Security News > 2024 > January

23andMe data breach: Hackers stole raw genotype data, health reports
2024-01-25 22:05

Genetic testing provider 23andMe confirmed that hackers stole health reports and raw genotype data of customers affected by a credential stuffing attack that went unnoticed for five months, from April 29 to September 27. The credentials used by the attackers to breach the customers' accounts were stolen in other data breaches or used on previously compromised online platforms.

How to Use Zoho Vault Password Manager: A Beginner’s Guide
2024-01-25 20:48

Zoho Vault is a business-focused password manager that provides convenient monitoring tools for administrators in large organizations. Figure D. While the password manager itself will work as advertised, I highly recommend also downloading Zoho Vault's browser extension.

Blackwood hackers hijack WPS Office update to install malware
2024-01-25 20:30

A previously unknown advanced threat actor tracked as 'Blackwood' is using sophisticated malware called NSPX30 in cyberespionage attacks against companies and individuals. Researchers at cybersecurity company ESET discovered Blackwood and the NSPX30 implant in a campaign in 2020 and believe that the group's activities align with Chinese state interests.

Zoho Vault Review (2024): Pricing, Features, Pros & Cons
2024-01-25 20:14

Zoho Vault is a business-oriented password manager that shines in its security dashboards and reporting capabilities, which are perfect for larger organizations. Aside from password generation and storage, Zoho Vault comes with team-focused features that business managers will find useful.

Russian TrickBot malware dev sentenced to 64 months in prison
2024-01-25 18:52

Russian national Vladimir Dunaev has been sentenced to five years and four months in prison for his role in creating and distributing the Trickbot malware used in attacks against hospitals, companies, and individuals worldwide. The initial indictment accused Dunaev and eight co-defendants of engaging in the development, deployment, administration, and financial gains from the Trickbot malware operation.

iPhone apps abuse iOS push notifications to collect user data
2024-01-25 18:28

Numerous iOS apps are using background processes triggered by push notifications to collect user data about devices, potentially allowing the creation of fingerprinting profiles used for tracking. "Apps should not attempt to surreptitiously build a user profile based on collected data and may not attempt, facilitate, or encourage others to identify anonymous users or reconstruct user profiles based on data collected from Apple-provided APIs or any data that you say has been collected in an 'anonymized,' 'aggregated,' or otherwise non-identifiable way," reads a section of Apple App Store review guidelines.

Microsoft Says State-Sponsored Attackers Accessed Senior Leaders’ Emails
2024-01-25 16:58

Microsoft disclosed on Jan. 19 that a nation-state backed attack occurred beginning in November 2023 in which the Russian state-sponsored threat actor group Midnight Blizzard accessed some Microsoft corporate emails and documents through compromised email accounts. The attackers gained access in November 2023 using a legacy test tenant account.

Tesla hacked again, 24 more zero-days exploited at Pwn2Own Tokyo
2024-01-25 15:49

Security researchers hacked the Tesla infotainment system and demoed 24 more zero-days on the second day of the Pwn2Own Automotive 2024 hacking competition. On the first day of Pwn2Own Automotive 2024, Synacktiv also collected another $295,000 after getting root on a Tesla Modem and hacking Ubiquiti Connect EV and JuiceBox 40 Smart EV Charging Stations using three chains, exploiting a total of seven zero-days.

More Australian IT Leaders Could Be Looking to Replace Passwords With Passkeys in 2024
2024-01-25 15:15

The Australian government announced in 2023 that it would phase out the use of passwords to access key government digital service platform myGov. In the first half of 2024, Australians may be asked to adopt passkeys, which use individual biometric data to authenticate users. The myGov passkey push across the Australian population will pave the way for IT leaders to adopt this more secure form of authentication in the private sector as public awareness and education rise.

Cisco warns of critical RCE flaw in communications software
2024-01-25 14:41

Cisco is warning that several of its Unified Communications Manager and Contact Center Solutions products are vulnerable to a critical severity remote code execution security issue. Cisco's Unified Communications and Contact Center Solutions are integrated solutions that provide enterprise-level voice, video, and messaging services, as well as customer engagement and management.