Security News

New ‘YouPorn’ sextortion scam threatens to leak your sex tape
2023-09-02 14:12

A new sextortion scam is making the rounds that pretends to be an email from the adult site YouPorn, warning that a sexually explicit video of you was uploaded to the site and suggesting you pay to have it taken down. In sextortion email scams the scammers pretend to have images or videos of you performing sexual acts and then demand money not publicly to publish them.

LockBit 3.0 Ransomware Builder Leak Gives Rise to Hundreds of New Variants
2023-08-26 10:26

The leak of the LockBit 3.0 ransomware builder last year has led to threat actors abusing the tool to spawn new variants. Russian cybersecurity company Kaspersky said it detected a ransomware intrusion that deployed a version of LockBit but with a markedly different ransom demand procedure.

Leak of 75k employee records was insiders' fault, claims Tesla
2023-08-21 17:35

The incident, Tesla disclosed in a data breach notification with the state of Maine and accompanying letter [PDF] to those affected, was the fault of two Tesla employees whom it alleged stole the info before sharing it with German business news outlet Handelsblatt. The 100GB of data it received from the leakers, which Handelsblatt has dubbed the "Tesla files," includes an "Abundance" of customer data, and PII for more than 100,000 Tesla employees - including Elon Musk.

Man arrested in Northern Ireland police data leak as more incidents come to light
2023-08-17 12:03

A man was arrested in Northern Ireland for suspected Collection of Terrorist Information following an incident where police mistakenly leaked details that identified 10,000 serving officers, but he has now been released on bail. The information was leaked when police posted a spreadsheet online listing the surnames and initials of 10,000 serving officers in the Police Service of Northern Ireland, plus civilian staff members.

Japan's digital minister surrenders salary to say sorry for data leaks
2023-08-17 04:58

Japan's digital minister has doubled down on a June promise to penalize himself for the poor rollout of the country's digital ID, My Number Card, by offering up three months salary on Tuesday. The interim report reportedly revealed a lack of knowledge among the public on how to link their My Number Card to disability records, cases of health insurance being connected to the wrong card, and errors in pension records of public servants.

You're not seeing double – yet another UK copshop is confessing to a data leak
2023-08-15 11:28

Norfolk and Suffolk police have stepped forward to admit that a "Technical issue" resulted in raw data pertaining to crime reports accidentally being included in Freedom of Information responses. "A technical issue has led to some raw data belonging to the constabularies being included within the files produced in response to the FoI requests in question. The data was hidden from anyone opening the files, but it should not have been included."

Downfall Vulnerability Affects Millions of Intel CPUs With Strong Data Leak Impact
2023-08-11 16:58

Downfall Vulnerability Affects Millions of Intel CPUs With Strong Data Leak Impact Learn technical details about this newly disclosed security vulnerability, as well as mitigation recommendations from the Google researcher who discovered it. Google researcher Daniel Moghimi discovered a new vulnerability affecting millions of Intel chip models.

Nearly every AMD CPU since 2017 vulnerable to Inception data-leak attacks
2023-08-09 22:52

AMD processor users, you have another data-leaking vulnerability to deal with: like Zenbleed, this latest hole can be to steal sensitive data from a running vulnerable machine. Inception utilizes a previously disclosed vulnerability alongside a novel kind of transient execution attack, which the researchers refer to as training in transient execution, to leak information from an operating system kernel at a rate of 39 bytes per second on vulnerable hardware.

New Inception attack leaks sensitive data from all AMD Zen CPUs
2023-08-08 15:00

Researchers have discovered a new and powerful transient execution attack called 'Inception' that can leak privileged secrets and data using unprivileged processes on all AMD Zen CPUs, including the latest models. Researchers at ETH Zurich have now combined an older technique named 'Phantom speculation' with a new transient execution attack called 'Training in Transient Execution' to create an even more powerful 'Inception' attack.

Clop ransomware now uses torrents to leak data and evade takedowns
2023-08-05 15:16

The Clop ransomware gang has once again altered extortion tactics and is now using torrents to leak data stolen in MOVEit attacks. On June 14th, the ransomware gang began extorting its victims, slowly adding names to their Tor data leak site and eventually publicly releasing the files.