The cyber crime group that locked up an Indonesian national data center last month, impacting hundreds of government services, has opted to provide the ransomware decryptor for free. This was accompanied by an apology, but also a donation link exhorting the Indonesian government and public to show gratitude for their supposed generosity.
Traditional form of security awareness training rarely achieves what it’s set out to do. Instead, valuable time is taken out of employees’ days to complete training that positions them as the problem, thereby reinforcing a negative stigma and undermining the entire process.
Leading data breach cross-checking service Have I Been Pwned has added about 71 million email addresses from "Naz.API," a new dataset circulating on the dark web that contains a massive collection of leaked credentials and plaintext passwords.
Mobile app makers can now use uninstall tracking software to inundate ex-users with advertising designed to win them back. Can app developers continue to use customer data for any purpose which fits their business model – even after users have deleted the mobile app?
Attackers approach targets for account takeover pretending to be a member of the Meta tech support team, using Facebook profiles that they have created that have a post history that makes it appear as if they are a legitimate employee.
A new FBI security alert indicates that a group of Iranian hackers are on a spree of compromising the BIG-IP products manufactured by F5 Networks.
Clop ransomware has breached dozens of organizations, including the City of Toronto, Virgin Red, and Pension Protection Fund via the GoAnywhere vulnerability.
A botnet used by a state-backed Chinese hacking group has lost at least some of its capacity, according to security officials that spoke to Reuters anonymously. The Volt Typhoon group has been targeting US critical infrastructure since at least mid-2021.
China’s new rules for facial recognition technology require companies to protect personal information, and to demonstrate a "specific purpose" and "sufficient necessity" when collecting biometric data of this nature.
MGM, one of the two largest casino-hotel chains on the Strip, has not yet confirmed the nature of the attack, calling it a 'cybersecurity issue.' The properties remain open, but operations such as front desk check-ins and payouts for casino games have had to shift to entirely manual operations.









