Tag Archives: hacking

The life and times of Cozy Bear, the Russian hackers who just hit Microsoft and HPE

Getty Images reader comments 38 Hewlett Packard Enterprise (HPE) said Wednesday that Kremlin-backed actors hacked into the email accounts of its security personnel and other employees last May—and maintained surreptitious access until December. The disclosure was the second revelation of a major corporate network breach by the hacking group in five days. The hacking group… Read More »

AI will increase the number and impact of cyberattacks, intel officers say

Getty Images reader comments 32 Threats from malicious cyberactivity are likely to increase as nation-states, financially motivated criminals, and novices increasingly incorporate artificial intelligence into their routines, the UK’s top intelligence agency said. The assessment, from the UK’s Government Communications Headquarters, predicted ransomware will be the biggest threat to get a boost from AI over… Read More »

Mass exploitation of Ivanti VPNs is infecting networks around the globe

Enlarge / Cybercriminals or anonymous hackers use malware on mobile phones to hack personal and business passwords online. Getty Images reader comments 8 Hackers suspected of working for the Chinese government are mass exploiting a pair of critical vulnerabilities that give them complete control of virtual private network appliances sold by Ivanti, researchers said. As… Read More »

Hackers spent 2+ years looting secrets of chipmaker NXP before being detected

reader comments 17 with A prolific espionage hacking group with ties to China spent over two years looting the corporate network of NXP, the Netherlands-based chipmaker whose silicon powers security-sensitive components found in smartphones, smartcards, and electric vehicles, a news outlet has reported. The intrusion, by a group tracked under names including “Chimera” and “G0114,”… Read More »

Okta hit by another breach, this one stealing employee data from 3rd-party vendor

Getty Images reader comments 25 with Identity and authentication management provider Okta has been hit by another breach, this one against a third-party vendor that allowed hackers to steal personal information for 5,000 Okta employees. The compromise was carried out in late September against Rightway Healthcare, a service Okta uses to support employees and their… Read More »

Microsoft profiles new threat group with unusual but effective practices

Enlarge / This is not what a hacker looks like. Except on hacker cosplay night. reader comments 4 with Microsoft has been tracking a threat group that stands out for its ability to cash in from data theft hacks that use broad social engineering attacks, painstaking research, and occasional physical threats. Unlike many ransomware attack… Read More »

Okta says hackers breached its support system and viewed customer files

reader comments 8 with Identity and authentication management provider Okta said hackers managed to view private customer information after gaining access to credentials to its customer support management system. “The threat actor was able to view files uploaded by certain Okta customers as part of recent support cases,” Okta Chief Security Officer David Bradbury said… Read More »

How China gets free intel on tech companies’ vulnerabilities

Wired staff; Getty Images reader comments 46 with For state-sponsored hacking operations, unpatched vulnerabilities are valuable ammunition. Intelligence agencies and militaries seize on hackable bugs when they’re revealed—exploiting them to carry out their campaigns of espionage or cyberwar—or spend millions to dig up new ones or to buy them in secret from the hacker gray… Read More »

Hacker gains admin control of Sourcegraph and gives free access to the masses

Getty Images reader comments 9 with An unknown hacker gained administrative control of Sourcegraph, an AI-driven service used by developers at Uber, Reddit, Dropbox, and other companies, and used it to provide free access to resources that normally would have required payment. In the process, the hacker(s) may have accessed personal information belonging to Sourcegraph… Read More »

Barracuda thought it drove 0-day hackers out of customers’ networks. It was wrong.

reader comments 31 with In late May, researchers drove out a team of China state hackers who over the previous seven months had exploited a critical vulnerability that gave them backdoors into the networks of a who’s who of sensitive organizations. Barracuda, the security vendor whose Email Security Gateway was being exploited, had deployed a… Read More »