Nokia's Threat Intelligence Report noted an increase in IoT attacks stemming from poor security practices, the use of automated tools by attackers, and Internet visibility of devices.
The unique device identifier that Apple uses for personalized ad tracking, the IDFA, has been in the news lately. You may soon be hearing just as much about Google's equivalent for Android, the AAID.
The report comes from Google’s TAG, which tracks over 30 of these commercial spyware vendors. The current crop of zero-days, which the report saw deployed in late 2022, targets Android and iOS as well as the Chrome web browsers.
Thomson Reuters database leak exposed 3TB of platform information and customer data after the media company left three databases unsecured and publicly accessible for days.
Nearly 25,000 active websites have over 47,000 malicious WordPress plugins installed, putting them at risk of attacks, including complete takeover by cybercriminals.
UK ICO is investigating claims of employee surveillance that include using tracking software to determine when and for how long employees were away from their desks.
Researchers recorded the largest Magecart attack that compromised over 2,000 Magento stores and exposed the private and financial details of over 10,000 customers.
Malware-free attacks now account for 51% of all cyberattacks according to CrowdStrike's latest threat report, up 11% compared to the previous year. The trend marks a shift in the types of attacks used by cybercriminals.
Sophos found that 64% of healthcare organizations chose to pay ransom after ransomware attacks in 2021, up from 34% in 2020, but only 2% of payers recovered all encrypted data.
An update from Okta on its October customer support security breach indicates that the damage is worse than initially expected, with all of the recent users of its Help Center service now being told that the attackers likely stole their uploaded files.









