Authorities in the U.S. and Australia have warned that the BianLian ransomware gang has abandoned the double extortion model for purely data extortion attacks. More groups are likely to follow suit and forego the hassle of developing and managing the encryption and decryption process in favor of a less complicated attack,
In what is being called the first cyber attack of its type, autonomous AI agents were used to map a score of Taiwan government systems and crack 85 accounts. While there has been no formal attribution as of yet, evidence points strongly to an overseas origin and likely to hackers based in China.
A hacker on a Russian-speaking forum is selling hundreds of business executives' email and password combinations for Office 365 and Microsoft accounts for use in BEC scams.
Red Dead Redemption 2 and GTA 5 game maker Rockstar Games confirms a data breach stemming from a third-party cloud provider after hackers threatened to leak stolen information.
Google admitted that back in March 2018, it became aware of a data breach that may have impacted up to 500,000 users, but failed to disclose it to users or regulators. Are big Silicon Valley tech giants are “too big to trust”?
Google Threat Intelligence Group has warned about sophisticated cyber attacks on critical infrastructure by the Scattered Spider ransomware gang via VMware.
Less than 100 days to go, and so far only two European countries have adapted their laws to be ready for GDPR. While the GDPR aims to harmonize rules across the European Union and to benefit companies to deal with just one law, many member states are eyeing possible exemptions as they change their national laws.
A new source of cyber risk and attack may come from posting instructions that include a ZIP or MOV file name, with that text automatically converted into a URL leading to one of these new top-level domains.
A new ransomware reporting bill introduced to the House of Representatives proposes putting new requirements on financial institutions, some of which are likely to be controversial. Any payment of over $100,000 would require the victim to first obtain special permission from the US Treasury.
Much-needed EDPB guidance on the Schrems II judgment has been released and the picture looks about as grim as possible for impacted companies thus far.









