Twitter hack report reveals that employees were tricked into visiting a phishing page that captured their VPN credentials, a technique that worked due to move to remote working during the pandemic.
Europol has dismantled a large-scale SIM farm operation, arresting seven suspects and seizing 1,200 SIM-box devices containing 40,000 SIM cards registered across 80 countries.
Google is making passkeys the default sign-in option across its services for all users. User feedback found that at least 64% of users said passkeys were easier to use than passwords or two-factor authentication.
Though the fine is not one of the largest issued by CNIL (or for general GDPR violations across the bloc), the case is noteworthy in that Discord is mostly being taken to task for not providing default or built-in security options rather than the fallout of a specific data breach.
Okta has warned about social engineering attacks by sophisticated actors targeting super administrators by tricking service desk staff into resetting multi-factor authentication for privileged users.
Google's new Cybersecurity Action Team warned that cybercriminals compromised unsecured or misconfigured Google Cloud instances to perform cryptocurrency mining.
In what is shaping up to be a major test case for the entire cyber insurance industry, Zurich Insurance is refusing to pay out a $100 million claim from Mondelez, saying that the ransomware attack was actually an act of “cyber war,” and therefore, is not covered by the policy.
Real time bidding is facing a smattering of privacy complaints in the EU based on a lack of required consumer consent under the terms of the GDPR.
The purpose of the cyber attack on WSJ appeared to be espionage, with information exfiltrated from email and Google Drive accounts since at least February 2020. Mandiant believes government-backed Chinese hackers conducted the operation.
Scattered Spider, ShinyHunters, and LAPSUS$ are the three groups involved, and have collectively been the most active of the major cybercrime gangs over roughly the past year. The groups all had prior ties via "The Com," a broader collection of cyber criminals that loosely affiliate and come together for singular projects in a fluid way.










