FreshRSS

🔒
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ ☆ ✇ The Hacker News

FBI Warns U.S. Healthcare Sector of Targeted BlackCat Ransomware Attacks

By: Newsroom — February 28th 2024 at 13:06
The U.S. government is warning about the resurgence of BlackCat (aka ALPHV) ransomware attacks targeting the healthcare sector as recently as this month. "Since mid-December 2023, of the nearly 70 leaked victims, the healthcare sector has been the most commonly victimized," the government said in an updated advisory. "This is likely in response to the ALPHV/BlackCat administrator's
☐ ☆ ✇ The Hacker News

SaaS Compliance through the NIST Cybersecurity Framework

By: The Hacker News — February 20th 2024 at 10:53
The US National Institute of Standards and Technology (NIST) cybersecurity framework is one of the world's most important guidelines for securing networks. It can be applied to any number of applications, including SaaS.  One of the challenges facing those tasked with securing SaaS applications is the different settings found in each application. It makes it difficult to develop a
☐ ☆ ✇ The Hacker News

LockBit Ransomware's Darknet Domains Seized in Global Law Enforcement Raid

By: Newsroom — February 20th 2024 at 05:25
Update: The U.K. National Crime Agency (NCA) has confirmed the takedown of LockBit infrastructure. Read here for more details.An international law enforcement operation has led to the seizure of multiple darknet domains operated by LockBit, one of the most prolific ransomware groups, marking the latest in a long list of digital takedowns. While the full extent of the effort, codenamed 
☐ ☆ ✇ The Hacker News

U.S. Offers $10 Million Bounty for Info Leading to Arrest of Hive Ransomware Leaders

By: Newsroom — February 12th 2024 at 04:31
The U.S. Department of State has announced monetary rewards of up to $10 million for information about individuals holding key positions within the Hive ransomware operation. It is also giving away an additional $5 million for specifics that could lead to the arrest and/or conviction of any person "conspiring to participate in or attempting to participate in Hive ransomware activity."
☐ ☆ ✇ The Hacker News

Why Public Links Expose Your SaaS Attack Surface

By: The Hacker News — January 9th 2024 at 11:27
Collaboration is a powerful selling point for SaaS applications. Microsoft, Github, Miro, and others promote the collaborative nature of their software applications that allows users to do more. Links to files, repositories, and boards can be shared with anyone, anywhere. This encourages teamwork that helps create stronger campaigns and projects by encouraging collaboration among employees
☐ ☆ ✇ The Hacker News

Make a Fresh Start for 2024: Clean Out Your User Inventory to Reduce SaaS Risk

By: The Hacker News — December 4th 2023 at 11:38
As work ebbs with the typical end-of-year slowdown, now is a good time to review user roles and privileges and remove anyone who shouldn’t have access as well as trim unnecessary permissions. In addition to saving some unnecessary license fees, a clean user inventory significantly enhances the security of your SaaS applications. From reducing risk to protecting against data leakage, here is how
☐ ☆ ✇ The Hacker News

How to Handle Retail SaaS Security on Cyber Monday

By: The Hacker News — November 27th 2023 at 17:57
If forecasters are right, over the course of today, consumers will spend $13.7 billion. Just about every click, sale, and engagement will be captured by a CRM platform. Inventory applications will trigger automated re-orders; communication tools will send automated email and text messages confirming sales and sharing shipping information.  SaaS applications supporting retail efforts
☐ ☆ ✇ The Hacker News

ServiceNow Data Exposure: A Wake-Up Call for Companies

By: The Hacker News — October 30th 2023 at 11:47
Earlier this week, ServiceNow announced on its support site that misconfigurations within the platform could result in “unintended access” to sensitive data. For organizations that use ServiceNow, this security exposure is a critical concern that could have resulted in major data leakage of sensitive corporate data. ServiceNow has since taken steps to fix this issue.  This article fully analyzes
☐ ☆ ✇ The Hacker News

The Danger of Forgotten Pixels on Websites: A New Case Study

By: The Hacker News — October 26th 2023 at 11:59
While cyberattacks on websites receive much attention, there are often unaddressed risks that can lead to businesses facing lawsuits and privacy violations even in the absence of hacking incidents. A new case study highlights one of these more common cases.  Download the full case study here. It's a scenario that could have affected any type of company, from healthcare to finance, e-commerce to
☐ ☆ ✇ The Hacker News

Live Webinar: Overcoming Generative AI Data Leakage Risks

By: The Hacker News — September 19th 2023 at 10:29
As the adoption of generative AI tools, like ChatGPT, continues to surge, so does the risk of data exposure. According to Gartner’s "Emerging Tech: Top 4 Security Risks of GenAI" report, privacy and data security is one of the four major emerging risks within generative AI. A new webinar featuring a multi-time Fortune 100 CISO and the CEO of LayerX, a browser extension solution, delves into this
☐ ☆ ✇ The Hacker News

Microsoft AI Researchers Accidentally Expose 38 Terabytes of Confidential Data

By: THN — September 19th 2023 at 04:05
Microsoft on Monday said it took steps to correct a glaring security gaffe that led to the exposure of 38 terabytes of private data. The leak was discovered on the company's AI GitHub repository and is said to have been inadvertently made public when publishing a bucket of open-source training data, Wiz said. It also included a disk backup of two former employees' workstations containing secrets
☐ ☆ ✇ Naked Security

“Snakes in airplane mode” – what if your phone says it’s offline but isn’t?

By: Paul Ducklin — August 21st 2023 at 17:45
WYSIWYG is short for "what you see is what you get". Except when it isn't...

☐ ☆ ✇ Naked Security

S3 Ep147: What if you type in your password during a meeting?

By: Paul Ducklin — August 10th 2023 at 13:34
Latest episode - listen now! (Full transcript inside.)

☐ ☆ ✇ Naked Security

Serious Security: Why learning to touch-type could protect you from audio snooping

By: Paul Ducklin — August 8th 2023 at 18:51
Fast, quiet, smooth, consistent and low impact... why true hacker-grade touch-typing might keep you more secure.

☐ ☆ ✇ Naked Security

S3 Ep146: Tell us about that breach! (If you want to.)

By: Paul Ducklin — August 3rd 2023 at 17:56
Serious security stories explained clearly in plain English - listen now. (Full transcript available.)

☐ ☆ ✇ Naked Security

Google Virus Total leaks list of spooky email addresses

By: Paul Ducklin — July 18th 2023 at 23:16
Careful with that file, Eugene!

☐ ☆ ✇ The Hacker News

VirusTotal Data Leak Exposes Some Registered Customers' Details

By: THN — July 18th 2023 at 11:34
Data associated with a subset of registered customers of VirusTotal, including their names and email addresses, were exposed after an employee inadvertently uploaded the information to the malware scanning platform. The security incident, which comprises a database of 5,600 names in a 313KB file, was first disclosed by Der Spiegel and Der Standard yesterday. Launched in 2004, VirusTotal is a
☐ ☆ ✇ Naked Security

Serious Security: Rowhammer returns to gaslight your computer

By: Paul Ducklin — July 10th 2023 at 21:22
Gaslights produce a telltale flicker when nearby lamps are lit; DRAM values do something similar when nearby memory cells are accessed.

☐ ☆ ✇ The Hacker News

Password Reset Hack Exposed in Honda's E-Commerce Platform, Dealers Data at Risk

By: Ravie Lakshmanan — June 12th 2023 at 08:26
Security vulnerabilities discovered in Honda's e-commerce platform could have been exploited to gain unrestricted access to sensitive dealer information. "Broken/missing access controls made it possible to access all data on the platform, even when logged in as a test account," security researcher Eaton Zveare said in a report published last week. The platform is designed for the sale of power
☐ ☆ ✇ The Hacker News

Taiwanese PC Company MSI Falls Victim to Ransomware Attack

By: Ravie Lakshmanan — April 8th 2023 at 14:37
Taiwanese PC company MSI (short for Micro-Star International) officially confirmed it was the victim of a cyber attack on its systems. The company said it "promptly" initiated incident response and recovery measures after detecting "network anomalies." It also said it alerted law enforcement agencies of the matter. That said, MSI did not disclose any specifics about when the attack took place
☐ ☆ ✇ Naked Security

Windows 11 also vulnerable to “aCropalypse” image data leakage

By: Paul Ducklin — March 22nd 2023 at 17:59
Turns out that the Windows 11 Snipping Tool has the same "aCropalypse" data leakage bug as Pixel phones. Here's how to work around the problem...

☐ ☆ ✇ Naked Security

SHEIN shopping app goes rogue, grabs price and URL data from your clipboard

By: Paul Ducklin — March 10th 2023 at 17:58
It's not exactly data theft, but it's worryingly close to "unintentional treachery" - apparently because it's great for marketing purposes

☐ ☆ ✇ Naked Security

Password-stealing “vulnerability” reported in KeePass – bug or feature?

By: Paul Ducklin — February 1st 2023 at 18:58
Is it a vulnerability if someone with control over your account can mess with files that your account is allowed to access anyway?

☐ ☆ ✇ Naked Security

Public URL scanning tools – when security leads to insecurity

By: Paul Ducklin — November 7th 2022 at 17:59
Never make your users cry/By how you use an API

☐ ☆ ✇ Naked Security

Breaching airgap security: using your phone’s gyroscope as a microphone

By: Paul Ducklin — August 24th 2022 at 18:59
One bit per second makes the Voyager probe data rate seem blindingly fast. But it's enough to break your security assumptions...

☐ ☆ ✇ Naked Security

WordPress backup plugin maker Updraft says “You should update”…

By: Paul Ducklin — February 22nd 2022 at 17:26
A straight-talking bug report written in plain English by an actual expert - there's a teachable moment in this cybersecurity story!

☐ ☆ ✇ Naked Security

Serious Security: Apple Safari leaks private data via database API – what you need to know

By: Paul Ducklin — January 18th 2022 at 17:23
There's a tiny data leakage bug in the WebKit browser engine... but it could act as a "supercookie" identifier for your browsing

☐ ☆ ✇ Naked Security

The cool retro phone with a REAL DIAL… plus plenty of IoT problems

By: Paul Ducklin — December 23rd 2021 at 17:58
You know you want one, because this retro phone is NOT A TOY... except when it comes to cybersecurity.

☐ ☆ ✇ Naked Security

Github cookie leakage – thousands of Firefox cookie files uploaded by mistake

By: Paul Ducklin — November 18th 2021 at 22:20
Be aware before you share! That's a good rule for developers and techies, just as much as it is for social media addicts.

❌