Shadow API is the greatest API security risk, with 31% of malicious requests targeting unknown, unmanaged, or unprotected APIs, according to the Cequence API protection report.
The Binance crypto hack manipulated the Binance Smart Chain Token Hub bridge to pass forged proof messages. The attackers were then able to generate BNB directly to wallets under their control.
A new poll from Deloitte finds there is an immediate and significant cyber risk from "harvest now decrypt later" (HNDL) attacks, in which attackers steal encrypted information and simply sit on it until quantum computing advances make it trivial to crack.
Ukraine warns of Russian plans for massive cyber attacks on Ukraine's critical infrastructure to slow down the counteroffensive and those of Kyiv's allies in retaliation for support.
Following Optus hack, the Telstra data breach appears to be limited to the signup process of a third-party rewards system for company staff, but two telcos losing personal information in two weeks has caused serious concern.
About 50% of those who had information stolen say they were victimized more than once. And the number of people that lost at least $10,000 to personal data theft jumped from 9% of respondents to 30% in 2021.
Microsoft Exchange zero-day vulnerabilities affect an estimated 250,000 on-premise servers. The company is aware of attacks involving a single state-sponsored group that compromised less than ten organizations.
The fallout from the Log4j vulnerability has prompted bipartisan action to beef up open source software security. Proposed act would task CISA with developing a risk framework to evaluate open source code used by the federal government, and could be passed on to critical infrastructure businesses.
Meta stands accused of breaking Apple privacy rules, as a set of proposed class-action lawsuits describes it using its in-app browsers to track activity without user knowledge or consent.
The EU privacy watchdog opened 2022 with an order to Europol to delete stored data on persons not connected to or involved with a crime. But a mid-2022 reform of Europol's governing regulations retroactively legalized this data practice.










