cybersecurity

North Korea launches new unit with a focus on AI hacking, per report

The North Korean government is reportedly establishing a new hacking group within the intelligence agency Reconnaissance General Bureau (RGB).  Daily NK, a news outlet that focuses on North Korea, reported last week that the new hacking unit, called Research Center 227, will focus on research to develop “offensive hacking technologies and programs,” citing a source […]

North Korea launches new unit with a focus on AI hacking, per report Read More »

Hackers are ramping up attacks using year-old ServiceNow security bugs to target unpatched systems

Hackers are ramping up their attempts to exploit a trio of year-old ServiceNow vulnerabilities to break into unpatched company instances, security researchers warned this week. Threat intelligence startup GreyNoise said in a blog post on Tuesday that it had observed a “notable resurgence of in-the-wild activity” targeting the three ServiceNow vulnerabilities, tracked as CVE-2024-4879, CVE-2024-5178,

Hackers are ramping up attacks using year-old ServiceNow security bugs to target unpatched systems Read More »

Hacked, leaked, exposed: Why you should never use stalkerware apps

There is a whole shady industry for people who want to monitor and spy on their families. Multiple app makers market their software — sometimes referred to as stalkerware — to jealous partners who can use these apps to access their victims’ phones remotely.  Yet, despite how sensitive this data is, an increasing number of

Hacked, leaked, exposed: Why you should never use stalkerware apps Read More »

Data breach at stalkerware SpyX affects close to 2 million, including thousands of Apple users

A consumer-grade spyware operation called SpyX was hit by a data breach last year, TechCrunch has learned. The breach reveals that SpyX and two other related mobile apps had records on almost two million people at the time of the breach, including thousands of Apple users. The data breach dates back to June 2024 but

Data breach at stalkerware SpyX affects close to 2 million, including thousands of Apple users Read More »

CISA scrambles to contact fired employees after court rules layoffs ‘unlawful’

The U.S. government’s cybersecurity agency is scrambling to contact more than 130 former employees after a federal court ruled that the Trump administration must reinstate workers it “unlawfully” fired. U.S. District Judge James Bredar last week ordered the Trump administration to reinstate employees laid off across a number of U.S. government agencies, including the Department

CISA scrambles to contact fired employees after court rules layoffs ‘unlawful’ Read More »

Texas man faces prison for activating ‘kill switch’ on former employer’s network

Texas software developer Davis Lu faces up to 10 years in prison after a federal jury convicted him of “causing intentional damage” to his former employer’s network. According to the Justice Department, Lu, 55, began sabotaging his employer’s systems after a 2018 corporate restructuring left Lu with reduced responsibilities and system access.  Lu is accused

Texas man faces prison for activating ‘kill switch’ on former employer’s network Read More »

Hackers are exploiting Fortinet firewall bugs to plant ransomware

Security researchers have observed hackers linked to the notorious LockBit gang exploiting a pair of Fortinet firewall vulnerabilities to deploy ransomware on several company networks.  In a report published last week, security researchers at Forescout Research said a group it’s tracking dubbed “Mora_001” is exploiting the Fortinet firewalls, which sit on the edge of a

Hackers are exploiting Fortinet firewall bugs to plant ransomware Read More »

DOGE staffer violated Treasury rules by emailing unencrypted personal data

A staffer working for the Department of Government Efficiency (DOGE) broke Treasury policies by sending an email containing unencrypted personal information, according to testimony from a senior government cybersecurity official in a federal lawsuit. Marko Elez, a DOGE staffer working at the U.S. Treasury, emailed a spreadsheet with unencrypted personally identifiable information to two Trump administration

DOGE staffer violated Treasury rules by emailing unencrypted personal data Read More »

Accused LockBit ransomware developer extradited to the US

Rostislav Panev, a 51-year-old dual Russian and Israeli national who is accused of being a key developer for the notorious LockBit ransomware gang, has been extradited from Israel to the United States, the Department of Justice announced on Thursday.  Panev was arrested in Israel in December 2024, becoming the third person arrested for their role

Accused LockBit ransomware developer extradited to the US Read More »