Tag: Security Software news and updates

Proton Authenticator: free open-source two-factor authentication app

Proton is on a role. The company released its privacy-friendly AI Lumo last week and has now released Proton Authenticator, a two-factor authentication app. Proton Authenticator is a cross-platform open source application […] Thank you for being a Ghacks reader.…

Brother releases firmware updates for hundreds of printers to address security issues

Security researchers at Rapid7 have discovered eight vulnerabilities in Brother printers that affect a total of 689 different printer models. Printers from Fujifilm Business, Ricoh, Toshiba, and Konica are also affected. It […] Thank you for being a Ghacks reader.…

Google “strongly encourages” its users to stop using passwords

Most users who have online accounts sign in using passwords. While there are some outliers, using security keys, passkeys and other advanced sign in options, the majority still relies heavily on passwords. […] Thank you for being a Ghacks reader.…

Europe just launched DNS4EU, a public DNS resolver with privacy and security options

DNS is one of the cornerstones of the Internet. Put simply, it is designed to turn domain names, say ghacks.net, into IP addresses. This process is usually handled by the Internet service […] Thank you for being a Ghacks reader.…

OneDrive flaw can give websites and apps full access to your files, even if you pick just one

Microsoft OneDrive is used by millions of users, largely thanks to its integration as the default cloud file hosting service on Windows and Microsoft 365. Security researchers at Oasis Security discovered a […] Thank you for being a Ghacks reader.…

184 million records data leak: Google, PayPal and Netflix passwords leaked online

Security researcher Jeremiah Fowler stumbled upon a large database of login information and passwords containing over 184 million records recently. He mentioned the discovery in an article on Website Planet. The data […] Thank you for being a Ghacks reader.…

Microsoft removes Authenticator App feature to promote Microsoft Edge

Microsoft Authenticator is a free security application by Microsoft. Its main function is the generation of security codes for two-factor authentication to better protect online accounts such as your eBay account. Microsoft […] Thank you for being a Ghacks reader.…

Data breach exposes 21 Million employee screenshots from a workplace surveillance tool

In a staggering privacy breach, over 21 million images documenting employee activity from a workplace surveillance tool have been leaked. The affected app is called WorkComposer, which is used by IT teams […] Thank you for being a Ghacks reader.…

FBI Issues new alert over phishing SMS scam targeting highway toll customers

The U.S. Federal Bureau of Investigation (FBI) has issued a nationwide warning about a surge in “smishing” attacks, a form of phishing conducted via SMS messages. These scams are designed to deceive […] Thank you for being a Ghacks reader.…

Windows has an 8-year-old security issue that is exploited and known by Microsoft for some time

Microsoft is doing a commendable job when it comes to Windows security. Keeping billions of devices secure is no small feat. Sometimes, however, it appears that someone at Microsoft is pushing the […] Thank you for being a Ghacks reader.…

1Password password manager gets location support for faster access

Password managers are useful tools. They help users create, store, and manage passwords and other sensitive data. Some offer additional features, like synchronization, two-step authentication, or SSO support. The core functionality remains […] Thank you for being a Ghacks reader.…

LibreOffice: Windows vulnerability affects links in documents, patch available

LibreOffice is a popular open source Office suite that is used by millions of users as an alternative to Microsoft Office. We have followed LibreOffice for almost 15 years here on this […] Thank you for being a Ghacks reader.…

There is a new PayPal Phishing Scam that you need to know about (using real PayPal emails)

Many PayPal users have seen their fair share of phishing emails ever since they signed up for the service. Being a financial service, PayPal is a high value target for criminal organizations. […] Thank you for being a Ghacks reader.…

Lexmark issues warning about critical security vulnerabilities in printer software

Lexmark has published several security warnings about recently disclosed vulnerabilities in Lexmark print software and firmware. Patches are provided and customers are asked to update their devices and software immediately to protect […] Thank you for being a Ghacks reader.…

Popular AI App DeepSeek Sends Unencrypted Data to ByteDance Servers

Recent security analyses have revealed that the iOS version of DeepSeek, a widely-used AI chatbot developed by a Chinese company, transmits user data unencrypted to servers controlled by ByteDance. This practice exposes […] Thank you for being a Ghacks reader.…

Mobile Malware attack used Store apps and OCR to steal cryptocurrency recovery codes

Malicious applications that are uploaded to Google’s Play Store or Apple’s App Store continue to be a problem for users worldwide. Google said that it blocked more than 2.3 million risky Android […] Thank you for being a Ghacks reader.…

Massive Data Leak Exposes 1.5 Billion Records from Chinese Platforms and Government

One of the largest data leaks in recent history has exposed a staggering 1.5 billion records, affecting major Chinese platforms, financial institutions, and even government-related entities. The unprotected dataset, discovered by Cybernews […] Thank you for being a Ghacks reader.…

Organizations with dark web presence face significantly higher breach likelihood

A recent study conducted by Searchlight Cyber in collaboration with Marsh McLennan Cyber Risk Intelligence Center has revealed a stark correlation between exposure on the dark web and heightened risks of cybersecurity […] Thank you for being a Ghacks reader.…

Bitwarden to enable two-step login for all users in the next days, sort of

Bitwarden is a popular open source password management solution that we have mentioned several times in the past. It is one of our recommended password managers. Bitwarden announced recently that it is […] Thank you for being a Ghacks reader.…

Cybersecurity Experts Warn of Privacy Risks in Modern Automobiles

A pair of hackers, Sam Curry and Shubham Shah, have exposed alarming security vulnerabilities within Subaru’s Starlink-connected infotainment system, enabling them to remotely take control of a Subaru Impreza. The duo gained […] Thank you for being a Ghacks reader.…

North America Faced Majority of Ransomware Incidents in December 2024

December 2024 saw an unprecedented surge in ransomware attacks, registering 574 incidents—the highest monthly total recorded since 2021. This spike came as shocking news, particularly as December typically experiences a decline in […] Thank you for being a Ghacks reader.…

Cybersecurity Alert: Users Deceived By Fake Google CAPTCHA Pages

In a significant security alert, cybersecurity firm CloudSek has unveiled a sophisticated phishing campaign linked to the Lumma Stealer malware, targeting Windows users. This approach leverages deceptive human verification pages that mimic […] Thank you for being a Ghacks reader.…

Microsoft changes account sign-in system to keep users logged in automatically

Microsoft is implementing a significant change to its account authentication system starting February 2025. Under the new system, users stay signed in across sessions unless they sign out explicitly. To better understand […] Thank you for being a Ghacks reader.…

VeraCrypt: update drops 32-bit support on Windows and fixes several security issues

The first update of 2025 for the open source encryption software VeraCrypt is now available. VeraCrypt 1.26.18 is a security update that is also introducing a number of fixes and other changes, […] Thank you for being a Ghacks reader.…

First Bitwarden password manager update of 2025 improves password auto-fill

Bitwarden is an open source password management solution that we have mentioned and recommended several times here on this site in the past. The developers have released the first major update of […] Thank you for being a Ghacks reader.…

iVerify: Pegasus spyware infections may be much higher than previously thought

Security experts at iVerify have developed a solution to detect traces of the spyware Pegasus on mobile devices. Pegasus is marketed as a solution to fight terrorism and crime, but governments all […] Thank you for being a Ghacks reader.…

Massive Breach at Internet Archive’s Wayback Machine – Millions of user records compromised

The Internet Archive has been hacked. The data breach has resulted in the theft of credentials of 31 million users. Good to know: The Internet Archive is a non-profit organization that aims […] Thank you for being a Ghacks reader.…

With Kaspersky banned in the US, what should customers do?

The United States are banning Kaspersky products. Starting July 20, Kaspersky is no longer allowed to sell its products to new customers. Software updates remain available until September 29, 2024. Customers who […] Thank you for being a Ghacks reader.…

TunnelVision attack against VPNs breaks anonymity and bypasses encryption

Researchers from Leviathan Security have discovered a new vulnerability that affects virtual private networks (VPNs) on most platforms. VPNs serve multiple purposes. They encrypt all traffic when connected to a VPN server […] Thank you for being a Ghacks reader.…

Bitwarden launches standalone Bitwarden Authenticator app

Bitwarden has released a first public version of Bitwarden Authenticator, a two-factor authentication app for Android and iOS. The app generates codes for services, which are then required to sign to accounts. […] Thank you for being a Ghacks reader.…

Bitwarden launches passkeys support in mobile apps for Android and iOS

Users of the password management solution Bitwarden are one step closer to full passkeys support. The organization launched new beta apps for Android and iOS earlier this month that introduced limited passkeys […] Thank you for being a Ghacks reader.…

Microsoft publishes new Registry security mitigation for Intel processors (Spectre)

About six years ago, vulnerabilities were discovered that affected most Intel and AMD processors. The vulnerabilities, Spectre and Meltdown, can be exploited to read sensitive data from attacked computer systems. Intel released […] Thank you for being a Ghacks reader.…

KeePassXC adds support for Passkeys, improves database import from Bitwarden and 1Password

KeePassXC has been updated to 2.7.7. The latest version of the open source password manager adds support for Passkeys, and has gained the ability to import your vault data from Bitwarden. Passkeys […] Thank you for being a Ghacks reader.…

RustDoor malware targets macOS users by posing as a Visual Studio Update

A new malware called RustDoor is targeting macOS users. The malware has been undetected for 3 months, and poses as a Microsoft Visual studio Update. The malware was discovered by Bitdefender. A […] Thank you for being a Ghacks reader.…

Its Groundhog Day at Microsoft! Vulnerability patched again

Remember the movie Groundhog Day? Bull Murray plays a rather self-centered weatherman who finds himself in a time loop on Groundhog Day. Windows administrators may have similar feelings to Murray’s in regards […] Thank you for being a Ghacks reader.…

The most popular passwords of 2023 are easy to guess and crack

Each year, analysts at various Internet security companies release lists of the most used (and known) passwords. These lists are based on leaked password database data. The passwords that are on these […] Thank you for being a Ghacks reader.…

Scam or not? BitDefender’s Scamio AI promises to have the answer

Scamio is a new AI tool that promises to help Internet users combat scams. Spam and scams are common on today’s Internet. Especially users who are not tech-savvy may have difficulties distinguishing […] Thank you for being a Ghacks reader.…

LogoFail vulnerability affects many Windows and Linux devices

Many commercial computers are vulnerable to a set of vulnerabilities that exploit flaws in the processing of startup logos during boot. Security researchers at Binarly have disclosed security vulnerabilities in system firmware […] Thank you for being a Ghacks reader.…

BLUFFS: new Bluetooth vulnerability discovered that affects most devices

BLUFFS is an acronym for a new Bluetooth vulnerability that security researcher Daniele Antonioli disclosed recently. BLUFFS, which stands for Bluetooth Forward and Future Secrecy, is actually a set of six unique […] Thank you for being a Ghacks reader.…

Enable 256-bit Bitlocker encryption on Windows 11 to boost security

Bitlocker is the default encryption technology of the Windows operating system. It is used widely on Windows, but some users prefer third-party solutions, such as VeraCrypt. What many users of Bitlocker don’t […] Thank you for being a Ghacks reader.…

Data of 8.5 million patients compromised in the United States

Healthcare SaaS provider Welltok has disclosed a data breach that has compromised the personal information of nearly 8.5 million patients in the United States. Welltok works with healthcare providers across the US, […] Thank you for being a Ghacks reader.…

Security researchers bypass Windows Hello fingerprint authentication

Security researchers at Blackwing Intelligence managed to bypass Windows Hello fingerprint authentication on devices with the three most used fingerprint sensors on Windows. The researchers were asked by Microsoft’s Offensive Research and […] Thank you for being a Ghacks reader.…

CVE-2023-4966 vulnerability becomes a global problem

Threat researcher Kevin Beaumont has been tracking attacks against various companies, including the Industrial and Commercial Bank of China (ICBC), DP World, Allen & Overy, and Boeing, and found they had something […] Thank you for being a Ghacks reader.…

CVE-2023-4966 vulnerability becomes a global problem

Threat researcher Kevin Beaumont has been tracking attacks against various companies, including the Industrial and Commercial Bank of China (ICBC), DP World, Allen & Overy, and Boeing, and found they had something […] Thank you for being a Ghacks reader.…

Mullvad’s public encrypted DNS Servers run in RAM now

Sweden-based VPN provider Mullvad announced today that its public encrypted DNS servers run fully in RAM. The announcement comes less than two months after Mullvad completed the migration of its VPN infrastructure […] Thank you for being a Ghacks reader.…

Suspicious Microsoft Authenticator requests don’t trigger notifications anymore

Microsoft Authenticator will suppress suspicious authentication prompts to protect users against social engineering attacks. Microsoft has now enabled the security feature, which it unveiled back in August 2023. Microsoft Authenticator is a […] Thank you for being a Ghacks reader.…

CVSS 4.0 standard has been released

The Common Vulnerability Scoring System (CVSS) is an open standard for assessing the severity of computer security vulnerabilities. CVSS scores are used by organizations and individuals around the world to prioritize vulnerability […] Thank you for being a Ghacks reader.…

Latest Bitwarden update introduces support for saving passkeys

A new version of the open source password manager Bitwarden is now available. Bitwarden 2023.10.0 introduces a number of important features to the password manager. Noteworthy additions are supported for saving passkeys […] Thank you for being a Ghacks reader.…

Watch out for StripedFly malware

Cybersecurity researchers have discovered a sophisticated cross-platform malware platform named StripedFly malware that has infected over 1 million Windows and Linux systems since 2017. The malware, which was wrongly classified as just […] Thank you for being a Ghacks reader.…

Tor Browser Security Audit reveals 2 high security issues

The Tor Browser project asked the penetration testers at Cure53 to audit core components of the project. Among the components were the BridgeDB software, building infrastructure, specific Tor Browser alterations and rdsys […] Thank you for being a Ghacks reader.…

Google to launch Android Earthquake Alerts in India

Earthquakes, one of the most frequent natural disasters globally, have the potential to cause widespread destruction and loss of life. In such dire circumstances, having advanced warning systems can be the difference […] Thank you for being a Ghacks reader.…

Google confirms CVE-2023-5129 is the hidden threat in Libwebp

Google’s recent confirmation of an exploited Chrome zero-day, CVE-2023-5129, has taken the cybersecurity world by storm. This exploit has a ripple effect that extends beyond Chrome, affecting numerous popular applications that rely […] Thank you for being a Ghacks reader.…

Nintendo adds Passkey passwordless authentication support to accounts

Nintendo users who have created an account at Nintendo may now switch to passwordless authentication thanks to passkey integration. Nintendo Switch users do not need an online account to use their device […] Thank you for being a Ghacks reader.…

LastPass to enforce minimum Master Password length of 12 characters

LastPass announced today (via email) that the requirements for the master password have been changed. The master password is the primary password used to gain access to accounts. In an email, LastPass […] Thank you for being a Ghacks reader.…

LastPass to enforce minimum Master Password length of 12 characters

LastPass announced today (via email) that the requirements for the master password have been changed. The master password is the primary password used to gain access to accounts. In an email, LastPass […] Thank you for being a Ghacks reader.…

Microsoft offers an explanation for the hack of its cloud

Bugs and coincidences seem to have allowed Chinese-based hacking group Storm-0558 to steal a private MSA key from Microsoft and gain access to the accounts of organizations, including American government agencies. The […] Thank you for being a Ghacks reader.…

UK Government withdraws proposal for controversial spy clause in its Online Safety Bill

The UK Government has announced that it will not scan users’ messages for harmful content. The announcement comes after Apple, WhatsApp and Signal had threatened to remove their messaging services from Britain […] Thank you for being a Ghacks reader.…

Critical security vulnerabilities in ASUS routers — update immediately

Three ASUS Wi-Fi routers are vulnerable to three critically rated remote code execution vulnerabilities that can be exploited by malicious actors to take over the devices. The affected wireless routers are the […] Thank you for being a Ghacks reader.…

Microsoft publishes mitigation instructions for Downfall vulnerability in Windows

Microsoft published a support article about the recently disclosed CVE-2022-40982 vulnerability, commonly referred to as Downfall, that affects Windows devices. The vulnerability was disclosed earlier this month. It affects several Intel processor […] Thank you for being a Ghacks reader.…

WinRAR security issue more wide-reaching than thought

A recently disclosed security issue in the archiving software WinRAR is affecting other software programs as well. The developers of WinRAR released version 6.23 of the popular archiving software earlier this month. […] Thank you for being a Ghacks reader.…

Privacy is Sexy: custom privacy scripts for Windows, Linux and macOS

Privacy is Sexy is a free service that allows users of desktop operating systems to improve their privacy by creating and executing custom scripts. The service is available for Windows, Linux and […] Thank you for being a Ghacks reader.…

Proton Sentinel: next level account security protection for (almost) everyone

Proton, maker of Proton Mail, VPN and several other services, announced the launch of Proton Sentinel earlier today. Proton Sentinel is a security add-on for Proton accounts that enables higher levels of […] Thank you for being a Ghacks reader.…

LinkedIn hack: You need to check your LinkedIn account

If you want to understand the ongoing LinkedIn hack easily, picture this: profiles locked, passwords changed, and the unsettling realization that unseen hands have infiltrated your professional realm. The battleground is set, […] Thank you for being a Ghacks reader.…

Discord.io data breach: 760K users affected

Following the Discord.io data breach, the custom invite platform has paused its operations, revealing the personal data of 760,000 users. Discord.io, a third-party entity distinct from the official Discord brand, enables server […] Thank you for being a Ghacks reader.…

LastPass improves passwordless logins with FIDO2 authenticator support for desktops

Lastpass, maker of the password management service of the same name, announced today that customers may now use FIDO2 compatible authenticators on desktop devices for passwordless logins to their vaults. The new […] Thank you for being a Ghacks reader.…

Microsoft Authenticator will soon provide codes via WhatsApp

Microsoft is working on two improvements for its Microsoft Authenticator application. The first tests the delivery of authentication codes via Meta’s WhatsApp application instead of SMS, the second attempts to limit Authenticator […] Thank you for being a Ghacks reader.…

0Patch promises to support Windows Server 2012 and 2012 R2 with 3 years of security updates

Microsoft is ending support for Windows Server 2012 and Windows Server 2012 R2 in October 2023. Just like the recently dropped operating systems Windows 7 and Windows 8.1, Windows Server 2012 will […] Thank you for being a Ghacks reader.…

Get Protected the Right Way with Avast Free Antivirus

Today’s internet safety is difficult to assess. Whereas the internet of yesteryear was a bit like the Far West, where only adventurous spirits wandered into the unknown, it’s a completely different picture […] Thank you for being a Ghacks reader.…

Hackers targeting air-gapped devices in Eastern Europe with new malware

A concerning cyber threat has emerged in Eastern Europe, where Chinese state-sponsored hackers are employing a new and sophisticated malware to breach air-gapped devices. These malicious actors, associated with the cyber espionage […] Thank you for being a Ghacks reader.…

Roblox data leak may have affected nearly 4000 users

On July 19, 2023, a data breach at Roblox exposed sensitive user information from attendees of the 2017-2020 Roblox Developers Conferences. The leaked list contained 4,000 unique email addresses, alongside personal details […] Thank you for being a Ghacks reader.…