Security News > 2019 > April

Password1, Password2, Password3 no more: Microsoft drops password expiration rec
2019-04-25 17:46

For years, Microsoft's baseline security policy has expired passwords after 60 days.

Cybercriminals Using GitHub to Host Phishing Kits
2019-04-25 17:02

Free code repositories on the Microsoft-owned GitHub have been abused since at least mid-2017 to host phishing websites, according to researchers from Proofpoint. read more

Leaked Carbanak Source Code Reveals No New Exploits
2019-04-25 16:17

FireEye’s analysis of the Carbanak source code that emerged on VirusTotal recently found no use of new exploits. Their review of the code also verified previous assumptions on the group behind a...

Amazon Employees Given ‘Broad Access’ to Personal Alexa Info
2019-04-25 15:55

An auditing program for the voice assistant technology exposes geolocation data that can be personally identified, sources said.

The 4 most important files for SSH connections
2019-04-25 15:44

You are better armed to make use of the SSH tool with an understanding of four key SSH files.

Special-Purpose Vehicle Maker Aebi Schmidt Hit by Malware
2019-04-25 15:37

Swiss-based special-purpose vehicle maker Aebi Schmidt informed customers and business partners on Thursday that some of its operations may be disrupted as a result of a cyberattack. read more

Enhancing Office 365 to Securely Manage and Share Sensitive Information
2019-04-25 15:33

Email is still the fundamental driver for Office 365 and the biggest risk to data security and compliance.Email is still the fundamental driver for Office 365 and the biggest risk to data security...

Enterprise cryptojacking attacks continue, despite overall decline in popularity among hackers
2019-04-25 15:22

A newly-discovered cryptojacking campaign uses familiar exploits to target enterprises and traverse network shares, infecting any connected computer.

Qualcomm Critical Flaw Exposes Private Keys For Android Devices
2019-04-25 15:19

A side-channel attack in Qualcomm technology, which is used by most modern Android devices, could allow an attacker to snatch private keys.

'Highly Critical' Unpatched Zero-Day Flaw Discovered In Oracle WebLogic
2019-04-25 15:03

A team of cybersecurity researchers today published a post warning enterprises of an unpatched, highly critical zero-day vulnerability in Oracle WebLogic server application that some attackers...