Security

Security news coverage encompasses investigative cybersecurity reporting and analysis on the latest security breaches, hacks and cyberattacks around the globe.

The person who claims to have 49 million Dell customer records told TechCrunch that he brute-forced an online company portal and scraped customer data, including physical addresses, directly from Dell’s…

Threat actor says he scraped 49M Dell customer addresses before the company found out

Technology giant Dell notified customers on Thursday that it experienced a data breach involving customers’ names and physical addresses. In an email seen by TechCrunch and shared by several people…

Dell discloses data breach of customers’ physical addresses

The federal government agency responsible for granting patents and trademarks is alerting thousands of filers whose private addresses were exposed following a second data spill in as many years. The…

US Patent and Trademark Office confirms another leak of filers’ address data

As part of an investigation into people involved in the pro-independence movement in Catalonia, the Spanish police obtained information from the encrypted services Wire and Proton, which helped the authorities…

Encrypted services Apple, Proton and Wire helped Spanish police identify activist

U.S. realty trust giant Brandywine Realty Trust has confirmed a cyberattack that resulted in the theft of data from its network. In a filing with regulators on Tuesday, the Philadelphia-based…

Brandywine Realty Trust says data stolen in ransomware attack

Five takeaways from the indictment of Dmitry Yuryevich Khoroshev, the hacker who U.S. and U.K. authorities accuse of being the mastermind of the LockBit ransomware gang.

What we learned from the indictment of LockBit’s mastermind

The identity of the leader of one of the most infamous ransomware groups in history has finally been revealed. On Tuesday, a coalition of law enforcement led by the U.K.’s…

US, UK police identify and charge Russian leader of LockBit ransomware gang

Wiz, the buzzy startup building an all-in-one cloud security platform, is on an acquisition march to expand its business quickly en route to an IPO. Now, it has closed a…

Wiz raises $1B at a $12B valuation to expand its cloud security platform through acquisitions

A couple of weeks ago, TechCrunch broke the news that Akamai was in discussions to acquire Noname Security, a specialist in API security, for around $500 million. Today, the deal…

Akamai confirms acquisition of Noname for $450M

An international coalition of police agencies have resurrected the dark web site of the notorious LockBit ransomware gang, which they had seized earlier this year, teasing new revelations about the…

Police resurrect LockBit’s site and troll the ransomware gang

Featured Article

UnitedHealth data breach should be a wake-up call for the UK and NHS

The ransomware attack that has engulfed U.S. health insurance giant UnitedHealth Group and its tech subsidiary Change Healthcare is a data privacy nightmare for millions of U.S. patients, with CEO Andrew Witty confirming this week that it may impact as much as one-third of the country. But it should also serve as a wake-up call…

8:43 am PDT • May 3, 2024
UnitedHealth data breach should be a wake-up call for the UK and NHS

A controversial push by European Union lawmakers to legally require messaging platforms to scan citizens’ private communications for child sexual abuse material (CSAM) could lead to millions of false positives…

EU plan to force messaging apps to scan for CSAM risks millions of false positives, experts warn

Ahead of the U.S. presidential election, Google is bringing passkey support to its Advanced Protection Program (APP), which is used by people who are at high risk of targeted attacks,…

Google expands passkey support to its Advanced Protection Program ahead of the US presidential election

Digital fraud detection company BioCatch has a new majority shareholder in the form of U.K private equity firm Permira.

Digital fraud detection startup BioCatch hits $1.3B valuation as Permira buys majority stake

Two months after hackers broke into Change Healthcare systems stealing and then encrypting company data, it’s still unclear how many Americans were impacted by the cyberattack. Last month, Andrew Witty,…

UnitedHealthcare CEO says ‘maybe a third’ of US citizens were affected by recent hack

UnitedHealth Group Chief Executive Officer Andrew Witty told senators on Wednesday that the company has now enabled multi-factor authentication on all the company’s systems exposed to the internet in response…

UnitedHealth CEO tells Senate all systems now have multi-factor authentication after hack

Developers have a problem. It used to be the case that only large enterprises needed to worry themselves with security, but today, every startup is capable of holding huge amounts…

Belgium’s Aikido lands $17M Series A for its ‘no BS’ security platform aimed at developers

The U.S. Federal Communications Commission said on Monday that it is fining the four U.S. major wireless carriers around $200 million in total for “illegally” sharing and selling customers’ real-time…

US fines telcos $200M for sharing customer location data without consent

Security review automation platform SafeBase has raised new cash from investors including Zoom’s corporate VC arm.

SafeBase taps AI to automate software security reviews

UnitedHealth’s CEO said in congressional testimony that the portal used by the hackers to break into Change Healthcare was not protected with a basic security feature.

Change Healthcare hackers broke in using stolen credentials — and no MFA, says UHG CEO

Apple’s App Store isn’t always as trustworthy as the company claims. The latest example comes from RockAuto, an auto parts dealer popular with home mechanics and other DIYers, which is…

Despite complaints, Apple hasn’t yet removed an obviously fake app pretending to be RockAuto

Darktrace is set to go private in a deal that values the U.K.-based cybersecurity giant at around $5 billion. 

Thoma Bravo to take UK cybersecurity company Darktrace private in $5B deal

This share price gives Rubrik a fully diluted valuation of $6.6 billion, up 88% from its last primary valuation of $3.5 billion in 2019.

Rubrik’s shares end trading up almost 16% on the company’s public debut

Kaiser, one of the largest healthcare organizations in the United States, said it was notifying 13.4 million members of a data breach earlier in April.

Health insurance giant Kaiser will notify millions of a data breach after sharing patients’ data with advertisers

Two veteran security experts are launching a startup that aims to help other makers of cybersecurity products to up their game in protecting Apple devices. Their startup is called DoubleYou,…

Ex-NSA hacker and ex-Apple researcher launch startup to protect Apple devices

ICICI Bank, one of India’s top private banks, exposed the sensitive data of thousands of new credit cards to customers who were not their intended recipients. The Mumbai-based bank confirmed…

India’s ICICI Bank exposed thousands of credit cards to ‘wrong’ users

Featured Article

Security bugs in popular phone-tracking app iSharing exposed users’ precise locations

The location-sharing app iSharing, which has 35 million users, fixed vulnerabilities that exposed users’ personal information and precise location data.

7:01 am PDT • April 24, 2024
Security bugs in popular phone-tracking app iSharing exposed users’ precise locations

Automation continues to be a major theme in the enterprise — underscored not least by the rise of AI as a tool to help fix some of the more routine,…

Tines taps $50M to expand its workflow automation beyond security teams

Featured Article

UnitedHealth says Change hackers stole health data on ‘substantial proportion of people in America’

The health tech giant processes 15 billion health transactions a year, and handles health information for about half of all Americans.

3:35 pm PDT • April 22, 2024
UnitedHealth says Change hackers stole health data on ‘substantial proportion of people in America’

CISA said Chirp Systems ignored the federal agency and the reporting security researcher.

US government downgrades bug in Chirp Systems app that contained hardcoded password