Cybersecurity News
Mozilla patches Firefox zero-day reported by Qihoo 360
Chinese security firm claims there's also an accompanying Internet Explorer zero-day.Google's Project Zero Policy Change Mandates 90-Day Disclosure
The updated disclosure policy aims to achieve more thorough and improved patch development, Google reports.Man Sentenced in ATM Skimming Conspiracy

Google Ditches Patch-Time Bug Disclosure in Favor of 90-Day Policy

CES – Taking a smart city for a test drive
No one has a road map for securing a connected city – but there should be a whole atlas of such maps
The post CES – Taking a smart city for a test drive appeared first on WeLiveSecurity
CES – Taking a smart city for a test drive
No one has a road map for securing a connected city – but there should be a whole atlas of such maps
The post CES – Taking a smart city for a test drive appeared first on WeLiveSecurity
In App Development, Does No-Code Mean No Security?

TikTok Bugs Put Users' Videos, Personal Data At Risk
Researchers found it was possible to spoof SMS messages from TikTok and exploit an API flaw that could grant access to users' personal data.The "Art of Cloud War" for Business-Critical Data
How business executives' best intentions may be negatively affecting security and risk mitigation strategies -- and exposing weaknesses in organizational defenses.Telegram opens lid on TON project amid SEC spat: ‘Grams won’t help you get rich’
No cryptocurrency wallet will be integrated with Telegram Messenger either -- at least, not yet.ATM skimmer sentenced for fleecing $400,000 out of US banks
ATM users had their cards read and bank accounts pillaged.Naive IoT botnet wastes its time mining cryptocurrency
Operators of LiquorBot botnet waste their time trying to mine Monero on hacked SOHO routers.Mobile Apps
Only install mobile apps from trusted places, and always double-check the privacy settings to ensure you are not giving away too much information.Signal app will support 'view-once' images and videos
Support for ephemeral multimedia messages to arrive in Signal within weeks.Google Chrome to hide notification spam starting February 2020
Chrome 80, scheduled for release in February 2020, will block notification popups by default.Tricky Phish Angles for Persistence, Not Passwords
Late last year saw the re-emergence of a nasty phishing tactic that allows the attacker to gain full access to a user's data stored in the cloud without actually stealing the account password. The phishing lure starts with a link that leads to the real login page for a cloud email and/or file storage service. Anyone who takes the bait will inadvertently forward a digital token to the attackers that gives them indefinite access to the victim's email, files and contacts -- even after the victim has changed their password.Facebook bans deepfakes but not all altered content
Footage defined as parody or satire will be permitted, as the social network isn’t slamming the door on all types of manipulated media
The post Facebook bans deepfakes but not all altered content appeared first on WeLiveSecurity
Facebook bans deepfakes but not all altered content
Footage defined as parody or satire will be permitted, as the social network isn’t slamming the door on all types of manipulated media
The post Facebook bans deepfakes but not all altered content appeared first on WeLiveSecurity