Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing
Grindr, which is the largest LGBTQ+ dating app, was sued in April 2024, accusing it of violating U.K. privacy laws by sharing sensitive data for commercial purposes such as advertising.
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
“Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium’s own Secure Preferences
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
The activity, which mainly singles out directors, vice presidents, and other executive staff
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management
Mathspace discloses data breach affecting over 1 million people
Trezor data breach impact now reaches 81,000 customers
Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits
The proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges.
The post Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits appeared first on SecurityWeek.
