Security News > 2019 > July

iOS and Android patched 440 security vulnerabilities in 2019, so far
2019-07-31 12:30

Android patched more CVEs than Apple did, according to a Zimperium report.

SanDisk's SSD Dashboard uses hardcoded password, lacks encrypted updates
2019-07-31 12:00

Lackadaisical security practices in proprietary management software from a hardware vendor underscore the need for a vendor-agnostic solution.

Another Attack Against Driverless Cars
2019-07-31 11:46

In this piece of research, attackers successfully attack a driverless car system -- Renault Captur's "Level 0" autopilot (Level 0 systems advise human drivers but do not directly operate cars) --...

What Does Summer Vacation Have to do With Information Security?
2019-07-31 11:27

There is something magical about children and summer vacation.  As adults, we sometimes get so caught up in day-to-day life that we forget about this magic that we once experienced.  That is,...

Lancaster Uni cordons off breached systems a week after thousands of folks' data pinched
2019-07-31 11:19

Educator, learn thyself. Prevention is better than cure Lancaster University has started withdrawing non-business-critical access to a breached student database – more than a week after the...

DHS Warns Small Airplanes Vulnerable to Flight Data Manipulation Attacks
2019-07-31 10:48

What could be more horrifying than knowing that a hacker can trick the plane's electronic systems into displaying false flight data to the pilot, which could eventually result in loss of control?...

Cyberattacks on connected cars could gridlock entire cities
2019-07-31 10:40

It would require taking over and stranding 20% of a city's cars to freeze traffic, and only 10% to impede ambulances, physicists calculate.

Capital One: Where Did the Bank Fail on Defense?
2019-07-31 09:48

Experts Say Bank May Have Made Several ErrorsThe cause of Capital One's breach is known. But experts say the incident still raises questions over why Capital One held onto personal data so long...

AWDL flaws open Apple users to tracking, MitM, malware planting
2019-07-31 09:48

Vulnerabilities in Apple Wireless Direct Link (AWDL), the wireless protocol that underpins Apple’s AirPlay and AirDrop services, could allow attackers to track users in spite of MAC randomization,...

Top Three Cross-Site Scripting Attacks You Need to Know Now
2019-07-31 08:35

Cross-Site scripting or XSS is and will remain to be a major pain for anyone trying to create a secure web application for their end-users.