Security News > 2019 > September

Hackers are infecting WordPress sites via a defunct plug-in
2019-09-26 10:37

If you're a Wordpress admin using a plug-in called Rich Reviews, you'll want to uninstall it. Now.

Russian pleads guilty in massive JPMorgan hacking scheme
2019-09-26 10:27

Andrei Tyurin is the first to be convicted in one of the largest thefts of customer data from a single US financial institution in history.

Update ColdFusion now! Emergency patch for critical flaws
2019-09-26 10:16

Adobe has rushed out fixes for three vulnerabilities in its ColdFusion web development platform, two of which have been given the top billing of ‘critical’.

Cybercriminals plan to make L7 routers serve card stealing code
2019-09-26 09:54

One of the Magecart cybercriminal groups is testing a new method for grabbing users’ credit card info: malicious skimming code that can be loaded into files used by L7 routers. What is Magecart?...

Vimeo sued for storing faceprints of people without their say-so
2019-09-26 09:47

The suit was filed under BIPA, the Illinois law that requires written consent to grab people's faceprints - the same law Facebook's battling.

iOS 13 Bug Gives Third-Party Keyboards "Full Access" Permissions
2019-09-26 08:46

An update that Apple will soon release for iOS 13 and iPadOS should resolve an issue that leads to third-party keyboard apps getting elevated permissions without the user’s approval. read more

TalkTalk still struggles to shut down legacy email addresses on request
2019-09-26 08:15

Another ex-customer struggles to get hacked account killed off Months after The Register first wrote about TalkTalk failing to close a former customer's email address, the firm is still using the...

vBulletin Patches Vulnerability Exploited in the Wild
2019-09-26 07:14

Developers of the vBulletin forum software have rushed to release a patch for a recently disclosed remote command execution vulnerability, but the flaw has already been exploited in the wild, with...

How can we thwart email-based social engineering attacks?
2019-09-26 05:30

More than 99 percent of cyberattacks rely on human interaction to work, Proofpoint recently shared. More often than not, the principal attack method is phishing emails. When hitting enterprises,...

Tackling biometric breaches, the decentralized dilemma
2019-09-26 05:12

A recent discovery by vpnMentor revealed a worst case scenario for biometrics: a large cache of biometric data being exposed to the rest of the world. In this case web-based biometric security...