Newsletter IconFacebook IconX IconThreads IconInstagram IconYouTube IconPinterest Icon
Giveaway: AVerMedia Creator Bundle (4K Webcam, Capture Card, Charging Hub, and Mouse Pad)

Hacking, Security & Privacy - Page 3

Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 3

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Add TweakTown as a preferred source on GoogleFind TweakTown on Apple News

As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.

16 billion accounts exposed: marking one of the biggest data breaches in history

| Jun 19, 2025 11:11 PM CDT

Welp... one of the largest data breaches in history has just happened, with 16 billion (yes, with a 'b') accounts exposed.

16 billion accounts exposed: marking one of the biggest data breaches in history

Cybernews is the team responsible for IDing and cataloging a large number of major leaks in the past, assembling the datasets that make up the new 16 billion accounts leaked. Just a single dataset from the breach represents 184 million records, which was previously reported by Wired. The rest of them are all new from across the globe, including three distinct batches that had over 1 billion credentials in each of them.

The 16 billion accounts breached were uncovered by security researchers in January 2025, with the largest batch of the leaks sourced from Portuguese-speaking populations that contained 3.5 billion credentials, with other large batches named after Russian logins, Telegram logins, and a bunch of mostly generic names.

0:00 / --:--

Continue reading: 16 billion accounts exposed: marking one of the biggest data breaches in history (full post)

ASUS router users warned: global hacking exploit detected requires factory reset

| May 30, 2025 1:02 PM CDT

GreyNoise, a threat monitoring company, has discovered a botnet named AyySSHush. According to Censys search, there are more than 8,000 infected hosts, and thousands of these are ASUS routers.

ASUS router users warned: global hacking exploit detected requires factory reset

The group behind the botnet is currently unknown, but according to GreyNoise's VP of data science, Bob Rudis, the movements and sophistication of the group suggest they are an "advanced, well-resourced adversary." They started with generic brute-force attacks, but have also incorporated an interesting security bypass to gain access to ASUS routers. The botnet locates ASUS routers and exploits various known bypass bugs to gain initial access to the router, then executes additional authentication bypass techniques to break into routers more effectively.

Once the hackers have cracked the router, they enable SSH, a remote command tool, and their own public key to the router, giving them secret, ongoing access, and begin disabling security tools. What's concerning is that they are able to do all of this using ASUS's own router settings, meaning the changes they have made will survive firmware updates and leave no malware trace, making this form of exploitation extremely difficult to detect.

0:00 / --:--

Continue reading: ASUS router users warned: global hacking exploit detected requires factory reset (full post)

NVIDIA says Cybersecurity teams will be made up of humans and AI agents

| May 5, 2025 10:33 PM CDT

NVIDIA describes Agentic AI or AI Agents as the next step beyond AI chatbots powered by generative AI. AI agents use "sophisticated reasoning and iterative planning to autonomously solve complex, multi-step problems." This sort of AI will revolutionize the customer service market, healthcare, software development, and cybersecurity.

NVIDIA says Cybersecurity teams will be made up of humans and AI agents

When it comes to cybersecurity, Agentic AI will reportedly work alongside cybersecurity experts to play an essential role in threat detection, response, and overall security. NVIDIA notes that this will help free up cybersecurity teams to focus on high-impact decisions and reduce workforce burnout as cybersecurity threats to businesses, individuals, and governments continue to ramp up year-over-year.

"AI agents can cut the time needed to respond to software security vulnerabilities by investigating the risk of a new common vulnerability or exposure in just seconds," NVIDIA's David Reber Jr. explains. "They can search external resources, evaluate environments, and summarize and prioritize findings so human analysts can take swift, informed action."

0:00 / --:--

Continue reading: NVIDIA says Cybersecurity teams will be made up of humans and AI agents (full post)

Apple alerts victims over government spyware infection in iPhones

| May 2, 2025 5:02 AM CDT

Apple has warned iPhone users in 100 countries about their devices being compromised due to spyware, and advised affected users to contact a nonprofit that specializes in investigating cyberattacks.

Apple alerts victims over government spyware infection in iPhones

So far, two people have come forward about Apple's recent alert. One is Italian journalist Ciro Pellegrino, who works for an online news outlet called Fanpage. Pellegrino explained in an article that Apple's alert arrived in the form of an email and a text message that informed him that he was targeted with spyware. The second individual who has come forward about the alert is Eva Vlaardingerbroek, a Dutch right-wing activist who took to X to share Apple's message in the form of screenshots.

Apple's message states the attack is mercenary spyware, which the company warns is "vastly more complex than regular cybercriminal activity and consumer malware" as mercenary spyware attackers apply exceptional resources to target a very small number of specific individuals and their devices. Apple writes on its website explaining its threat notifications that "Mercenary spyware attacks cost millions of dollars and often have a short shelf life, making them much harder to detect and prevent. The vast majority of users will never be targeted by such attacks."

0:00 / --:--

Continue reading: Apple alerts victims over government spyware infection in iPhones (full post)

Man admits to hacking Disney's Slack channel and stealing 1.1TB of data

| May 2, 2025 4:05 AM CDT

A Californian man has pleaded guilty to hacking Disney's Slack channel and stealing 1.1TB of internal company data, according to the Department of Justice (DOJ).

Man admits to hacking Disney's Slack channel and stealing 1.1TB of data

The man is 25-year-old Ryan Kramer, who operated under the alias "NullBulge," and according to the DOJ, Kramer created a malicious program in early 2025 that he promoted as an AI image generation tool on GitHub and various other platforms. The program was actually malware that enabled Kramer to gain access to a computer that downloaded the program and steal the passwords and data from the device.

The Wall Street Journal writes that one of the people who downloaded the program was Disney employee Matthew Van Andel, who had his passwords stolen from his 1Password password manager. With Van Andel's passwords, Kramer signed into Disney's Slack Channels where he began downloading data, amounting to 1.1TB of Disney's confidential company data.

0:00 / --:--

Continue reading: Man admits to hacking Disney's Slack channel and stealing 1.1TB of data (full post)

Widespread VPN attack: 2.8 million IPs involved in brute-force campaign

| Feb 12, 2025 1:01 AM CST

An unidentified threat actor is conducting brute-force attacks targeting over 2.8 million VPN and network devices worldwide. Threat monitoring platform The Shadowserver Foundation posted the reports to X, highlighting a wave of intrusion attempts against networks using devices from Palo Alto, Ivanti, and SonicWall.

Widespread VPN attack: 2.8 million IPs involved in brute-force campaign

There's a specific concentration of attacks in Brazil, Turkey, Russia, and Argentina, with 1.1 million of the 2.8 million affected devices located in Brazil. The foundation also reports that the brute-force attacks are primarily targeting vulnerable edge (network) devices - particularly compromised routers from manufacturers such as MikroTik, Huawei, Cisco, Boa, and ZTE. Threat actors are leveraging a botnet or residential proxy network to disguise malicious traffic, making detection and mitigation more difficult.

The companies above often provide enterprise-level VPNs used for remote work and secure corporate access, making them targets for network infiltration. As reported by Techradar, the attack fits the profile of a conventional brute-force attack, during which threat actors submit large numbers of username and password combinations until breaking through. In that regard, devices with week or reused credentials are particularly vulnerable.

0:00 / --:--

Continue reading: Widespread VPN attack: 2.8 million IPs involved in brute-force campaign (full post)

Intel's Security Report for 2024 says its products are more secure than AMD's or NVIDIA's

| Feb 11, 2025 10:02 PM CST

Intel has released its 2024 Intel Product Security Report, which includes several findings and statistics designed to showcase the company's "competitive edge in security assurance." Especially when compared to its main competition in the CPU space, AMD, and especially when it comes to Intel's proactive approach to discovering vulnerabilities.

Intel's Security Report for 2024 says its products are more secure than AMD's or NVIDIA's

According to a detailed slide in the report, "Intel's proactive product security assurance efforts resulted in the discovery and mitigation of 94% of platform firmware vulnerabilities" compared to just 57% on AMD's side. This is for vulnerabilities discovered within CPU firmware, which is a significant concern. One of the highest-profile security stories of 2024 was the 'Sinkclose' vulnerability affecting millions of Ryzen CPUs.

Intel also outlines how its GPU security stacks up against NVIDIA and AMD, where Team Blue had the "fewest number of GPU vulnerabilities in 2024 at 10, while AMD had 13 and NVIDIA posted 18." And of those 18 for NVIDIA, they are all 'high severity.'

0:00 / --:--

Continue reading: Intel's Security Report for 2024 says its products are more secure than AMD's or NVIDIA's (full post)

Microsoft Defender had a built-in VPN - but not anymore as little-known feature has been canned

| Feb 3, 2025 10:20 AM CST

Microsoft Defender has a VPN, and if this is the first you're hearing of this - and you wouldn't be alone in that - well, the discovery comes a bit late, as the news here is that the software giant is ditching this feature.

Microsoft Defender had a built-in VPN - but not anymore as little-known feature has been canned

Microsoft Defender is a solid enough option for security that's left in place as default coverage in Windows for less tech-savvy people who don't know much, or indeed care much, about antivirus apps.

It has a built-in VPN feature called 'privacy protection' which rolled out last year (actually from late 2023). Microsoft implemented it as a basic service, as you might imagine, with no server choice, so it's just a simple switch to hook you up to the nearest server and provide encryption for your data being sent online (and anonymity for your IP address).

0:00 / --:--

Continue reading: Microsoft Defender had a built-in VPN - but not anymore as little-known feature has been canned (full post)

FBI seizes domains for infamous hacking forums that created 17 million US victims

| Feb 1, 2025 12:01 AM CST

The Department of Justice has announced the FBI has seized two infamous hacking forums that created 17 million American victims.

FBI seizes domains for infamous hacking forums that created 17 million US victims

The two hacking forums that are now in possession of the US government are Cracked.io and Nulled.to, which are known hubs for cybercriminal activity, with their main focus being password theft, cracked software sharing, credential theft, hacking tools, and data breaches. According to the press release from the DOJ, the domains for each of the forums were seized under Operation Talent, a multinational law enforcement operation that included authorities from the following countries: the United States, Italy, Spain, Europe, France, Greece, Australia, and Romania.

Banners have now been placed on both of the websites, stating the domains have been seized by international law enforcement partners. Cracked.io staff initially published an announcement on their Telegram channel where they wrote the problems users were reporting with the website, such as error messages being presented when loading was attempted, was related to a data center issue. However, an update from Cracked.io staff confirmed, "Cracked.io has been seized under operation talent with specific reasons being undisclosed."

0:00 / --:--

Continue reading: FBI seizes domains for infamous hacking forums that created 17 million US victims (full post)

Stop Spam and Scams: Create a Private Online Identity

| Dec 17, 2024 7:07 AM CST

With so much personal information and data stored online, identity theft, getting scammed, and being the victim of fraud is a real threat.

Stop Spam and Scams: Create a Private Online Identity

From online shopping to dating apps to streaming services and simply creating an account to access a single piece of information you're interested in, we're all potentially exposing our sensitive personal information and data every time we hit that 'sign up' button.

Millions see the effects daily, from online-specific data points like usernames and email addresses leading to email inboxes filled with spam and phishing attempts to exposed phone numbers leading to scam calls and text messages. The latter can lead to severe outcomes, with scam calls and phishing texts looking to infect your mobile device, make a payment, or trick you into revealing additional personal information.

Continue reading: Stop Spam and Scams: Create a Private Online Identity (full post)

See if Your Personal Data is Compromised with the Free Data Leak Checker

| Dec 16, 2024 6:39 PM CST

The email addresses we use daily with online service require a login, and this data point is often linked with additional information like passwords, personal information, and phone numbers.

See if Your Personal Data is Compromised with the Free Data Leak Checker

In Q3 2024, over 100 million North American accounts were breached - a figure that makes up a quarter of affected accounts. Globally, that number skyrockets to over 420 million, which means over 3,200 accounts were compromised every minute. This covers small businesses, large corporations, and everyday internet users with sensitive personal data, leaving many individuals vulnerable to identity theft and fraud.

Due to a recent "security event," one of the largest companies in the world, Amazon, saw phone numbers, email addresses, and locations of its employees stolen as part of last year's MOVEit Transfer hack. In another recent example, U.S. communications giant T-Mobile was reportedly breached as part of a Chinese hacking operation targeting international telecommunications companies.

Continue reading: See if Your Personal Data is Compromised with the Free Data Leak Checker (full post)

Microsoft confirms Ukrainian frontline was hit with hacks traced back to Russia

| Dec 12, 2024 4:33 AM CST

A group of hackers connected to the Russian government have launched cyber attacks at Starlink-connected infrastructure in Ukraine to target devices being used by Ukrainian soldiers on the frontline. Microsoft has confirmed the infrastructure has been compromised, and currently, investigators still don't know what vulnerability was exploited.

Microsoft confirms Ukrainian frontline was hit with hacks traced back to Russia

Microsoft has labeled the group as "Secret Blizzard," and according to reports and the latest Microsoft Security blog post, in at least one instance this year when Ukrainian frontline devices were targeted, Secret Blizzard used infrastructure created by a cybercrime group Microsoft tracks as Storm-1919. In another instance,e Secret Blizzard leveraged infrastructure from another group called Storm-1837, a Russian-based cybercrime group that targets Ukrainian drone operations.

So, how did they gain access to the infrastructure? Microsoft explains the cybercriminals between March and April this year used a bot swarm attack to install the XMRIG cryptocurrency app on targeted servers. Typically, hackers will install this malware and then use the device's resources to mine a cryptocurrency, which they then sell online for real money. However, Microsoft writes the ultimate objective of bot swarm malware was to install Tavdig, a backdoor Secret Blizzard used to conduct reconnaissance on the target device.

Continue reading: Microsoft confirms Ukrainian frontline was hit with hacks traced back to Russia (full post)

Microsoft sounds alarm on cyberspy group now targeting critical US infrastructure

| Dec 6, 2024 11:06 AM CST

Microsoft Threat Intelligence has warned that a Chinese government espionage hacking group is targeting critical US infrastructure, such as telecommunications networks, financial and legal services industries, and government and non-government agencies.

Microsoft sounds alarm on cyberspy group now targeting critical US infrastructure

Sherrod DeGrippo, the director of threat intelligence strategy at Microsoft, spoke with The Register, saying the new group Microsoft is tracking under the moniker "Storm-0227" began targeting critical US infrastructure as soon as yesterday. DeGrippo says the group has been active since January but didn't say its total number of victims. Notably, DeGrippo said the group's members have some overlap with Silk Typhoon, a notorious Chinese government-affiliated hacking group known for healthcare, law firms, higher education, defense contractors, and non-governmental organizations.

Furthermore, over the past 12 months, Microsoft has seen a significant increase in the frequency of attacks by Chinese hacking groups. As for how the hacking is done, The Register reports Storm-0227 typically infiltrates a system by exploiting security vulnerabilities in public-facing applications and spear-fishing emails that contain contaminated links or attachments. The objective of Storm-0227 is to get a victim to click on a document that automatically downloads SparkRAT, an open-source remote administration tool that enables the controller administrative access to a machine.

Continue reading: Microsoft sounds alarm on cyberspy group now targeting critical US infrastructure (full post)

Top US senator confirms China is listening in on phone calls, including the Presidents

| Nov 27, 2024 12:32 AM CST

Last week, telecommunications executives sat in front of the Biden administration and discussed the exponential frequency of cyber attacks from China on the United States, with one Senator saying the attacks from China make severe cyber security events such as Solar Winds caused by Russia-affiliated bad actors look like "child's play."

Top US senator confirms China is listening in on phone calls, including the Presidents

The details come from Senator Mark R Warner, who spoke to the press and said that "my hair is on fire" with the ramping cyber attacks from China, which started increasing well before the recent US election. Additionally, the Senator stated the presence and nature of the attacks may require the replacement of "literally thousands and thousands and thousands" of routers, switches, and other potentially infiltrated hardware.

Furthermore, the Senator warned that the extent to which these attacks have affected US networks is currently unknown, describing the situation as follows: "The barn door is still wide open, or mostly open." More specifically, US telecommunications networks that have been infiltrated may provide Chinese state employees or affiliated hackers with the means of listening in on phone calls, even as high as President-elect Donald Trump.

Continue reading: Top US senator confirms China is listening in on phone calls, including the Presidents (full post)

Microsoft asks President Trump for help against Russian and Chinese cyber attacks

| Nov 25, 2024 12:04 AM CST

In a recent interview with the Financial Times, Brad Smith, the vice chair and top legal officer at Microsoft, said that he is hoping President Trump and his administration push back harder against foreign cyber attacks, particularly those that originate from Russia and China.

Microsoft asks President Trump for help against Russian and Chinese cyber attacks

Cyber attacks from Russia and China have become more and more frequent, with Microsoft only recently confirming that Russian state-backed hacking group Midnight Blizzard infiltrated its servers. Microsoft has since implemented security updates to mitigate the likelihood of breaches, but attacks are still increasing and only becoming more sophisticated. Brad Smith, Microsoft's vice chair and top legal officer, has called upon the Trump Administration to "push harder" against cyber attacks, saying the issue "deserves to be a more prominent issue of international relations".

Smith has said he hopes Trump is prepared to send a "strong message" to Russia, Iran, and any other nation that is launching cyber attacks on the US. It was only earlier this month US authorities accused China of launching widespread cyber espionage campaigns against the US, with a recent Microsoft-led study finding that more than 600 million cyber attacks are launched at its customers every day. Moreover, Microsoft found that criminal gangs are now increasingly teaming up with "nation-state groups" to launch operations against targets and share hacking tools.

Continue reading: Microsoft asks President Trump for help against Russian and Chinese cyber attacks (full post)

Officials warn of new hacking scheme involving QR codes and your physical mailbox

| Nov 20, 2024 1:02 AM CST

Scammers are always looking for new ways to take advantage of unsuspecting people, and according to Switzerland's National Cyber Security Center (NCSC) there is a rise in a new method of scamming, and it involves the use of QR codes and the traditional postage system.

Officials warn of new hacking scheme involving QR codes and your physical mailbox

In a new statement issued by the National Cyber Security Center, hackers are attempting a new scheme to get malware into as many devices as possible, and it involves sending fake letters, such as the one above, to residents that request they download a "Severe Weather Warning App" for Android via the provided QR code. The letters were faked to look like letters sent from the nation's Federal Office of Meteorology and Climatology, and the app the scammers requested residents to download was designed to mimic the official Alertswiss weather app by using a similar name "AlertSwiss," and a slightly different logo.

The fraudulent app took users that scanned it to a third-party site and not the official Google Play Store, which, for those unfamiliar with the rules of the road when downloading apps - the general rule of thumb is don't download any application onto your device that isn't from the official app marketplaces. The scamming app contained a version of the Copper trojan, malware designed specifically for keylogging purposes, gathering two-factor authentication information, tracking notifications and SMSs, and stealing stored user credentials from other applications.

Continue reading: Officials warn of new hacking scheme involving QR codes and your physical mailbox (full post)

FBI confirms Chinese government-linked hackers breached US government networks

| Nov 14, 2024 9:02 AM CST

The FBI and CISA have posted a joint statement revealing that numerous commercial telecommunications organizations have been breached by a hacking group associated with the Chinese government.

FBI confirms Chinese government-linked hackers breached US government networks

The joint statement posted to the official FBI website states the US government is continuing its investigation into the People's Republic of China (PRC) targeting of commercial telecommunications infrastructure across the US, and that it can confirm the existence of a "broad and significant cyber espionage campaign." More specifically, the joint statement reads that US officials have identified PRC-affiliated actors that have "compromised networks at multiple telecommunications companies" to steal customer call data, information, and other data.

Notably, the group behind these attacks on US infrastructure is reportedly Salt Typhoon, which has gained access to customer call records data along with private communications of individuals within the US government. Furthermore, US officials can also confirm the group gained access to a US wiretap system, which is used by authorities to submit requests for court orders. It was only in September 2024 that Salt Typhoon targeted a selection of US internet service providers in what is believed to be a reconnaissance attack to gather information on potential targets for future heavier attacks.

Continue reading: FBI confirms Chinese government-linked hackers breached US government networks (full post)

Microsoft confirms US government officials are being targeted by notorious hackers

| Oct 30, 2024 2:32 AM CDT

Microsoft has taken to its security blog to shine a light on the company's recent observations in the cybersecurity space, and according to the Redmond company, a known hacking group is now going after US government officials in a series of highly-targeted spear-phishing email waves.

Microsoft confirms US government officials are being targeted by notorious hackers

According to Microsoft, the hacking group is Russian government-backed bad actors Midnight Blizzard, which have been on Microsoft's radar since October 22, 2024. Microsoft Threat Intelligence is quite familiar with Midnight Blizzard, as the hacking group targeted Microsoft servers on January 12, 2024, which ended up becoming compromised and Midnight Blizzard gaining access to federal government email accounts, Microsoft's corporate email accounts, and more.

At the time, Microsoft described these attacks by Midnight Blizzard as a "sustained, significant commitment of the threat actor's resources, coordination, and focus." Now, Microsoft has put out a new warning that Midnight Blizzard is sending a series of highly targeted spear-phishing emails to individuals in government, academia, defense, non-governmental organizations, and other sectors. Microsoft writes this activity is ongoing, and the likely goal of this operation is to collect intelligence.

Continue reading: Microsoft confirms US government officials are being targeted by notorious hackers (full post)

100,000+ United Nations documents exposed by cybersecurity researcher

| Oct 23, 2024 1:03 AM CDT

A cybersecurity researcher has discovered more than 100,000 United Nations-associated documents containing financial reports, audits, bank account information, staff documents, email addresses, and more in a non-password-protected text database.

100,000+ United Nations documents exposed by cybersecurity researcher

vpnMentor cybersecurity researcher Jeremiah Fowler has published a new report revealing the discovery of a non-password-protected database that contained 115,000 records associated with the United Nations Trust Fund to End Violence against Women. The trust fund was set up to provide financial and technical support to local, national, and regional organizations working toward reducing gender-based violence. According to the report the database held 115,141 files that amounted to 228GB of data.

According to Fowler, many of the documents in the database were marked as confidential, with the cybersecurity researcher pointing out one .xls file contained a list of "1,611 civil society organizations, including their internal UN application numbers, whether they are eligible for support, the status of their applications, whether they are local or national, and a range of detailed answers regarding the groups' missions."

Continue reading: 100,000+ United Nations documents exposed by cybersecurity researcher (full post)

World's biggest tech companies and government agencies hit by DDoS attacks by two men

| Oct 22, 2024 5:34 AM CDT

Federal authorities have charged two brothers with launching cyberattacks at some of the world's biggest technology companies, including streaming services and social platforms.

World's biggest tech companies and government agencies hit by DDoS attacks by two men

The US Department of Justice has alleged two brothers are behind the hacktivist group Anonymous Sudan, which launched thousands of powerful distributed denial-of-service (DDoS) attacks at some of the biggest tech companies in the world. Additionally, the group targeted government agencies such as the FBI, Department of Justice (DOJ), Pentagon, and FBI. The charges by the DOJ outline the two Sudanese brothers are also responsible for a series of cyberattacks against Microsoft, OpenAI, Riot Games, PayPal, Steam, Hulu, Netflix, Reddit, GitHub, and Cloudflare.

Ahmed Salah Yousif Omer, 22, and Alaa Salah Yusuuf Omer, 27, were charged with one count of conspiracy to damage protected computers. Ahmed Salah was separately charged with three counts of damaging protected computers and an attempt to "knowingly and recklessly cause death" after launching several cyberattacks at hospitals in retaliation for hospitals being bombed in Gaza. If convicted of all charges, Ahmed Salah will face a maximum sentence of life in federal prison.

Continue reading: World's biggest tech companies and government agencies hit by DDoS attacks by two men (full post)

Join Our Newsletter

Join the TweakTown Newsletter for daily tech updates delivered to your inbox.

See previous giveaways.

Newsletter Subscription