15 Nov

Google Workspace weaknesses allow plaintext password theft

Novel weaknesses in Google Workspace have been exposed by researchers, with exploits potentially leading to ransomware attacks, data exfiltration, and password decryption. Researchers at Bitdefender

Author rabih
15 Nov

Fake Android and iOS apps steal SMS and contacts in South Korea

Authored by Dexter Shin Most people have smartphones these days which can be used to easily search for various topics of interest on the Internet.

Author rabih
15 Nov

FBI Director: FISA Section 702 warrant requirement a ‘de facto ban’

FBI director Christopher Wray made yet another impassioned plea to US lawmakers to kill a proposed warrant requirement for so-called “US person queries” of data

Author rabih
15 Nov

How cyber training can help you beat the bad guys

Sponsored Post Fighting cybercrime demands constant vigilance and can be a huge drain on time and resources. So it’s good to know that not every

Author rabih
15 Nov

Ransomware more efficient than ever, and baddies are still after your logs

Organizations are still failing to implement adequate logging measures, increasing the difficulty faced by defenders and incident responders to identify the cause of infosec attacks.

Author rabih
15 Nov

Another month, another bunch of fixes for Microsoft security bugs exploited in the wild

Patch Tuesday Heads up: Microsoft’s November Patch Tuesday includes fixes for about 60 vulnerabilities – including three that have already been found and abused in

Author rabih
14 Nov

Russian national pleads guilty to building now-dismantled IPStorm proxy botnet

The FBI says it has dismantled another botnet and collared its operator, who admitted hijacking tens of thousands of machines around the world to create

Author rabih
14 Nov

AMD SEV OMG: Trusted execution undone by cache meddling

Boffins based in Germany and Austria have found a flaw in AMD’s SEV trusted execution environment that makes it less than trustworthy. The researchers –

Author rabih
14 Nov

Intel out-of-band patch addresses privilege escalation flaw

Intel on Tuesday issued an out-of-band security update to address a privilege escalation vulnerability in recent server and personal computer chips. The flaw, designated INTEL-SA-00950

Author rabih
14 Nov

Ransomware royale: US confirms Royal, BlackSuit are linked

The US’ Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) have released fresh guidance on the Royal ransomware operation, saying that

Author rabih
14 Nov

Novel backdoor persists even after critical Confluence vulnerability is patched

A new backdoor was this week found implanted in the environments of organizations to exploit the recently disclosed critical vulnerability in Atlassian Confluence. The backdoor

Author rabih
14 Nov

Level up! These games will make learning about cybersecurity fun

We Live Progress Discover six games that will provide valuable knowledge while turning learning about digital security into an enjoyable and rewarding adventure Luiza Pires

Author rabih
14 Nov

Bug hunters on your marks: TETRA radio encryption algorithms to enter public domain

A set of encryption algorithms used to secure emergency radio communications will enter the public domain after an about-face by the European Telecommunications Standards Institute

Author rabih
14 Nov

NCSC says cyber-readiness of UK’s critical infrastructure isn’t up to scratch

The UK’s National Cyber Security Centre (NCSC) has once again sounded its concern over the rising threat level to the nation’s critical national infrastructure (CNI).

Author rabih
14 Nov

Beijing reportedly asked Hikvision to identify fasting students in Muslim-majority province

US-based research group IPVM has accused Chinese video surveillance equipment company Hikvision of engaging with a contract to develop technology that can identify Muslim students

Author rabih
14 Nov

Passive SSH server private key compromise is real … for some vulnerable gear

An academic study has shown how it’s possible for someone to snoop on certain devices’ SSH connections and, with a bit of luck, impersonate that

Author rabih
14 Nov

Google sues scammers peddling fake malware-riddled Bard chatbot download

Google has sued three scammers for offering a fake download of its Bard AI chatbot that contained malware capable of stealing credentials for small business’

Author rabih
13 Nov

Royal Mail cybersecurity still a bit of a mess, infosec bods claim

Infosec in brief After spending almost a year cleaning up after various security snafus, the UK’s Royal Mail had an open redirect flaw on one

Author rabih
Load moreLoadingAll items loaded