Cybersecurity News


Verizon DBIR: Web App Attacks and Security Errors Surge

Verizon DBIR: Web App Attacks and Security Errors Surge Threatpost talks to Verizon DBIR co-author Gabriel Bassett about the top takeaways from this year's Data Breach Investigations Report.
20 May 2020

Signal to move away from using phone numbers as user IDs

Signal launches profile PINs, the first step in supporting Signal user accounts that are not tied to phone numbers.
20 May 2020

Is Zero Trust the Best Answer to the COVID-19 Lockdown?

Is Zero Trust the Best Answer to the COVID-19 Lockdown? Enterprises need to recognize that remote access and other pandemic-related security challenges cannot be fixed with buzzwords or silver-bullet security tools.
20 May 2020

Alleged Hacker Behind Massive ‘Collection 1’ Data Dump Arrested

Alleged Hacker Behind Massive ‘Collection 1’ Data Dump Arrested The threat actor known as ‘Sanix’ had terabytes of stolen credentials at his residence, authorities said.
20 May 2020

‘Flight risk’ employees involved in 60% of insider cybersecurity incidents

The majority of staff planning their exit also take sensitive information with them, research suggests.
20 May 2020

Adobe issues out-of-band patch to fix remote code execution flaw in animation software

Information leaks have also been patched up in Premiere Rush, Audition, and Premiere Pro.
20 May 2020

These things may be cool, but are they safe?

In the rush to embrace IoT devices, we shouldn’t trade in our privacy and security for the added convenience

The post These things may be cool, but are they safe? appeared first on WeLiveSecurity

20 May 2020

NXNSAttack technique can be abused for large-scale DDoS attacks

New vulnerability in DNS server software can be leveraged for DDoS attacks with an 1620x amplification factor.
19 May 2020

Magecart Plants Card Skimmers via Old Magento Plugin Flaw

The FBI has warned ecommerce sites about attacks targeting a more than three-year-old flaw in the Magmi mass importer.
19 May 2020

Google Chrome Redesign Puts Security & Privacy in Users' Hands

The Chrome browser will tell users if their browser is up to date, malicious extensions are installed, and/or a password has been compromised.
19 May 2020

The Windows 7 Postmortem: What’s at Stake

The Windows 7 Postmortem: What’s at Stake Nearly a quarter of endpoints still run Windows 7, even though support and security patches have ended.
19 May 2020

Unpatched Open Source Libraries Leave 71% of Apps Vulnerable

PHP and JavaScript developers need to pay close attention because different languages and frameworks have different rates of vulnerability, research finds.
19 May 2020

EasyJet Hackers Take Off with Travel Details for 9M Customers

EasyJet Hackers Take Off with Travel Details for 9M Customers The vacation-centric airline is warning victims about social-engineering attacks.
19 May 2020

Web Application Attacks Double from 2019: Verizon DBIR

Web Application Attacks Double from 2019: Verizon DBIR Verizon's annual data breach report shows most attackers are external, money remains their top motivator, and web applications and unsecured cloud storage are hot targets.
19 May 2020

Bluetooth flaw exposes countless devices to BIAS attacks

As many as 30 smartphones, laptops and other devices were tested – and all were found to be vulnerable

The post Bluetooth flaw exposes countless devices to BIAS attacks appeared first on WeLiveSecurity

19 May 2020

Long-Term Remote Work: Keeping Workers Productive & Secure

The pandemic has changed how we get work done. Now, data security must catch up.
19 May 2020

Hacker arrested in Ukraine for selling billions of stolen credentials

Hacker "Sanix" has been selling billions of hacked user credentials on hacker forums and Telegram channels.
19 May 2020

WolfRAT Android Malware Targets WhatsApp, Facebook Messenger

WolfRAT Android Malware Targets WhatsApp, Facebook Messenger Researchers link the malware to Wolf Research operators with "high confidence" after it was spotted in campaigns targeting Thai users.
19 May 2020

WolfRAT targets WhatsApp, Facebook Messenger app users on Android devices

The new malware is unstable and appears to be a slapdash effort based on leaked DenDroid code.
19 May 2020

Ukraine Nabs Suspect in 773M Password ‘Megabreach’

In January 2019, dozens of media outlets raised the alarm about a new “megabreach” involving the release of some 773 million stolen usernames and passwords that was breathlessly labeled “the largest collection of stolen data in history.” A subsequent review by KrebsOnSecurity quickly determined the data was years old and merely a compilation of credentials pilfered from mostly public data breaches. Earlier today, authorities in Ukraine said they’d apprehended a suspect in the case.
19 May 2020