News
-
"82% of Public Sector Applications Contain Security Flaws"Security researchers at Veracode have discovered that more than four-fifths (82%) of public sector applications have security flaws, the highest proportion of any industry. The researchers also found that the public sector takes around twice as…
-
"US Proposes Healthcare Cybersecurity Act"Lawmakers in the United States have proposed a new bill that aims to enhance the cybersecurity of America's healthcare and public health (HPH) sector. The new bill is called the Healthcare Cybersecurity Act. A primary goal of the act is to improve…
-
"Hackers Hijack Email Reply Chains on Unpatched Exchange Servers to Spread Malware"A new email phishing campaign has been discovered hijacking conversations to deliver IcedID information-stealing malware. The campaign exploits unpatched and publicly-exposed Microsoft Exchange servers. The phishing emails apply the social engineering…
-
"Researchers Hack Remote Keyless System of Honda Vehicles"A researcher at the University of Massachusetts Dartmouth has published Proof-of-Concept (PoC) videos demonstrating how an attacker can remotely unlock a Honda vehicle's doors or start its engine. The attack is made possible by a vulnerability contained…
-
"Browser-in-the Browser (BITB) – A New Born Phishing Methodology"Browser-in-the-Browser (BITB) is a novel phishing method in which third-party Single Sign-On (SSO) options are abused. These SSO options are embedded on websites and issue pop-up windows for authentication via Google, Facebook, Apple, or Microsoft. The…
-
"Washington Health District Suffers Another Data Breach"A Health District in the State of Washington has made its second data breach announcement of 2022. Both data breaches at the Spokane Regional Health District (SRHD) occurred when employees fell victim to phishing attacks. The district…
-
"Utah Becomes Latest US State to Pass a Data Privacy Law"Utah has passed a new privacy law called the Utah Consumer Privacy Act (UCPA). UCPA will take effect in under two years, on December 31, 2023. The provisions will apply to organizations with annual revenue of $25m or more that conduct…
-
"Microsoft Help Files Disguise Vidar Malware"Trustwave SpiderLabs released a report detailing a new phishing campaign that plants the Vidar information-stealing malware on target machines. This malicious campaign hides its complex malware behind a Microsoft Compiled HTML Help (.CHM) file, which is…
-
"An Algorithm Makes It Possible to Identify People by Their Heartbeat"Biometrics help identify and authenticate a person by analyzing and measuring physical characteristics such as the face, voice, fingerprint, retina, and more. Biometric-based tools are increasingly supplementing or replacing password systems in the realm…
-
"Protecting Picture Passwords"Researchers from the University of Tsukuba, Japan, propose the use of an alternative approach to text passwords, which involves using an enhanced graphical authentication method. They developed the "Estimating Your Encodable Distorted images" (EYEDi)…
-
"Dual North Korean Hacking Efforts Found Attacking Google Chrome Vulnerability"Google's Threat Analysis Group discovered that two distinct sets of North Korean hackers were exploiting the same remote code execution vulnerability in the Chrome web browser. One set of North Korean hackers targeted news media and IT…
-
"4.1 Million Websites Infected With Malware Worldwide"Security researchers at Sectigo have found that 4.1 million websites globally are currently infected with malware. According to the study, bot traffic accounted for 5.5 times more than human traffic in 2021, compared to 2020, with 2,306 weekly…