Close Menu
London Tribune
  • Home
  • Top Stories
  • Global Trends
  • Business
  • Politics
  • More
    • Sports
    • Lifestyle
    • Technology
    • Health
    • Fashion
    • Food & Recipes
    • Gaming
    • Music
    • Travel

Subscribe to Updates

Get the latest business and politics news about UK and the world directly to your inbox.

Trending

£12,570 state pensioner personal tax allowance increase update as key threshold hit

November 17, 2025

Developer made one wrong click and sent his AWS bill into the stratosphere

November 17, 2025

Black Friday Started Early at Made In — These Are the 10 Best Deals to Snag Before They Sell Out

November 17, 2025
Facebook X (Twitter) Instagram
  • About
  • DMCA
  • Privacy
  • Terms
  • Contact
Facebook X (Twitter) Instagram YouTube
Login
London Tribune
  • Home
  • Top Stories

    Bill Maher urges Democrats to accept moderate candidates after socialism surge in November election

    November 16, 2025

    James Carville tells Dems they should consider packing Supreme Court if they regain power

    November 16, 2025

    ‘The View’ co-host warns Zohran Mamdani may hit ‘roadblocks’ due to lack of experience

    November 15, 2025

    White House eviscerates Katie Couric for pressing Fetterman to rebuke Charlie Kirk, Trump

    November 15, 2025

    Jen Psaki says Karine Jean-Pierre’s book is ‘outdated’ in former press secretary clash

    November 14, 2025
  • Global Trends

    New survey reveals just how much Brits love classical music | UK | News

    May 23, 2024

    Remove yellow stains from mattress fast using cheap grooming product

    May 23, 2024

    Cleaning guru warns drain cleaning hack is damaging your home

    May 23, 2024

    Zeta Quantum Diamonds by Themis Ecosystem: Approved to Hit Sooner Than Predicted

    May 23, 2024

    ‘Best winter destination’ in Europe has ‘hearty food’ and public baths

    December 7, 2023
  • Business
  • Politics
  • More
    • Sports
    • Lifestyle
    • Technology
    • Health
    • Fashion
    • Food & Recipes
    • Gaming
    • Music
    • Travel
London Tribune
  • Top Stories
  • Global Trends
  • Business
  • Politics
  • Lifestyle
  • Sports
  • Technology
Home»Technology»Logitech leaks data after zero-day attack
Technology

Logitech leaks data after zero-day attack

LondonTribuneBy LondonTribuneNovember 16, 20255 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram WhatsApp Copy Link

INFOSEC IN BRIEF The US Senate passed a resolution in July to force the US Cybersecurity and Infrastructure Security Agency (CISA) to publish a 2022 report into poor security in the telecommunications industry but the agency has not delivered the document.

Senator Ron Wyden (D-OR), who has been pushing for the report’s release since it was written, last week sent yet another strongly-worded letter to the Department of Homeland Security (DHS), CISA’s parent agency, to point out that keeping the report secret is detrimental to the entire American cybersecurity community. Senator Mark Warner (D-VA) co-signed the letter.

“The continued suppression of a report identifying serious vulnerabilities of the U.S. telecommunications sector undermines the public’s understanding of these threats and stymies an important public debate on a path forward,” the pair wrote in their letter to DHS Secretary Kristi Noem. “We urge you to ensure the immediate public release … and to call for the FCC to establish mandatory minimum cybersecurity standards for the communications sector.”

The Senators noted that their chamber voted unanimously to require CISA to release the report but the agency “has inexplicably failed” to do so despite promising to do so shortly after the vote.

Wyden and Warner also reminded Noem of the Salt Typhoon hack of 2024 (which keeps looking worse) that targeted US telecom firms, plus the recent hackof a company that provides software and networking equipment, to illustrate the severity of the situation.

Whether CISA will finally spill the beans is anyone’s guess. They’ve already proven an act of Congress won’t force their hand, and the senators didn’t threaten them any further in the latest letter.

Logitech suffers zero day attack

Computer peripheral specialist Logitech last Friday published a regulatory filing [PDF] in which it admits to falling victim to a zero-day attack that led to exfiltration of data.

“Logitech believes that the unauthorized third party used a zero-day vulnerability in a third-party software platform and copied certain data from the internal IT system,” the filing reads. The company patched the zero-day vulnerability “following its release by the software platform vendor.”

The company isn’t sure what data it lost, but said it “likely included limited information about employees and consumers and data relating to customers and suppliers.”

“Logitech does not believe any sensitive personal information, such as national ID numbers or credit card information, was housed in the impacted IT system,” the filing states. – Simon Sharwood

Attacker stuffs npm with thousands of junk packages

If you thought those prior npm supply chain attacks were bad, you ain’t seen nothing like the latest discovery.

According to security researcher Paul McCarty at software supply chain security outfit SourceCodeRed, the npm worm he’s dubbed “IndonesianFoods” has published more than 78,000 malicious packages to the npm registry, nearly doubling the amount of known malicious packages in npm.

The attack appears to be a long-term, coordinated campaign, McCarty suggested. It’s not clear who’s behind the newly-discovered worm, but they appear to be thorough, using 55 npm user accounts created specifically to deploy the packages to the registry, which hide under the guise of legitimate Next.js applications.

Once installed, the malicious packages self-replicate, flooding npm registries with junk packages that can be used to further weaponize it to spread additional malware. McCarty advises everyone who relies on npm packages to give this list a look for any potential malicious content in their systems, and be very careful.

Lumma Stealer returns

It was nice while the FBI’s disruption of the Lumma Stealer network lasted, but it appears to be back.

Trend Micro reported an uptick in Lumma activity late last month, and said the stealer now uses different methods and has become harder to detect.

The new variant uses browser fingerprinting to collect system data, and masks its initial infection by hiding within Microsoft Edge Update installers and using process injection to work its way into Chrome browser processes.

“This technique allows the malware to execute within the context of a trusted browser process, effectively bypassing many security controls and appearing as legitimate browser traffic to network monitoring systems,” Trend Micro noted.

DoorDash breached again

Food delivery service DoorDash has leaked data, for the third time.

The outfit last week sent breach notice messages to customers, informing them someone got into the company’s systems and made off with user info including names, physical and email addresses, and phone numbers.

According to Bleeping Computer, a DoorDash employee falling victim to a social engineering scam was the cause of the incident. In 2022 the company fell victim to phishing. DoorDash blamed a 2019 leak of customer data on problems at a third-party service provider.

The delivery outfit’s breach notification letter says DoorDash can find no suggestion that attackers have used the purloined personal information to perpetrate fraud or identity theft. Nonetheless, the company is advising customers to be wary of unsolicited communications that include the stolen info and being extra careful if they receive email attachments from mysterious sources. ®

Source link

Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email

Related Posts

Developer made one wrong click and sent his AWS bill into the stratosphere

Jaguar Land Rover hack cost India’s Tata Motors around $2.4 billion and counting

Nvidia-backed photonics startup Ayar Labs eyes hyperscale customers with GUC design collab

GPU goliaths are devouring supercomputing – and legacy storage can’t feed the beast

FBI flags scam targeting Chinese speakers with bogus surgery bills

Project Kuiper becomes Amazon Leo as satellite network trickles into orbit

Demo
Our Picks

Developer made one wrong click and sent his AWS bill into the stratosphere

November 17, 2025

Black Friday Started Early at Made In — These Are the 10 Best Deals to Snag Before They Sell Out

November 17, 2025

Magic: The Gathering Avatar Collector Boosters Back In Stock At Amazon

November 17, 2025

EXCLUSIVE: Miu Miu Taps Amelia Gray for Upcoming Select Event in London

November 17, 2025
Don't Miss
finance

£12,570 state pensioner personal tax allowance increase update as key threshold hit

By LondonTribuneNovember 17, 20250

A campaign calling on the Government to provide pensioners with a special exemption from the…

Developer made one wrong click and sent his AWS bill into the stratosphere

November 17, 2025

Black Friday Started Early at Made In — These Are the 10 Best Deals to Snag Before They Sell Out

November 17, 2025

Magic: The Gathering Avatar Collector Boosters Back In Stock At Amazon

November 17, 2025
London Tribune
Facebook X (Twitter) Instagram Pinterest
  • About
  • DMCA
  • Privacy
  • Terms
  • Contact
© 2025 London Tribune. All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?
This website uses cookies. By continuing to use this website, you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.