Skip to main content

Security

See All Stories

T-Mobile breached by cybercrime group LAPSUS$ through compromised employee accounts

T-Mobile 3.3Gbps speed 5G SA

T-Mobile has suffered another data breach, this time carried out by young hackers that were part of the LAPSUS$ group. While T-Mobile has said that no customer or government information was compromised, it appears LAPSUS$ gained access to T-Mobile’s source code repositories along with its customer account management system.

Expand Expanding Close

Pegasus targeted US iPhones indirectly; device infected in British prime minister’s office; Catalans targeted in Spain

Site default logo image

NSO spyware Pegasus targeted US iPhones indirectly, despite the company forbidding customers from infecting phones with American SIMs. Devices belonging to Catalan politicians and others were also infected, with the Spanish government suspected to be responsible.

Additionally, it was discovered that a device connected to the network at 10 Downing Street – the office of British prime minister Boris Johnson – was also infected …

Expand Expanding Close

Pegasus hacked the iPhone of award-winning journalist, weeks after Apple’s injunction attempt

Pegasus hacked the iPhone of award-winning journalist

It’s been revealed that NSO’s Pegasus hacked the iPhone of an award-winning journalist, just weeks after Apple sought an injunction that would bar the company from targeting iPhone users.

NSO’s Pegasus software is so dangerous for two reasons. First, it gives access to almost all the data on the phone, including messages, photos, and location. Second, it works via a zero-click approach …

Expand Expanding Close

Wyze Cam security flaw gave hackers access to video; went unfixed for almost three years

Wyze Cam security flaw gave hackers access to video for three years

A major Wyze Cam security flaw easily allowed hackers to access stored video, and it went unfixed for almost three years after the company was alerted to it, says a new report today.

Additionally, it appears that Wyze Cam v1 – which went on sale back in 2017 – will never be patched, so it will remain vulnerable for as long as it is used …

Expand Expanding Close

Yandex is sending data harvested from millions of iOS users to Russia

Yandex is sending data harvested from millions of iOS users to Russia

A report today says that ‘Russian Google’ Yandex is sending data harvested from millions of iOS app users to Russia – whether or not you use the company’s apps. Laws there could compel the company to make the data available to the Russian government.

Your data can be grabbed from a wide range of third-party apps which use a developer tool created by Yandex. Developers save time and money by using the Yandex API AppMetrica to obtain analytics data for their app, while the company gets user data in return …

Expand Expanding Close

Security experts debate messaging interoperability encryption challenges

Messaging interoperability encryption challenges

Messaging interoperability encryption challenges are being discussed by security experts, following the European Union’s decision to make cross-platform messaging capabilities a legal requirement.

There was much debate on whether or not to include messaging interoperability in the Digital Markets Act (DMA), and the challenges of maintaining end-to-end encryption was one of the key issues …

Expand Expanding Close

Okta hack may have impacted 366 clients; company says it should have acted faster

Site default logo image

The Okta hack revealed yesterday, and which dated back to January, may have impacted up 366 clients, says the company’s chief security officer, David Bradbury. Okta hasn’t named any of them, so it’s not known at this stage how many end users may be affected.

We noted yesterday that Okta offers single sign-on services to a huge range of blue-chip clients, with its services running on Mac, iOS, Windows, and Android …

Expand Expanding Close

Okta security breach may affect Mac and iPhone enterprise setups; vigilance urged

Site default logo image

Hackers have posted credible screengrabs to back reports of an Okta security breach. Otka provides single sign-on user authentication tools in the enterprise sector, with a huge range of blue-chip clients. Its tools are available for Mac and iOS, as well as Windows and Android.

The hacking group LAPSUS$, known for its ransomware attacks, says that it is targeting Otka users …

Expand Expanding Close

T2 Mac security vulnerability means passwords can now be cracked

T2 Mac security vulnerability means encryption key can now be cracked

A company selling password-cracking tools says that a newly-discovered T2 Mac security vulnerability allows it to crack passwords on these machines, bypassing the lockouts.

The method used is far slower than conventional password-cracking tools, but although the total time needed could run into thousands of years, that could fall to as little as 10 hours when the Mac owner has used a more typical password…

Expand Expanding Close

US government Cellebrite customers: 2,800 departments, including Fish & Wildlife Service

Site default logo image

There are more than 2,800 US government Cellebrite customers, according to the smartphone hacking company. The tech can be used to extract most data from both iPhones and Android phones.

The company also boasts that its private sector clients include “six out of the world’s 10 largest pharmaceutical companies and six of the 10 largest oil refineries”…

Expand Expanding Close

Apple two-factor authentication feature now blocks SMS autofill for phishing attacks

Apple’s two-factor authentication autofill feature makes it painless to enter verification codes sent via SMS, but phishing attackers are getting savvy to this.

When they trick people into clicking on a fake link to a site that prompts for an SMS code, they do the same, so it looks legit when autofill offers to paste it in for you …

Expand Expanding Close

Future AirPods may verify your identity by checking the shape of your ear canal

Future AirPods may verify your identity

While most current Apple devices can verify your identity by fingerprint or face recognition, Apple is also considering adding biometric identification to future AirPods.

A patent application describes two potential ways that AirPods could confirm your identity before allowing access to sensitive data, like asking Siri to read your messages…

Expand Expanding Close

DazzleSpy Mac malware enabled key-logging, screen captures, file extraction, more

DazzleSpy Mac malware

Security researchers have released details of DazzleSpy – Mac malware that enabled key-logging, screen captures, microphone access, and more.

DazzleSpy was used to target Hong Kong democracy activists, initially through a fake pro-democracy website, and later through a real one, in a so-called watering hole attack …

Expand Expanding Close