Iran-nexus threat operation Handala has purportedly compromised the Dubai Courts Department, Dubai Land Department, and Dubai Roads and Transport Authority as part of a major cyberattack against the United Arab Emirates, which was claimed to have resulted in the destruction of 6 petabytes of data, as well as theft of 149 TB of sensitive information, according to Security Affairs.
A recent Politico European Pulsepoll revealed that 84% of surveyed Europeans do not trust American tech firms with their data, while 93% feel the same about Chinese companies.
The vulnerability, discovered by Nicholas Carlini, is a cryptographic validation flaw affecting multiple signature algorithms in wolfSSL, including ECDSA/ECC, DSA, ML-DSA, Ed25519, and Ed448.
The breach involved unauthorized access to booking information, potentially exposing full names, email addresses, postal addresses, phone numbers, and communications between users and property providers.
The breach, detected and stopped within minutes by Basic-Fit's system monitoring, allowed attackers to exfiltrate data including full names, physical addresses, email addresses, phone numbers, dates of birth, and bank account details.
Cybernews reports that a threat actor claiming to have breached the enterprise intelligence software provider Infodesk has put up the compromised data for sale on a dark web forum.
A sprawling advertising-based surveillance apparatus known as Webloc, capable of tracking the historical movements of up to half a billion mobile devices, has been linked to law enforcement and intelligence agencies across Hungary, El Salvador, and numerous U.S. jurisdictions, according to an investigation by the University of Toronto's Citizen Lab, according to The Hacker News.