Forever 21 data breach affects half a million people | TechCrunch

image via techcrunch.com
image via techcrunch.com

A data breach notice filed with Maine’s attorney general said the fashion giant was hacked over a three-month period beginning early January 2023, during which intruders obtained files from its systems. This data included the personal information of current and former employees, said Lorena Terroba Urruchua, a spokesperson for Forever 21 via public relations firm FTI Consulting, in an email to TechCrunch.

https://techcrunch.com/2023/08/31/forever-21-data-breach-half-million/

A popular Android app began secretly spying on its users months after it was listed on Google Play

image via techcrunch.com
image via techcrunch.com

Research by ESET found that the Android app, “iRecorder — Screen Recorder,” introduced the malicious code as an app update almost a year after it was first listed on Google Play. The code, according to ESET, allowed the app to stealthily upload a minute of ambient audio from the device’s microphone every 15 minutes, as well as exfiltrate documents, web pages and media files from the user’s phone.

https://techcrunch.com/2023/05/29/popular-android-app-microphone-spying-google-play/

TikTok’s Answer to Security Concerns? Grant Oracle Full Source Code Access

image via pcmag.com
image via pcmag.com

According to TikTok, "many of the major components of Project Texas are already operational, and we will continue bringing more parts of the initiative online in the coming weeks and months." This comes amid continued scrutiny of the service by the US government, and an impending ban of the service in Montana (TikTok has sued to stop the latter).

https://www.pcmag.com/news/tiktoks-answer-to-security-concerns-grant-oracle-full-source-code-access

WordPress plugin flaw puts ‘millions of websites’ at risk

image via theregister.com
image via theregister.com

WordPress users with the Advanced Custom Fields plugin on their website should upgrade after the discovery of a vulnerability in the code that could open up sites and their visitors to cross-site scripting (XSS) attacks. Essentially, it allows someone to run JavaScript within another person's view of a page, allowing the attacker to do things like steal information from the page, perform actions as the user, and so on. That's a big problem if the visitor is a logged-in administrative user, as their account could be hijacked to take over the website.

https://www.theregister.com/2023/05/08/wordpress_plugin_vulnerability/?td=rt-3a

Twitter alternative Hive shuts down its app to fix critical security issues

Image Credits: Hive

The team at the newly popular Twitter alternative Hive is in over its head. The company has now taken the fairly radical step of fully shutting down its servers for a couple of days in response to concerns raised by security researchers who discovered a number of critical vulnerabilities on Hive, several of which they say remain unfixed. The issues they found would allow attackers access to all data, including private posts and messages, shared media and even deleted direct messages, as well as the ability to edit other people’s Hive posts.

https://techcrunch.com/2022/12/01/twitter-alternative-hive-shuts-down-its-app-to-fix-critical-security-issues/

Overwatch 2 will no longer require legacy players to verify their phone number

Blizzard

“Blizzard originally made SMS Protect, which requires players to link a phone number to their Battle.net accounts, a requirement to access Overwatch as a way to make it harder for people to cheat or to troll others. It doesn’t always work with numbers associated with prepaid plans, though, and therein lies the problem. While some Mint customers were able able to link their numbers to SMS Protect just fine, players on Cricket seem to be completely locked out of the game. As Kotaku reports, fans feel like they’re being punished or shamed for ‘being poor.'”

https://www.engadget.com/overwatch-2-no-longer-requires-legacy-players-verify-phone-number-114017280.html

Rockstar Games confirms GTA 6 footage leak

Rockstar Games has confirmed that it recently “suffered a network intrusion” that resulted in the massive leak of 90 videos of early development versions of Grand Theft Auto 6. The company said in an official statement on Monday morning that the intrusion resulted in “an unauthorized third party illegally” accessing and downloading “confidential information from our systems,” though it adds that they don’t anticipate this will have any effect on its ongoing live game services or development timeline.

https://techcrunch.com/2022/09/19/rockstar-games-confirms-gta-6-footage-leak/