Apple has introduced significant changes to the security and privacy features in iOS 13 which could cause users to ignore important prompts and use unsafe workarounds to get rid of them.
Windows Hello Vulnerability Allows Attackers To Bypass Biometric Authentication Using Spoofed Images
Researcher discovered a Microsoft Windows Hello vulnerability allowing an attacker to bypass biometric authentication using images recreated from the target's face.
Malwarebytes discovered a malvertising campaign targeting top keywords and users' search behavior to display malicious Google Ads and redirecting to Windows support scam websites.
Winnti malware makes a “comeback”, victimizing major international firms including Bayer, BASF, Siemens and others. The attackers are particularly interested in industrial secret and tracking movements of specific people.
New proposed Washington Privacy Act will have provisions on facial recognition technology that require explicit opt-in consent for companies to collect and use biometric data.
WK Kellogg Confirms Data Breach from Cleo Managed File Transfer System Attributed to Clop Ransomware
U.S. food giant WK Kellogg Co. has disclosed a data breach that affected Cleo, a third-party managed file transfer system that allowed a threat actor to access sensitive information.
The original version of Wordle, hosted by creator Josh Wardle on a self-hosted website, did not have any advertising or connection to ad tracking networks.
Human capital management (HCM) software giant Workday says that a social engineering data breach on a third-party CRM system has impacted its clients’ business information.
The mass shift to working from home precipitated by the Covid-19 pandemic created massive security challenges. A full 30% of remote workers under the age of 24 say that they circumvent or ignore security policies when they get in the way of getting work done.
Scattered Spider, ShinyHunters, and LAPSUS$ are the three groups involved, and have collectively been the most active of the major cybercrime gangs over roughly the past year. The groups all had prior ties via "The Com," a broader collection of cyber criminals that loosely affiliate and come together for singular projects in a fluid way.









