An attacker could use a vulnerability to issue fake alerts via the Emergency Alert Systems. The vulnerable software is in the possession of television and radio stations throughout the country, who are being called upon to download a software update.
Security researchers have found over 35,000 code repositories with malicious forks or clones leading back to a single source. Malware in the tainted code repositories is designed to steal environment variables, stored elements that serve as authentication for various online services.
A cybersecurity startup Buguard said hackers used malware to steal passwords for Wiseasy's remote control dashboards to compromise payment terminals worldwide. Hackers could control payment terminals, install and remove apps, access personal information, and make configuration changes using the remote control dashboards.
The problem stems from developers failing to remove the Twitter API keys they use for authentication from the app before they release it to the public. This creates the possibility of account hijacking.
The FCC warned about increased robotext scams from automated smishing attacks stealing personal information by impersonating known companies such as credit card companies, parcel delivery services, and law enforcement agencies.
New FTC rules governing consumer data processing and handling, with a focus on the "commercial surveillance" conducted by data brokers, have entered a public comment period.
The Cisco network breach was traced back to an employee's personal Google account. It was protected by multi-factor authentication (MFA), but the attacker tried a number of different voice phishing attempts.
The UK government line is that it does not want to outlaw end-to-end encryption, but simply "provide necessary tools" to law enforcement to ensure child cyber safety. This may include client-side scanning.
Reasonable anonymous transactions have been proposed for the digital yuan, which is currently in testing in multiple regions of the country. PBOC officials have also promised to deliver the best privacy protection, though questions remain.
An SMS phishing attack compromised cloud communications giant Twilio, leaking customer data and targeted content delivery network provider Cloudflare. Twilio says the data breach impacted at least 125 customers.










