Profile avatar
carlypage.bsky.social
senior cybersecurity reporter @techcrunch.com signal: carlypage.44 [email protected]
60 posts 3,094 followers 263 following
Prolific Poster

NEW: Apple said it "can no longer" offer iCloud end-to-end encryption in the UK, and turned off the option to enable it for new users in the country. The unprecedented move comes after the British government demanded a backdoor into Apple's cloud service. techcrunch.com/2025/02/21/a...

A trove of chat logs allegedly belonging to the prolific Black Basta ransomware group has leaked online, revealing unprecedented insights into the gang's operations The logs, seen by TechCrunch, also name several previously unknown targeted organizations techcrunch.com/2025/02/21/a...

NEW, by me: A bug in phone spyware apps Cocospy and Spyic are exposing the phone data of ~2.65 million people, according to a security researcher. The bug also exposes the email address of the people who signed up. Now those email addresses are in Have I Been Pwned. techcrunch.com/2025/02/20/s...

UK healthcare giant HCRG Care Group has confirmed it’s investigating an "IT security incident" after the Medusa ransomware gang claimed to have breached the company's systems to steal troves of sensitive data techcrunch.com/2025/02/20/u...

NEW: Former U.S. Army soldier Cameron John Wagenius pleads guilty to hacking Verizon and AT&T as part of the massive Snowflake-related data breaches. Wagenius faces up to $500,000 in fines and 20 years in prison, according to court records we reviewed. techcrunch.com/2025/02/19/u...

Australian IVF giant Genea has disclosed a cybersecurity incident that disrupted patient services and led to the access of potentially sensitive information techcrunch.com/2025/02/19/a...

Palo Alto Networks has warned that hackers are exploiting another vulnerability in its firewall software to break into unpatched customer networks techcrunch.com/2025/02/19/p...

The dozens of individuals who work under, or advise, Musk and the Department of Government Efficiency are a real-life illustration of Musk’s web-like reach in the tech industry. But who are the individuals in Musk’s inner circle and how did they get there? Find out here: tcrn.ch/4gKMJWA

US-based VC giant Insight Partners has confirmed that hackers breached its systems in January. The company said hackers had accessed “certain Insight information systems through a sophisticated social engineering attack”, but did not say whether any data was stolen techcrunch.com/2025/02/18/v...

New: Newspaper giant Lee Enterprises blames a ransomware attack for encrypting critical applications and systems used by dozens of media outlets across the United States. Several local U.S. outlets owned by Lee continue to report outages. More: techcrunch.com/2025/02/18/a...

NEW: Valve removed from Steam a videogame that contained malware. A strange case with a lot of open questions. Was this an accident? Did someone inject the malware into the game? Or hackers developed a game with the single purpose of infecting players? techcrunch.com/2025/02/13/v...

NEW: We caught another government spyware vendor, which made fake Android apps masquerading as WhatsApp and cellphone providers' apps. The spyware, called Spyrtacus, was made by SIO, which sells to Italian government and says that it partners with "Police and Intelligence Agencies."

British cybersecurity firm Sophos is laying off 6% of its workforce less than two weeks after completing its acquisition of Secureworks techcrunch.com/2025/02/13/s...

Barcelona-based spyware vendor Variston has reportedly gone into liquidation. This comes almost exactly a year after TechCrunch reported that Variston was in the process of shutting down after letting go of more than half-a-dozen employees techcrunch.com/2025/02/13/b...

The China-backed Salt Typhoon group is still hacking telecommunications providers, despite government sanctions. Recorded Future says Salt Typhoon breached five firms between December and January, including a US affiliate of a prominent UK provider and a US-based ISP techcrunch.com/2025/02/13/c...

NEW: Another Italian involved in rescuing immigrants in the Mediterranean says he was targeted in the Paragon spyware campaign that WhatsApp revealed recently. There are now four people who have come forward pas alleged targets of this hacking campaign. techcrunch.com/2025/02/11/a...

Amid uncertainty about the future of the cybersecurity agency, CISA has reportedly placed several members of its election security team on administrative leave techcrunch.com/2025/02/11/c...

A global law enforcement operation has led to the arrest of four individuals who authorities accuse of being key figures in the 8base ransomware operation. The four suspects are accused of amassing $16 million through attacks against more than 1,000 organizations techcrunch.com/2025/02/11/a...

NEW: Apple released a fix for a zero-day bug for iOS that “may have been exploited in an extremely sophisticated attack against specific targeted individuals.” AFAIK this is the first time Apple uses "extremely sophisticated attack" in an official release. techcrunch.com/2025/02/10/a...

A group of international law enforcement agencies have seized the dark web leak site of the 8base ransomware gang. The NCA confirmed the legitimacy of the takedown message to TechCrunch and said the UK played a “supportive role” in the operation techcrunch.com/2025/02/10/g...

The UK government's secret demands for backdoor access to encrypted iCloud accounts is a "global emergency", critics have warned techcrunch.com/2025/02/10/u...

New, by me: Media giant Lee Enterprises says it was hit by a cyberattack last week, per an email seen by TechCrunch. Lee confirmed it was working to restore its systems. Lee publishes dozens of newspapers across the U.S., many of which are reporting disruption. techcrunch.com/2025/02/10/m...

New, by me: Hewlett Packard Enterprise (HPE) has begun notifying data breach victims after it was hacked by Russian government-backed hackers in 2023. techcrunch.com/2025/02/07/h...

New: A coalition of more than a dozen U.S. states say they plan to file a lawsuit after Elon Musk’s DOGE gained access to the federal government's banks of Americans’ personal data. The states haven't yet filed the lawsuit... and Musk still has broad access to data. techcrunch.com/2025/02/07/c...

Government officials in the UK have reportedly ordered Apple to build a backdoor that would give it access to users’ encrypted iCloud data. Apple will likely stop offering its encrypted cloud storage service, Advanced Data Protection, to users in the country techcrunch.com/2025/02/07/u...

The PowerSchool data breach saw hackers access the sensitive data of 16,000 students in the UK. In a letter sent to those affected, seen by TechCrunch, the company said this data includes contact details, medical data and other unspecified “related information” techcrunch.com/2025/02/07/p...

NEW: Paragon has reportedly cut ties with Italy and disconnected two local customers from the company's surveillance systems. The decision comes after allegations that Italian government may have abused the system to spy on a journalist and an activist.

British engineering giant IMI has disclosed a cybersecurity incident just days after rival firm Smiths said it was targeted by hackers techcrunch.com/2025/02/06/i...

Ransomware payments fell by more than one-third in 2024 as an increasing number of victims refused to negotiate with hackers

NEW: There's now a third person who has come forward saying they were targeted on WhatsApp with spyware made by Paragon. And just like the two others, he has been critical of the current Italian government, led by far-right Prime Minister Giorgia Meloni. techcrunch.com/2025/02/05/n...

Zyxel has no plans to release patches for two zero-days under attack and is advising customers to replace vulnerable routers. The company says these devices have been “EOL for years” - but the devices are not on Zyxel’s EOL page, and some are still available to buy techcrunch.com/2025/02/05/r...

New, by @carlypage.bsky.social: Grubhub says it was hacked and that customer and driver data was stolen in a data breach. Grubhub has tens of millions of customers. techcrunch.com/2025/02/04/g...

US food delivery giant Grubhub has confirmed a data breach after hackers accessed the personal details of customers and drivers techcrunch.com/2025/02/04/g...

Tata Technologies says ransomware attack hit IT assets, investigation ongoing

NEW: WhatsApp says it has notified 90 victims, including journalists and members of civil society, that they were targeted with spyware made by Paragon. This is the first time that Paragon is linked to alleged abuse of its products. techcrunch.com/2025/01/31/w...

Community Health Center, a Connecticut-based nonprofit healthcare provider, said hackers accessed the sensitive health information of more than a million patients during a recent cyberattack techcrunch.com/2025/01/31/u...

NEW: The U.S. Department of Justice says that the hacking forum Cracked, which was seized and shut down, affected 17 million of Americans. One victims is a woman who was allegedly “cyberstalked,” “sextorted,” and harassed, according to the DOJ. techcrunch.com/2025/01/30/u...

NEW: An international coalition of law enforcement agencies announced it has seized and taken down two prominent hacking forums with more than 10 million users. German police called them “the world’s two largest trading platforms for cybercrime.” techcrunch.com/2025/01/30/i...

Chinese AI company DeepSeek exposed an internal back-end database to the internet without a password. The database contained chat histories and API keys. techcrunch.com/2025/01/30/d...

New York Blood Center (NYBC), one of the largest nonprofit blood centers in the United States, says it is experiencing service disruptions after being hit by a ransomware attack techcrunch.com/2025/01/30/u...

UK engineering giant Smiths Group has disclosed a cybersecurity incident that involved “unauthorized access” to its systems techcrunch.com/2025/01/29/e...

NEW: Apple's new iOS 18.3 fixes a zero-day bug that “may have been actively exploited” — meaning hackers were using it to compromise devices. Not details on who was behind it, or who they were targeting. It's the first iPhone in the wild bug of 2025. techcrunch.com/2025/01/28/a...

PowerSchool has begun notifying individuals affected by a December 2024 data breach. The US edtech giant says it “cannot confirm” how many people had data stolen, but millions of students are known to be affected techcrunch.com/2025/01/28/p...

US government contractor ENGlobal says hackers accessed “sensitive personal information” from its systems during a November cyberattack techcrunch.com/2025/01/28/e...

New: SonicWall says hackers are exploiting a new zero-day bug in one of its products to breach corporate networks. This is the latest in a long list of bugs in security products that allow the hacking of big networks, which these devices are tasked with protecting. techcrunch.com/2025/01/27/s...

With iOS 18.3, Apple is switching Apple Intelligence on by default (for newer devices). Given how faulty it is, and maybe for other concerns (environment, ethical), you may want to switch it off. Here's how to do it: techcrunch.com/2025/01/27/h...

How the ransomware attack at Change Healthcare went down: A timeline

TalkTalk has confirmed it’s investigating a data breach after a hacker claimed to have stolen the personal data of millions of subscribers. However, the telecoms giant says the number of customers allegedly impacted is “very significantly overstated" techcrunch.com/2025/01/27/t...

BREAKING: UnitedHealth has confirmed the ransomware attack and data breach on its Change Healthcare subsidiary in February 2024 now affects around 190 million people — almost double the previous estimate. techcrunch.com/2025/01/24/u...