Blog
-
Cyber Attacks on Australian Superannuation Funds Appeared to Use Recycled Passwords
Early indications are that a recent rash of cyber attacks on Australia’s biggest superannuation funds were a credential stuffing campaign making use of information from older data breaches. The attacks compromised at least a few hundred accounts and led to the theft of at least AUD 500,000.
-
Serious WhatsApp Vulnerability Allows Concealment of Executables as Images and Documents
Versions prior to 2.2450.6 of the Windows client are subject to a WhatsApp vulnerability that allows threat actors to attack users via file attachments that look innocuous, such as image files.
-
Oracle Tested on Data Breaches, Gets Low Marks For Transparency
Oracle is presently dealing with the fallout of either one or two data breaches, apparently depending upon who’s doing the asking. Recent March breach of Oracle Cloud appears to be information only available to some of the company’s larger clients, at least going by recent news reports.
-
Was the Data Leak of 2.8 Billion Twitter/X User Profiles the Work of a Laid-off Employee?
Many questions remain about the data leak: if it was in fact the work of a former employee, if it was a matter of revenge for Musk’s sweeping layoffs, and if the entirety of the new information is in fact new and accurate.
-
Massive Oracle Cloud Data Breach Impacts Unknown Number of Clients
It’s unclear how many of the 140,000 or so Oracle Cloud clients have suffered damage from the recent data breach, but the keys the attackers claim to have raise a lot of alarm.
-
Has DeepSeek Become a Malware Machine? New Research Finds Guardrails are Weak
The report takes DeepSeek R1 to task for its poor guardrails, documenting the creation of malware including a basic keylogger and several types of ransomware via very basic sorts of prompt hacking that other major models long ago addressed.
-
Organized Crimes Going High-Tech With AI-Powered Tools, Europol Warns
Types of organized crimes seeing outsized benefit from AI-powered tools include human trafficking and all types of illicit international smuggling, waste management fraud, and of course a spectrum of cyber attacks. Europol also notes use by state-sponsored hacking groups in disruption and propaganda campaigns.
-
Security of GitHub Repositories Called Into Question as Multiple Supply Chain Attacks Uncovered
How safe are your GitHub repositories? If they are public, a set of recent compromises has called their security into question. The widely-used GitHub Actions tool, owned and maintained by Microsoft, has been the source of at least one major supply chain attack.
-
Will the Trump Administration Commit to Loose AI Regulations? OpenAI Hopes So
OpenAI’s proposal invokes China as the central motivation for its requests for lighter AI regulations, but the company is under a variety of legal pressures that could be eased by federal relief: hundreds of emerging US state laws and lawsuits from copyright holders among them.
-
US Electric Grid Company Compromised by Volt Typhoon for Most of 2023
When Dragos was contracted to implement operational technology security measures for a Massachusetts electric grid company in late 2023, it found that Volt Typhoon had been lurking in their systems since February of that year.










