The Uber data breach resulted in the theft of a variety of internal company information, and stemmed from a third-party vendor. The thieves also got away with source code and employee personal information.
Study examined 640 of the most popular shopping apps currently available via the Google Play Store. About two-thirds of these make use of ad libraries, and on average these apps connect with 1.8 ad networks that can share phone permissions.
Organizations found to be responsible for a privacy breach now face a maximum penalty of AUD 50 million, 30% of adjusted annual domestic turnover, or three times the value of any benefit obtained through the misuse of the leaked information.
Security researchers discovered an Android malware active since 2008 in Google Play Store and third-party app stores stealing Facebook logins of 300,000 users in 71 countries.
Amnesty International Canada experienced a security breach on October 5 with the ultimate conclusion being that state-sponsored Chinese hackers penetrated the system for espionage purposes.
The US Secret Service is now pointing the finger at state-backed Chinese hackers, accusing a known advanced persistent threat group APT41 of stealing about $20 million of US Covid benefits during the pandemic.
The DoD has published a strategy and roadmap directing all the department's agencies to migrate to zero trust architecture by 2027. Strategy identified 90 target capabilities and 62 capabilities to achieve “more advanced zero trust.”
One of the few significant holes in Apple's end user security is set to be addressed, as Cupertino has announced plans to introduce end-to-end encryption to iCloud backups. A feature Apple has delayed due primarily to pressure from US federal law enforcement agencies.
Security leak of manufacturing keys from major device producers (such as LG and Samsung) allows signing of malware apps, providing full access to an Android device, as the operating system trusts any signed app with complete system-level access.
Ragnar Locker ransomware gang targeted the municipality of Zwijndrecht but instead hacked a local Belgian police unit, releasing sensitive police data, including investigation reports and criminal records.










