Post Overview
-
Analysis
5 years ago+13 13 0Busted: Kaspersky AV Tracked Your Every Click
Kaspersky Lab’s endpoint security products track your web activity. The Russian company even monitors visits to https-secured websites.
-
Analysis
5 years ago+20 20 0O.MG USB cable will pwn your Mac or PC, PDQ
The moral of the story? Your users are innocently picking up spare cables in conference rooms, or buying generic Chinese cables on Amazon. Think about that for a moment—now panic.
-
Analysis
5 years ago+15 17 2Screwed Drivers: Windows Third-Party Device Code is Huge Mess
Driver Danger; Firmware Fracas: Many Windows drivers permit malware to access anything, subverting controls that separate user space from the kernel.
-
Analysis
5 years ago+16 16 0US Voting Machines Internet-Connected, Despite Denials
Researchers found 35 ES&S voting machines connected to the internet, contradicting statements by election officials and the manufacturer.
-
Analysis
5 years ago+4 4 0Ma’s malware malarkey: AT&T employees took $1M in bribes from phone-unlock gang
Insider threats come in many forms. How bribable are your employees?
-
Analysis
5 years ago+11 11 0Wi-Fi WPA3 Standard Fails Again as New ‘Dragonblood’ Bugs Found
A few months after confirming five vulnerabilities known as Dragonblood in the WPA3 standard, researchers have now found two more.
-
Analysis
5 years ago+8 8 0Capital One ‘deeply sorry’ to leak 106M personal records
Never mind your wallet—what’s in your WAF ruleset?
-
Analysis
5 years ago+11 13 23 Candles on No More Ransom’s Cake
No More Ransom is a global partnership between public and private sectors, including community involvement, 151-strong over three years.
-
Analysis
5 years ago+20 20 0After Mueller, Senate Intel Reports on Russian Election Hacks
Now we have the Senate Intel Committee’s report on how Russia sought to influence the 2016 elections and how it might do it again in 2020.
-
Analysis
5 years ago+35 35 0Fury as Equifax gets $4.76-per-victim slap on wrist
The moral of the story: Try to avoid being inept and negligent, OK?
-
Analysis
5 years ago+16 17 1Russia Cracks Tor? Hackers Dump 7.5TB of FSB Secrets
Russia’s notorious federal security service, the FSB, has a secret project to de-anonymize Tor. Big news or nothing to see here?
-
Analysis
5 years ago+20 22 2DataSpii: 'Catastrophic' Browser Data Leak 'Train Wreck'
Browser extensions might be selling your private data to the highest bidder—actions that might violate GDPR and similar regulations.
-
Analysis
5 years ago+12 12 0Another Android FAIL: Samsung leaks Sprint customer data
The moral of the story: Audit and red-team your partners too—not just your own architecture.
-
Analysis
5 years ago+4 5 1Zoom Spying Vulnerability: The Plot Thickens
Last week, we learned that the Zoom app for macOS has a nasty bug, allowing a hacker to spy on you. But the issue is worse than we thought.
-
Analysis
5 years ago+21 21 0OK Google, Stop Eavesdropping on Me!
Google gives contractors access to your voice, and now, recordings made secretly by Google devices and apps have leaked to the press.
-
Analysis
5 years ago+15 15 07-Eleven's 7pay app hacked in a day due to 'appalling security lapse'
The moral of the story? Red-team your apps—before someone else does.
-
Analysis
5 years ago+25 25 0Astaroth-Dropper Trojan Hides in Plain Sight
A spear-phishing campaign has been detected that uses fileless and living-off-the-land methods to run the Astaroth data-stealing malware.
-
Analysis
5 years ago+23 23 0Federal Facial Recognition by Stealth – With Zero Oversight
Multiple organizations are using facial recognition on driver's license photos to catch criminals. That's a major privacy violation, some say.
-
Analysis
5 years ago+13 14 1More Medtronic Hack Malarkey: This Time It’s Insulin Pumps
The U.S. Food and Drug Administration says certain insulin pumps made by Medtronic are hackable, and there’s no way to fix them. Once again, there’s no encryption and precious little authentication.
-
Analysis
5 years ago+11 11 0What if Hawaii Missile Message was a Hack?
What if the missile warning to residents in Hawaii 18 months ago wasn't a "miscommunication" but a hack done by North Korea? Researchers show how easy it is to spoof an emergency alert.