Security News > 2018 > April

Drupal 8 Updated to Patch Flaw in WYSIWYG Editor
2018-04-19 11:41

Updates released on Wednesday for Drupal 8 patch a moderately critical cross-site scripting (XSS) vulnerability affecting a third-party JavaScript library. The flaw impacts CKEditor, a WYSIWYG...

Silence! Chrome hushes noisy autoplaying videos
2018-04-19 11:15

With the Chrome 66 comes blissful quiet: Google is muting all autoplay content by default.

'iTunes Wi-Fi Sync' Feature Could Let Attackers Hijack Your iPhone, iPad Remotely
2018-04-19 11:03

Be careful while plugging your iPhone into a friend's laptop for a quick charge or sharing selected files. Researchers at Symantec have issued a security warning for iPhone and iPad users about a...

US-CERT issues alert for Russian attacks targeting IoT devices
2018-04-19 10:25

Attorney and former CIA case officer Jack Rice explains how foreign actors could attack critical infrastructure, and how US intelligence agencies deploy a proportional response to cyber attacks.

Cutting custody snaps too costly for cash-strapped cops – UK.gov
2018-04-19 08:02

Home Office admits national and local databases don't talk to each other, so everything is manual The UK government has admitted it can only delete custody images from its massive database through...

#UK
Another Critical Flaw Found In Drupal Core—Patch Your Sites Immediately
2018-04-19 07:33

It's time to update your Drupal websites, once again. For the second time within a month, Drupal has been found vulnerable to another critical vulnerability that could allow remote attackers to...

PCI Council releases vastly expanded cards-in-clouds guidance
2018-04-19 05:58

First word on how card security for containers, VDI, SDN and web apps The Payment Card Industry Security Standards Council (PCI SSC) has issued a big update to its guidance on using payment cards...

iPhones, iPads Can Be Hacked via 'Trustjacking' Attack
2018-04-19 05:24

A feature that allows users to wirelessly sync their iPhones and iPads with iTunes can be abused by hackers to take control of iOS devices in what researchers call a “Trustjacking” attack. read more

Facebook's login-to-other-sites service lets scum slurp your stuff
2018-04-19 01:58

Your security's only as good as your partners'. And some Facebook partners are rotten A security researcher has claimed it's possible to extract user information from Facebook's Login service, the...

Popular Android Apps Leak User Data via Third-Party SDKs
2018-04-19 01:04

Popular mobile applications that use third-party, ready-to-go advertising Software Development Kits (SDKs) expose user data by transmitting it over the insecure HTTP protocol, Kaspersky Lab warns....