U.S. and key allies accuse China of Microsoft Exchange cyberattacks - Axios

https://www.axios.com/china-cyberattacks-nato-181e71d2-7414-45f3-9463-c8b1d46392c1.html

The U.S., NATO, European Union, U.K., Australia, Canada, New Zealand and Japan say they can now, “with high confidence,” attribute the March attack using the Exchange flaw to cyberattackers affiliated with China’s state security ministry. That attack crippled thousands of computers around the world.

TikTok insiders say Chinese parent ByteDance is in control

https://www.cnbc.com/2021/06/25/tiktok-insiders-say-chinese-parent-bytedance-in-control.html

Former TikTok employees say there is cause for concern when it comes to the popular social media app’s Chinese parent company.

They say ByteDance has access to TikTok’s American user data and is closely involved in the Los Angeles company’s decision-making and product development. 

Some cybersecurity experts worry that the Chinese government could use TikTok to spread propaganda or censorship to American audience, or to exercise influence over users who may come to regret what they posted on the service.

Trust in Software, an All Time Low - Underjord

https://underjord.io/trust-in-software-an-all-time-low.html

I don’t think I’ve ever had more distrust and as a consequence distate for software than in recent years

So while the big actors are slightly less likely to completely screw you on security, software quality or straight money. They are pretty much guaranteed to screw you on privacy.

Your privacy is very important to us. We would like to know what you are doing at all times. Accept / Ask me again later.

Stort dataangrep mot norsk ingeniørselskap – NRK Norge – Oversikt over nyheter fra ulike deler av landet

https://www.nrk.no/norge/stort-dataangrep-mot-norsk-ingeniorselskap-1.15568171

Hackargruppa hevdar dei har 2000 gigabyte med sensitiv informasjon som dei vil publisere viss selskapet ikkje innfrir kravet

A new ‘digital violence’ platform maps dozens of victims of NSO Group’s spyware - TechCrunch

https://techcrunch.com/2021/07/03/digital-violence-nso-group-spyware/

The research reveals new links between phone hacks and real-world violence

For the first time, researchers have mapped all the known targets, including journalists, activists, and human rights defenders, whose phones were hacked by Pegasus, a spyware developed by NSO Group

Sverige: Hackere krever 600 millioner kroner – NRK

https://www.nrk.no/urix/sverige_-hackere-krever-600-millioner-kroner-1.15564723

Angrepet har rammet hundrevis av selskaper over hele verden. Blant dem er svenske Coop, som har måttet stenge hundrevis av dagligvarebutikker, Apotek Hjärtat og SJ.

Kravet er blitt publisert på bloggen til hackergruppen Revil og virker ifølge eksperter autentisk.

Angrepet ble innledet fredag og var rettet mot det amerikanske programvareselskapet Kaseya, som selger tjenester til kunder over hele verden, deriblant Coop.

It-attack bakom Coops kassahaveri – stänger butikerna i hela Sverige - SVT

https://www.svt.se/nyheter/inrikes/coop-tvingas-stanga-efter-kassahaveri

French Spyware Executives Are Indicted for Aiding Torture - WIRED

https://www.wired.com/story/french-spyware-executives-indicted-aiding-torture/

The managers are accused of selling tech to Libya and Egypt that was used to identify activists, read private messages, and kidnap, torture, or kill them.

NFC Flaws Let Researchers Hack ATMs by Waving a Phone - WIRED

https://www.wired.com/story/atm-hack-nfc-bugs-point-of-sale/

FOR YEARS, SECURITY researchers and cybercriminals have hacked ATMs by using all possible avenues to their innards, from opening a front panel and sticking a thumb drive into a USB port to drilling a hole that exposes internal wiring. Now one researcher has found a collection of bugs that allow him to hack ATMs—along with a wide variety of point-of-sale terminals—in a new way: with a wave of his phone over a contactless credit card reader.

Rodriguez has built an Android app that allows his smartphone to mimic those credit card radio communications and exploit flaws in the NFC systems’ firmware.

North Korean hackers breach South Korean submarine builder (again) - The Record

https://therecord.media/north-korean-hackers-breach-south-korean-submarine-builder-again/

The target of the attack was Daewoo Shipbuilding & Marine Engineering (DSME), one of the country’s three primary shipbuilding companies—together with Hyundai and Samsung—and the only submarine builder.

Sources said that some of the stolen files included plans for a nuclear-powered submarine that DSME and the South Korean Navy had been working on for the past few years.