News
Self-replicating botnet attacks Ray clusters
Malefactors are actively attacking internet-facing Ray clusters and abusing the open source AI framework to spread a self-replicating botnet that mines for cryptocurrency, steals data, and launches distributed denial of service (DDoS) attacks.…
FCC looks to torch Biden-era cyber rules sparked by Salt Typhoon mess
The Federal Communications Commission (FCC) will vote this week on whether to scrap Biden-era cybersecurity rules, enacted after the Salt Typhoon attacks came to light in 2024, that required telecom carriers to adopt basic security controls.…
Take fight to the enemy, US cyber boss says
America is fed up with being the prime target for foreign hackers. So US National Cyber Director Sean Cairncross says Uncle Sam is going on the offensive – he just isn't saying when.…
Google Chrome bug exploited as an 0-day - patch now or risk full system compromise
Google pushed an emergency patch on Monday for a high-severity Chrome bug that attackers have already found and exploited in the wild.…
Zoomers are officially worse at passwords than 80-year-olds
Gen Z can get off their digital high horses because their passwords are no more secure than their grandparents'.…
'Largest-ever' cloud DDoS attack pummels Azure with 3.64B packets per second
Azure was hit by the "largest-ever" cloud-based distributed denial of service (DDoS) attack, originating from the Aisuru botnet and measuring 15.72 terabits per second (Tbps), according to Microsoft.…
Pentagon and soldiers let too many secrets slip on social networks, watchdog says
Loose lips sink ships, the classic line goes. Information proliferation in the internet age has government auditors reiterating that loose tweets can sink fleets, and they're concerned that the Defense Department isn't doing enough to stop sensitive info from getting out there. …
Security researcher calls BS on Coinbase breach disclosure timeline
A security researcher says Coinbase knew about a December 2024 security breach during which miscreants bribed its support staff into handing over almost 70,000 customers' details at least four months before it disclosed the data theft.…
Selling your identity to North Korean IT scammers isn't a sustainable side hustle
It sounds like easy money. North Koreans pay you to use your identity so they can get jobs working for American companies in IT. However, if you go this route, the US Department of Justice promises to catch up with you eventually.…
Game over: Europol storms gaming platforms in extremist content sweep
Europol's Internet Referral Unit (EU IRU) says a November 13 operation across gaming and "gaming-adjacent" services led its partners to report thousands of URLs hosting terrorist and hate-fueled material, including 5,408 links to jihadist content, 1,070 pushing violent right-wing extremist or terrorist propaganda, and 105 tied to racist or xenophobic groups.…
Overconfidence is the new zero-day as teams stumble through cyber simulations
Teams that think they're ready for a major cyber incident are scoring barely 22 percent accuracy and taking more than a day to contain simulated attacks, according to new data out Monday.…
Eurofiber admits crooks swiped data from French unit after cyberattack
French telco Eurofiber says cybercriminals swiped company data during an attack last week that also affected some internal systems.…
UK prosecutors seize £4.11M in crypto from Twitter mega-hack culprit
British prosecutors have secured a civil recovery order to seize crypto assets worth £4.11 million ($5.39 million) from Twitter hacker Joseph James O'Connor, clawing back the proceeds of a scam that used hijacked celebrity accounts to solicit digital currency and threaten high-profile individuals.…
Jaguar Land Rover hack cost India's Tata Motors around $2.4 billion and counting
Asia In Brief India’s Tata Motors, owner of Jaguar Land Rover, has revealed the cyberattack that shut down production in the UK has so far cost it around £1.8 billion ($2.35 billion).…
Logitech leaks data after zero-day attack
INFOSEC IN BRIEF The US Senate passed a resolution in July to force the US Cybersecurity and Infrastructure Security Agency (CISA) to publish a 2022 report into poor security in the telecommunications industry but the agency has not delivered the document.…
Fortinet finally cops to critical make-me-admin bug under active exploitation
Fortinet finally published a security advisory on Friday for a critical FortiWeb path traversal vulnerability under active exploitation – but it appears digital intruders got a month's head start.…
Crims poison 150K+ npm packages with token-farming malware
Yet another supply chain attack has hit the npm registry in what Amazon describes as "one of the largest package flooding incidents in open source registry history" - but with a twist. Instead of injecting credential-stealing code or ransomware into the packages, this one is a token farming campaign.…
FBI flags scam targeting Chinese speakers with bogus surgery bills
Chinese speakers in the US are being targeted as part of an aggressive health insurance scam campaign, the FBI warns.…
CISA flags imminent threat as Akira ransomware starts hitting Nutanix AHV
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued new guidance to organizations on the Akira ransomware operation, which poses an imminent threat to critical sectors.…
Clop claims it hacked 'the NHS.' Which bit? Your guess is as good as theirs
The UK's National Health Service (NHS) is investigating claims of a cyberattack by extortion crew Clop.…