Security News > 2022 > January

Apple Home software bug could lock you out of your iPhone
2022-01-04 19:23

The bug affects the Home app, Apple's home automation software that lets you control home devices - webcams, doorbells, thermostats, light bulbs, and so on - that support Apple's HomeKit ecosystem. Wiping your data is quick and reliable because Apple mobile devices always encrypt your data, even if you don't set a lock code of your own, using a randomly chosen passphrase kept in secure storage.

Hackers use video player to steal credit cards from over 100 sites
2022-01-04 17:52

Hackers used a cloud video hosting service to perform a supply chain attack on over one hundred real estate sites that injected malicious scripts to steal information inputted in website forms. In a new supply chain attack discovered by Palo Alto Networks Unit42, threat actors abused a cloud video hosting feature to inject skimmer code into a video player.

SlimPay fined €180k after 12 million customers' bank data publicly accessible for 5 years
2022-01-04 17:33

Using real data is a good way to ensure that development code is working as expected before live deployment, but when you are dealing with sensitive information such as bank account details, great care must be taken not to fall foul of data protection regulations. In a later data breach notification, the firm disclosed more details on the security incident, including the number of people and the type of personal data affected by the data breach.

Purple Fox Rootkit Dropped by Malicious Telegram Installers
2022-01-04 17:12

A malicious Telegram instant-messaging app installer scurries past a slew of antivirus engines to deliver Purple Fox malware, evading detection by separating the attack into bite-sized morsels that fly under the radar. "We have often observed threat actors using legitimate software for dropping malicious files," analysts wrote.

UScellular discloses data breach after billing system hack
2022-01-04 17:07

UScellular, self-described as the fourth-largest wireless carrier in the US, has disclosed a data breach after the company's billing system was hacked in December 2021. "On December 13, 2021, UScellular detected a data security incident in 'which unauthorized individuals illegally accessed our billing system and gained access to wireless customer accounts that contain personal information," the carrier explained.

McMenamins Data Breach Affects 12 Years of Employee Info
2022-01-04 16:43

A ransomware attack on the McMenamins dining and hospitality empire in the Pacific Northwest came along with a data breach covering 12 years of employee data, the organization has confirmed. The Dec. 12 incident - which some have attributed to the Conti gang - forced McMenamins to shut down various operations, though locations can still receive customers.

Have I Been Pwned warns of DatPiff data breach impacting millions
2022-01-04 16:22

The cracked passwords for almost 7.5 million DatPiff members are being sold online, and users can check if they are part of the data breach through the Have I Been Pwned notification service. It is unclear when the data breach occurred, but the DatPiff database was first sold privately and then publicly on hacking forums in July 2020.

Online privacy: DuckDuckGo just finished a banner year and looks for an even better 2022
2022-01-04 14:28

Commentary: The privacy-oriented search engine keeps winning fans. The privacy-oriented search engine netted more than 35 billion search queries in 2021, a 46.4% jump over 2020.

John Edwards takes the reins at the UK's data protection watchdog
2022-01-04 13:58

The Information Commissioner's Office has confirmed that former New Zealand privacy commissioner John Edwards has started his new role as the UK's Information Commissioner. While legal experts have warned of the dangers of the UK straying too far from the EU's General Data Protection Directive - or risking the adequacy decision which currently allows data sharing between the UK and the EU to support business as usual - his message is don't stop believing.

#UK
Portugal Media Giant Impresa Crippled by Ransomware Attack
2022-01-04 13:16

Media giant Impresa, which owns the largest television station and newspaper in Portugal, was crippled by a ransomware attack just hours into 2022. The suspected ransomware gang behind the attack goes by the name Lapsus$.