FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayZDNet | security RSS

Congress asks Juniper for the results of its 2015 NSA backdoor investigation

Thirteen US government officials ask Juniper to publish the findings of its 2015 investigation.
  • June 10th 2020 at 22:45

Slovak police seize wiretapping devices connected to government network

Slovak police also arrest four people, including the head of the government agency responsible for managing the government network.
  • June 10th 2020 at 16:43

Jenkins team avoids security disaster after partial user database loss

Loophole caused by deleted user database could have allowed threat actors to hijack the user accounts of Jenkins plugin authors.
  • June 10th 2020 at 14:03

Arm CPUs impacted by rare side-channel attack

Arm issues guidance to developers to mitigate new "straight-line speculation" attack.
  • June 10th 2020 at 04:30

New CrossTalk attack impacts Intel's mobile, desktop, and server CPUs

Academics detail a new vulnerability named CrossTalk that can be used to leak data across Intel CPU cores.
  • June 9th 2020 at 19:27

Microsoft June 2020 Patch Tuesday fixes 129 vulnerabilities

This month's updates have started rolling out earlier today.
  • June 9th 2020 at 17:43

KingMiner botnet brute-forces MSSQL databases to install cryptocurrency miner

The KingMiner gang is brute-forcing the "sa" user, the highest-privileged account on a MSSQL database.
  • June 9th 2020 at 13:00

CallStranger vulnerability lets attacks bypass security systems and scan LANs

The CallStranger vulnerability can also be used to launch major DDoS attacks.
  • June 8th 2020 at 19:51

Vulnerabilities in popular open source projects doubled in 2019

Jenkins and MySQL vulnerabilities have had the most weaponized vulnerabilities in the past five years.
  • June 8th 2020 at 13:00

Apple publishes free resources to improve password security

The new tools are meant to help the developers of password managers and Apple hopes the tools will reduce the instances where users chose their own password rather than rely on the password manager.
  • June 6th 2020 at 00:56

QNAP NAS devices targeted in another wave of ransomware attacks

eCh0raix ransomware gang returns with a new wave of attacks against QNAP NAS devices.
  • June 5th 2020 at 16:50

China, Iran, and Russia worked together to call out US hypocrisy on BLM protests

Report from social media research group shows foreign diplomats and state-controlled media pounced on the US' abysmal handling of the BLM protests to attack the US as a beacon of freedom and further their own political goals.
  • June 5th 2020 at 03:55

Google: Chinese and Iranian hackers targeted Biden and Trump campaign staffers

Google's TAG team said phishing attacks against Biden and Trump campaign staffers were unsuccessful.
  • June 4th 2020 at 17:28

Incognito mode detection still works in Chrome despite promise to fix

Google said last year that it would fix a bug that allowed sites to detect incognito mode, but no fix ever came.
  • June 4th 2020 at 04:15

Hackers hijack one of Coincheck's domains for spear-phishing attacks

Hackers hijacked Coincheck's domain registrar account and then changed DNS settings.
  • June 3rd 2020 at 22:41

Google apps and websites get support for more security keys on iOS devices

You can now use hardware security keys to access Google apps and services running on iOS devices.
  • June 3rd 2020 at 18:00

Large-scale attack tries to steal configuration files from WordPress sites

Attackers tried to download configuration files from WordPress sites so they could steal database credentials.
  • June 3rd 2020 at 16:14

Facebook software engineer resigns with scathing criticism of the network’s refusal to act on β€˜weaponized hatred’

The former Facebook employee accuses the social network of allowing β€œpoliticians to radicalize individuals and glorify violence.”
  • June 3rd 2020 at 11:27

Tor’s latest release makes it easier to find secure onion services

Tor Browser 9.5 is also working towards making Dark Web addresses easier to remember.
  • June 3rd 2020 at 10:00

Google opens up Advanced Protection Program to Nest devices

The move follows integration with services including Android and Chrome.
  • June 3rd 2020 at 09:06

Ransomware gang says it breached one of NASA's IT contractors

DopplePaymer ransomware gang claims to have breached DMI, a major US IT and cybersecurity provider, and one of NASA IT contractors.
  • June 3rd 2020 at 00:29

New cold boot attack affects seven years of LG Android smartphones

LG has released a firmware fix in May 2020. Attack requires physical access.
  • June 2nd 2020 at 20:19

REvil ransomware gang launches auction site to sell stolen data

Ransomware gang takes extortion to a whole new level. Threatens to auction Madonna's legal documents in a future auction.
  • June 2nd 2020 at 16:04

G Suite Marketplace primed for a privacy scandal, researchers warn

G Suite apps that have access to Drive and Gmail data found communicating with undisclosed external services.
  • June 2nd 2020 at 11:34

Amtrak discloses data breach, potential leak of customer account data

The rail service says that customer PII may have been compromised.
  • June 2nd 2020 at 08:34

White House says security incidents at US federal agencies went down in 2019

US federal agencies reported 28,581 cyber-security incidents in 2019, down by 8% from 31,107 in 2018.
  • June 1st 2020 at 20:58

After a breach, users rarely change their passwords, study finds

Only a third of users changed their password following a data breach.
  • June 1st 2020 at 17:39

Researcher lands $100,000 reward for β€˜Sign in with Apple’ authentication bypass bug

User accounts could be hijacked through missing validation processes on Apple servers.
  • June 1st 2020 at 10:25

Joomla team discloses data breach

Joomla says a team member left an unencrypted backup of the JRD portal on a private AWS S3 bucket.
  • June 1st 2020 at 02:05

Hacker leaks database of dark web hosting provider

Leaked data contains email addresses, site admin passwords, and .onion domain private keys.
  • May 31st 2020 at 10:43

NCA launches UK ad campaign to divert kids searching for cybercrime tools

DDoS-for-hire and Trojan-related searches are on the agency’s radar.
  • May 29th 2020 at 12:16

Judge demands Capital One release Mandiant cyberforensic report on data breach

Attorneys suing the company will now have access to the report in preparation for a potential trial.
  • May 29th 2020 at 10:51

GitHub warns Java developers of new malware poisoning NetBeans projects

The malware's end goal was to install a remote access trojan and grant hackers access to highly sensitive workstations were sensitive projects were being developed.
  • May 29th 2020 at 05:00

Google to enable the Chrome anti-notification spam system in July 2020

Chrome will block sites from showing notification spam by default. Has been an opt-in feature since February.
  • May 28th 2020 at 20:56

Fortune 500 company NTT discloses security breach

Japanese telecommunications giant NTT says hackers breached its internal network and stole data on 621 customers.
  • May 28th 2020 at 19:16

Cisco discloses security breach that impacted VIRL-PE infrastructure

Hackers used vulnerabilities in the SaltStack data center software to breach six Cisco servers.
  • May 28th 2020 at 18:05

NSA warns of new Sandworm attacks on email servers

NSA says Russia's military hackers have been attacking Exim email servers to plant backdoors since August 2019.
  • May 28th 2020 at 15:31

All the security features added in the Windows 10 May 2020 update

Windows 10 v2004 comes with Windows Sandbox improvements, WiFi 6, WPA3, and Windows Hello in Safe Mode.
  • May 28th 2020 at 04:20

Valak targets Microsoft Exchange servers to steal enterprise data

The malware has been β€œdramatically changed” in the past six months.
  • May 28th 2020 at 04:00

Michigan State University hit by ransomware gang

The operators of the NetWalker ransomware gang have given MSU officials seven days to pay the ransom or they will leak stolen university files.
  • May 28th 2020 at 01:53

Google highlights Indian 'hack-for-hire' companies in new TAG report

Google also discloses seven coordinated political influence campaigns that took place on its platforms during Q1 2020.
  • May 27th 2020 at 21:43

Microsoft warns about attacks with the PonyFinal ransomware

PonyFinal infections have been reported in India, Iran, and the US.
  • May 27th 2020 at 16:58

OpenSSH to deprecate SHA-1 logins due to security risk

Breaking a SHA-1-generated SSH authentication key now costs roughly $50,000, putting high-profile remote servers at risk of attacks.
  • May 27th 2020 at 14:45

New fuzzing tool finds 26 USB bugs in Linux, Windows, macOS, and FreeBSD

Eighteen of the 26 bugs impact Linux. Eleven have been patched already.
  • May 27th 2020 at 11:23

26 million LiveJournal credentials leaked online, sold on the dark web

LiveJournal credentials were obtained in a 2014 hack, but leaked online earlier this month.
  • May 27th 2020 at 00:55

Qihoo & Baidu disrupt malware botnet with hundreds of thousands of victims

There's malware in China, too. Meet DoubleGuns, one of China's largest malware botnets.
  • May 26th 2020 at 15:18

Europol, Capgemini team up in cybercrime prevention, awareness campaigns

Capgemini is now also supporting the No More Ransom Project.
  • May 26th 2020 at 12:01

Forescout files lawsuit against Advent for withdrawal of merger plans due to COVID-19

Advent says the pandemic has resulted in β€œmaterial” changes at Forescout. The company disagrees.
  • May 26th 2020 at 11:26

EasyJet faces Β£18 billion class-action lawsuit over data breach

The lawsuit aims to secure up to Β£2,000 per impacted customer.
  • May 26th 2020 at 10:38

Turla hacker group steals antivirus logs to see if its malware was detected

Turla, one of Russia's most advanced hacker groups, has created malware that gets its orders from email attachments sent to an arbitrary Gmail inbox.
  • May 26th 2020 at 09:30

RangeAmp attacks can take down websites and CDN servers

Twelve of thirteen CDN providers said they fixed or planned to fix the problem.
  • May 25th 2020 at 21:28

Thousands of enterprise systems infected by new Blue Mockingbird malware gang

Hackers are exploiting a dangerous and hard to patch vulnerability to go after enterprise servers.
  • May 25th 2020 at 14:33

New Unc0ver jailbreak released, works on all recent iOS versions

New "Unc0ver" jailbreak unlocks devices, even those running the current iOS 13.5 release.
  • May 24th 2020 at 10:52

Chrome: 70% of all security bugs are memory safety issues

Google software engineers are looking into ways of eliminating memory management-related bugs from Chrome.
  • May 23rd 2020 at 06:00

25 million user records leak online from popular math app Mathway

The Mathway user data has been previously on sale on the dark web, hacker forums, and Telegram channels for the past two weeks.
  • May 22nd 2020 at 16:45

Windows malware opens RDP ports on PCs for future remote access

Security experts believe the malware's operators are very likely to sell access to infected hosts to other hacker groups.
  • May 22nd 2020 at 14:50

Privilege escalation vulnerability patched in Docker Desktop for Windows

The security flaw could be used to trick the service into connecting to malicious processes.
  • May 22nd 2020 at 12:21

Silent Night Zeus financial botnet sold in underground forums

The botnet is being spread through the RIG exploit kit and COVID-19 spam campaigns.
  • May 22nd 2020 at 11:05
❌