Threat group commits financial theft by hiding inside the victims’ networks for months while studying their financial systems and injecting fraudulent transactions into regular activity.
CISA stresses that "significant" Log4j breaches have not yet been found in the networks of federal agencies or critical infrastructure, but that it is not yet possible to assess whether the vulnerability is present across all of these disparate systems.
Lapsus$ cybercrime gang claimed responsibility for the Impresa group ransomware attack by defacing the media company’s website and tweeting from its verified Twitter account.
Thousands of companies using popular NPM libraries have just learned that the hidden price of free software is that the open source developer may withdraw their consent at any time.
FlexBooker, a commonly used appointment scheduling and calendar service, is apologizing to its customers after 3.7 million records appeared on a dark web hacker forum following a DDoS attack.
The fallout from the Pegasus spyware incident has prompted the Biden administration to issue a warning to the general public about commercial surveillance tools, offering advice for self-protection to journalists and dissidents.
Tech giants are facing hefty fines after France's CNIL ruled that their cookie consent processes were too confusing and difficult. Central to the case was the use of "dark patterns" by each site.
The Office of the Attorney General of New York has recorded 1.1 million compromised accounts. The stolen logins were put to use in credential stuffing attacks against a variety of "well-known" online retail, food and delivery businesses.
Legal action may be forthcoming for organizations that do not patch Log4j. The FTC has issued an alert that references the Equifax breach (which ended in a settlement of $700 million) as a precedent.
Password Manager LastPass says no master password was compromised after multiple users received unauthorized login alerts. The company blamed credential stuffing and system errors.










