35.5 million customers of major apparel brands have their data breached after ransomware attack

Bought some Timberland shoes? Wear a North Face jacket? You, and millions of purchasers of other popular high-street brands, could have had their data stolen by the ALPHV ransomware group.

Read more in my article on the Hot for Security blog. Continue reading 35.5 million customers of major apparel brands have their data breached after ransomware attack

Smashing Security podcast #355: Fishy Rishi, 23andMe, and the labour of love

Has the British Prime Minister been caught secretly profiting from a cryptocurrency app? Were 23andMe right to blame their users after a data breach? And Indian men have hard feelings after falling for a money-for-sex scam.

All this and much much mo… Continue reading Smashing Security podcast #355: Fishy Rishi, 23andMe, and the labour of love

Heartless scammers prey on hundreds of lost pet owners, demanding ransoms or else…

Hundreds of pet owners across the UK have reported that they have received blackmail threats from scammers who claim to have found their lost pooches and missing moggies.

Read more in my article on the Hot for Security blog. Continue reading Heartless scammers prey on hundreds of lost pet owners, demanding ransoms or else…

Critical flaw found in WordPress plugin used on over 300,000 websites

A WordPress plugin used on over 300,000 websites has been found to contain vulnerabilities that could allow hackers to seize control.

Security researchers at Wordfence found two critical flaws in the POST SMTP Mailer plugin.

Read more in my artic… Continue reading Critical flaw found in WordPress plugin used on over 300,000 websites

Security firm Mandiant says it didn’t have 2FA enabled on its hacked Twitter account

Anyone who works in computer security knows that they should have two-factor authentication (2FA) enabled on their accounts.

2FA provides an additional layer of security. A hacker might be able to guess, steal, or brute force the password on your a… Continue reading Security firm Mandiant says it didn’t have 2FA enabled on its hacked Twitter account

Twitter says, It’s not our fault the SEC’s account got hacked

The safety team at Twitter has responded to the high profile hack of the SEC Twitter account, which made headlines around the world.

And what do they have to say?

Well, in a nutshell – “it’s not our fault. They lost control of their mobile phone … Continue reading Twitter says, It’s not our fault the SEC’s account got hacked

Smashing Security podcast #354: Chuck Norris and the fake CEO, artificial KYC, and an Airbnb scam

Chuck Norris gives a helping hand to a mysterious cryptocurrency CEO who may have separated investors from over a billion dollars, generative AI creates a nightmare for those wanting to Know Their Customer, and a determined journalist finally gets thei… Continue reading Smashing Security podcast #354: Chuck Norris and the fake CEO, artificial KYC, and an Airbnb scam

SEC’s Twitter account hacked to say Bitcoin ETFs approved. Politicians and lawyers demand investigation into security breach

The official Twitter account of the US Securities and Exchange Commission (SEC) was hacked yesterday, with scammers posting an unauthorised message to its 660,000+ followers.

The false message – which has since been deleted – claimed that the SEC ha… Continue reading SEC’s Twitter account hacked to say Bitcoin ETFs approved. Politicians and lawyers demand investigation into security breach