Skip to main content
All Stories Tagged:

Security

Cybersecurity is the rickety scaffolding supporting everything you do online. For every new feature or app, there are a thousand different ways it can break – and a hundred of those can be exploited by criminals for data breaches, identity theft, or outright cyber heists. Staying ahead of those exploits is a full-time job, and one of the most lucrative and sought-after skills in the tech industry. All too often, it’s something up-and-coming companies decide to skip out on, only to pay the price later on.

A
The car dealership cyberattack is so bad that Auto News gave it its own landing page.

“CDK GLOBAL CYBERATTACK” blares the headline on Automotive News’ landing page for all the site’s reporting on the ransomware attack, which is now in its seventh day. The cyberattack against the software provider to nearly 15,000 dealerships across North America has caused a massive outage that could ultimately affect vehicle sales. Naturally, AutoNews has been following the story closely — including this editorial calling for “creative defense strategies” against cyber criminals.


R
CDK Global is starting to recover from the cyberattacks causing outages at car dealerships.

Systems that support sales, service, and inventory for more than 15,000 dealerships have been shut off since June 19th in the wake of two separate cyberattacks.

After some dealers resorted to pen and paper to keep going amid reported negotiations between CDK and the BlackSuit ransomware group, Reuters reports restoration work has begun but that it may take “several days.”


S
Peak Design’s data breach is a lesson in taking things seriously.

The awesome bag company only told us about our data getting breached after Cybernews went public. Why? Peak initially assumed it was a vulnerability, not a breach, and never followed up with Cybernews after plugging the hole. Cybernews never sent Peak the ransom note, both entities confirm to The Verge.

“Simply put, we weren’t aware of the data compromise until [June 4th,]” Peak’s CEO tells me.


E
Olivia Rodrigo’s tour broke Ticketmaster — but bots may be to blame.

A report from 404 Media highlights a new type of bot that gets around Ticketmaster’s queuing system by opening dozens of different browsing sessions on one computer, giving them multiple chances to snag tickets from fans. The mix of bots — and fans — likely contributed to Ticketmaster’s latest crash.


A
1Password is introducing recovery codes.

The password manager is finally making it easier for users who’ve forgotten their password, or lost their Secret Key, to regain access to their accounts.

Starting today, users can generate (and make sure to safely store) a recovery code that streamlines the process of recovering their 1Password account. However, the recovery codes will only work for those who still have access to the email address associated with their accounts.


M
The Stanford Internet Observatory is facing “funding challenges.”

In a statement published yesterday, Stanford University denied it was shuttering the prominent research center studying abuse and disinformation online. In recent months, key staff have departed and others have been told to look for new jobs.

The Internet Observatory is, however, looking for money: Stanford says “founding grants will soon be exhausted” as the center moves under new leadership.


S
London hospitals cancel over 800 operations in a single week after crippling ransomware attack.

The NHS has now revealed the scope of the damage following the June 3rd cyberattack. In addition to the operations, over 800 outpatient appointments were canceled, and 18 organ transplants were diverted.

“The cyber-attack has had a significant impact on our services, and this is likely to remain the case for some time yet,” say hospital execs.


C
A Peak Design “data compromise” leaked 10 years worth of customer service tickets.

In the grand scheme of things, there have been far worse security breaches than what Peak Design, the popular camera accessory brand, is currently dealing with.

But if you had any customer service interactions with the company between October 2013 and May 2023, well... everything contained in those tickets was accessed by an unknown third party before the issue was fixed. Not great.


A
Even iPhone thieves and scammers can have a tough day at work.

Journalist Veronica de Souza had her phone stolen and immediately replaced it, but the thieves very much wanted her to unlock her old iPhone as it was effectively useless without her password.

So they asked her to unlock. Repeatedly.


R
TikTok is aware of a ‘potential’ exploit being used to take over brand accounts.

According to Forbes, TikTok accounts for Paris Hilton and CNN have been hijacked recently by a “zero-day” attack in the app’s DMs that could be activated simply by opening the message.

TikTok spokesperson Alex Haurek sent us this statement:

Our security team is aware of a potential exploit targeting a number of brand and celebrity accounts. We have taken measures to stop this attack and prevent it from happening in the future. We’re working directly with affected account owners to restore access, if needed.


R
The Internet Archive is being DDoS’d.

A blog post says the attack has gone on intermittently for three days, making access to the archives inconsistent. However, founder Brewster Kahle says patrons should worry more about lawsuits from book publishers and the recording industry that “are trying to destroy this library entirely and hobble all libraries everywhere.”


J
Ready for GPT-5?

OpenAI says that training of its latest frontier model “has recently begun” — something that’s been rumored for a while — on the path to developing artificial general intelligence (AGI).

Altman and Co have also formed a new Safety and Security Committee to help guide critical decisions for OpenAI projects. This follows the resignation of a key OpenAI researcher over concerns that safety had taken ‘a backseat to shiny products.’


T
Christie’s auction house under ransom threat.

RansomHub is claiming responsibility for an attack earlier this month that forced Christie’s to take its website offline for over a week, according to the New York Times. Hackers are now threatening to release details on the auction house’s wealthy clients in the next few days if it doesn’t comply with demands. A sample has already been released.