Charming Kitten targets critical infrastructure in US and elsewhere with BellaCiao malware

Iranian state-sponsored hacking group Charming Kitten has been named as the group responsible for a new wave of attacks targeting critical infrastructure in the United States and elsewhere.

Read more in my article on the Tripwire State of Security b… Continue reading Charming Kitten targets critical infrastructure in US and elsewhere with BellaCiao malware

Smashing Security podcast #319: The CEO who also ran IT, Strava strife, and TikTok tall tales

A boss is bitten in the bottom after being struck by one of the worst crimes in Finnish history, Strava’s privacy isn’t so private, and a private investigator uncovers some TikTok tall tales. All this and much much more is discussed in the … Continue reading Smashing Security podcast #319: The CEO who also ran IT, Strava strife, and TikTok tall tales

Pro-Russia hackers attack European air traffic control website, but don’t panic! Flights continue as normal

Eurocontrol, the European air traffic control agency, has revealed that it has been under cyber attack for the last week, and says that pro-Russian hackers have claimed responsibility for the disruption.

When you first see the headline in the likes … Continue reading Pro-Russia hackers attack European air traffic control website, but don’t panic! Flights continue as normal

US Facebook users can now claim their share of $725 million Cambridge Analytica settlement

Were you a US-based Facebook user between May 24 2007 and December 22 2022?

If so, I’ve got some good news for you.

Read more in my article on the Hot for Security blog. Continue reading US Facebook users can now claim their share of $725 million Cambridge Analytica settlement

US charges three men with six million dollar business email compromise plot

Three Nigerian nationals face charges in a US federal court related to a business email compromise (BEC) scam that is said to have stolen more than US $6 million from victims.

Read more in my article on the Tripwire State of Security blog. Continue reading US charges three men with six million dollar business email compromise plot

MacStealer – newly-discovered malware steals passwords and exfiltrates data from infected Macs

I’m still encountering people who, even after all these years, believe that their Apple Mac computers are somehow magically invulnerable to ever being infected by malware.

Maybe details of this new Mac malware will change their mind… Continue reading MacStealer – newly-discovered malware steals passwords and exfiltrates data from infected Macs

Ex-CEO of hacked therapy clinic sentenced for failing to protect patients’ session notes

A Finnish court has given the former CEO of a chain of psychotherapy clinics a suspended jail sentence after failing to adequately protect highly sensitive notes of patients’ therapy sessions from falling into the hands of blackmailing hackers.

Read… Continue reading Ex-CEO of hacked therapy clinic sentenced for failing to protect patients’ session notes

FTC accuses payments firm of knowingly assisting tech support scammers

Multinational payment processing firm Nexway has been rapped across the knuckles by the US authorities, who claim that the firm knowingly processed fraudulent credit card payments on behalf of tech support scammers.

Read more in my article on the Tr… Continue reading FTC accuses payments firm of knowingly assisting tech support scammers

Smashing Security podcast #318: Tesla workers spy on drivers, and Operation Fox Hunt scams

Graham wonders what would happen if his bouncing buttocks were captured on camera by a Tesla employee, and we take a look at canny scams connected to China’s Operation Fox Hunt.

All this and more is discussed in the latest edition of the “Smashing S… Continue reading Smashing Security podcast #318: Tesla workers spy on drivers, and Operation Fox Hunt scams