Security News > 2020 > April

Critical Adobe Illustrator, Bridge and Magento Flaws Patched
2020-04-28 20:20

Adobe is warning of critical flaws in Adobe Bridge, Adobe Illustrator and the Magento e-commerce platform. The majority of these flaws affect Adobe Bridge, the company's digital asset management software.

Mozilla ranks video call apps by security and privacy features
2020-04-28 17:35

12 of the 15 most popular video call apps meet Mozilla's Minimum Security Standards, according to a new report. Researchers with Mozilla decided to comb through the privacy policies, app specifications, and security features of 15 video call apps and platforms in their latest report, "*Privacy Not Included.

Hackers Leak Biopharmaceutical Firm’s Data Stolen in Ransomware Attack
2020-04-28 16:36

The Clop ransomware group attacked biopharmaceutical company ExecuPharm and reportedly leaked some of the company's compromised data on underground forums. According to a recent data breach notice, various ExecuPharm servers were hit in a ransomware attack on March 13, which compromised "Select corporate and personnel information." The attack was initiated through phishing emails that were sent to ExecuPharm employees.

iPhone “word of death” could crash your phone – what you need to know
2020-04-28 16:25

A weird combination of Unicode characters that make up a nonsense word can crash your iPhone, apparently by confusing the iOS operating system when it tries to figure out how to display the "Word". We don't know how to read Arabic writing, or indeed the text of any Semitic language, but we do know that the writing systems of these languages generally differ from most European languages.

Cybersecurity professionals are being repurposed during COVID-19 pandemic
2020-04-28 16:03

47% of respondents have been temporarily moved to assist with IT-related tasks during remote work,2 survey finds. Eighty-one percent of cybersecurity professionals said their job function has changed during the COVID-19 pandemic, while at the same time, 23% reported cyberattacks at their organizations have increased since transitioning to remote work, according to a new survey by².

PhantomLance: Vietnamese Cyberspies Targeted Android Users for Years
2020-04-28 15:47

Kaspersky's security researchers have uncovered a long-running spyware campaign targeting Android users that bears the marks of Vietnam-linked hacking group OceanLotus. Multiple variants of the malware were identified by BlackBerry researchers too, who included information on them in a report published in October 2019.

Tech company offers free online cybersecurity training courses
2020-04-28 15:47

No need to post "Boredom" as a status update on social media because you can temper a staid stay-at-home experience with free tech courses designed to address the skills gap and an increase in security threats. The tech company Fortinet is offering self-paced training for technical security and broad cyber awareness, and has started the program with three courses at no cost.

Fooling NLP Systems Through Word Swapping
2020-04-28 15:38

The software, developed by a team at MIT, looks for the words in a sentence that are most important to an NLP classifier and replaces them with a synonym that a human would find natural. Abstract: Machine learning algorithms are often vulnerable to adversarial examples that have imperceptible alterations from the original counterparts but can fool the state-of-the-art models.

Research shows malware is easy to buy, own, and deploy
2020-04-28 15:36

A new study from research organization CyberNews.com found that malware is becoming increasingly easy to buy and deploy, even for those without technical backgrounds. CyberNews researchers looked at 10 so-called DarkNet marketplaces and found that buying malware is easy and fast, with cheap or even free programs allowing people to own malware.

Critical Security Patches Released for Magento, Adobe Illustrator and Bridge
2020-04-28 15:24

It's not 'Patch Tuesday,' but software giant Adobe today released emergency updates for three of its widely used products that patch dozens of newly discovered critical vulnerabilities. The list of affected software includes Adobe Illustrator, Adobe Bridge, and Magento e-commerce platform, containing a total of 35 vulnerabilities where each one of them is affected with multiple critical arbitrary code execution flaws.