Security News > 2024 > November

German Police Disrupt DDoS-for-Hire Platform dstat[.]cc; Suspects Arrested
2024-11-04 12:02

German law enforcement authorities have announced the disruption of a criminal service called dstat[.]cc that made it possible for other threat actors to easily mount distributed denial-of-service...

Why the long name? Okta discloses auth bypass bug affecting 52-character usernames
2024-11-04 11:28

Mondays are for checking months of logs, apparently, if MFA's not enabled In potentially bad news for those with long names and/or employers with verbose domain names, Okta spotted a security hole...

THN Recap: Top Cybersecurity Threats, Tools, and Practices (Oct 28 - Nov 03)
2024-11-04 11:28

This week was a total digital dumpster fire! Hackers were like, "Let's cause some chaos!" and went after everything from our browsers to those fancy cameras that zoom and spin. (You know, the ones...

Cyber Threats That Could Impact the Retail Industry This Holiday Season (and What to Do About It)
2024-11-04 11:00

As the holiday season approaches, retail businesses are gearing up for their annual surge in online (and in-store) traffic. Unfortunately, this increase in activity also attracts cybercriminals...

Public sector cyber break-ins: Our money, our lives, our right to know
2024-11-04 10:27

Is that a walrus in your server logs, or aren't you pleased to see me? Opinion At the start of September, Transport for London was hit by a major cyber attack. TfL is the public body that moves...

Google’s AI Tool Big Sleep Finds Zero-Day Vulnerability in SQLite Database Engine
2024-11-04 10:04

Google said it discovered a zero-day vulnerability in the SQLite open-source database engine using its large language model (LLM) assisted framework called Big Sleep (formerly Project Naptime)....

Cisco says DevHub site leak won’t enable future breaches
2024-11-04 09:14

​Cisco says that non-public files recently downloaded by a threat actor from a misconfigured public-facing DevHub portal don't contain information that could be exploited in future breaches of the...

New FakeCall Malware Variant Hijacks Android Devices for Fraudulent Banking Calls
2024-11-04 06:13

Cybersecurity researchers have discovered a new version of a well-known Android malware family dubbed FakeCall that employs voice phishing (aka vishing) techniques to trick users into parting with...

Hiring guide: Key skills for cybersecurity researchers
2024-11-04 05:30

In this Help Net Security interview, Rachel Barouch, an Organizational Coach for VCs and startups and a former VP HR in both a VC and a Cybersecurity startup, discusses the dynamics of...

Whispr: Open-source multi-vault secret injection tool
2024-11-04 05:00

Whispr is an open-source CLI tool designed to securely inject secrets from secret vaults, such as AWS Secrets Manager and Azure Key Vault, directly into your application’s environment. This...