A lawsuit filed in California is accusing Google's "Gemini" AI assistant of spying on private communications, citing an undeclared change in policy from opt-in to opt-out that took place in October of this year.
The UK has experienced a long string of disruptive cyber incidents, but the announcement of the cyber resilience bill cites attacks on managed service providers as a particular impetus for the overhaul of existing laws.
Europol has dismantled a cybercrime operation tied to Elysium, Rhadamanthys, and VenomRAT malware networks, which stole millions of credentials and over 100,000 crypto wallets.
A new report from the Association of British Insurers (ABI) has tallied up the cyber insurance claims from 2024 and found that payout numbers more than tripled from those recorded in 2023, with a 230% year-on-year increase.
The Swedish Authority for Privacy Protection (IMY) is investigating a data breach at major government software supplier Miljödata that has compromised the personal information of 1.5 million people.
Scattered Spider, ShinyHunters, and LAPSUS$ are the three groups involved, and have collectively been the most active of the major cybercrime gangs over roughly the past year. The groups all had prior ties via "The Com," a broader collection of cyber criminals that loosely affiliate and come together for singular projects in a fluid way.
Google's report of novel AI-enabled malware in the wild is a game changer if these capabilities are now being picked up by sophisticated attackers. It identifies two specific new malware families, "PROMPTFLUX" and "PROMPTSTEAL," that are the first to incorporate a "just in time" dynamic function creation feature that draws on an LLM.
Nikkei, the world’s largest business news outlet, which owns over 40 affiliates, including The Financial Times, and has more than 3.7 million paid subscribers and over 1.7 million daily readers, has confirmed a data breach that leaked personal information after threat actors compromised its Slack accounts.
The apparently partially politically motivated attacker claimed to have exfiltrated over 1.2 million records of personal information in the data breach, some of which dates back decades and included banking information.
The Canadian Centre for Cyber Security has warned of hacktivists breaching critical infrastructure via Internet-exposed ICS devices, posing serious safety risks.










