News
  • "Minecraft Apps on Google Play Fleece Players Out of Big Money"
    Researchers at Avast have discovered, 7 mobile apps on Google Play that are meant to fool users into spending hundreds of dollars per month by offering skins, wallpapers, and game mods for Minecraft and other games at super-premium prices.  The apps…
  • "Ragnar Locker Ransomware Gang Takes Out Facebook Ads in Key New Tactic"
    Researchers have discovered that following a ransomware attack against Italian liquor conglomerate Campari on November 3rd, the Ragnar Locker group has created Facebook ads threatening to release stolen data to add additional pressure on its latest high-…
  • The science on password security vs usability
    Researchers at Carnegie Mellon University’s CyLab Security and Privacy Institute have developed a science-based policy for creating passwords that balances security and usability.
  • Take my word for it: Privacy and COVID alert apps can coexist
    BY LORRIE CRANOR, OPINION CONTRIBUTOR — 11/10/20 09:30 AM EST  Since the COVID-19 pandemic began, technologists across the country have rushed to develop digital apps for contact tracing and exposure notifications. New York, New…
  • "New Tool Can Check for Data Leakage From AI Systems"
    Artificial Intelligence (AI) helps companies power many applications, such as those used to improve marketing strategies, recommendation services, and health services. Although AI offers many benefits, security and privacy researchers have…
  • "Cadbury Social Media Scammers Take Chocoholics for a Ride"
    A fake Facebook Group has been discovered and is being used to trick social media users into divulging their personal and financial details to win free Cadbury chocolate.  Various posts from the group claim that the chocolate-maker, now owned by…
  • "Malicious Use of SSL Increases as Attackers Deploy Hidden Attacks"
    Researchers at Zscaler analyzed 6.6 billion security threats in a new study and discovered that there had been a 260% increase in the use of encrypted traffic to "hide" attacks during the first nine months of 2020. They also found that the use of…
  • "Insecure APIs a Growing Risk for Organizations"
    Application Programming Interfaces (APIs) face the same vulnerabilities as regular web applications. According to Forrester Research, as APIs enable direct external access to transaction updates and mass data, they are subjected to more threats than…
  • "Vulnerabilities Affect 100,000 Sites Using WordPress Plugin"
    Three critical privilege-escalation vulnerabilities were discovered in a WordPress plugin, impacting 100,000 websites. Wordfence's Threat Intelligence Team detected the flaws in Ultimate Member, which is a free user profile WordPress plugin that supports…
  • "Apple Releases Patches for 3 iOS Zero-Days That Hackers Used for Targeted Attacks"
    Apple has released patches for three critical vulnerabilities discovered in its software used for iPhones, iPads, and iPods. Two of the critical bugs impact the core of the device's operating system called the kernel, responsible for handling…
  • "New Tool Detects Unsafe Security Practices in Android Apps"
    Computer scientists at the Columbia University developed a new tool called CRYLOGGER to detect when an Android app is misusing cryptography. The tool detects whether an Android app violates guidelines set by expert cryptographers and organizations such…
  • "SwRI Hacks Electric Vehicle Charging to Demonstrate Cybersecurity Vulnerabilities"
    Engineers at Southwest Research Institute simulated an attack on the charging process of an electric vehicle (EV) to bring further attention to the cybersecurity vulnerabilities associated with EV charging. They reverse-engineered the signals and…