03 Apr

Meet clickjacking’s slicker cousin, ‘gesture jacking,’ aka ‘cross window forgery’

Web browsers still struggle to prevent clickjacking, an attack technique first noted in 2008 that repurposes web page interface elements to deceive visitors. Despite continuing

Author rabih
03 Apr

Microsoft slammed for lax security that led to China’s cyber-raid on Exchange Online

A review of the June 2023 attack on Microsoft’s Exchange Online hosted email service – which saw accounts used by senior US officials compromised by

Author rabih
03 Apr

Pandabuy confirms crooks nabbed data on 1.3M punters

Ecommerce platform Pandabuy has apologized after two cybercriminals were spotted hawking personal data belonging to 1.3 million of its customers. A user with the alias

Author rabih
02 Apr

Feds finally decide to do something about years-old SS7 spy holes in phone networks

The FCC appears to finally be stepping up efforts to secure decades-old flaws in American telephone networks that are allegedly being used by foreign governments

Author rabih
02 Apr

OWASP server blunder exposes decade of resumes

A misconfigured MediaWiki web server allowed digital snoops to access members’ resumes containing their personal details at the Open Web Application Security Project (OWASP) Foundation.

Author rabih
02 Apr

Distinctive Campaign Evolution of Pikabot Malware

Authored by Anuradha and Preksha PikaBot is a malicious backdoor that has been active since early 2023. Its modular design is comprised of a loader

Author rabih
02 Apr

Pandabuy admits to data breach of 1.3 million unique records

Ecommerce platform Pandabuy has apologized after two cybercriminals were spotted hawking personal data belonging to 1.3 million customers. A user with the alias Sanggiero originally

Author rabih
02 Apr

Microsoft warns deepfake election subversion is disturbingly easy

As hundreds of millions of voters around the globe prepare to elect their leaders this year, there’s no question that trolls will try to sway

Author rabih
02 Apr

Are You a Victim of a Deepfake Attack? Here’s What to Do Next

With the rise of cheap and easy-to-use AI tools, deepfake attacks find themselves likewise on the rise. Startling as that news might sound, you have

Author rabih
02 Apr

Rubrik files to go public following alliance with Microsoft

Cloud security provider Rubrik has filed for an IPO on the New York Stock Exchange following a flurry of similar flotations. The company, which provides

Author rabih
02 Apr

Polish officials may face criminal charges in Pegasus spyware probe

Former Polish government officials may face criminal charges following an investigation into their use of the notorious spyware Pegasus to surveil political opponents and others.

Author rabih
02 Apr

INC Ransom claims to be behind ‘cyber incident’ at UK city council

The cyber skids at INC Ransom are claiming responsbility for the ongoing cybersecurity incident at Leicester City Council, according to a post caught by eagle-eyed

Author rabih
02 Apr

Malware hiding in pictures? More likely than you think

Malware, Digital Security There is more to some images than meets the eye – their seemingly innocent façade can mask a sinister threat. Márk Szabó

Author rabih
02 Apr

Happy 20th birthday Gmail, you’re mostly grown up – now fix the spam

It was 20 years ago on Monday that Google unleashed Gmail on the world, and the chocolate factory is celebrating with new rules that just

Author rabih
02 Apr

Apple’s GoFetch silicon security fail was down to an obsession with speed

Opinion Apple is good at security. It’s good at processors. Thus GoFetch, a major security flaw in its processor architecture, is a double whammy. What

Author rabih
02 Apr

Six banks share customer info to help Singapore fight money laundering

ASIA IN BRIEF Singapore’s Monetary Authority on Monday launched an application, intuitively named “COllaborative Sharing of Money Laundering/TF Information & Cases” (COSMIC for short, obviously)

Author rabih
01 Apr

US House of Reps tells staff: No Microsoft Copilot for you!

Staff working at the US House Of Representatives have been barred from using Microsoft’s Copilot chatbot and AI productivity tools, pending the launch of a

Author rabih
01 Apr

Malicious xz backdoor reveals fragility of open source

Analysis The discovery last week of a backdoor in a widely used open source compression library called xz could have been a security disaster had

Author rabih
Load moreLoadingAll items loaded