infosec

Congressional Budget Office confirms it was hacked

The U.S. Congressional Budget Office has confirmed it was hacked.  Caitlin Emma, a spokesperson for CBO, told TechCrunch on Friday that the agency is investigating the breach and “has identified the security incident, has taken immediate action to contain it, and has implemented additional monitoring and new security controls to further protect the agency’s systems […]

Congressional Budget Office confirms it was hacked Read More »

How an ex-L3 Harris Trenchant boss stole and sold cyber exploits to Russia

Peter Williams, the former general manager of Trenchant, a division of defense contractor L3Harris that develops surveillance and hacking tools for Western governments, pleaded guilty last week to stealing some of those tools and selling them to a Russian broker.   A court document filed in the case, as well as exclusive reporting by TechCrunch

How an ex-L3 Harris Trenchant boss stole and sold cyber exploits to Russia Read More »

Apple alerts exploit developer that his iPhone was targeted with government spyware 

Earlier this year, a developer was shocked by a message that appeared on his personal phone: “Apple detected a targeted mercenary spyware attack against your iPhone.”   “I was panicking,” Jay Gibson, who asked that we don’t use his real name over fears of retaliation, told TechCrunch.   Gibson, who until recently built surveillance technologies for Western

Apple alerts exploit developer that his iPhone was targeted with government spyware  Read More »

European airports still dealing with disruptions days after ransomware attack 

A ransomware attack against Collins Aerospace, a company that provides check-in systems to several airports in Europe, is still causing disruptions across the continent for the fourth day in a row.   As of this writing, according to FlightRadar24, a website that monitors air traffic live, London’s Heathrow airport has 90% of flights delayed, with

European airports still dealing with disruptions days after ransomware attack  Read More »

Hackers who exposed North Korean government hacker explain why they did it

Earlier this year, two hackers broke into a computer and soon realized the significance of what this machine was. As it turned out, they had landed on the computer of a hacker who allegedly works for the North Korean government.  The two hackers decided to keep digging and found evidence that they say linked the

Hackers who exposed North Korean government hacker explain why they did it Read More »

New zero-day startup offers $20 million for tools that can hack any smartphone

A new United Arab Emirates-based startup is offering up to $20 million for hacking tools that could help governments break into any smartphone with a text message. Advanced Security Solutions launched this month and is now offering some of the highest prices, at least public ones, in the whole zero-day market. Zero-days are flaws in

New zero-day startup offers $20 million for tools that can hack any smartphone Read More »

U.S. government seized $1 million from Russian ransomware gang

The U.S. Department of Justice announced on Monday it has seized the servers and $1 million in Bitcoin from the prolific Russian ransomware gang behind the BlackSuit and Royal malware.  According to the press release, a coalition of global law enforcement agencies, including from the U.S., Canada, Germany, Ireland, France, U.K., and others, seized four

U.S. government seized $1 million from Russian ransomware gang Read More »

Citizen Lab director warns cyber industry about US authoritarian descent

The director of Citizen Lab, one of the most prominent organizations investigating government spyware abuses, is sounding the alarm to the cybersecurity community and asking them to step up and join the fight against authoritarianism.  On Wednesday, Ron Deibert will deliver a keynote at the Black Hat cybersecurity conference in Las Vegas, one of the

Citizen Lab director warns cyber industry about US authoritarian descent Read More »

Hacker used a voice phishing attack to steal Cisco customers’ personal information

A cybercriminal tricked a Cisco representative into granting them access to steal the personal information of Cisco.com users, the company said on Tuesday. Cisco said it discovered the breach on July 24, blaming the incident on a voice phishing or “vishing” call. The hackers accessed and exported “a subset of basic profile information” from the

Hacker used a voice phishing attack to steal Cisco customers’ personal information Read More »

Google says its AI-based bug hunter found 20 security vulnerabilities

Google’s AI-powered bug hunter has just reported its first batch of security vulnerabilities.  Heather Adkins, Google’s vice president of security, announced Monday that its LLM-based vulnerability researcher Big Sleep found and reported 20 flaws in various popular open source software. Adkins said that Big Sleep, which is developed by the company’s AI department DeepMind as

Google says its AI-based bug hunter found 20 security vulnerabilities Read More »