https://cyberinsider.com/u-s-bans-kaspersky-software-over-national-security-concerns/
The U.S. has prohibited Kaspersky Lab and its affiliates from providing anti-virus software and cybersecurity services in the country.
national securitybanskasperskysoftwareconcerns
https://cyberinsider.com/new-fishxproxy-phishing-kit-lowers-barriers-for-cybercriminals/
The FishXProxy phishing kit simplifies the execution of sophisticated phishing campaigns, posing a significant threat to online security.
phishing kitnewlowersbarrierscybercriminals
https://cyberinsider.com/nissan-oceania-double-breached-by-call-center-provider-incident/
Nissan Oceania has disclosed a security incident involving a third-party call center provider, OracleCMS, who exposed their clients' data.
call center providernissanoceaniadoublebreached
https://cyberinsider.com/cymbal-maker-sabian-reports-outage-as-8base-ransomware-claims-breach/
Canadian cymbals maker Sabian is dealing with a widespread IT service outage that has impacted all its internal systems.
cymbalmakersabianreportsoutage
https://cyberinsider.com/co-op-confirms-cyberattack-exposed-data-of-all-6-5-million-members/
Co-op has confirmed that the personal data of all 6.5 million of its members was stolen in a cyberattack disclosed earlier this year.
co opconfirmscyberattackexposeddata
https://cyberinsider.com/ftc-fines-goodrx-1-5m-for-sharing-health-data-with-google-facebook/
The FTC has imposed a fine of $1.5M on GoodRx for failing to report they were disclosing user health information to Google and Facebook.
health dataftcfinesgoodrxsharing
https://cyberinsider.com/escape-from-tarkov-cheat-developer-embedded-info-stealer-malware/
The developer of the EvolvedAim cheat for the game "Escape From Tarkov" embedded malware in his product, stealing sensitive user information.
info stealerescapetarkovcheatdeveloper
https://cyberinsider.com/sophisticated-ad-cloaking-operation-merry-go-round-exposed/
Researchers have uncovered an ad fraud operation named "Merry-Go-Round," involving two rings of websites designed to conceal ad impressions.
merry go roundsophisticatedadcloakingoperation
https://cyberinsider.com/cisa-advisory-highlights-apt40-cyber-threat-for-u-s-australian-orgs/
The Chinese state-sponsored group, APT40, has been identified as a significant threat to Australian networks, according to a new advisory.
cisa advisorycyber threathighlightsu
https://cyberinsider.com/most-password-managers-store-secrets-in-plaintext-in-memory/
A new study highlights sensitive data leak risks in password managers due to the lack of encryption in all steps of data storage.
password managersstoresecretsplaintextmemory
https://cyberinsider.com/microsoft-releases-windows-11-update-with-new-features-and-fixes/
Microsoft released the KB5039302 update for Windows 11, introducing new OS builds along with many new features and improvements.
new featuresmicrosoftreleaseswindowsupdate
https://cyberinsider.com/vo1d-botnet-resurfaces-infects-1-6-million-android-tvs-worldwide/
A new variant of the Vo1d botnet has infected over 1.6 million Android TV devices globally, expanding its scale and capabilities.
android tvsbotnetinfectsmillionworldwide
https://cyberinsider.com/critical-cosmicsting-bug-threatens-most-adobe-commerce-sites/
Sansec warns about the CosmicSting vulnerability, affecting 75% of Adobe Commerce and Magento stores, posing a significant security threat.
adobe commercecriticalbugthreatenssites
https://cyberinsider.com/tunnelbear-adds-ech-support-on-android-app-to-beat-censorship/
TunnelBear announced the support of the ECH protocol in their Android app to empower the tool's censorship circumvention performance.
android apptunnelbearaddsechsupport
https://cyberinsider.com/play-ransomware-deploying-new-linux-variant-in-attacks-targeting-esxi/
Trend Micro's threat hunting team has uncovered a new Linux variant of the Play ransomware, specifically targeting VMware ESXi environments.
play ransomwaredeployingnewlinuxvariant
https://cyberinsider.com/powerschool-notifies-students-and-educators-of-major-data-breach/
PowerSchool has begun notifying impacted individuals about a data breach that compromised personal data from its Student Information System .
data breachpowerschoolstudentseducatorsmajor
https://cyberinsider.com/fake-sites-impersonate-popular-av-products-to-spread-malware/
Trellix's Advanced Research Center uncovered a series of fake antivirus (AV) websites distributing sophisticated malware.
fake sitesav productsimpersonatepopularspread
https://cyberinsider.com/att-admits-data-leak-impacting-73-million-current-and-former-customers/
AT&T has determined that the data a threat actor published on a hacker forum two weeks ago is theirs, impacting 73 million customers.
data leakfinallyadmitsmillioncustomers
https://cyberinsider.com/disgomoji-malware-uses-emojis-to-execute-commands-on-breached-systems/
Volexity identified a sophisticated cyber-espionage campaign targeting Indian government entities, utilizing malware dubbed Disgomoji.
malwareusesemojisexecutecommands
https://cyberinsider.com/backdoor-in-widely-used-xz-utils-library-shakes-the-linux-world/
A cyberattack targeting the widely-used XZ Utils software, was recently unveiled, shaking the open-source software community.
widely usedxz utilsbackdoorlibraryshakes
https://cyberinsider.com/snowflake-breach-at-laschools-and-edgenuity-allegedly-impacts-4-million-students/
A Snowflake data breach at LA schools and Edgenuity has surfaced, and the threat actor claims to have stolen the data of over 4M students.
snowflakebreachedgenuityallegedlyimpacts
https://cyberinsider.com/catddos-botnet-surges-in-activity-targets-over-80-vulnerabilities/
CatDDoS activtiy surged over the past three months, with the botnet now exploiting over 80 known vulnerabilities targeting 300 entities daily
botnetsurgestargetingvulnerabilities
https://cyberinsider.com/teamviewer-suffers-internal-it-systems-breach-says-users-not-affected/
TeamViewer has confirmed a breach in its internal corporate IT environment, reportedly linked to the Russian cyber-threat group APT-29
teamviewersuffersinternalsystemsbreach
https://cyberinsider.com/idaho-national-laboratory-informs-staff-their-personal-data-was-stolen/
Idaho National Laboratory published an alert informing current and former employees that hackers have stolen their personal information.
idaho national laboratorypersonal datainformsstaffstolen
https://cyberinsider.com/android-app-with-100m-downloads-found-sending-data-to-remote-servers/
SHEIN, a shopping Android app that has over 100 million downloads on Google Play, was sending sensitive clipboard content to a remote server.
android appsending datadownloadsfoundremote
https://cyberinsider.com/apple-removes-icloud-encryption-in-the-uk-after-govt-backdoor-order/
Apple has removed its ADP feature for iCloud users in the UK following a government order demanding a backdoor to encrypted cloud data.
appleremovesicloudencryptionuk
https://cyberinsider.com/surfshark-unveils-everlink-for-uninterrupted-vpn-connections/
Surfshark has introduced Everlink, a new self-healing VPN infrastructure designed to maintain uninterrupted service during server failures.
surfsharkunveilsuninterruptedvpnconnections
https://cyberinsider.com/hacker-alleges-breach-at-disney-leaks-1-1tb-of-internal-slack-data/
A threat actor claims to have exfiltrated 1.1 TiB of data from Disney's internal Slack channels, potentially exposing unreleased projects.
hackerallegesbreachdisneyleaks
https://cyberinsider.com/telegram-sharing-user-data/
Nov 18, 2024 - Telegram’s website states that a disclosure of user data to government agencies “has never happened.” However, a recent investigation in Germany claims...
user datagovernment agenciestelegramsharingcyberinsider
https://cyberinsider.com/dell-warns-of-dangerous-bios-flaw-in-multiple-alienware-laptops/
Dell urges users to update the BIOS of several Alienware models to address a Secure Boot bypass and arbitrary code execution vulnerability.
alienware laptopsdellwarnsdangerousbios
https://cyberinsider.com/downgrade-attack-on-1password-for-mac-could-expose-vault-data/
A vulnerability in 1Password 8 for Mac has been identified, allowing downgrade attacks that could expose the contents of users' vaults.
downgrade attackmaccouldexposevault