Neopets virtual pet website suffered a data breach that allowed hackers to access the platform's source code and personal information of 69 million users. Hacker continues to maintain access after confirmed data breach.
Popular cloud-based word processor app WPS, one of the most widely used of its type in China, may be facilitating state censorship of user’s private documents. User complained million-word document was locked due to "sensitive content."
Since June, some ransomware gangs have begun incorporating search functions into their data leak sites, making stolen data more accessible to put added pressure on victims.
MiCODUS MV720 vehicle GPS tracker has sold some 1.5 million units across 169 countries and used in military vehicles, government cars, etc. Of the six serious vulnerabilities, one is a hard-coded password that allows anyone to send commands to the GPS units.
Ride hailing giant Didi's exile into the wilderness appears to be ending, and the Chinese government's harsh wave of regulatory crackdowns has taken sharper focus, as the investigation has concluded and a fine of $1.2 billion has been announced.
Hackers were impersonating cybersecurity companies by sending phishing emails asking the target to callback to resolve potential network compromise. Victims are then guided to install remote administration tools.
Microsoft discovered a coordinated phishing campaign targeting Office 365 users and leveraging an Adversary-in-the-Middle (AiTM) MFA bypass to execute business email compromise (BEC) attacks and commit fraud.
Fake crypto apps have grown to be a significant problem in the United States, with the FBI reporting a flurry of activity since October 2021. The agency has logged at least 244 victims during this period.
The Cyber Safety Review Board finds that the open source community is "under-equipped" to fully deal with the Log4j vulnerability and that it will be making appearances in the wild for "a decade or more."
Tekken, Elden Ring, Gundam and Pac-Man game publisher Bandai Namco confirmed a suspected BlackCat ransomware attack that potentially exposed sensitive customer information.









