16 Jan

Raspberry Pi hands out prizes to all in the RP2350 Hacking Challenge

Raspberry Pi has given out prizes for extracting a secret value from the one-time-programmable (OTP) memory of the Raspberry Pi RP2350 microcontroller – awarding a

Author rabih
16 Jan

Infoseccer: Private security biz let guard down, exposed 120K+ files

A London-based private security company allegedly left more than 120,000 files available online via an unsecured server, an infoseccer told The Register. The independent security

Author rabih
16 Jan

Under the cloak of UEFI Secure Boot: Introducing CVE-2024-7344

ESET researchers have discovered a vulnerability that allows bypassing UEFI Secure Boot, affecting the majority of UEFI-based systems. This vulnerability, assigned CVE-2024-7344, was found in

Author rabih
15 Jan

GoDaddy slapped with wet lettuce for years of lax security and ‘several major breaches’

GoDaddy has failed to protect its web-hosting platform with even basic infosec tools and practices since 2018, according to the FTC, but the internet giant

Author rabih
15 Jan

DJI loosens flight restrictions, decides to trust operators to follow FAA rules

Drone maker DJI has decided to scale back its geofencing restrictions, meaning its software won’t automatically stop operators from flying into areas flagged as no-fly

Author rabih
15 Jan

China’s Salt Typhoon spies spotted on US govt networks before telcos, CISA boss says

Beijing’s Salt Typhoon cyberspies had been seen in US government networks before telcos discovered the same foreign intruders in their own systems, according to CISA

Author rabih
15 Jan

Even modest makeup can thwart facial recognition

Researchers at cyber-defense contractor PeopleTec have found that facial recognition algorithms’ focus on specific areas of the face opens the door to subtler surveillance avoidance

Author rabih
15 Jan

Windows Patch Tuesday hits snag with Citrix software, workarounds published

Devices that have Citrix’s Session Recording software installed are having problems completing this month’s Microsoft Patch Tuesday update, which includes important fixes. Microsoft noted the

Author rabih
15 Jan

Crypto klepto North Korea stole $659M over just 5 heists last year

North Korean blockchain bandits stole more than half a billion dollars in cryptocurrency in 2024 alone, the US, Japan, and South Korea say. The sum

Author rabih
15 Jan

Cybersecurity and AI: What does 2025 have in store?

Digital Security In the hands of malicious actors, AI tools can enhance the scale and severity of all manner of scams, disinformation campaigns and other

Author rabih
15 Jan

Microsoft fixes under-attack privilege-escalation holes in Hyper-V

Patch Tuesday The first Patch Tuesday of 2025 has seen Microsoft address three under-attack privilege-escalation flaws in its Hyper-V hypervisor, plus plenty more problems that

Author rabih
14 Jan

FBI wipes Chinese PlugX malware from thousands of Windows PCs in America

The FBI, working with French cops, obtained nine warrants to remotely wipe PlugX malware from thousands of Windows-based computers that had been infected by Chinese

Author rabih
14 Jan

Snyk appears to deploy ‘malicious’ packages targeting Cursor for unknown reason

Developer security company Snyk is at the center of allegations concerning the possible targeting or testing of Cursor, an AI code editor company, using “malicious”

Author rabih
14 Jan

It’s not just Big Tech: The UK’s Online Safety Act applies across the board

Analysis A little more than two months out from its first legal deadline, the UK’s Online Safety Act is causing concern among smaller online forums

Author rabih
14 Jan

UK floats ransomware payout ban for public sector

A total ban on ransomware payments across the public sector might actually happen after the UK government opened a consultation on how to combat the

Author rabih
14 Jan

Protecting children online: Where Florida’s new law falls short

Kids Online Some of the state’s new child safety law can be easily circumvented. Should it have gone further? Tony Anscombe 14 Jan 2025  • 

Author rabih
14 Jan

Miscreants ‘mass exploited’ Fortinet firewalls, ‘highly probable’ zero-day used

Miscreants running a “mass exploitation campaign” against Fortinet firewalls, which peaked in December, may be using an unpatched zero-day vulnerability to compromise the equipment, according

Author rabih
13 Jan

Cryptojacking, backdoors abound as fiends abuse Aviatrix Controller bug

“Several cloud deployments” are already compromised following the disclosure of the maximum-severity vulnerability in Aviatrix Controller, researchers say. CVE-2024-50603 leads to remote code execution (RCE)

Author rabih
Load moreLoadingAll items loaded