Security

Security news coverage encompasses investigative cybersecurity reporting and analysis on the latest security breaches, hacks and cyberattacks around the globe.

The data breach is the latest security issue to beset CSC ServiceWorks over the past year, after multiple researchers found security bugs.

CSC ServiceWorks reveals 2023 data breach affecting thousands of people

Featured Article

After global IT meltdown, CrowdStrike courts hackers with action figures and gratitude

CrowdStrike tried to go back to business as usual at one of the world’s largest annual cybersecurity conferences, weeks after its massive global IT crash.

After global IT meltdown, CrowdStrike courts hackers with action figures and gratitude

This is the second cyberattack targeting the school device management service Mobile Guardian this year.

Student raised security concerns in Mobile Guardian MDM weeks before cyberattack

The internet is full of deepfakes — and most of them are nudes. According to a report from Home Security Heroes, deepfake porn makes up 98% of all deepfake videos…

How to ask Google to remove deepfake porn results from Google Search

Researchers found flaws that could allow anyone to spy on the owners of Ecovacs home robots by hijacking their cameras and microphones.

Ecovacs home robots can be hacked to spy on their owners, researchers say

Featured Article

How a cybersecurity researcher befriended, then doxed, the leader of LockBit ransomware gang

Jon DiMaggio used sockpuppet accounts, then his own identity, to infiltrate LockBit and gain the trust of its alleged admin, Dmitry Khoroshev.

How a cybersecurity researcher befriended, then doxed, the leader of LockBit ransomware gang

The vulnerabilities allowed one security researcher to peek inside the leak sites without having to log in.

Security bugs in ransomware leak sites helped save six companies from paying hefty ransoms

The home security company says attackers accessed databases containing customer home addresses, email addresses, and phone numbers.

Home security giant ADT says it was hacked

Security researchers found a dozen vulnerabilities in 5G baseband chips found in phones made by Google, OPPO, OnePlus, Motorola, and Samsung.

Hackers could spy on cell phone users by abusing 5G baseband flaws, researchers say

Cybersecurity remains a white-hot space for investors. In the latest example of that demand, EQT has bought a majority stake in Acronis, a security company that specializes in data protection,…

EQT takes a majority stake in cybersecurity firm Acronis at $3.5B+ valuation

The ICO issued the provisional fine in “failing to implement appropriate security measures prior to the attack.”

UK data watchdog to fine NHS vendor Advanced for security failures prior to LockBit ransomware attack

Students that use school devices managed by Mobile Guardian have been unable to access their files for days following a cyberattack.

Cyberattack knocks Mobile Guardian MDM offline and wipes thousands of student devices

When a company is the size of Amazon, a lot of bad actors will come after it and its customers, which makes defending the network a monster job. Over the…

AWS unveils Mithra to identify and mitigate malicious domains across its massive system

Featured Article

How the theft of 40M UK voter register records was entirely preventable

A scathing rebuke by the U.K. data protection watchdog reveals what led to the compromise of tens of millions of U.K. voters’ information.

How the theft of 40M UK voter register records was entirely preventable

As widely reported, Wiz recently said no to a $23 billion acquisition offer from Google. At that price, it would have been Google’s biggest acquisition…

TechCrunch Minute: Why did Wiz walk away from $23 billion?

The pharma giant won’t say how many patients were affected by its February data breach. A count by TechCrunch confirms that over a million people are affected.

Pharma giant Cencora is alerting millions about its data breach

Badoo, Bumble, Grindr, happn, Hinge and Hily all had the same flaw that could have helped a malicious user identify the near-exact location of another user.

Bumble and Hinge allowed stalkers to pinpoint users’ locations down to 2 meters, researchers say

The software supply chain faces threats from all sides. A 2024 report by the Ponemon Institute found that over half of organizations have experienced a software supply chain attack, with…

Lineaje raises $20M to help organizations combat software supply chain threats

For one thing, Wiz could have seen Google’s offer as validation that it’s better off staying independent.

It took some serious nerve for Wiz to walk away from Google’s $23B offer

HealthEquity said the March data breach included personal information and protected health data on millions of people.

HealthEquity data breach affects 4.3M people

U.S. airports are rolling out facial recognition to scan travelers’ faces before boarding their flights. Americans, at least, can opt out. 

How to opt out of facial recognition at airports (if you’re American)

Critics have long argued that wararantless device searches at the U.S. border are unconstitutional and violate the Fourth Amendment.

US border agents must get warrant before cell phone searches, federal court rules

iCloud Private Relay has not been working for some Apple users across major markets, including the U.S., Europe, India and Japan.

Apple reports iCloud Private Relay global outages for some users

With the CrowdStrike update continuing to cause havoc across the planet, a startup has raised $13.5 million to at least improve some level of security for the kinds of devices…

ZeroTier raises $13.5M to help avert CrowdStrike-like network problems

Featured Article

Hacked, leaked, exposed: Why you should never use stalkerware apps

Using stalkerware is creepy, unethical, potentially illegal, and puts your data and that of your loved ones in danger.

Hacked, leaked, exposed: Why you should never use stalkerware apps

Featured Article

Data breach exposes US spyware maker behind Windows, Mac, Android and Chromebook malware

Exclusive: The Minnesota-based spyware maker Spytech snooped on thousands of devices before it was hacked earlier this year.

Data breach exposes US spyware maker behind Windows, Mac, Android and Chromebook malware

A hacker claims to be selling data relating to thousands of current and former employees of India’s Piramal Group.

Hacker claims theft of Piramal Group’s employee data

Several people who received the CrowdStrike offer found that the gift card didn’t work, while others got an error saying the voucher had been canceled.

CrowdStrike offers a $10 apology gift card to say sorry for outage

The startup is not disclosing its valuation, but sources close to the company say the figure is just under $400 million post-money.

Dazz snaps up $50M for AI-based, automated cloud security remediation

Cybersecurity firm Dragos and Ukrainian authorities found a cyberattack targeting critical infrastructure in Lviv.

Hackers shut down heating in Ukrainian city with malware, researchers say