Tag: SecurityWeek RSS Feed

Chrome Will Block Insecure Downloads on HTTPS Pages

In an attempt to improve the security of its users, the Chrome browser will soon start blocking insecure downloads on HTTPS pages, Google announced. The plan, which the Internet giant laid out this week, is expected to be completed sometime…

Brazil Judge Rejects Hacking Accusation Against Greenwald

A judge in Brazil’s capital on Thursday dismissed accusations that journalist Glenn Greenwald was involved in hacking phones of officials, following weeks of criticism that his prosecution would infringe on constitutional protections for the press. read more   Advertise on…

DLL Hijacking Vulnerability Found in Realtek HD Audio Driver

A vulnerability in the Realtek HD Audio Driver package could be abused to execute arbitrary payloads with elevated privileges on a vulnerable machine, SafeBreach Labs has discovered. Tracked as CVE-2019-19705, the vulnerability could be leveraged to evade defenses and achieve…

Chrome 80 Released With 56 Security Fixes

Google this week released Chrome 80 to the stable channel with 56 vulnerability patches and various other improvements to user security. read more   Advertise on IT Security News. Read the complete article: Chrome 80 Released With 56 Security Fixes

Google Shared Private Videos With Wrong Users

A bug in the Google Takeout download service has resulted in some users’ videos being inadvertently shared with other people.  read more   Advertise on IT Security News. Read the complete article: Google Shared Private Videos With Wrong Users

CERN Physics Lab Drops Facebook Over Data Concerns

Europe’s physics lab CERN on Wednesday said it had stopped using a Facebook team-chat application because of concerns about handing over data to the US tech giant. CERN said it had wound up its Facebook Workplace account on January 31…

Vulnerability in WhatsApp Desktop Exposed User Files

Facebook has patched a vulnerability in WhatsApp Desktop that could allow an attacker to launch cross-site scripting (XSS) attacks and access files from the victim’s system when paired with WhatsApp for iPhone. read more   Advertise on IT Security News.…

Iowa Fiasco Highlights Security Risks in US Vote, Officials Say

US officials and cyber experts warned Tuesday that the voting debacle in the Democratic caucuses in Iowa underscored the vulnerabilities in the country’s election infrastructure in everything from hacking to trust-eroding conspiracy theories. read more   Advertise on IT Security…

Vulnerabilities in Mini-SNMPD Lead to DoS, Information Disclosure

Vulnerabilities recently patched in Mini-SNMPD could be abused for denial-of-service (DoS) attacks or to obtain sensitive information, Cisco Talos’ security researchers report. read more   Advertise on IT Security News. Read the complete article: Vulnerabilities in Mini-SNMPD Lead to DoS,…

HPE Acquires Identity Management Firm Scytale

Hewlett Packard Enterprise (HPE) on Monday announced that it has acquired Scytale, an identity management startup that specializes in cloud-native security and zero trust networking. read more   Advertise on IT Security News. Read the complete article: HPE Acquires Identity…

Changing the Disclosure Shame Culture

For Cyberdefense to Progress, We Must Break Through the Cultural Barrier of Breach Disclosure Shame read more   Advertise on IT Security News. Read the complete article: Changing the Disclosure Shame Culture

Australian Shipping Giant Toll Hit by Ransomware

Australian transportation and logistics giant Toll Group was forced to shut down some of its online services in response to a ransomware attack and customers are not happy with the way the company has handled the incident. read more  …

Six Arrested in UK Over Malta Bank Cyber-Heist

Six individuals were arrested in the United Kingdom last week for their involvement in a bank cyber-heist and money laundering operation. read more   Advertise on IT Security News. Read the complete article: Six Arrested in UK Over Malta Bank…

Elevate Your Intelligence Game

Over the past five years, Cyber threat intelligence (CTI) has become one of the fastest growing elements in the cybersecurity space. Gartner expects as much as $2.3 billion to spent on it by 2023. read more   Advertise on IT…

Election Officials Get Training Before 2020 Voting Begins

When state election officials gathered ahead of the last presidential election, major topics were voter registration, identity theft and ballot design. This year, the main theme is election security. read more   Advertise on IT Security News. Read the complete…

New Project Informs Security Teams of Phished Users

A newly launched project wants to help inform IT security representatives and domain owners when their users fall victim to phishing. read more   Advertise on IT Security News. Read the complete article: New Project Informs Security Teams of Phished…

US Says EU Understands 5G Risks But Pushes on Huawei

The United States on Thursday welcomed the European Union’s new rules on fifth-generation internet but pressed them to go further after the bloc resisted Washington’s pressure to ban China’s Huawei directly. read more   Advertise on IT Security News. Read…

Hackers Can Earn $20,000 for Xbox Vulnerabilities

Microsoft on Thursday announced the launch of an Xbox bug bounty program with rewards of up to $20,000 for critical remote code execution vulnerabilities. read more   Advertise on IT Security News. Read the complete article: Hackers Can Earn $20,000…

Devices Still Vulnerable to DMA Attacks Despite Protections

Many devices, including ones often found in enterprise environments, are likely still vulnerable to direct memory access (DMA) attacks, despite the fact that hardware and software vendors have implemented protections that should prevent such attacks, firmware security company Eclypsium said…

SEO Spam Dominated Website Infections in 2019: Report

Last year, SEO spam was the most frequently observed threat on compromised websites, according to a new report from GoDaddy-owned web security company Sucuri. read more   Advertise on IT Security News. Read the complete article: SEO Spam Dominated Website…

EU Stops Short of Recommending Ban on China’s Huawei

LONDON (AP) — The European Union unveiled security guidelines for next generation high-speed wireless networks that stop short of calling for a ban on Huawei, in the latest setback for the U.S. campaign against the Chinese tech company. read more…

Serious Vulnerability Discovered in OpenSMTPD

Researchers at cybersecurity firm Qualys have identified a potentially serious vulnerability in OpenSMTPD that can allow remote command execution with elevated privileges. read more   Advertise on IT Security News. Read the complete article: Serious Vulnerability Discovered in OpenSMTPD

Leaked Report Shows United Nations Suffered Hack

The United Nations has been hacked. An internal confidential document from the United Nations, leaked to The New Humanitarian and seen by The Associated Press, says that dozens of servers were “compromised” at offices in Geneva and Vienna. read more…

Russia Blocks Swiss-based ProtonMail Over Wave of Bomb Threats

Russia has blocked a second encrypted email provider, Swiss-based ProtonMail, in efforts to halt a prolonged series of anonymous bomb threats, the security service said Wednesday. The FSB security service said Russia acted against Geneva-based ProtonMail after blocking another social…

Ring Doorbell App for Android Sends Out Loads of User Data

The Ring doorbell application for Android contains third-party trackers and sends out a large amount of personally identifiable information (PII), the Electronic Frontier Foundation (EFF) has discovered. read more   Advertise on IT Security News. Read the complete article: Ring…

Vulnerability Allowed Attackers to Join Zoom Meetings

A vulnerability in the Zoom online meeting system could allow attackers eavesdrop on meetings and view all shared content, Check Point security researchers have discovered.  read more   Advertise on IT Security News. Read the complete article: Vulnerability Allowed Attackers…

New Snake Ransomware Targets ICS Processes

A recently uncovered piece of file-encrypting ransomware, which some believe may be linked to Iran, has been targeting processes and files associated with industrial control systems (ICS). read more   Advertise on IT Security News. Read the complete article: New…

Engaging the Attacker Prior to Impact

Engaging Attacker Prior to Impact Will Significantly Reduce the Overall Operational Risk of Your Networks read more   Advertise on IT Security News. Read the complete article: Engaging the Attacker Prior to Impact

UK Approves Restricted Huawei Role in 5G Network

Britain on Tuesday greenlighted a limited role for Chinese telecoms giant Huawei in the country’s 5G network, but underscored that “high risk vendors” would be excluded from “sensitive” core infrastructure. read more   Advertise on IT Security News. Read the…

Cisco Launches Industrial IoT Security Solution

Cisco on Tuesday announced the launch of a security solution for the Industrial Internet of Things (IIoT) that is designed to help organizations identify threats across their IT and OT environments. read more   Advertise on IT Security News. Read…

German Privacy Watchdog Investigates Clothing Retailer H&M

A German privacy watchdog says it has opened an investigation into clothing retailer H&M amid evidence that the Swedish retailer had committed “massive data protection breaches” by spying on its customer service representatives in Germany. read more   Advertise on…

Three Magecart Hackers Arrested in Indonesia

Three individuals suspected of being involved in Magecart online skimming attacks were arrested late last year in Indonesia. read more   Advertise on IT Security News. Read the complete article: Three Magecart Hackers Arrested in Indonesia

NSA Shares Guidance on Mitigating Cloud Vulnerabilities

The U.S. National Security Agency (NSA) has published advice on mitigating cloud vulnerabilities. While the advice is primarily designed for government agencies and departments, it nevertheless contains good advice for any commercial organization considering or embarking on — or already…

Trump, Johnson Talk Security Ahead of Huawei Decision

Prime Minister Boris Johnson discussed telecoms security with US President Donald Trump as he prepares to announce if Britain will use China’s Huawei in its 5G networks, officials said Saturday. read more   Advertise on IT Security News. Read the…

Questions Linger Over Investigation Into Jeff Bezos’ Hacking

Cybersecurity experts said Thursday there were still many unanswered questions from an investigation commissioned by Jeff Bezos that concluded the billionaire’s cellphone was hacked, apparently after receiving a video file with malicious spyware from the WhatsApp account of Saudi Arabia’s…