scraped data of 2.6 million Duolingo users released on hacking forum

The scraped data of 2.6 million DuoLingo users was leaked on a hacking forum, allowing threat actors to conduct targeted phishing attacks using the exposed information. Duolingo is one of the largest language learning sites in the world, with over 74 million monthly users worldwide. In January 2023, someone was selling the scraped data of 2.6 million DuoLingo users on…