Security

North Korean hackers exploited Chrome zero-day to steal crypto

A North Korean hacking group earlier in August exploited a previously unknown bug in Chrome to target organizations with the goal of stealing cryptocurrency, according to Microsoft. In a report published on Friday, the tech giant’s cybersecurity researchers said they first saw evidence of the hackers’ activities on August 19, and said the hackers were […]

North Korean hackers exploited Chrome zero-day to steal crypto Read More »

Russian government hackers found using exploits made by spyware companies NSO and Intellexa

Google says it has evidence that Russian government hackers are using exploits that are “identical or strikingly similar” to those previously made by spyware makers Intellexa and NSO Group. In a blog post on Thursday, Google said it is not sure how the Russian government acquired the exploits, but said this is an example of

Russian government hackers found using exploits made by spyware companies NSO and Intellexa Read More »

Durex India spilled customers’ private order data

Durex India, the Indian subsidiary of the British condom and personal lubricants brand, has exposed its customers’ personal information, including their full names and order details. Security researcher Sourajeet Majumder contacted TechCrunch this week about the issue of exposing sensitive customer data on the condom maker’s website. The brand’s website spilled customer names, phone numbers,

Durex India spilled customers’ private order data Read More »

Ex-Twitter CISO Lea Kissner appointed as LinkedIn security chief

LinkedIn has a new chief information security officer, Lea Kissner. Announcing the appointment in a LinkedIn post (fittingly), Kissner said they are “excited” to take on the new role.  Kissner most recently served as CISO at cloud security startup Lacework. Prior to that, they were Twitter’s CISO until their departure in November 2022, weeks after Elon

Ex-Twitter CISO Lea Kissner appointed as LinkedIn security chief Read More »

Chinese government hackers targeted U.S. internet providers with zero-day exploit, researchers say

A group of hackers linked to the Chinese government used a previously unknown vulnerability in software to target U.S. internet service providers, security researchers have found.  The group known as Volt Typhoon was exploiting the zero-day flaw — meaning the software maker was unaware of it before having time to patch — in Versa Director,

Chinese government hackers targeted U.S. internet providers with zero-day exploit, researchers say Read More »

Halliburton shuts down systems after cyberattack

Oil drilling and fracking giant Halliburton said it has shut down some of its internal systems following a cyberattack earlier this week.  In a brief statement filed with government regulators on Thursday, Halliburton said it became aware of unauthorized access to its systems on Wednesday and responded by “proactively taking certain systems offline.” The company

Halliburton shuts down systems after cyberattack Read More »

Ecovacs says it will fix bugs that can be abused to spy on robot owners

Earlier this month, security researchers warned that a series of security flaws in vacuum and lawn mower robots made by Ecovacs could allow hackers to spy on their owners through the devices’ microphones and cameras.  At the time, Ecovacs told TechCrunch it concluded that the flaws found by the researchers “are extremely rare in typical

Ecovacs says it will fix bugs that can be abused to spy on robot owners Read More »