According to cyber security firm Check Point Software Technologies, Android app makers are still not patching old security flaws, some of which date back to 2014.
Data leak occurred when a sensitive document was mistakenly shared in connection to a freedom of information request, and takes place amidst a backdrop of increased tensions and fears of terrorism that have been growing since early 2023.
About 26 Million Fortune 1000 Employee Credentials Available on the Dark Web, Password Reuse Rampant
SpyCloud found about 26 million Fortune 1000 employee credentials circulating on the dark web. Password reuse, weak passwords, and infostealers were responsible for the leaks.
Cloud security firm Ermetic found that vulnerable identities and misconfigured environments on most AWS accounts expose 90% of S3 buckets to potential ransomware attacks.
Maze ransomware attack on the IT services company may cause chain reaction across the industry. Besides service disruptions, customers may face elevated risks of fraud and cyber threats.
Russian phishing campaign targets commercial messaging apps, specifically Signal, to steal recovery keys, access historical messages, private and group chats, and take over accounts.
More than one-third of organizations are concerned about privacy compliance budget spending to meet the requirements of evolving data privacy laws around the globe.
The international community is under no illusion regarding the persistent threat that is posed by Russian hackers as the U.S. Department of Justice indicts 7 Russian GRU members, and other nations including the U.K. and the Netherlands protest hacking activities.
For the first time in its publication history of nearly 20 years, Verizon's annual Data Breach Investigations Report (DBIR) is tracking vulnerability exploitation as the leading initial access method for attackers. Stolen credentials had been the #1 method for the entirety of the report's history up to this year.
Russian firm of uncertain backing called Operation Zero appears to be shaking up the zero-day exploit market, offering up to $20 million if hackers and researchers come to them first. Company claims that the market is undervalued.










