Montenegro is dealing with a brutal ongoing campaign of ransomware attacks that appears to be coming from criminal groups in Russia. Government agencies in Chile have also been hit by a new form of ransomware that targets Linux servers.
A new ePrivacy complaint from noyb alleges that advertising emails are sent to Gmail users without their consent, a violation of that directive.
The FBI warned about the prevalent use of proxies and configurations to mask and automate credential stuffing attacks. Threat actors extensively leveraged residential proxies instead of those connected to data centers to avoid triggering suspicious behavior monitors.
Cybersecurity researchers discovered over 80,000 Hikvision cameras exposed online without security fixes for an critical exploited vulnerability whose patch was released in September 2021.
The first CCPA enforcement action has just been handed down, resulting in $1.2 million in penalties and a mandatory compliance program for Sephora’s privacy violation.
The attack the food delivery company DoorDash appears to have been part of the ongoing "0ktapus" campaign, which first made news when it ensnared Twilio. Customers may have had contact information exposed along with order information and partial credit card information.
Hackers demanded $10 million after executing a ransomware attack on a French hospital, disrupting operations and forcing the deferral of appointments and referral of patients to other facilities.
In the roughly five months that the Okta phishing campaign has been active, it has racked up 9,931 login credentials from about 130 organizations. 5,541 included MFA codes, and 3,120 included the victim's email account.
Alarms raised about embedded TikTok browser capable of tracking keystrokes. Company says that the ability exists within the code, but that it is not active and only used internally for debugging and testing purposes.
Recent security breach at password manager LastPass does not appear to be an immediate threat to the encrypted vaults that customers use to store their passwords, but the hackers may have made off with source code and proprietary information.









