‘Minecraft Mods’ Attack More Than 1 Million Android Devices

Fake Minecraft Modpacks on Google Play deliver millions of abusive ads and make normal phone use impossible. Continue reading ‘Minecraft Mods’ Attack More Than 1 Million Android Devices

GoDaddy Employees Tricked into Compromising Cryptocurrency Sites

‘Vishing’ attack on GoDaddy employees gave fraudsters access to cryptocurrency service domains NiceHash, Liquid. Continue reading GoDaddy Employees Tricked into Compromising Cryptocurrency Sites

Google Services Weaponized to Bypass Security in Phishing, BEC Campaigns

Attackers exploiting an array of Google Services, including Forms, Firebase, Docs and more to boost phishing and BEC campaigns. Continue reading Google Services Weaponized to Bypass Security in Phishing, BEC Campaigns

German COVID-19 Contact-Tracing Vulnerability Allowed RCE

Bug hunters at GitHub Security Labs help shore up German contact tracing app security, crediting open source collaboration. Continue reading German COVID-19 Contact-Tracing Vulnerability Allowed RCE

Dating Site Bumble Leaves Swipes Unsecured for 100M Users

Bumble fumble: An API bug exposed personal information of users like political leanings, astrological signs, education, and even height and weight, and their distance away in miles. Continue reading Dating Site Bumble Leaves Swipes Unsecured for 100M Users

Amazon Sues Instagram, TikTok Influencers Over Knockoff Scam

‘Order This, Get This’: Social-media influencers are in Amazon’s legal crosshairs for promoting generic Amazon listings with the promise to get prohibited counterfeit luxury items instead. Continue reading Amazon Sues Instagram, TikTok Influencers Over Knockoff Scam

Animal Jam Hacked, 46M Records Roam the Dark Web

Animal Jam, just the latest in a string of attacks on gaming apps, has adopted a transparent communications strategy after stolen data turned up on a criminal forum. Continue reading Animal Jam Hacked, 46M Records Roam the Dark Web