infosec

Hackers who exposed North Korean government hacker explain why they did it

Earlier this year, two hackers broke into a computer and soon realized the significance of what this machine was. As it turned out, they had landed on the computer of a hacker who allegedly works for the North Korean government.  The two hackers decided to keep digging and found evidence that they say linked the […]

Hackers who exposed North Korean government hacker explain why they did it Read More »

New zero-day startup offers $20 million for tools that can hack any smartphone

A new United Arab Emirates-based startup is offering up to $20 million for hacking tools that could help governments break into any smartphone with a text message. Advanced Security Solutions launched this month and is now offering some of the highest prices, at least public ones, in the whole zero-day market. Zero-days are flaws in

New zero-day startup offers $20 million for tools that can hack any smartphone Read More »

U.S. government seized $1 million from Russian ransomware gang

The U.S. Department of Justice announced on Monday it has seized the servers and $1 million in Bitcoin from the prolific Russian ransomware gang behind the BlackSuit and Royal malware.  According to the press release, a coalition of global law enforcement agencies, including from the U.S., Canada, Germany, Ireland, France, U.K., and others, seized four

U.S. government seized $1 million from Russian ransomware gang Read More »

Citizen Lab director warns cyber industry about US authoritarian descent

The director of Citizen Lab, one of the most prominent organizations investigating government spyware abuses, is sounding the alarm to the cybersecurity community and asking them to step up and join the fight against authoritarianism.  On Wednesday, Ron Deibert will deliver a keynote at the Black Hat cybersecurity conference in Las Vegas, one of the

Citizen Lab director warns cyber industry about US authoritarian descent Read More »

Hacker used a voice phishing attack to steal Cisco customers’ personal information

A cybercriminal tricked a Cisco representative into granting them access to steal the personal information of Cisco.com users, the company said on Tuesday. Cisco said it discovered the breach on July 24, blaming the incident on a voice phishing or “vishing” call. The hackers accessed and exported “a subset of basic profile information” from the

Hacker used a voice phishing attack to steal Cisco customers’ personal information Read More »

Google says its AI-based bug hunter found 20 security vulnerabilities

Google’s AI-powered bug hunter has just reported its first batch of security vulnerabilities.  Heather Adkins, Google’s vice president of security, announced Monday that its LLM-based vulnerability researcher Big Sleep found and reported 20 flaws in various popular open source software. Adkins said that Big Sleep, which is developed by the company’s AI department DeepMind as

Google says its AI-based bug hunter found 20 security vulnerabilities Read More »

Telecom giant Orange warns of disruption amid ongoing cyberattack

Orange, a French telecommunications giant and one of the largest phone providers in the world, announced on Monday that it was the victim of an unspecified cyberattack. In the announcement, the company said that it detected a cyberattack “on one of its information systems” on July 25, and that it proceeded to “isolate potentially affected

Telecom giant Orange warns of disruption amid ongoing cyberattack Read More »

New York state cyber chief calls out Trump for cybersecurity cuts

During the first few months of the new Trump administration, the White House slashed cybersecurity budgets, staff, and initiatives. And some, including cybersecurity experts and legislators, are not happy about it. One of them is Colin Ahern, the chief cyber officer for the state of New York. In a recent interview with TechCrunch, Ahern said

New York state cyber chief calls out Trump for cybersecurity cuts Read More »

Hackers exploiting SharePoint zero-day seen targeting government agencies

The hackers behind the initial wave of attacks exploiting a zero-day in Microsoft SharePoint servers have so far primarily targeted government organizations, according to researchers as well as news reports. Over the weekend U.S. cybersecurity agency CISA published an alert, warning that hackers were exploiting a previously unknown bug — known as a “zero-day” —

Hackers exploiting SharePoint zero-day seen targeting government agencies Read More »

These are our favorite cyber books on hacking, espionage, crypto, surveillance, and more

In the last 30 years or so, cybersecurity has gone from being a niche specialty within the larger field of computer science, to an industry estimated to be worth more than $170 billion made of a globe-spanning community of hackers. In turn, the industry’s growth, and high-profile hacks such as the 2015 Sony breach, the

These are our favorite cyber books on hacking, espionage, crypto, surveillance, and more Read More »