Recently discovered TikTok's security flaws make it possible to spoof the source of SMS messages, alter people's feeds and accounts, and also access sensitive personal information via API calls.
CDK Global, a SaaS provider for the auto industry, has suffered a second cyber attack while recovering from a previous cybersecurity incident, disrupting thousands of auto dealers.
A new report indicates that ransomware costs are being cut considerably due to better preparedness. And though cyber insurance claims spiked in early 2021 due to the Microsoft Exchange vulnerability, they have been on a steep downward trend since.
A new theoretical attack described by researchers with LayerX lays out how frighteningly simple it would be for a malicious or compromised browser extension to intercept user chats with LLMs and insert prompt injection attacks designed to exfiltrate data without the target being aware.
A ransomware attack on eResearch Technology, the firm behind three-quarters of FDA drug approvals, slowed down clinical trials for several research facilities.
Business users' billing information was inadvertently stored in the browser's cache, making it possible for the exposed data to be accessed by users who share computers.
Despite the NSA warning of hackers exploiting bugs such as Bluekeep and Heartbleed vulnerabilities and updates being released, millions of vulnerable systems remained unpatched.
SK Telecom, South Korea’s largest mobile network operator, warns about a malware attack that leaked sensitive USIM data, exposing subscribers to potential SIM swaps and surveillance.
A security breach affecting the AI aggregator platform OmniGPT has leaked the sensitive information of 30,000 individuals including API keys, chat logs, and uploaded files.
Whether it is company culture or an individual attitude, developers do appear to be commonly shipping vulnerable code with the full knowledge that there are weaknesses in it.










