Experts say the detection delay of 17 months is a colossal security blunder by the retailer.
Threatpost
Security
MFA Glitch Leads to 6K+ Coinbase Customers Getting Robbed
Coinbase suspects phishing led to attackers getting personal details needed to access wallets but also blamed a flaw in its SMS-based 2FA.
Threatpost
IOTW: Giant Pay’s devastating ransomware attack affects lorry drivers and more
Attack on Giant Group’s network becomes the latest in a spate of cloning and ransomware incidents with umbrella and payroll companies in recent months
Military’s RFID Tracking of Guns May Endanger Troops
RFID gun tags leave the military exposed to tracking, sniffing and spoofing attacks, experts say.
Threatpost
Google Emergency Update Fixes Two Chrome Zero Days
This is the second pair of zero days that Google’s fixed this month, all four of which have been actively exploited in the wild.
Threatpost
Apple AirTag Zero-Day Weaponizes Trackers
Apple’s personal item-tracker devices can be used to deliver malware, slurp credentials, steal tokens and more thanks to XSS.
Threatpost
Keep Attackers Out of VPNs: Feds Offer Guidance
The NSA and CISA issued recommendations on choosing and hardening VPNs to prevent nation-state APTs from weaponizing flaws & CVEs to break into protected networks.
Gamers Beware: Malware Hunts Steam, Epic and EA Origin Accounts
The BloodyStealer trojan helps cyberattackers go after in-game goods and credits.
Threatpost
How to Prevent Account Takeovers in 2021
Dave Stewart, Approov CEO, lays out six best practices for orgs to avoid costly account takeovers.
Threatpost
Women, Minorities Are Hacked More Than Others
Income level, education and being part of a disadvantaged population all contribute to cybercrime outcomes, a survey suggests.
Threatpost

