The UK financial regulator found that cyber insurance firms "mostly" weathered the stress test, in the sense that only a small number reported concluding the scenario with an amount of funds on hand that would put them beneath national solvency capital requirements.
A new development in an old data breach has seen 73 million AT&T customer passcodes published to an underground forum. The data leak now appears to be as bad as originally advertised with customer contact information attached to weakly encrypted passcodes that are easily deciphered.
The official word from Meta, via its main Instagram account, is that an "issue" that allowed third parties to request password resets for "some people" was fixed on January 11 and that users could safely ignore the strange password reset messages. They also reassured users that there is no new data breach.
20 NGOs from across the world published a common statement about their serious concerns on Google's access to health data with the planned takeover of Fitbit.
DPC has opened a privacy investigation against Google over location tracking and its capacity to collect massive location data that could be in breach of GDPR regulations.
A threat actor sold for an undisclosed amount a toolkit to conceal and execute malicious code without detection on most graphics cards, including AMD, Nvidia, and Intel.
The Russian hackers call themselves "Killnet" and first made the news in April with declarations of intent to conduct cyber attacks on critical infrastructure in other countries. The group has been linked to prior DDoS campaigns.
Russia's current conflict with Ukraine is so far playing out with cyber attacks rather than physical warfare. A series of defacement attacks on government websites appears to be the opening salvo.
Report found that API security was a major concern for businesses as malicious traffic grew triple that of legitimate sources and causing delays in application rollout.
Hackers exploited Pulse Connect Secure VPN vulnerabilities to collect passwords, install web shells, and bypass multi-factor authentication on victims’ networks, including federal agencies.









