Apple Blocked $2.2bn in App Store Fraud in the Last Year
Total figure for fraudulent transactions Apple has blocked since 2020 now stands at over $11bn
20 articles
Total figure for fraudulent transactions Apple has blocked since 2020 now stands at over $11bn
First VPN, a service used by ransomware actors and fraudsters, was dismantled by Europol
A threat actor compromised an Nx developer and posed as a legitimate maintainer to publish a malicious extension on Visual Studio Marketplace
AI risks threaten to permeate supply chains through unvetted code and unaudited suppliers
Qualys finds nine-year-old Linux ptrace flaw exposing SSH keys and password hashes locally
Grafana Labs has confirmed a recent data breach was caused by the TanStack supply chain attack
Premium Deception campaign uses 250 Android apps to silently sign victims up to paid services
Mini Shai-Hulud worm hits Alibaba AntV ecosystem in largest npm supply chain wave to date
China-linked Webworm APT expands beyond Asia, targeting European government organizations and refining its cyber espionage tactics, according to ESET research
The prolific threat group TeamPCP has claimed a hack into GitHub’s internal repositories
Barracuda reveals new CypherLoc scareware has featured in nearly three million attacks
Verizon DBIR finds 31% of data breaches began with software flaws last year
Microsoft’s Digital Crimes Unit has taken down the infrastructure of Fox Tempest, a prolific cybercrime-enabling threat group
AI-powered vulnerability scanning leaves no excuse for unpatched bugs as the EU Cyber Resilience Act pushes firms toward secure-by-design software
Digital.
Open source tool maker Grafana says hackers stole codebase via GitHub breach
Bridewell report calls out emergence of “fix-style” attacks
2.5 million people were affected, in a breach that could spell more trouble down the line.
Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.