Hackers compromised carding site Card Mafia exposing 300,000 user account credentials. A hacker later offered the stolen data for free on a different hacking forum.
Vulnerable IT service providers are becoming entry points for supply chain attacks as seen in the recent attack on Wipro. The attack follows closely after Wipro CEO declares "security cannot be a show stopper for business priorities".
Group of nine privacy and anti-monopoly advocacy groups have called on the FTC to break up Facebook, citing the tech company’s long track record of ignoring privacy concerns, the group also called on the FTC to fine Facebook as much as $2 billion.
Chinese APT group Weaver Ant breached and maintained a foothold on a large Asian telco network for four years using compromised Zyxel CPE routers for cyber espionage.
Maze ransomware attack on the IT services company may cause chain reaction across the industry. Besides service disruptions, customers may face elevated risks of fraud and cyber threats.
The Qantas breach appears to be isolated to a third-party contact center that the airline uses for customer service queries. Unusual activity was detected on June 30, leading to discovery of the data breach and "immediate" actions to contain it, and up to six million customers may be impacted.
A member of a hacker forum claims that they have stolen Razer's "keys to the kingdom" in the form of source code, encryption keys and employee credentials, and is looking for a $100,000 Monero payout. Razer has yet to confirm the data breach.
The US tech companies oppose what they call an "undue expansion of government access," but also a requirement that they seek permission before being allowed to send local data overseas. The proposed data protection law also has vague and expansive terms here.
The NSA urged developers and organizations to switch to memory-safe languages to address memory safety issues responsible for most exploitable vulnerabilities. Microsoft and Google attribute 70% of some of their product vulnerabilities to software memory safety issues.
Microsoft discovered a coordinated phishing campaign targeting Office 365 users and leveraging an Adversary-in-the-Middle (AiTM) MFA bypass to execute business email compromise (BEC) attacks and commit fraud.










