New Citizens Lab report reveals that the government of Bahrain has used the Pegasus iPhone spyware to track at least nine activists since June 2020. Two zero-days used in zero click iPhone exploit targeting iMessage.
Poor corporate data responsibility hurts consumer trust, preventing users from sharing data because of privacy and safety concerns as organizations stepped up data collection.
Report says merchants are overconfident about their ability to stop online shopping fraud while their customers think otherwise and blame them instead of criminals for breaches.
Microsoft Power Apps appears to list all data types as public unless the default settings are changed. The data leak exposed several coronavirus tracing and vaccination portals, as well as at least one job applicant database that contained social security numbers.
Research on underground forums found that cybercriminals made careers selling network access for up to five figures instead of exploiting the networks themselves.
Germany's data protection authority has determined that Zoom's data transfers to the U.S. are in violation of the terms of the GDPR in light of the Schrems II ruling, and has issued a formal warning.
Most ransomware attacks begin with some combination of phishing and social engineering. An enterprising ransomware gang in Nigeria appears to be skipping this messy step, simply making a direct pitch to employees to join in on the attack.
Crypto exchange Liquid, one Japan's most popular exchanges, is now short $97 million in total assets after a cyber attack that pulled funds directly from the wallets of some of its customers.
China’s new GDPR-style data protection law does almost nothing to curb the state's unfettered access to data stored within the country, but does sharply limit the ways in which tech firms can handle and share it.
Supply chain vulnerability in the ThroughTek "Kalay" network, a cloud-based communications platform used by an estimated 83 million IoT devices, could allow for remote compromise and control.










