Security News > 2019 > January

Fortnite Hacked Via Insecure Single Sign-On
2019-01-16 16:16

Leaky Fortnite single sign-on mechanism could have allowed hackers to access game accounts.

Quantum Computing: Sizing Up the Risks to Security
2019-01-16 16:03

Within the next five to 10 years, quantum computing will get so powerful that it could be used to break encryption on the fly, predicts Steve Marshall, CISO at U.K.-based Bytes Software Services.

WordPress to Warn on Outdated PHP Versions
2019-01-16 15:41

In an effort to improve the security of websites, WordPress will display a warning starting in April 2019 when encountering outdated PHP versions. In December last year, the free and open-source...

Avoiding Critical Security Risk Analysis Mistakes
2019-01-16 15:33

Privacy attorney Adam Greene provides tips for avoiding mistakes when conducting a HIPAA security risk analysis and spells out the essential steps to take.

Top 10 app vulnerabilities: Unpatched plugins and extensions dominate
2019-01-16 15:25

Despite the existence of patches, the proliferation of unpatched installations are enticing targets for malicious actors, according to a WhiteHat report.

Magecart Returns with Advertising Library Tactic
2019-01-16 15:11

The threat group also has a new subsidiary, Magecart Group 12.

Hackers Can Abuse Legitimate Features to Hijack Industrial Controllers: Expert
2019-01-16 14:45

Hackers can abuse legitimate features present in industrial controllers to hijack these devices and leverage them to gain a foothold in a network, a researcher warns. read more

Epic's Fortnite fail: Ancient UT2004 server used for login-stealing proof-of-concept
2019-01-16 14:13

A tale of XSS, SQL injection and OAuth implementation Crafty infosec bods exploited XSS vulns on dusty corners of Epic Games’ web infrastructure to steal Fortnite gamers’ login tokens and...

VOIPO Database Exposes Millions of Texts, Call Logs
2019-01-16 14:00

VOIPO acknowledged that a development server had been accidentally left publicly accessible, and took the server offline.