News
MIT Sloan quietly shelves AI ransomware study after researcher calls BS
Do 80 percent of ransomware attacks really come from AI? MIT Sloan has now withdrawn a working paper that made that eyebrow-raising claim after criticism from security researcher Kevin Beaumont.…
Ransomware negotiator, pay thyself! Rogues committed extortion while working for infosec firms
A ransomware negotiator and an incident response manager at two separate cybersecurity firms have been indicted for allegedly carrying out ransomware attacks of their own against multiple US companies.…
AWS, Nvidia, CrowdStrike seek security startups to enter the arena
Cloud and AI security startups have two weeks to apply for a program that fast-tracks access to investors and mentors from Amazon Web Services, CrowdStrike, and Nvidia.…
Cybercrooks team up with organized crime to steal pricey cargo
Cybercriminals are increasingly orchestrating lucrative cargo thefts alongside organized crime groups (OCGs) in a modern-day resurgence of attacks on freight companies.…
Metropolitan Police hails facial recognition tech after record year for arrests
London's Metropolitan Police Service (MPS) says the hundreds of live facial recognition (LFR) deployments across the Capital last year led to 962 arrests, according to a new report on the controversial tech's use.…
The race to shore up Europe’s power grids against cyberattacks and sabotage
Feature It was a sunny morning in late April when a massive power outage suddenly rippled across Spain, Portugal, and parts of southwestern France, leaving tens of millions of people without electricity for hours.…
Attackers targeting unpatched Cisco kit notice malware implant removal, install it again
Infosec in brief Australia’s Signals Directorate (ASD) last Friday warned that attackers are installing an implant named “BADCANDY” on unpatched Cisco IOS XE devices and can detect deletion of their wares and reinstall their malware.…
Russia finally bites the cybercrooks it raised, arresting suspected Meduza infostealer devs
Russia's Interior Ministry says police have arrested three suspects it believes helped build and spread the Meduza infostealer.…
Attackers dig up $11M in Garden Finance crypto exploit
Blockchain company Garden admits it was compromised and temporarily shut down its app after approximately $11 million worth of assets were stolen.…
Resilience, not sovereignty, defines OpenStack's next chapter
OpenInfra Summit Sovereignty might be the word of the hour, but the OpenStack community has another – resilience.…
NHS left with sick PCs as suppliers resist Windows 11 treatment
NHS hospitals are being blocked from fully upgrading to Windows 11 by a small number of suppliers that have yet to make their medical devices compatible with Microsoft's latest operating system.…
Europe preps Digital Euro to enter circulation in 2029
The Governing Council of the European Central Bank (ECB) has decided the bloc needs a digital version of the Euro, and ordered work that could see it enter circulation in 2029.…
Suspected Chinese snoops weaponize unpatched Windows flaw to spy on European diplomats
Cyber spies linked to the Chinese government exploited a Windows shortcut vulnerability disclosed in March – but that Microsoft hasn't fixed yet – to target European diplomats in an effort to steal defense and national security details.…
Proton trains new service to expose corporate infosec cover-ups
Some orgs would rather you not know when they've suffered a cyberattack, but a new platform from privacy-focused tech firm Proton will shine a light on the big breaches that might otherwise stay buried.…
Docker Compose vulnerability opens door to host-level writes – patch pronto
Docker Compose users are being strongly urged to upgrade their versions of the orchestration tool after a researcher uncovered a flaw that could allow attackers to stage path traversal attacks.…
Invisible npm malware pulls a disappearing act – then nicks your tokens
A new supply chain attack dubbed PhantomRaven has flooded the npm registry with malicious packages that steal credentials, tokens, and secrets during installation. The packages appear safe when first downloaded, making them particularly difficult for security apps to identify.…
Cyberpunks mess with Canada's water, energy, and farm systems
Hacktivists have breached Canadian critical infrastructure systems to meddle with controls that could have led to dangerous conditions, marking the latest in a string of real-world intrusions driven by online activists rather than spies.…
Postcode Lottery's lucky dip turns into data slip as players draw each other's info
A major UK lottery organization says it has resolved a technical error that exposed customer data to other users.…
France jacks into the Matrix for state messaging – and pays too
Comment Decentralized communications network Matrix is hoping to be the beneficiary as European public and private sector organizations ponder alternatives to the messaging status quo.…
This security hole can crash billions of Chromium browsers, and Google hasn't patched it yet
Exclusive A critical, currently unpatched bug in Chromium's Blink rendering engine can be abused to crash many Chromium-based browsers within seconds, causing a denial-of-service condition – and, in some tests, freezing the host system.…