Infosecurity News

Twitter Password Reset Bug Exposed User Accounts
Social media firm fixes issue that left sessions open

Authorized Push Payments Surge to 75% of Banking Fraud
Social engineering tactics bear fruit for digital scammers

Iranian Hackers Hid in Albanian Networks for Over a Year
CISA report reveals extent of state-backed campaign

Microsoft Upgrades Windows 11 With New Security Features
The list includes application control enhancements and vulnerable drivers protection, among others

350K Open-Source Projects At Risk of Supply Chain Vulnerability
The flaw resides in the tarfile module, automatically installed in any Python project

NCSC: British Retailers Need to Move Beyond Passwords
The UK’s national cybersecurity agency also advised organizations on what steps they should take if their brand has been spoofed online

Multiple Vulnerabilities Discovered in Dataprobe's iBoot-PDUs
They pose a number of risks to Dataprobe, including giving control of the iBoot-PDU to attackers

Two-Fifths of US Consumers Suffer Personal Data Theft
Those suffering emotional and physical impact surges

Video Game Publisher Admits Helpdesk Was Hijacked
Players were sent malicious links disguised as support tickets

Open Source Repository Attacks Soar 700% in Three Years
Sonatype says it has detected 95,000 since 2019

California Signs Internet Privacy Legislation to Boost Children's Safety Online
The new legislation will implement some of the strictest privacy requirements in the US

Critical Vulnerability in Oracle Cloud Infrastructure Allowed Unauthorized Access
Potential attacks resulting from it may include privilege escalation and cross–tenant access

Europol and Bitdefender Jointly Release LockerGoga Decryptor
LockerGoga targeted several companies in Norway and across the US in 2019

Grand Theft Auto Publisher Rockstar Games Hacked
The threat actor ‘teapotuberhacker’ could be linked to the Lapsus$ hacking group

Hackers Admit Destroying InterContinental Hotels Group's Data 'For Fun'
They tried to conduct a ransomware attack against IHG and upon failing, decided to delete the data

Quantum Computing Already Putting Data at Risk, Cyber Pros Agree
In the Deloitte poll, 50.2% of respondents said their organization is at risk of ‘harvest now, decrypt later’ attacks

American Airlines Breach Exposes Customer and Staff Information
An undisclosed number of people have been impacted

Revolut Breach May Have Hit 50,000+ Customers
Major phishing risk as personal details are compromised

Uber Blames Lapsus$ for Breach
Threat actor bombarded Uber contractor with 2FA requests

New Spear Phish Methodology Relies on PuTTY SSH Client to Infect Systems
It tried to trick victims into clicking on malicious files as part of a fake Amazon job assessment



