The long-running Qakbot malware botnet was disrupted by international law enforcement action in August, but its operators appear to still have some capability and are continuing to run spam email campaigns that attempt to pass ransomware.
Canada Post has been scanning address data from the outside of envelopes it delivers and selling it to third-party mail marketing lists. The Office of the Privacy Commissioner of Canada (OPCC) found that this violates a Privacy Act requirement to obtain authorization from individuals before collecting information in this way.
Proposed EU Cyber Resilience Act includes a vulnerability disclosure requirement that would have all manufacturers report to the government within 24 hours of first discovered exploitation. In most cases, this would mean disclosing before the vulnerability has been mitigated.
MGM's ransomware attack in September is expected to have $100 million negative impact for Q3 due to cleanup costs and lost business. The company believes that its cybersecurity insurance will cover nearly all of the ransomware attack's associated costs.
Cybercriminals inserted malicious ads into Microsoft Bing Search AI chatbot to trick unsuspecting users into downloading trojanized software from spoofed domains.
A security vulnerability that was initially documented as a Chrome bug is likely part of the attack chain employed by NSO Group's Pegasus spyware, and has been revised as a critical libwebp flaw in a new CVE ID filed by Google.
State-backed Chinese hackers can modify Cisco routers without being detected and install custom firmware that allows for persistent access, according to a new joint cybersecurity advisory published by CISA and both US and Japanese law enforcement agencies.
Small businesses with under AUD 3 million annual turnover have been exempt from Australia's Privacy Act terms to date, but that has been taken off the table in a new round of reforms that could become law in 2024.
A third-party breach on a reputable service provider has leaked OpenSea API keys, exposing NFT holders’ accounts to exploitation by unauthorized external parties.
Russian firm of uncertain backing called Operation Zero appears to be shaking up the zero-day exploit market, offering up to $20 million if hackers and researchers come to them first. Company claims that the market is undervalued.










