Category: News

Bogus Cryptomining Apps Infest Google Play

The apps attempt to swindle users into buying in-app upgrades or clicking on masses of ads.

T-Mobile: >40 Million Customers’ Data Stolen

Attackers stole tens of millions of current, former or prospective customers’ personal data, the company confirmed. It’s providing 2 years of free ID protection.

Memory Bugs in BlackBerry’s QNX Embedded OS Open Devices to Attacks

The once-dominant handset maker BlackBerry is busy squashing BadAlloc bugs in its QNX real-time operating system used in cars in medical devices.

Kerberos Authentication Spoofing: Don’t Bypass the Spec

Yaron Kassner, CTO at Silverfort, discusses authentication-bypass bugs in Cisco ASA, F5 Big-IP, IBM QRadar and Palo Alto Networks PAN-OS.

Unpatched Fortinet Bug Allows Firewall Takeovers

The OS command-injection bug, in the web application firewall (WAF) platform known as FortiWeb, will get a patch at the end of the month.

HolesWarm Malware Exploits Unpatched Windows, Linux Servers   

The botnet cryptominer has already compromised 1,000-plus clouds since June.

The Overlooked Security Risks of The Cloud

Nate Warfield, CTO of Prevaliion, discusses the top security concerns for those embracing virtual machines, public cloud storage and cloud strategies for remote working.

LockBit 2.0 Ransomware Proliferates Globally

Fresh attacks target companies’ employees, promising millions of dollars in exchange for valid account credentials for initial access.

Bug in Millions of Flawed IoT Devices Lets Attackers Eavesdrop

A remote attacker could exploit a critical vulnerability to eavesdrop on live audio & video or take control. The bug is in ThroughTek’s Kalay network, used in 83m devices.

Terrorist Watchlist Exposed Online with Nearly 1.9M Records

A researcher discovered a data cache from the FBI’s Terrorist Screening Center left online without a password or authentication requirement.