VPN flaws allowed Chinese hackers to compromise dozens of Ivanti customers, says report

VPN flaws allowed Chinese hackers to compromise dozens of Ivanti customers, says report

In February 2021, software giant Ivanti discovered that Chinese hackers had breached the network of Pulse Secure, one of its subsidiaries that provided VPN appliances to dozens of companies and government agencies around the world, according to new reporting by Bloomberg. The hackers exploited a secret backdoor they had planted in Pulse Secure’s VPN software,…

Read More
Indian pharmacy chain giant exposed customer data and internal systems

Indian pharmacy chain giant exposed customer data and internal systems

A security lapse by one of India’s largest pharmacy chains allowed outsiders to gain full administrative control of its platform, exposing customer order data and sensitive drug-control functions, TechCrunch has exclusively learned. The issue affected DavaIndia Pharmacy, the pharmacy arm of Zota Healthcare, which operates a large network of retail outlets across India. Security researcher…

Read More
DOJ says Trenchant boss sold exploits to Russian broker capable of accessing ‘millions of computers and devices’

DOJ says Trenchant boss sold exploits to Russian broker capable of accessing ‘millions of computers and devices’

The former boss of a U.S. maker of hacking and surveillance tools stole and sold technology that can hack millions of computers and people worldwide, U.S. prosecutors have confirmed for the first time. In October, Australian national Peter Williams, 39, pleaded guilty to selling eight hacking tools that he stole from his employer Trenchant, a…

Read More
Senator, who has repeatedly warned about secret U.S. government surveillance, sounds new alarm over ‘CIA activities’

Senator, who has repeatedly warned about secret U.S. government surveillance, sounds new alarm over ‘CIA activities’

A senior Democratic lawmaker with knowledge of some of the U.S. government’s most secretive operations has said he has “deep concerns” about certain activities by the Central Intelligence Agency.  The two-line letter written by Sen. Ron Wyden, the longest serving member of the Senate Intelligence Committee, does not disclose the nature of the CIA’s activities…

Read More
Trump’s acting cybersecurity chief uploaded sensitive government docs to ChatGPT

Trump’s acting cybersecurity chief uploaded sensitive government docs to ChatGPT

The acting head of U.S. cybersecurity agency CISA uploaded sensitive contracting documents marked “for official use only” to ChatGPT, according to Politico. The outlet, citing officials, reported Tuesday that CISA’s acting director, Madhu Gottumukkala, appointed by Trump, triggered multiple automated security warnings that are designed to prevent the theft or inadvertent disclosure of government files…

Read More
UStrive security lapse exposed personal data of its users, including children

UStrive security lapse exposed personal data of its users, including children

Online mentoring site UStrive has resolved a security lapse that exposed the personal information of its users, including children.  The exposed data included the full names, email addresses, phone numbers, and other non-public and user-provided information of UStrive users, which was accessible to any other logged-in user. The nonprofit, previously known as Strive for College,…

Read More