FreshRSS

πŸ”’
☐ β˜† βœ‡ ZDNet | security RSS

Chrome 84 released with support for blocking notification popups on spammy sites

July 14th 2020 at 20:35
Other new features that shipped with Chrome 84 include a new animations engine and a one-tap system for importing SMS passcodes into Chrome web forms.
☐ β˜† βœ‡ ZDNet | security RSS

Microsoft July 2020 Patch Tuesday fixes 123 vulnerabilities

July 14th 2020 at 17:51
This month's patches fix a major wormable bug in the Windows Server DNS component.
☐ β˜† βœ‡ ZDNet | security RSS

SigRed: A 17-year-old 'wormable' vulnerability for hijacking Microsoft Windows Server

July 14th 2020 at 17:43
The vulnerability, fixed in Microsoft's Patch Tuesday, has been awarded a severity rating of 10.0.
☐ β˜† βœ‡ ZDNet | security RSS

EFF’s new database reveals what tech local police are using to spy on you

July 14th 2020 at 09:32
Updated: An interactive map shows you everything from Ring partnerships to predictive policing.
☐ β˜† βœ‡ ZDNet | security RSS

RECON bug lets hackers create admin accounts on SAP servers

July 14th 2020 at 02:15
SAP patches bug impacting most of its apps and customer base.
☐ β˜† βœ‡ ZDNet | security RSS

A hacker is selling details of 142 million MGM hotel guests on the dark web

July 14th 2020 at 01:49
EXCLUSIVE: The MGM Resorts 2019 data breach is much larger than initially reported.
☐ β˜† βœ‡ ZDNet | security RSS

Google Meet adds zoombombing protection for education customers

July 13th 2020 at 20:05
Google will block anonymous users from joining Google Meet video conferences organized by G Suite for Education customers.
☐ β˜† βœ‡ ZDNet | security RSS

Hacker breaches security firm in act of revenge

July 13th 2020 at 02:53
Hacker claims to have stolen more than 8,200 databases from a security firm's data leak monitoring service.
☐ β˜† βœ‡ ZDNet | security RSS

Researchers create magstripe versions from EMV and contactless cards

July 11th 2020 at 00:05
Banking industry loophole reported more than a decade ago still remains open and ripe for exploitation today.
☐ β˜† βœ‡ ZDNet | security RSS

Amazon tells employees to remove TikTok from their phones due to security risk

July 10th 2020 at 18:25
Accessing the TikTok website from work laptops is still allowed, according to an internal email Amazon sent to employees today.
☐ β˜† βœ‡ ZDNet | security RSS

Backdoor accounts discovered in 29 FTTH devices from Chinese vendor C-Data

July 10th 2020 at 11:30
The backdoor accounts grant access to a secret Telnet admin account running on the devices' external WAN interface.
☐ β˜† βœ‡ ZDNet | security RSS

Smartwatch tracker for the vulnerable can be hacked to send medication alerts

July 10th 2020 at 09:53
API issues could be exploited to make calls, spy on users, send fake messages, and more.
☐ β˜† βœ‡ ZDNet | security RSS

KingComposer patches XSS flaw impacting 100,000 WordPress websites

July 10th 2020 at 07:08
The vulnerability could be exploited to execute malicious payloads in visitor browsers.
☐ β˜† βœ‡ ZDNet | security RSS

Google bans stalkerware ads

July 9th 2020 at 21:36
New Google Ads policy that bans stalkerware enters into effect on August 11.
☐ β˜† βœ‡ ZDNet | security RSS

Zoom working on patching zero-day disclosed in Windows client

July 9th 2020 at 18:00
UPDATE: The zero-day has now been patched. Updates are available to Zoom Windows users.
☐ β˜† βœ‡ ZDNet | security RSS

Researchers connect Evilnum hacking group to cyberattacks against Fintech firms

July 9th 2020 at 09:30
The APT is also a loyal customer of Golden Chickens, a Malware-as-a-Service outfit.
☐ β˜† βœ‡ ZDNet | security RSS

Google abandons Isolated Region cloud services project in China

July 9th 2020 at 06:20
Google says the Isolated Region project was scrapped due to other services offering β€œbetter outcomes.”
☐ β˜† βœ‡ ZDNet | security RSS

More pre-installed malware has been found in budget US smartphones

July 9th 2020 at 04:40
Cheap phones often have tradeoffs but researchers say this should never compromise user safety.
☐ β˜† βœ‡ ZDNet | security RSS

Conti ransomware uses 32 simultaneous CPU threads for blazing-fast encryption

July 9th 2020 at 02:42
The Conti ransomware also abuses the Windows Restart Manager component to unlock apps and free up their data (for encryption).
☐ β˜† βœ‡ ZDNet | security RSS

Nvidia fixes code execution vulnerability in GeForce Experience

July 9th 2020 at 02:42
Security updates have also been released for the JetPack software development kit.
☐ β˜† βœ‡ ZDNet | security RSS

Microsoft's new KDP tech blocks malware by making parts of the Windows kernel read-only

July 8th 2020 at 23:09
New KDP security feature is currently being tested with Windows 10 Insider builds.
☐ β˜† βœ‡ ZDNet | security RSS

Google open-sources Tsunami vulnerability scanner

July 8th 2020 at 17:16
Google says Tsunami is an extensible network scanner for detecting high-severity vulnerabilities with as little false-positives as possible.
☐ β˜† βœ‡ ZDNet | security RSS

Civil rights auditors slam Facebook stance on Trump, voter suppression

July 8th 2020 at 12:09
Facebook has admitted there is still a β€œlong way to go” to quell recent criticism of civil rights issue handling.
☐ β˜† βœ‡ ZDNet | security RSS

Fxmsp hacker indicted by feds for selling backdoor access to hundreds of companies

July 8th 2020 at 10:02
Backdoors into government networks and corporations were allegedly sold to other criminal enterprises.
☐ β˜† βœ‡ ZDNet | security RSS

Mozilla suspends Firefox Send service while it addresses malware abuse

July 7th 2020 at 22:22
Mozilla has temporarily suspended the Firefox Send file-sharing service while it adds a Report Abuse mechanism.
☐ β˜† βœ‡ ZDNet | security RSS

Free decryptor available for ThiefQuest ransomware victims

July 7th 2020 at 19:39
ThiefQuest (EvilQuest) ransomware victims can now recover their encrypted files for free, without needing to pay the ransom demand.
☐ β˜† βœ‡ ZDNet | security RSS

German authorities seize 'BlueLeaks' server that hosted data on US cops

July 7th 2020 at 17:38
BlueLeaks portal is now down. The website hosted 269 GB of files stolen from more than 200 US police departments and fusion training centers.
☐ β˜† βœ‡ ZDNet | security RSS

Microsoft seizes six domains used in COVID-19 phishing operations

July 7th 2020 at 16:00
Hackers used malicious Office 365 apps to gain access to customer accounts, which they later used to orchestrate BEC attacks.
☐ β˜† βœ‡ ZDNet | security RSS

'Keeper' hacking group behind hacks at 570 online stores

July 7th 2020 at 14:00
Hackers also accidentally leaked more than 184,000 stolen cards through an improperly secured backend server.
☐ β˜† βœ‡ ZDNet | security RSS

Researchers learn how to pinpoint malicious drone operators

July 7th 2020 at 13:13
With high accuracy, it is now possible to trace drone operators that could be ill-wishers near protected airspace.
☐ β˜† βœ‡ ZDNet | security RSS

Energy company EDP confirms cyberattack, Ragnar Locker ransomware blamed

July 7th 2020 at 11:39
The energy firm denies the loss of customer data. Attackers claim to have stolen 10TB in business records.
☐ β˜† βœ‡ ZDNet | security RSS

Cerberus banking Trojan infiltrates Google Play

July 7th 2020 at 10:28
The malware was found buried within a seemingly-innocent currency converter.
☐ β˜† βœ‡ ZDNet | security RSS

US Secret Service reports an increase in hacked managed service providers (MSPs)

July 6th 2020 at 17:15
US Secret Service says hackers are breaching MSPs to orchestrate ransomware attacks, point-of-sale intrusions, and business email compromise (BEC) scams.
☐ β˜† βœ‡ ZDNet | security RSS

VaultAge Solutions CEO goes into hiding to avoid cryptocurrency investors allegedly scammed out of $13 million

July 6th 2020 at 11:51
Roughly 2,000 investors have been left out of pocket by the alleged misappropriation of funds.
☐ β˜† βœ‡ ZDNet | security RSS

Yahoo engineer gets no jail time after hacking 6,000 accounts to look for porn

July 6th 2020 at 10:53
Hacker sentenced to five years probation, with home confinement condition.
☐ β˜† βœ‡ ZDNet | security RSS

North Korean hackers linked to web skimming (Magecart) attacks, report says

July 6th 2020 at 06:00
After hacking banks and cryptocurrency exchanges, orchestrating ATM cash-outs, and deploying ransomware, North Korean hackers have now set their sights on online stores.
☐ β˜† βœ‡ ZDNet | security RSS

Hackers are trying to steal admin passwords from F5 BIG-IP devices

July 4th 2020 at 20:20
Threat actors have already started exploiting the F5 BIG-IP mega-bug, three days after it was disclosed.
☐ β˜† βœ‡ ZDNet | security RSS

Infosec community disagrees with changing 'black hat' term due to racial stereotyping

July 4th 2020 at 15:44
A Google security researcher withdrew from the Black Hat security conference and asked the community to stop using the 'black hat' term.
☐ β˜† βœ‡ ZDNet | security RSS

F5 patches vulnerability that received a CVSS 10 severity score

July 3rd 2020 at 19:44
Remote code execution in F5 BIG-IP devices exposes governments, cloud providers, ISPs, banks, and many Fortune 500 companies to possible intrusions.
☐ β˜† βœ‡ ZDNet | security RSS

New Apple macOS Big Sur feature to hamper adware operations

July 3rd 2020 at 15:25
Apple has disabled the ability to silently install macOS profiles from the CLI in macOS 11, a measure that was widely employed by adware and malware gangs.
☐ β˜† βœ‡ ZDNet | security RSS

LinkedIn says iOS clipboard snooping after every key press is a bug, will fix

July 3rd 2020 at 10:03
The new clipboard access detection and warning feature in iOS 14 exposes another app.
☐ β˜† βœ‡ ZDNet | security RSS

Roblox accounts hacked with pro-Trump messages

July 2nd 2020 at 23:05
Hackers are taking Roblox credentials leaked on Pastebin, accessing accounts, and leaving the same "Ask your parents to vote for Trump this year" message on thousands of Roblox profiles.
☐ β˜† βœ‡ ZDNet | security RSS

Sixteen Facebook apps caught secretly sharing data with third-parties

July 2nd 2020 at 18:21
Academic study used unique "honeytoken" emails to install Facebook apps and see which inboxes received emails from unrecognized senders.
☐ β˜† βœ‡ ZDNet | security RSS

V Shred data leak exposes PII, sensitive photos of fitness customers and trainers

July 2nd 2020 at 14:00
V Shred defended the public status of its open bucket and only partially solved the problem.
☐ β˜† βœ‡ ZDNet | security RSS

This is how EKANS ransomware is targeting industrial control systems

July 2nd 2020 at 12:02
New samples of the ransomware reveal the techniques used to attack critical ICS systems.
☐ β˜† βœ‡ ZDNet | security RSS

Facebook says 5,000 app developers got user data after cutoff date

July 2nd 2020 at 02:26
A Facebook privacy mechanism blocks apps from receiving user data if users didn't use an app for 90 days. Facebook said 5,000 apps continued to receive user data regardless.
☐ β˜† βœ‡ ZDNet | security RSS

Connection discovered between Chinese hacker group APT15 and defense contractor

July 2nd 2020 at 01:25
Lookout said it linked APT15 malware to Xi'an Tianhe Defense Technology, a Chinese defense contractor.
☐ β˜† βœ‡ ZDNet | security RSS

Hacker ransoms 23k MongoDB databases and threatens to contact GDPR authorities

July 1st 2020 at 21:14
The hacker has attempted to ransom nearly 47% of all MongoDB databases left exposed online.
☐ β˜† βœ‡ ZDNet | security RSS

One out of every 142 passwords is '123456'

July 1st 2020 at 15:09
The '123456' password was spotted 7 million times across a data trove of one billion leaked credentials, in one of the biggest password re-use studies of its kind.
☐ β˜† βœ‡ ZDNet | security RSS

AT&T dragged to court, again, over SIM hijacking and cryptocurrency theft

July 1st 2020 at 12:38
A customer allegedly lost $1.9 million due to AT&T’s handling of a number transfer request.
☐ β˜† βœ‡ ZDNet | security RSS

UK court shuts down scam cryptocurrency platform GPay Ltd, Β£1.5 million in client funds lost

July 1st 2020 at 10:59
GPay used fake celebrity endorsements and ads to lure traders to invest.
☐ β˜† βœ‡ ZDNet | security RSS

Microsoft releases emergency security update to fix two bugs in Windows codecs

July 1st 2020 at 01:44
Security updates have been silently deployed to customers on Tuesday through the Windows Store app.
☐ β˜† βœ‡ ZDNet | security RSS

Apple tells app devs to use IPv6 as it's 1.4 times faster than IPv4

July 1st 2020 at 00:31
Company also urges app devs to start using newer web tech like HTTP/2 and TLS 1.3, citing similar performance and speed improvements.
☐ β˜† βœ‡ ZDNet | security RSS

New ThiefQuest ransomware discovered targeting macOS users

June 30th 2020 at 16:02
ThiefQuest ransomware encrypts macOS systems but also installs a keylogger and a reverse shell for full control over infected hosts.
☐ β˜† βœ‡ ZDNet | security RSS

Promethium APT attacks surge, new Trojanized installers uncovered

June 30th 2020 at 12:35
The hacking group behind StrongPity is ignoring constant exposure by researchers in its quest for global intelligence and surveillance.
☐ β˜† βœ‡ ZDNet | security RSS

University of California SF pays ransomware hackers $1.14 million to salvage research

June 30th 2020 at 10:02
The malware infected crucial research stored in the UCSF medical school’s network.
☐ β˜† βœ‡ ZDNet | security RSS

The more cybersecurity tools an enterprise deploys, the less effective their defense is

June 30th 2020 at 10:00
New research highlights how throwing money indiscriminately at security doesn’t guarantee results.
☐ β˜† βœ‡ ZDNet | security RSS

Google removes 25 Android apps caught stealing Facebook credentials

June 30th 2020 at 09:49
The malicious apps were downloaded more than 2.34 million times.
☐ β˜† βœ‡ ZDNet | security RSS

US Cyber Command says foreign hackers will attempt to exploit new PAN-OS security bug

June 30th 2020 at 01:04
Palo Alto Networks disclosed today a major bug that lets hackers bypass authentication on its firewall and corporate VPN products.
❌