Tag: security

Leading AI companies keep leaking their own information on GitHub

Researchers find 65% of the Forbes top 50 AI companies are leaking secrets These come in the form of tokens, API keys, and sensitive credentials Wiz used a ‘‘Depth, Perimeter, and Coverage’ approach to spot leaks AI companies have had a pretty rocky history with cybersecurity and data privacy, and…

Read More

Fake Facebook Business pages are bombarding users with phishing messages – so what can be done?

Hackers spoof Facebook alerts using real facebookmail.com domain to phish Business Suite users Over 40,000 emails sent; one firm received 4,000+—mostly templated, wide-net campaigns Defense requires MFA, password managers, staff training, and vigilant account monitoring Cybercriminals are targeting Facebook Business Suite users with highly convincing phishing emails, tricking them into…

Read More

Samsung phones under threat from this dangerous new spyware cyberattack – here’s how to stay safe

CVE-2025-21042 flaw enabled remote code execution on multiple Samsung Galaxy devices Attackers used WhatsApp to deliver LandFall spyware via malformed image files Victims targeted in the Middle East; Stealth Falcon group suspected behind the campaign Multiple Samsung Galaxy device series were vulnerable to a flaw that allowed threat actors to…

Read More

These are still the most popular passwords around – and surely, we can do better than this as a species

Predictable password habits continue to enable attackers who rely on automated large-scale cracking Length remains the defining factor that determines a password’s actual resistance Administrators heavily influence password strength through the rules they choose Yet more research has revealed that when it comes to thinking up strong passwords, we’re all…

Read More

Can’t think of a good password for every account? It’s not your fault – you can also blame the websites themselves, a new study says

Weak password rules engineer unsafe habits across major global websites Critical industries still rely on outdated requirements while handling sensitive user data Automated attacks exploit insecure credentials faster than websites can adapt Many users struggle to create strong password credentials across multiple accounts because the broader digital ecosystem rarely pushes…

Read More

Experts warn ClickFix malware attacks are back, and more dangerous than ever before – here’s how to stay safe

ClickFix now uses OS detection, timers, and video guides to boost malware delivery success Attackers host popups on compromised sites and promote them via Google malvertising Victims are tricked into running malware via fake problem/solution instructions in system dialogs The dreaded malware deployment technique known as ClickFix is evolving, and…

Read More