Security News

Ransomware gang leaks data stolen in Rhode Island's RIBridges Breach
2025-01-02 22:51

The Brain Cipher ransomware gang has begun to leak documents stolen in an attack on Rhode Island's "RIBridges" social services platform. [...]

Chinese cyber-spies reportedly targeted sanctions intel in US Treasury raid
2025-01-02 22:28

OFAC, Office of the Treasury Secretary feared hit in data-snarfing swoop Chinese spies who compromised the US Treasury Department's workstations reportedly stole data belonging to a government...

Apple offers to settle 'snooping Siri' lawsuit for an utterly incredible $95M
2025-01-02 21:15

Even the sound of a zip could be enough to start the recordings, according to claims Apple has filed a proposed settlement in California suggesting it will pay $95 million to settle claims that...

New DoubleClickjacking attack exploits double-clicks to hijack accounts
2025-01-02 20:26

A new variation of clickjacking attacks called "DoubleClickjacking" lets attackers trick users into authorizing sensitive actions using double-clicks while bypassing existing protections against...

Google Is Allowing Device Fingerprinting
2025-01-02 20:22

Lukasz Olejnik writes about device fingerprinting, and why Google’s policy change to allow it in 2025 is a major privacy setback.

China-Linked Cyber Threat Group Hacks US Treasury Department
2025-01-02 19:45

Threat actors entered Treasury Department systems through BeyondTrust. The breach may be related to the Salt Typhoon attacks reported throughout the year.

Chinese hackers targeted sanctions office in Treasury attack
2025-01-02 18:09

​Chinese state-backed hackers have reportedly breached the Office of Foreign Assets Control (OFAC), a Treasury Department office that administers and enforces trade and economic sanctions programs. [...]

Over 3 million mail servers without encryption exposed to sniffing attacks
2025-01-02 15:54

Over three million POP3 and IMAP mail servers without TLS encryption are currently exposed on the Internet and vulnerable to network sniffing attacks. [...]

Severe Security Flaws Patched in Microsoft Dynamics 365 and Power Apps Web API
2025-01-02 12:53

Details have emerged about three now-patched security vulnerabilities in Dynamics 365 and Power Apps Web API that could result in data exposure. The flaws, discovered by Melbourne-based...

Cross-Domain Attacks: A Growing Threat to Modern Security and How to Combat Them
2025-01-02 10:53

In the past year, cross-domain attacks have gained prominence as an emerging tactic among adversaries. These operations exploit weak points across multiple domains – including endpoints, identity...