A fortnight in to 2020 and we have the first security flaw to be given its own name: Cable Haunt – complete with eye-catching logo. | Continue reading
We said, “Assume that someone will find out how to do it pretty soon,” and that’s exactly what happened. | Continue reading
New research has heightened an already urgent call to abandon SHA-1, a cryptographic algorithm still used in many popular online services. | Continue reading
Turns out that if you drop your CPU voltage just enough, it makes mistakes that could let you sneak in where you shouldn’t. | Continue reading
The Russian ‘Sandworm’ hacking group has been caught repeatedly uploading fake and modified Android apps to Google’s Play Store. | Continue reading
Android could be returning to its roots. | Continue reading
The voice had the hint of a German accent and the same “melody” that an employee recognized in his boss’s voice. | Continue reading
Researchers have found a flaw that could lead to denial of service attacks on content distribution networks around the world. | Continue reading
The fingerprint reader on Samsung’s flagship S10 and Note10 smartphones can be spoofed with a $3 screen protector. | Continue reading
According to a new report, its algorithmic labelling may expose minors to age-inappropriate, targeted advertising. | Continue reading
Police overcame not only digital defenses of the “bulletproof” provider CyberBunker but also barbed wire fences and surveillance cams. | Continue reading
Admins have a spot of patching work on their hands after the company released updates addressing two critical flaws. | Continue reading
Google has discovered a flaw in a Chromebook security feature which allows owners to press their device’s power button to initiate U2F 2FA. | Continue reading
Mozilla is about to turn on-by-default an oft-overlooked privacy feature in Firefox. | Continue reading
How did the Correct Horse Battery get Stapled? | Continue reading
Google is patching a serious bug in the desktop version of its Chrome browser that could let an attacker take over a computer simply by luring them to a website. | Continue reading
More than a decade after hitting the headlines, clickjacking fraud remains an under-reported hazard on hundreds of popular websites. | Continue reading
Netflix has identified several denial of service (DoS) flaws in HTTP/2, a popular network protocol that underpins large parts of the web. Exploiting them could bring servers grinding to a halt. | Continue reading
The class action charges Capital One and GitHub, charging it with being “friendly” (at least) toward hacking and for the hackers’ posts. | Continue reading
Apple Watch and HomePod have the highest rate of inadvertent recordings, a whistleblower says. | Continue reading
At some dark moment, have you ever wondered: what if the programmers are adding the bugs deliberately? | Continue reading
Google’s throwing in the towel on XSS Auditor and putting its trust in Trusted Types instead. | Continue reading
Apple disabled the app after somebody reported a bug – not exploited yet – that could allow an eavesdropper to listen in on another iPhone. | Continue reading
It’s outside of Sidewalk Labs HQ in Toronto, where Google’s sister company is working on stuffing the city with data-collecting sensors. | Continue reading
“We don’t need to regulate it, we need to ban it entirely.” | Continue reading
An eagle-eyed developer has discovered a backdoor recently sneaked into a library (or ‘gem’) used by Ruby on Rails (RoR) web apps to check password strength. | Continue reading
An open letter from the OpenID Foundation says that Apple introduced potential risks when it diverged from the OpenID Connect protocol. | Continue reading
Halloween came a little early for some Android users this year after a horror-themed computer game was found stealing their account credentials and displaying potentially malicious ads. | Continue reading
A deepfake was reportedly spotted in the wild: LinkedIn’s well-connected, young, attractive Eurasia/Russia expert “Katie Jones.” | Continue reading
Hugely popular news aggregation site Flipboard – one billion app downloads from Google Play and counting – has become the latest internet company to admit it has suffered a breach. | Continue reading
Suse developer Aleksa Sarai has uncovered a bug in the way that the container framework handles path names. | Continue reading
One of the US’s most widely used vehicle license plate reader (LPR) companies, Perceptics, is reportedly investigating a data breach. | Continue reading
Unpatched Linux systems are vulnerable to remote compromise from the local network. | Continue reading
Microsoft has fixed an RDP vulnerability that can be exploited remotely, without authentication and used to run arbitrary code. | Continue reading
Belgian coder Bernard Fabrot just finished a 3.5-year computational marathon, solving a fascinating cryptopuzzle set at MIT back in 1999. | Continue reading
DNS over HTTPS (DoH), backed by Google, Mozilla and Cloudflare, is about to make web surveillance a lot more difficult. | Continue reading
Nearly four years after it was replaced by Edge as Microsoft’s preferred Windows browser, researchers keep finding unpleasant security flaws in Internet Explorer (IE). | Continue reading
Forthcoming versions of the Chrome, Apple Safari and Opera are in the process of removing the ability to disable a long-ignored tracking feature called hyperlink auditing pings. | Continue reading
They’re facing charges of computer criminal activity after allegedly disrupting the network at the request of their friends. | Continue reading
Tomorrow night, the GPS “earth clock” has a Y2K event – but here’s why you should be OK. | Continue reading
Researchers have found that one of the most popular source code repositories in the world is still housing thousands of publicly accessible user credentials. | Continue reading
He was fired after four weeks, ripped off the credentials of former colleague “Speedy”, and will be mulling it all over for two years in jail. | Continue reading
He was fired after four weeks, ripped off the credentials of former colleague “Speedy”, and will be mulling it all over for two years in jail. | Continue reading
The researcher says it works without root or administrator privileges and without password prompts. But he’s not revealing how it works to Apple because there’s no money for him in its … | Continue reading
A researcher has discovered an alarming way that an attacker controlling a Microsoft Exchange mailbox account could potentially elevate their privileges to become a Domain Administrator. | Continue reading
Users of Microsoft’s Azure system lost database records as part of a mass outage on Tuesday. A combination of DNS problems and automated scripts were to blame, said reports. | Continue reading
A proof of concept attack uses malware to turn headphones into microphones that can eavesdrop from across a room. | Continue reading
An experiment to make the internet safer ended up breaking parts of it last week. | Continue reading