Gravy Analytics sued for data breach containing location data of millions of smartphones

Gravy Analytics has been sued yet again for allegedly failing to safeguard its vast stores of personal data, which are now feared stolen. And by personal data we mean information including the locations of tens of millions of smartphones, coordinates of which were ultimately harvested from installed apps. A complaint [PDF], filed in federal court Read more about Gravy Analytics sued for data breach containing location data of millions of smartphones[…]

Apple chips can be hacked to leak secrets from Gmail, iCloud, and more in a browser

Apple-designed chips powering Macs, iPhones, and iPads contain two newly discovered vulnerabilities that leak credit card information, locations, and other sensitive data from the Chrome and Safari browsers as they visit sites such as iCloud Calendar, Google Maps, and Proton Mail. The vulnerabilities, affecting the CPUs in later generations of Apple A- and M-series chip Read more about Apple chips can be hacked to leak secrets from Gmail, iCloud, and more in a browser[…]

WhatsApp says journalists and civil society members were targets of Israeli spyware

Nearly 100 journalists and other members of civil society using WhatsApp, the popular messaging app owned by Meta, were targeted by spyware owned by Paragon Solutions, an Israeli maker of hacking software, the company alleged on Friday. The journalists and other civil society members were being alerted of a possible breach of their devices, with Read more about WhatsApp says journalists and civil society members were targets of Israeli spyware[…]

US healthcare provider data breach impacts 1 million patients

Community Health Center (CHC), a leading Connecticut healthcare provider, is notifying over 1 million patients of a data breach that impacted their personal and health data. The non-profit organization provides primary medical, dental, and mental health services to more than 145,000 active patients. CHC said in a Thursday filing with Maine’s attorney general that unknown Read more about US healthcare provider data breach impacts 1 million patients[…]

Trump Disbands Cybersecurity Board Investigating Worst Hack in US History: Massive Chinese Phone System Invasion

[…] We’re still nowhere near understanding just how bad the Chinese hack of our phone system was. The incident that was only discovered last fall involved the Chinese hacking group Salt Typhoon, which used the US’s CALEA phone wiretapping system as a backdoor to gain incredible, unprecedented access to much of the US’s phone system Read more about Trump Disbands Cybersecurity Board Investigating Worst Hack in US History: Massive Chinese Phone System Invasion[…]

Subaru Security Flaws Exposed Its System for Tracking, remote controlling Millions of Cars

About a year ago, security researcher Sam Curry bought his mother a Subaru, on the condition that, at some point in the near future, she let him hack it. It took Curry until last November, when he was home for Thanksgiving, to begin examining the 2023 Impreza’s internet-connected features and start looking for ways to Read more about Subaru Security Flaws Exposed Its System for Tracking, remote controlling Millions of Cars[…]

Magic packet Backdoor found on Juniper VPN routers

Someone has been quietly backdooring selected Juniper routers around the world in key sectors including semiconductor, energy, and manufacturing, since at least mid-2023. The devices were infected with what appears to be a variant of cd00r, a publicly available “invisible backdoor” designed to operate stealthily on a victim’s machine by monitoring network traffic for specific Read more about Magic packet Backdoor found on Juniper VPN routers[…]

Volkswagen data leak exposed the precise locations of 800,000 EV owners

A Volkswagen software subsidiary called Cariad experienced a massive data leak that left 800,000 EV owners exposed, according to reporting by the German publication Spiegel Netzwelt. The leak allowed personal information to be left online for months, including movement data and contact information. This included precise location data for 460,000 vehicles made by VW, Seat Read more about Volkswagen data leak exposed the precise locations of 800,000 EV owners[…]

Hackers Can Jailbreak Digital License Plates to Make Others Pay Their Tolls and Tickets

Digital license plates, already legal to buy in a growing number of states and to drive with nationwide, offer a few perks over their sheet metal predecessors. You can change their display on the fly to frame your plate number with novelty messages, for instance, or to flag that your car has been stolen. Now Read more about Hackers Can Jailbreak Digital License Plates to Make Others Pay Their Tolls and Tickets[…]

Feds Warn SMS Authentication Is Unsafe

Hackers aligned with the Chinese government have infiltrated U.S. telecommunications infrastructure so deeply that it allowed the interception of unencrypted communications on a number of people, according to reports that first emerged in October. The operation, dubbed Salt Typhoon, apparently allowed hackers to listen to phone calls and nab text messages, and the penetration has Read more about Feds Warn SMS Authentication Is Unsafe[…]

Researchers uncover Chinese spyware used to target Android devices

The tool, named “EagleMsgSpy,” was discovered by researchers at U.S. cybersecurity firm Lookout. The company said at the Black Hat Europe conference on Wednesday that it had acquired several variants of the spyware, which it says has been operational since “at least 2017.” Kristina Balaam, a senior intelligence researcher at Lookout, told TechCrunch the spyware Read more about Researchers uncover Chinese spyware used to target Android devices[…]

China complete pwn of US all telco means a physical rebuild is necessary

The Biden administration on Friday hosted telco execs to chat about China’s recent attacks on the sector, amid revelations that US networks may need mass rebuilds to recover. Details of the extent of China’s attacks came from senator Mark R Warner, who on Thursday gave both The Washington Post and The New York Times insights Read more about China complete pwn of US all telco means a physical rebuild is necessary[…]

Mystery Palo Alto Networks 0-day RCE now actively exploited – shut off access to Management Interface NOW

A critical zero-day vulnerability in Palo Alto Networks’ firewall management interface that can allow an unauthenticated attacker to remotely execute code is now officially under active exploitation. According to the equipment maker, the vulnerability requires no user interaction or privileges to exploit, and its attack complexity is deemed “low.” There’s no CVE number assigned to Read more about Mystery Palo Alto Networks 0-day RCE now actively exploited – shut off access to Management Interface NOW[…]

Data broker gathers records on 100M+ people, gets stolen, put up for sale

What’s claimed to be more than 183 million records of people’s contact details and employment info has been stolen or otherwise obtained from a data broker and put up for sale by a miscreant. The underworld merchant, using the handle KryptonZambie, has put a $6,000 price tag on the information in a cybercrime forum posting. Read more about Data broker gathers records on 100M+ people, gets stolen, put up for sale[…]

Hacker bans thousands of Call of Duty gamers through anti-cheat software, shows how dangerous this poorly written kernel acces junk is.

In October, video game giant Activision said it had fixed a bug in its anti-cheat system that affected “a small number of legitimate player accounts,” who were getting banned because of the bug. In reality, according to the hacker who found the bug and was exploiting it, they were able to ban “thousands upon thousands” Read more about Hacker bans thousands of Call of Duty gamers through anti-cheat software, shows how dangerous this poorly written kernel acces junk is.[…]

How to trick ChatGPT into writing exploit code using hex

OpenAI’s language model GPT-4o can be tricked into writing exploit code by encoding the malicious instructions in hexadecimal, which allows an attacker to jump the model’s built-in security guardrails and abuse the AI for evil purposes, according to 0Din researcher Marco Figueroa. […] In a recent blog, Figueroa detailed how one such guardrail jailbreak exposed Read more about How to trick ChatGPT into writing exploit code using hex[…]

a robot vacuum behind a running dog. The dog is terrified

Hacked Robot Vacuums Shout Slurs at Their Owners, Chase down their dogs

[…] hackers gained control of the devices and used the onboard speakers to blast racial slurs at anyone within earshot. One such person was a lawyer from Minnesota named Daniel Swenson. He was watching TV when he heard some odd noises coming from the direction of his vacuum. He changed the password and restarted it. Read more about Hacked Robot Vacuums Shout Slurs at Their Owners, Chase down their dogs[…]

MoneyGram says hackers stole customers’ personal information and transaction data

U.S. money transfer giant MoneyGram has confirmed that hackers stole its customers’ personal information and transaction data during a cyberattack last month. The company said in a statement Monday that an unauthorized third party “accessed and acquired” customer data during the cyberattack on September 20. The cyberattack — the nature of which remains unknown — Read more about MoneyGram says hackers stole customers’ personal information and transaction data[…]

Pro-Palistian Hacktivists Claim Responsibility for Taking Down the Internet Archive, piss off pro Palestinians globally

[…] A pro-Palestenian hacktivist group called SN_BLACKMETA has taken responsibility for the hack on X and Telegram. “They are under attack because the archive belongs to the USA, and as we all know, this horrendous and hypocritical government supports the genocide that is being carried out by the terrorist state of ‘Israel,’” the group said Read more about Pro-Palistian Hacktivists Claim Responsibility for Taking Down the Internet Archive, piss off pro Palestinians globally[…]

Internet Archive hacked, data breach impacts 31 million users

Internet Archive’s “The Wayback Machine” has suffered a data breach after a threat actor compromised the website and stole a user authentication database containing 31 million unique records. News of the breach began circulating Wednesday afternoon after visitors to archive.org began seeing a JavaScript alert created by the hacker, stating that the Internet Archive was breached. Read more about Internet Archive hacked, data breach impacts 31 million users[…]

Insecure Robot Vacuums From Chinese Company Deebot Collect Photos and Audio to Train Their AI

Ecovacs robot vacuums, which have been found to suffer from critical cybersecurity flaws, are collecting photos, videos and voice recordings — taken inside customers’ houses — to train the company’s AI models. The Chinese home robotics company, which sells a range of popular Deebot models in Australia, said its users are “willingly participating” in a Read more about Insecure Robot Vacuums From Chinese Company Deebot Collect Photos and Audio to Train Their AI[…]

Man-in-the-Middle PCB Unlocks HP Ink Cartridges

It’s a well-known secret that inkjet ink is being kept at artificially high prices, which is why many opt to forego ‘genuine’ manufacturer cartridges and get third-party ones instead. Many of these third-party ones are so-called re-manufactured ones, where a third-party refills an empty OEM cartridge. This is increasingly being done due to digital rights Read more about Man-in-the-Middle PCB Unlocks HP Ink Cartridges[…]

Flaw in Kia’s web portal let researchers track, hack cars. Again.

[…] Today, a group of independent security researchers revealed that they’d found a flaw in a web portal operated by the carmaker Kia that let the researchers reassign control of the Internet-connected features of most modern Kia vehicles—dozens of models representing millions of cars on the road—from the smartphone of a car’s owner to the Read more about Flaw in Kia’s web portal let researchers track, hack cars. Again.[…]

Fortinet confirms data breach after hacker claims to steal 440GB of files

Cybersecurity giant Fortinet has confirmed it suffered a data breach after a threat actor claimed to steal 440GB of files from the company’s Microsoft Sharepoint server. Fortinet is one of the largest cybersecurity companies in the world, selling secure networking products like firewalls, routers, and VPN devices. The company also offers SIEM, network management, and Read more about Fortinet confirms data breach after hacker claims to steal 440GB of files[…]