Amazon agreed to pay $25 million to settle allegations it violated children's privacy rights when it failed to delete Alexa recordings at the request of parents News 

Amazon Pays $30 Million for Alexa & Doorbell Camera Privacy Breach

Amazon.com and one of its subsidiaries reached separate multimillion-dollar settlements with the U.S. Federal Trade Commission on Wednesday over violations of children’s privacy using its Alexa voice assistant and its Ring camera in a doorbell. Amazon has agreed to pay $25 million to settle allegations that it violated children’s privacy by failing to delete Alexa recordings at parents’ request and keeping them longer than necessary, according to a filing in federal court in Seattle. “While we disagree with the FTC’s allegations against both Alexa and Ring and deny any violation…

Read More
The attack on MCNA is the largest health breach this year. News 

Ransomware attack exposes sensitive information of nearly 9 million dental patients

A recently disclosed ransomware attack compromised some particularly sensitive medical data. Dental insurer Managed Care of North America (MCNA) said the intruder accessed patients and took copies of patient information between February 26 and March 7, including addresses, social security numbers, driver’s licenses and insurance information. MCNA says some of the information is for parents, guardians and guarantors (people who pay bills on behalf of others). A filing provided by the Maine Attorney General indicates that more than 8.9 million people have been affected. The company has not identified the…

Read More
Indian researchers have come across a new malware called DogeRAT (Remote Access Trojan)—which is targeting users through the distribution of fake Android apps masquerading as legitimate apps. Here's what we know. News 

A new malware called DogeRAT is spreading through fake Android apps

A new malware called DogeRAT (Remote Access Trojan) targets users by distributing fake Android apps. The apps containing the malware are said to be sent to users via Telegram and other social media apps. Discovered by CloudSEK’s TRIAD team, DogeRAT is an open-source Android malware that can steal important information such as bank passwords and government credentials, leaving victims vulnerable. It targets users in a variety of industries, including banking, e-commerce, and entertainment. DogeRAT is a malware that disguises itself as popular apps, and once it infects a victim’s device…

Read More
Authorities said the virus is also capable of "bypassing anti-virus programs and deploying ransomware on the targeted devices" News 

“Daam” virus steals call logs and reads history from Android phones

The National Cyber Security Agency said in its latest alert that an Android malware called “booster” infects mobile phones and compromises sensitive data such as call logs, contacts, history and camera. India’s Computer Emergency Response Team, or CERT-In, said the virus is also capable of “bypassing antivirus software and spreading ransomware on target devices.” The agency is the federal technology division that combats cyberattacks and protects cyberspace from phishing, hacking, and similar cyberattacks. The agency said botnets are distributed through third-party websites or apps downloaded from untrusted/unknown sources. Once installed…

Read More
Play Store continues to harbour malicious apps that Google is finding to trace and remove before it causes damage. News 

Screen Recorder App recorded thousands of users without consent

Android apps have a notorious track record of circumventing privacy, either by acting maliciously or by using your phone to steal data or track it. Now, a new kind of problem has emerged in Android apps, where one of the apps available through the Play Store started recording users without their permission to use the microphone. That’s not all, the app even sent the data via an encrypted link to the app developer’s server. According to a report by Ars Technica, an app called iRecorder Screen Recorder was the guilty…

Read More
The tech giant uncovered stealthy and targeted malicious activity focused on post-compromise credential access and network system discovery aimed at critical infrastructure organisations in the US. News 

China-sponsored hackers targeting critical US infrastructure: Microsoft

Microsoft has revealed that a state-sponsored Chinese hacker group called Volt Typhoon, which typically focuses on espionage and data collection, has targeted US critical infrastructure. The tech giant revealed a stealthy and targeted malicious activity focused on post-breach access and network discovery targeting critical infrastructure organizations in the United States. “The strike was carried out by Volt Typhoon, a state-sponsored actor in China. This campaign aims to develop capabilities that can disrupt critical communications infrastructure between the US and Asia during future crises,” the company said in a blog post…

Read More
Phone Link has been around for a long time, and it allows users to connect their Android phone to their PC via a Wi-Fi connection. News 

Cyberstalkers Using Windows 11 Phone Link Feature to Monitor iPhone

Microsoft’s recently released Phone Link feature for Windows 11 users, which allows iPhone owners to view notifications on their Windows PCs, could pose a significant security risk. According to app developer Certo Software, the inclusion of the new Windows 11 feature raises concerns about potential security vulnerabilities that cyberstalkers can exploit against iPhone users. Phone Link has been around for a long time, and it allows users to connect an Android phone to a computer over Wi-Fi. Last month, Microsoft released the Phone Link feature for iOS to all Windows…

Read More
Apple has joined the growing list of conglomerates that have asked their employees to stop using generative AI-based chatbots—including OpenAI's ChatGPT. News 

Apple bans employees from using ChatGPT over data leak

After Samsung, Apple has joined a growing number of groups asking their employees to stop using creative AI-powered chatbots — including OpenAI’s ChatGPT — to prevent the leak of confidential information about internal company matters. According to a report by The Wall Street Journal, Apple has stated that generative artificial intelligence cannot be used for work purposes. They’ve even banned other AI-based platforms like Github Copilot, which happens to be owned by Microsoft, which allows users to automate writing code. By default, ChatGPT records user conversations, which are later used…

Read More
Last month, Microsoft told customers of its advertising platform that it would remove Twitter from the platform News 

Twitter accuses Microsoft of misusing its data: Report

Twitter sent Microsoft CEO Satya Nadella a letter accusing the tech giant of misusing the social media company’s data, the New York Times (NYT) reported Thursday. Twitter has accused Microsoft of violating the data agreement and refusing to pay for its use, according to a letter reviewed by NYT. The letter alleges that Microsoft exceeded its authorized use of Twitter data in certain cases and shared it with government agencies without permission. Twitter on Thursday sent a letter to Microsoft’s chief executive, accusing the tech giant of improperly using the…

Read More
If you have an internet router that is not up to date or obsolete, you may want to be careful—as a new report claims that Chinese hackers are targeting them to install backdoor malware to compromise networks. News 

Chinese Hackers Exploiting Internet Routers and Installing Malware to Compromise Networks: Report

If you have an internet router that is out of date or out of date, you should be careful, as a new report claims that Chinese hackers are targeting them to install backdoor malware to compromise networks. As reported by Check Point Research, a hacker group called Camaro Dragon is planting malware on TP-Link routers, including a backdoor called “Horse Shell.” This backdoor agent can give hackers full control over the infected device. it remains undetected and continues to access compromised networks. The attacks are said to be targeting European…

Read More
The breach hit systems for processing TRANServe transit benefits that reimburse government employees for some commuting costs News 

The US Department of Transportation suffered a major data breach, 237,000 employee records compromised

The personal information of 237,000 current and former federal employees was exposed in a data breach at the U.S. Department of Transportation (USDOT), sources briefed on the matter said Friday. Violation systems for processing TRANServe’s transit benefits, which compensate state employees for part of their commuting expenses. It was not clear whether the personal data was used for criminal purposes. USDOT said in a statement to Reuters that the breach did not affect the transportation security systems. It did not say who might be responsible for the hack. The department…

Read More
With security keys, even if someone has your Apple ID and password, they still cannot access your account without your physical security key. News 

Protecting your Apple ID with security keys: A step-by-step guide

US tech giant Apple recently released a new security feature to help users protect their Apple ID account. The company introduced Security Keys, a physical device that can authenticate your Apple ID instead of a password. This new feature is considered the most secure way to protect your Apple ID. With the release of iOS 16.3, iPadOS 16.3, and macOS Ventura 13.2, Apple introduced support for security keys or physical devices that can verify your Apple ID instead of a password. To enable this feature, users need to configure it…

Read More
WhatsApp offers a host of features which needs access to your phone's mic, camera and storage. But that has raised concerns. News 

WhatsApp didn’t spy: Google confirms Android bug caused privacy breach

Earlier this week, WhatsApp was accused of using the phone’s microphone without the user’s permission. Many people criticized the messaging app, Elon Musk said that WhatsApp is not safe and some of you even wanted to take action against WhatsApp for this privacy breach. Meta, the company that owns WhatsApp, claimed in its defense that a bug in Android caused this problem, implying that the messaging app was not to blame for this behavior. Turns out they were right after all. Google has confirmed that there is a bug in…

Read More
Western Digital Corp said on Friday it had restored My Cloud services and expects customer access to its online store to be normalized in the week of May 15, more than a month after the data storage chip maker disclosed a security breach. News 

Western Digital Brings Services Back Online Soon After Breach: All the Details

Western Digital Corp said Friday it has restored My Cloud services and expects customer access to its online store to return to normal in the week of May 15, more than a month after the storage chip maker disclosed a security breach. Western Digital said it was moving forward with the restoration process and most systems and services were operational. An “unauthorized party” obtained customers’ names, phone numbers and partial credit card numbers from their systems, Western Digital said in a statement. The company said it is communicating directly with…

Read More
India witnessed an 18 per cent increase in weekly cyber attacks during the first quarter (Q1) of 2023, with each organisation facing an average of 2,108 attacks per week, News 

India Sees 18% Increase in Weekly Cyber Attacks in Q1 2023: Report

In India, the number of weekly cyber attacks increased by 18 percent in the first quarter of 2023, with each organization facing an average of 2,108 attacks per week, a new report released on Friday showed. According to Check Point Research (CPR), global weekly cyber attacks increased 7 percent in the first quarter of 2023 compared to the same quarter last year, with each organization experiencing an average of 1,248 attacks per week. Globally, in the first quarter of 2023, the education/research sector suffered the most attacks, with an average…

Read More
WhatsApp has slowly become a hub for spam calls and messages but a new issue raises further alarm. News 

Beware! There is a new WhatsApp calling scam that demands your attention

WhatsApp has become a hub for spam and marketing messages, which is the exact reason why millions of people switched to the messaging app from traditional text messages. But the sophistication of WhatsApp scams is evolving. Now you don’t have to worry about nagging advertising messages from brands (who are not allowed to message you on WhatsApp), there have been regular cases of people receiving WhatsApp calls (both voice and video calls) from random international calls. numbers which, according to the given ISD codes, originate from Malaysia, Kenya and Vietnam.…

Read More
The call forwarding scam has been in existence for a while now—with fraudsters finding new and unique ways to trick their victims. Here's how you can be safe. News 

How to protect yourself from call forwarding scams: tips and more

In the online world, with the proliferation of mobile phones in countries including India, the call forwarding scam has been around for quite some time – scammers have found new and unique ways to trick their victims. There are a few ways you can prevent falling victim to these scams. But before we learn the ways, let’s understand how the call forwarding scam works. According to Truecaller, scammers can call you pretending to be your mobile operator or Internet Service Provider (ISP) – claiming that your account has been compromised…

Read More
Meta would also be subject to other limitations, including with its use of face-recognition technology News 

Facebook has misled parents, failed to protect children’s privacy: US regulators

U.S. regulators say Facebook has misled parents and failed to protect the privacy of children using its Messenger Kids app, including by misrepresenting app developers’ access to private user data. As a result, the Federal Trade Commission on Wednesday proposed sweeping changes to Facebook’s 2020 Privacy Rule (now Meta) that would prohibit it from profiting from data it collects on users under 18. This would include data collected through its virtual reality. Products. The FTC said the company has not fully complied with the 2020 order. Meta would also be…

Read More
Passkeys offer a safer alternative to passwords and texted confirmation codes. Users won’t ever see them directly News 

Google is making strides in online security with cross-passwords for more secure logins

Good news for all password haters: Google has taken a big step to make them an afterthought by adding “passwords” as a simpler and more secure way to log into its services. Here’s what you need to know: WHAT ARE PASSION KEYS? Passwords provide a more secure alternative to passwords and SMS verification codes. Users never see them directly; instead, a web service like Gmail uses them to communicate directly with a trusted device like a phone or computer to sign in. All you need to do is verify your…

Read More
The researchers have recently discovered a Telegram channel advertising this new information-stealing malware. News 

Hackers are selling new malware on Telegram that targets MacOS users

Threat actors are selling a new malware called Atomic macOS Stealer (AMOS) for macOS platforms on the Telegram channel, which is capable of extracting autofill information, passwords, wallets and more. According to Cyble Research and Intelligence Labs (CRIL), the Atomic macOS Stealer malware is specifically designed to target macOS and can steal sensitive data from a victim’s machine. Researchers have recently discovered a Telegram channel promoting this new data-stealing malware. Also, according to the report, the hacker behind this thief is constantly improving this malware and adding new features to…

Read More