Thousands of exposed GitHub repositories, now private, can still be accessed through Copilot

Security researchers are warning that data exposed to the internet, even for a moment, can linger in online generative AI chatbots like Microsoft Copilot long after the data is made private. Thousands of once-public GitHub repositories from some of the world’s biggest companies are affe

US employee screening giant DISA says hackers accessed data of more than 3M people

DISA Global Solutions, a U.S.-based provider of employee screening services, has said it suffered a data breach that affects more than 3.3 million people. DISA, which provides services like drug and alcohol testing and background checks to more than 55,000 enterprises and a third of Fortune 500 co

DOGE’s HR email is getting the ‘Bee Movie’ spam treatment

Over the weekend, Elon Musk surveyed his followers on X — the platform he spent $44 billion to buy — asking whether federal employees should be required to send his team an email with a list of five things they accomplished this week. With the yes votes totaling over 70%, Musk followed through.

Three years on, Europe looks to Ukraine for the future of defense tech

Today marks three years since Russia's illegal, unprovoked, and brutal invasion of Ukraine. The Ukrainian people have heroically fought the war with grit and determination, but they have also, against the odds, innovated on and off the battlefield.  In addition to establishing a defense t

Australia bans government use of Kaspersky software due to 'unacceptable security risk'

Australia has become the latest country to ban government officials from using software made by Russian cybersecurity firm Kaspersky, arguing that the software poses an “unacceptable security risk.”  Australia's Department of Home Affairs last week issued a directive that prohibits go

Researchers accuse North Korea of $1.4 billion Bybit crypto heist

On Friday, hackers stole around $1.4 billion in Ethereum cryptocurrency from crypto exchange Bybit, in what is the largest crypto heist of all time. After the hack, several blockchain monitoring firms, as well as the well-known crypto investigator ZachXBT, have all pointed to the North Korean gove

A single default password exposes access to dozens of apartment buildings

A security researcher says the default password shipped in a widely used door access control system allows anyone to easily and remotely access door locks and elevator controls in dozens of buildings across the U.S. and Canada. Eric Daigle said he found exposed residential and office buildings acr

Crypto exchange Bybit says it was hacked and lost around $1.4B

Crypto exchange Bybit announced on Friday that “a sophisticated attack” led to the theft of Ethereum (ETH) from one of the company's offline wallets. Bybit's chief executive and co-founder Ben Zhou said in a livestream that the hackers stole around 401,346 ETH, which at the time of the

Apple pulls iCloud end-to-end encryption feature for UK users after government demanded backdoor

Apple confirmed Friday that it “can no longer” offer a security feature that allows users in the United Kingdom to encrypt their iCloud data.  In a statement provided to technewss, Apple spokesperson Fred Sainz said the company’s Advanced Data Protection feature will no lon

A huge trove of leaked Black Basta chat logs expose the ransomware gang's key members and victims

A trove of chat logs allegedly belonging to the Black Basta ransomware group has leaked online, exposing key members of the prolific Russia-linked gang.  The chat logs, which include over 200,000 messages spanning from September 18, 2023, to September 28, 2024, were shared with threat intelli

Stalkerware apps Cocospy and Spyic are exposing phone data of millions of people

A security vulnerability in a pair of phone-monitoring apps is exposing the personal data of millions of people who have the apps unwittingly installed on their devices, according to a security researcher who found the flaw.  The bug allows anyone to access the personal data — messages, pho

California privacy regulator seeks to fine Florida data broker after huge breach of Social Security numbers

California’s privacy regulator is asking a court to fine a data broker that lost hundreds of millions of Social Security numbers in one of last year’s biggest data breaches. The California Privacy Protection Agency (CPPA), which enforces California’s state rules on data protectio

UK healthcare giant HCRG confirms hack after ransomware gang claims theft of sensitive data

U.K. healthcare giant HCRG Care Group has confirmed it's investigating a cybersecurity incident after a ransomware gang claimed to have breached the company’s systems to steal troves of sensitive data.  HCRG Care Group is one of the largest independent providers of community health

US Army soldier pleads guilty to AT&T and Verizon hacks

Cameron John Wagenius pleaded guilty to hacking AT&T and Verizon and stealing a massive trove of phone records from the companies, according to court records filed on Wednesday. Wagenius, who was a U.S. Army soldier, pleaded guilty to two counts of “unlawful transfer of confidential phone re