Security News

Walmart-controlled flight booking service suffers substantial data leak
2022-07-19 11:15

An Indian flight booking website majority-owned by US retail colossus Walmart has experienced a data breach, but is saying very little about what happened or the risks to customers. Cleartrip would you mind telling us when the breach happened? pic.

Alibaba execs hauled in to discuss Shanghai Police data leak
2022-07-18 01:15

Senior execs from Alibaba Cloud were summoned to discuss the data leak that saw information pertaining to a billion Chinese citizens sold on the dark web, according to Nikkei and The Wall Street Journal. The Shanghai Police leak is believed to be the biggest data breach ever.

Bandai Namco confirms hack after ALPHV ransomware data leak threat
2022-07-13 20:50

Game publishing giant Bandai Namco has confirmed that they suffered a cyberattack that may have resulted in the theft of customers' personal data. This past Monday, the BlackCat ransomware operation claimed to have breached Bandai Namco and stolen corporate data during the attack.

Human Error Blamed for Leak of 1 Billion Records of Chinese Citizens
2022-07-06 10:33

A prominent Chinese tech CEO has cited human error as the likely reason hackers got their hands on the personal data of 1 billion people in China from a Shanghai police database and then put some of it up for sale on illicit online markets. An annual report on data breaches by Verizon-the 2022 Data Breach Investigations Report-cited the "Human element" as responsible for 82 percent of the breaches analyzed by researchers, with 13 percent directly attributed to human error.

OpenSea phishing threat after rogue insider leaks customer email addresses
2022-06-30 21:20

An employee of OpenSea's email delivery vendor Customer.io "Misused" their access to download and share OpenSea users' and newsletter subscribers' email addresses "With an unauthorized external party," Head of Security Cory Hardman warned on Wednesday. "If you have shared your email with OpenSea in the past, you should assume you were impacted," Hardman continued.

Microsoft 365 now prevents data leaks with new session timeouts
2022-06-28 20:10

Microsoft announced today the general availability of tenant-wide idle session timeout for Microsoft 365 web apps to protect confidential data on shared or non-company devices left unattended. After an IT admin such as a Microsoft 365 or Office 365 global admin enables this new feature, users who have reached the configured period of inactivity will be notified that they're going to be automatically signed out.

Conti ransomware finally shuts down data leak, negotiation sites
2022-06-24 14:35

The Conti ransomware operation has finally shut down its last public-facing infrastructure, consisting of two Tor servers used to leak data and negotiate with victims, closing the final chapter of the notorious cybercrime brand. Conti left one member behind to continue leaking data and taunting Costa Rica to create a facade of a running operation while its members quietly moved to other ransomware gangs.

Indian government issues confidential infosec guidance to staff – who leak it
2022-06-20 03:32

India's government last week issued confidential information security guidelines to the 30 million plus workers it employs - and as if to prove a point, the document quickly leaked on a government website. The document, and the measures it contains, suggest infosec could be somewhat loose across India's government sector.

Elasticsearch server with no password or encryption leaks a million records
2022-06-16 08:13

Researchers at security product recommendation service Safety Detectives claim they've found almost a million customer records wide open on an Elasticsearch server run by Malaysian point-of-sale software vendor StoreHub. Safety Detectives' report states it found a StoreHub sever that stored unencrypted data and was not password protected.

WiFi probing exposes smartphone users to tracking, info leaks
2022-06-11 15:46

Researchers at the University of Hamburg in Germany have conducted a field experiment capturing hundreds of thousands of passersby's WiFi connection probe requests to determine the type of data transmitted without the device owners realizing it. WiFi probing is a standard process, part of the bilateral communication required between a smartphone and an access point to establish a connection.