Wed.Nov 13, 2024

article thumbnail

Inside the DemandScience by Pure Incubation Data Breach

Troy Hunt

Apparently, before a child reaches the age of 13, advertisers will have gathered more 72 million data points on them. I knew I'd seen a metric about this sometime recently, so I went looking for "7,000", which perfectly illustrates how unaware we are of the extent of data collection on all of us. I started Have I Been Pwned (HIBP) in the first place because I was surprised at where my data had turned up in breaches. 11 years and 14 billion breached records later, I'm still surp

article thumbnail

Mapping License Plate Scanners in the US

Schneier on Security

DeFlock is a crowd-sourced project to map license plate scanners. It only records the fixed scanners, of course. The mobile scanners on cars are not mapped. The post Mapping License Plate Scanners in the US appeared first on Schneier on Security.

Mobile 235
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Digital Identities: Getting to Know the Verifiable Digital Credential Ecosystem

NSTIC

If you are interested in the world of digital identities, you have probably heard some of the buzzwords that have been floating around for a few years now… “verifiable credential,” “digital wallet,” “mobile driver’s license” or “mDL.” These terms, among others, all reference a growing ecosystem around what we are calling “verifiable digital credentials.

Insurance 122
article thumbnail

OvrC Platform Vulnerabilities Expose IoT Devices to Remote Attacks and Code Execution

The Hacker News

A security analysis of the OvrC cloud platform has uncovered 10 vulnerabilities that could be chained to allow potential attackers to execute code remotely on connected devices.

IoT 112
article thumbnail

Optimizing The Modern Developer Experience with Coder

Many software teams have migrated their testing and production workloads to the cloud, yet development environments often remain tied to outdated local setups, limiting efficiency and growth. This is where Coder comes in. In our 101 Coder webinar, you’ll explore how cloud-based development environments can unlock new levels of productivity. Discover how to transition from local setups to a secure, cloud-powered ecosystem with ease.

article thumbnail

China’s Volt Typhoon botnet has re-emerged

Security Affairs

China’s Volt Typhoon botnet has re-emerged, using the same core infrastructure and techniques, according to SecurityScorecard researchers. The China-linked Volt Typhoon’s botnet has resurfaced using the same infrastructure and techniques, per SecurityScorecard researchers. In May 2023, Microsoft reported that the Volt Typhoon APT infiltrated critical infrastructure organizations in the U.S. and Guam without being detected.

VPN 112
article thumbnail

Free Decryptor Released for BitLocker-Based ShrinkLocker Ransomware Victims

The Hacker News

Romanian cybersecurity company Bitdefender has released a free decryptor to help victims recover data encrypted using the ShrinkLocker ransomware.

More Trending

article thumbnail

These 20 D-Link Devices Have Critical RCE Bug — but NO Patch NEVER

Security Boulevard

‘Bobby’ flaw flagged WONTFIX: Company doesn’t make storage devices now; has zero interest in fixing this catastrophic vulnerability. The post These 20 D-Link Devices Have Critical RCE Bug — but NO Patch NEVER appeared first on Security Boulevard.

Internet 110
article thumbnail

Russian Hackers Exploit New NTLM Flaw to Deploy RAT Malware via Phishing Emails

The Hacker News

A newly patched security flaw impacting Windows NT LAN Manager (NTLM) was exploited as a zero-day by a suspected Russia-linked actor as part of cyber attacks targeting Ukraine. The vulnerability in question, CVE-2024-43451 (CVSS score: 6.5), refers to an NTLM hash disclosure spoofing vulnerability that could be exploited to steal a user's NTLMv2 hash.

Phishing 105
article thumbnail

Bitdefender released a decryptor for the ShrinkLocker ransomware

Security Affairs

Bitdefender released a decryptor for the ShrinkLocker ransomware, which modifies BitLocker configurations to encrypt a system’s drives. ShrinkLocker ransomware was first discovered in May 2024 by researchers from Kaspersky. Unlike modern ransomware it doesn’t rely on sophisticated encryption algorithms and modifies BitLocker configurations to encrypt a system’s drives.

article thumbnail

7 things to know about Bluesky before you join - and why you should

Zero Day

It's not a direct replacement for Twitter (X), but Bluesky has a lot to offer those who want a fresh start in a decentralized, privacy-minded network.

140
140
article thumbnail

The Tumultuous IT Landscape Is Making Hiring More Difficult

After a year of sporadic hiring and uncertain investment areas, tech leaders are scrambling to figure out what’s next. This whitepaper reveals how tech leaders are hiring and investing for the future. Download today to learn more!

article thumbnail

Teen Behind Hundreds of Swatting Attacks Pleads Guilty to Federal Charges

WIRED Threat Level

Alan Filion, believed to have operated under the handle “Torswats,” admitted to making more than 375 fake threats against schools, places of worship, and government buildings around the United States.

article thumbnail

How to add PGP support on Android for added security and privacy

Zero Day

If you need to add encryption or digital signing to the Thunderbird email app (or other supporting apps) on Android, there's one clear and easy route to success.

article thumbnail

SSL Certificate Best Practices Policy

Tech Republic Security

SSL certificates are essential for encrypting traffic between systems such as clients, which access servers via web browsers or applications that communicate with remote systems. Certificates protect client and server data, commonly involving confidential information such as credit card details or social security numbers. The purpose of this SSL Certificate Best Practices Policy, created by.

article thumbnail

Upgrade to Microsoft Office Pro and Windows 11 Pro for 87% off with this bundle

Zero Day

This lifetime license bundle deal gives you access to the entire Microsoft Office Pro 2021 suite and Windows 11 Pro for just $53 for a limited time.

95
article thumbnail

The Cloud Development Environment Adoption Report

Cloud Development Environments (CDEs) are changing how software teams work by moving development to the cloud. Our Cloud Development Environment Adoption Report gathers insights from 223 developers and business leaders, uncovering key trends in CDE adoption. With 66% of large organizations already using CDEs, these platforms are quickly becoming essential to modern development practices.

article thumbnail

Patch Tuesday: Four Critical Vulnerabilities Paved Over

Tech Republic Security

The November 2024 Microsoft updates let Windows 11 users remap the Copilot button.

Software 114
article thumbnail

Temu must respect consumer protection laws, says EU

Malwarebytes

Temu has been accused of a number of infringements on its platform against European Union (EU) consumer law. The Consumer Protection Cooperation (CPC) Network of national consumer authorities and the European Commission teamed up for a coordinated ongoing investigation into Temu and its practices. The investigation covers a range of misleading and “unduly influences” on consumers’ purchasing decisions, and looks at the information obligations that need to be met by an online marketplace.

article thumbnail

Businesses must reinvent themselves in the age of agentic AI

Zero Day

Being prepared for reinvention is crucial in an AI-first future. This research suggests your architecture and mindset need to adapt accordingly.

article thumbnail

Amazon's Latest Data Breach a Ripple Effect of MOVEit

SecureWorld News

On Monday, November 11, Amazon confirmed a data breach that impacted its employee data. The breach, linked to the infamous MOVEit Transfer vulnerability, underscores the far-reaching consequences of last year's major supply chain attack. The MOVEit vulnerability (CVE-2023-34362), first exploited in May 2023, allowed unauthenticated attackers to gain unauthorized access to vulnerable systems.

article thumbnail

Bringing the Cybersecurity Imperative Into Focus

Tech leaders today are facing shrinking budgets and investment concerns. This whitepaper provides insights from over 1,000 tech leaders on how to stay secure and attract top cybersecurity talent, all while doing more with less. Download today to learn more!

article thumbnail

We tested the iPhone 16 Pro camera system, and it's highly underrated - with one tragic flaw

Zero Day

With a fix for Apple's computational photography and another huge video upgrade, the iPhone 16 Pro camera delivers lots of value. But its flagship feature is a bit of a letdown.

88
article thumbnail

Smashing Security podcast #393: Who needs a laptop to hack when you have a Firestick?

Graham Cluley

Arion Kurtaj, a teenager from the UK, amassed a fortune through audacious cybercrimes. From stealing Grand Theft Auto 6 secrets to erasing Brazil's COVID vaccination data, his exploits were legendary. But his hacking spree took a bizarre turn when he was placed under police protection. in a Travelodge outside Oxford. Plus Bengal cat lovers in Australia should be on their guard, as your furry feline friends might be leading you into a dangerous trap., and there's yet more headaches for troubled 2

Hacking 79
article thumbnail

How Amazon Haul aims to beat Temu and Shein with its $20-or-less store

Zero Day

If you're wary of purchasing from popular discount apps, you now have a new, more familiar option with 'crazy low prices'.

99
article thumbnail

Comprehensive Guide to Building a Strong Browser Security Program

The Hacker News

The rise of SaaS and cloud-based work environments has fundamentally altered the cyber risk landscape. With more than 90% of organizational network traffic flowing through browsers and web applications, companies are facing new and serious cybersecurity threats. These include phishing attacks, data leakage, and malicious extensions.

article thumbnail

Introducing CDEs to Your Enterprise

Explore how enterprises can enhance developer productivity and onboarding by adopting self-hosted Cloud Development Environments (CDEs). This whitepaper highlights the simplicity and flexibility of cloud-based development over traditional setups, demonstrating how large teams can leverage economies of scale to boost efficiency and developer satisfaction.

article thumbnail

These Guys Hacked AirPods to Give Their Grandmas Hearing Aids

WIRED Threat Level

Three technologists in India used a homemade Faraday cage and a microwave oven to get around Apple’s location blocks.

Hacking 96
article thumbnail

Threats in space (or rather, on Earth): internet-exposed GNSS receivers

SecureList

What is GNSS? Global Navigation Satellite Systems (GNSS) are collections, or constellations of satellite positioning systems. There are several GNSSs launched by different countries currently in operation: GPS (US), GLONASS (Russia), Galileo (EU), BeiDou Navigation Satellite System (BDS, China), Navigation with Indian Constellation (NavIC, India) and Quazi-Zenith Satellite System (QZSS, Japan).

article thumbnail

One of the best cheap earbuds I've tested isn't made by Soundcore or Earfun

Zero Day

If you're tired of hearing the same old, over-driven, bass-enhanced EQ of most earbuds, the Soundpeats Air 5 delivers an almost studio-quality sound without breaking the bank.

Banking 81
article thumbnail

Warning: Online shopping threats to avoid this Black Friday and Cyber Monday 

Malwarebytes

It’s that time of year again. Thanksgiving will pass just as quickly as it arrived, and the festive season will soon hit full swing as countless people go online for some gift shopping. But where there’s a gift to be bought, there’s also a scammer out to make money. And make money they do. In the last five years, the Internet Crime Complaint Center (IC3) said it has received 3.79 million complaints for a wide range of internet scams, resulting in $37.4 billion in losses.

Scams 69
article thumbnail

IT Leadership Agrees AI is Here, but Now What?

IT leaders are experiencing rapid evolution in AI amid sustained investment uncertainty. As AI evolves, enhanced cybersecurity and hiring challenges grow. This whitepaper offers real strategies to manage risks and position your organization for success.

article thumbnail

We tested the iPhone 16 Pro camera system, and it's highly underrated - with one tragic flaw

Zero Day

With a fix for Apple's computational photography and another huge video upgrade, the iPhone 16 Pro camera delivers lots of value. But its flagship feature is a bit of a letdown.

80
article thumbnail

Right-Click to Hack: Zero-Day CVE-2024-43451 Vulnerability Targets Windows Users

Penetration Testing

ClearSky Cyber Security has uncovered a new zero-day vulnerability, CVE-2024-43451, actively exploited in the wild, targeting Windows systems primarily in Ukraine. This flaw enables attackers to exploit URL files for... The post Right-Click to Hack: Zero-Day CVE-2024-43451 Vulnerability Targets Windows Users appeared first on Cybersecurity News.

Hacking 75
article thumbnail

Google Pixel 9 Pro XL vs. Samsung Galaxy S24 Ultra: I tested both and the winner is not so obvious

Zero Day

I've reviewed and tested the two best Android phones on the market. These are the main reasons to buy one over the other.

article thumbnail

CVE-2024-10914: Critical Flaw in D-Link NAS Devices Actively Exploited, No Patch!

Penetration Testing

A critical command injection vulnerability (CVE-2024-10914) impacting numerous end-of-life D-Link network-attached storage (NAS) devices is currently under active exploitation. This vulnerability, assigned a CVSSv3 score of 9.2, poses a significant... The post CVE-2024-10914: Critical Flaw in D-Link NAS Devices Actively Exploited, No Patch!

article thumbnail

Enhance Innovation and Governance Through the Cloud Development Maturity Model

Leverage the Cloud Development Environment Maturity Model to elevate your software development practices with scalable, secure cloud-based workspaces. This model offers a structured approach to modernizing development, aligning technology, developer experience, security, and workflows. By implementing Cloud Development Environments (CDEs), teams can boost efficiency, improve security, and streamline operations through centralized governance.