Europol has dismantled a cybercrime operation tied to Elysium, Rhadamanthys, and VenomRAT malware networks, which stole millions of credentials and over 100,000 crypto wallets.
The UK has experienced a long string of disruptive cyber incidents, but the announcement of the cyber resilience bill cites attacks on managed service providers as a particular impetus for the overhaul of existing laws.
A lawsuit filed in California is accusing Google's "Gemini" AI assistant of spying on private communications, citing an undeclared change in policy from opt-in to opt-out that took place in October of this year.
While the proposed EU privacy law changes seem almost entirely like concessions to big tech desires at first glance, the European Commission is selling them as removement of onerous restrictions on smaller businesses. Critics such as noyb are calling this a "side-show" meant to pass changes that are instead really tailored to the tech industry.
Anthropic's calls the incident the "first reported AI-orchestrated cyber espionage campaign" and has attributed it with high confidence to a Chinese state-sponsored group it calls GTG-1002. The campaign took place in mid-September and the integration of AI agents for performance of autonomous tasks is described as unprecedented.
Logitech confirms a third-party data breach after Cl0p ransomware, which is infamous for exploiting Oracle’s E-Business Suite zero-day vulnerabilities, claims responsibility.
With the first new release since 2021, the one thing that hasn't changed about the OWASP Top 10 is that "broken access control" is still the lead category after all this time, present as a security risk in 3.73% of the apps that were tested.
DoorDash has confirmed a data breach that exposed customer, Dasher, and merchant information after an employee fell victim to a compelling social engineering scam.
Google says that Chinese SMS phishing campaigns have collectively yielded somewhere between 15 million and 100 million stolen credit cards in the US alone. The case names 25 individuals and believes the hackers produced over 100 different fraudulent websites that made use of Google branding.
Microsoft says its Azure cloud platform was hit by the largest of its kind DDoS attack from a Turbo Mirai-class IoT botnet, Aisuru, harnessing over 500,000 residential IPs.










