Cybersecurity News
Filters
Filtered by tag: computing security × Clear
Why is the Premier League now subject to new cybersecurity rules, and what punishments could they face? The experts weigh in
The Premier League must now comply with the UK's Network and Information Systems (NIS) regulations, which have been expanded to cover major sports organisations due to their large audiences and significant revenue. Clubs face fines of up to £17 million for failing to meet required cybersecurity standards. Experts say teams must improve incident response planning, staff training, and protection of operational systems to comply.
Experts warn 2,000 hacked WordPress sites were secretly running a global crime ring
Around 2,000 hacked WordPress sites were used as infrastructure for a global cybercrime operation. The compromised sites served multiple roles: delivering malware to victims, acting as command-and-control servers for infected devices, and storing stolen data. Security experts warn the scheme exploited the sites' legitimacy to avoid detection, highlighting risks for website owners who neglect security updates.
Experts warn expired credit cards can be brought back from the dead to make contactless payments
Researchers have found that expired credit cards can still be used for contactless payments, with one successfully used to buy $100 worth of groceries. The vulnerability exists because some payment terminals fail to properly verify expiration dates. Experts warn consumers to properly destroy old cards and urge banks and retailers to strengthen their verification processes.
Even dead websites aren't safe — experts warn hackers are spending millions on expired domains to enable malware scams
Cybercriminals are buying expired domains at scale — around 65,000 change hands daily — to exploit the inherited trust and search rankings of formerly legitimate sites. One criminal group is estimated to have spent $7 million acquiring these domains to distribute malware and run scams, raising concerns about how domain expiration creates persistent security vulnerabilities.
Scammers pose as ransomware recovery agents, but just go on to steal more from victims
Cybercriminals are posing as ransomware recovery specialists to defraud victims twice. Groups like "Ransom Busters" pose as legitimate recovery firms, approach ransomware victims, and pocket fees without delivering results. In reality, they are ransomware affiliates exploiting desperate victims. Experts warn organizations to thoroughly vet any recovery service before paying, as the fake recovery industry is growing alongside ransomware itself.
Experts manage to hack Microsoft Copilot by continually asking it questions about itself
Researchers discovered they could manipulate Microsoft Copilot by persistently questioning it about its own nature and system instructions. Through repeated probing, the AI revealed internal configurations it was meant to keep hidden. The findings highlight concerns that AI assistants can be socially engineered into bypassing safeguards, raising questions about whether current security measures are sufficient for enterprise deployment.
Microsoft smothers malware by tracking behavior instead of blocking domains
Microsoft has shifted its malware defense strategy from blocking malicious domains to tracking behavioral patterns. Because attackers can rapidly automate new domains to replace blocked ones, domain-blocking proves ineffective. By monitoring how malware behaves rather than where it connects, Microsoft aims to identify and neutralize threats more reliably, staying ahead of attackers who exploit the limitations of domain-based defenses.
Ransomware gang crashes own attack — with no-one to blame but themselves
Ransomware group Akira accidentally sabotaged its own attack after using a driver exploit to disable endpoint detection software — the same technique also killed their encryption tool. Researchers noted the self-inflicted failure but warned the tactic of using vulnerable drivers to bypass security is increasingly common and remains a serious threat even when, as here, it backfires on the attackers.
Is the new Water Cyber Shield Act too little, too late, and can a cyber group do it better? The experts weigh in
Proposed US legislation called the Water Cyber Shield Act would establish voluntary cybersecurity baseline standards for water utilities, with federal support and information sharing. Experts are divided: some say it's a meaningful step given the sector's fragmented, under-resourced nature, while others argue voluntary measures are insufficient given the severity of recent attacks by foreign actors on water infrastructure.
Scammers hijack real Shopify notifications to swindle victims — here's how to stay safe
Cybercriminals are exploiting Shopify's legitimate notification system to send fraudulent messages that appear authentic. By creating fake stores, scammers trigger real Shopify emails to potential victims, making them harder to detect. Experts recommend verifying unexpected order confirmations directly through official websites, avoiding links in unsolicited emails, and enabling two-factor authentication to protect accounts.
