NERC, a non-profit regulatory authority that oversees utilities, revealed this week that about 25% of the electric utilities on the North American power grid downloaded the SolarWinds backdoor.
Threat intelligence firm Group-IB says cybercriminals actively used Google Forms and Telegram bots to collect stolen data from exploit kits during phishing attacks.
The gift cards belonged to 3,010 companies, including Amazon and Walmart, and were allegedly stolen from Cardpool’s backend. Both sales closed very quickly on the dark web forum.
Hot on the heels of high-profile data scraping incidents at Facebook and LinkedIn, the personal information of about 1.3 million users of chat app Clubhouse has been found posted to a hacker forum.
Onapsis and SAP say that cybercriminals are actively exploiting known SAP security vulnerabilities in the wild, sometimes with a cyber attack within 72 hours after patches are released.
Tripwire report finds that IoT security is a major issue at nearly every company; 99% of respondents have security challenges, and over 75% report problems fitting these devices into their present security approach.
Update to the ACLU's privacy policy indicates that the organization is now feeding the same Facebook targeted advertising system it criticizes. Data sharing includes names, email addresses, and phone numbers.
Since 2019, Facebook has been talking about adding end-to-end encryption to all its messaging services. It appears that the government of the United Kingdom would prefer that these plans go no further.
The unique device identifier that Apple uses for personalized ad tracking, the IDFA, has been in the news lately. You may soon be hearing just as much about Google's equivalent for Android, the AAID.
Survey of nearly 2,000 IT professionals indicates that cloud security has been improving as the need for these services grows, but organizations are still hitting some common stumbling blocks.









