infosec

Researchers say they found spyware used in war for the first time

Security researchers and digital rights organizations believe the government of Azerbaijan used spyware produced by NSO Group to target a government worker, journalists, activists and the human rights

US government targets North Korea’s illicit IT workforce with new sanctions

The U.S. government announced new sanctions against North Korea related to its army of illicit IT workers that have fraudulently gained employment to finance the regime’s weapons of mass destruc

Consulting firm Krebs Stamos Group lays off six employees

A consulting firm founded and run by two well-known cybersecurity veterans laid off six people last week, TechCrunch has learned. Krebs Stamos Group was founded in 2021 by former Facebook chief securi

Bishop Fox lays off employees days after throwing conference party

Cybersecurity firm Bishop Fox laid off around 50 employees — or 13% of its workforce — on Tuesday, the company told TechCrunch. The layoffs come just a few days after the company threw a party at

Hackers claim vast access to Western Digital systems

The hackers who breached data storage giant Western Digital claim to have stolen around 10 terabytes of data from the company, including reams of customer information. The extortionists are pushing th

How the FBI caught the BreachForums admin

On Friday, the U.S. Justice Department announced that the now-arrested alleged administrator of the infamous hacking forum BreachForums facilitated the sale and purchase of private information that be

Beloved hacking veteran Kelly ‘Aloria’ Lum passes away at 41

Kelly Lum, better known in hacking circles as Aloria, passed away on Sunday. Aloria was a veteran of the cybersecurity community, especially the one in New York, her home for many years. The Twitter a

Hackers steal gun owners’ data from firearm auction website

Hackers breached a website that allows people to buy and sell guns, exposing the identities of its users, TechCrunch has learned. The breach exposed reams of sensitive personal data for more than 550,

Activision did not notify employees of data breach for months

On December 4, hackers successfully phished an employee at the games giant Activision, gaining access to some internal employee and game data. This data breach was not disclosed until last weekend, wh

Hackers steal Activision games and employee data

Unknown hackers stole internal data from the games giant Activision. On Sunday, the cybersecurity and malware research group vx-underground published screenshots of data purportedly stolen from Activi

Digital rights defenders infiltrate alleged mercenary hacking group

Cooper Quintin has been tracking the activities of a cyber mercenary group called Dark Caracal for years. On July 28, 2022, he said he discovered traces of a new ongoing hacking campaign by the group

Hacker finds bug that allowed anyone to bypass Facebook 2FA

A bug in a new centralized system that Meta created for users to manage their logins for Facebook and Instagram could have allowed malicious hackers to switch off an account’s two-factor protect

Behavioral cybersecurity platform CybSafe raises $28M Series B led by Evolution Equity Partners

Last year, U.K. cybersecurity startup CybSafe, a “behavioral security” platform, raised a $7.9 million Series A. This SaaS product with a per-user-based, subscription licensing model has a “beha

Starting your journey to zero trust adoption

"Zero trust" is certainly a buzzword that gets freely thrown around in cybersecurity. But what does it actually mean?

Essential advice for securing your small startup

Jeff Bezos’ phone was hacked. And if the richest person in the world is vulnerable, chances are good that your startup could get hacked, too. The good news is that, as a tiny company, you’re not a

How I made my own WireGuard VPN server

Some of you may have heard about VPN protocols that let you establish a connection between your device and a server, such as OpenVPN and IPsec. But there’s a brand new shiny protocol that promises t

CryptoMove protects sensitive data by fragmenting it and moving it around

CryptoMove thinks that data encryption is not enough. If you want to protect your data against hackers, the startup is using a new strategy by fragmenting your data, encrypting it and moving it around

WTF is a VPN?

You’re watching a movie. A criminal is trying to evade a crime scene in a sports car on the highway. A helicopter is following the car from above. The car enters a tunnel with multiple exits and the

Didi Chuxing makes information security push with new U.S. research lab and hires

Didi Chuxing, China's largest ride-hailing company, has hired two distinguished security experts to lead a new U.S.-based research center as part of a major push to increase its data security efforts.

iMessage encryption isn’t perfect as researchers find a security hole

Encryption is a cat-and-mouse game, and Johns Hopkins University researchers have found a great way to prove it. In a new research that they <a target="_blank" href="https://www.washingtonpost.com/wor