Security News > 2020

Week in review: Most exploited vulns in 2019, Emotet sprads via Wi-Fi, Patch Tuesday forecast
2020-02-09 12:00

Wuhan coronavirus exploited to deliver malware, phishing, hoaxesThe Wuhan coronavirus continues to spread and create anxiety across the globe, allowing malicious individuals and groups to exploit the situation to spread fake news, malware and phishing emails. USB armory Mk II: A secure computer on a USB stick featuring open source hardware designThe hardware security professionals at F-Secure have created a new version of the USB armory - a computer on a USB stick built from the ground up to be secure.

Dangerous Domain Corp.com Goes Up for Sale
2020-02-08 17:32

As an early domain name investor, Mike O'Connor had by 1994 snatched up several choice online destinations, including bar.com, cafes.com, grill.com, place.com, pub.com and television.com. At issue is a problem known as "Namespace collision," a situation where domain names intended to be used exclusively on an internal company network end up overlapping with domains that can resolve normally on the open Internet.

Cyborgs, Trolls and Bots: A Guide to Online Misinformation
2020-02-08 16:50

Cyborgs, trolls and bots can fill the internet with lies and half-truths. WAR OF THE BOTS AND CYBORGS. The disposable foot soldiers in this digital conflict are bots.

How to protect your privacy on an iOS device
2020-02-08 06:00

Learn how to keep your iOS devices-and your data-secure with these iOS 13 privacy settings and Apple resources. How to access the Privacy page in your iOS 13 Settings app.

Wacom Tablet Data Exfiltration Raises Security Concerns
2020-02-07 22:25

The Wacom digital drawing tablet appears to be silently exfiltrating user data, according to an investigation by software engineer Robert Heaton - and the company responded on Friday, downplaying the report. Though the data seen by Wacom is supposedly aggregated, Heaton said that it could use the "User Explorer" tool in Google Analytics to drill deeper, possibly to build a fairly rich profile that could be used for phishing or scam attacks.

Friday Squid Blogging: An MRI Scan of a Squid's Brain
2020-02-07 22:11

From the individual perspective the first thing to note, is if you are not infected then a facemask of the sort most people are wearing is going to be more of a hinderence than a help and potentialy more likely to cause you to become infected. Your best stratagy short term is "Self issolation" but you need to stock up on food and water and flu medications as well as the likes of dioralyte and certain vitimins and minerals and keep as far away from other people as possible.

Google Chrome to block file downloads – from .exe to .txt – over HTTP by default this year. And we're OK with this
2020-02-07 20:44

Continuing to drop flame retardant on the dumpster fire that is web security, Google on Thursday said it will soon prevent Chrome users from downloading files over insecure, plain old, unencrypted HTTP. "All insecure downloads are bad for privacy and security," declared Joe DeBlasio, who works on the Chrome security team, in a Twitter thread. "An eavesdropper can see what a user is downloading, or an active attacker can swap the download for a malicious one." "We hope to stop all unsafe downloads, but Chrome doesn't currently tell users on HTTPS pages that their downloads are insecure. That's weird! Users expect that what they do on secure pages to be... well secure! So we're blocking these downloads first."

Critical Android Bluetooth Bug Enables RCE, No User Interaction Needed
2020-02-07 20:35

A critical vulnerability in the Bluetooth implementation on Android devices could allow attackers to launch remote code execution attacks - without any user interaction. Researchers on Thursday revealed further details behind the critical Android flaw, which was patched earlier this week as part of Google's February Android Security Bulletin.

How to use 7zip to encrypt files
2020-02-07 19:34

If you need strong command line encryption on Linux, look no further than 7zip.

Hackers imitating CDC, WHO with coronavirus phishing emails
2020-02-07 19:02

Last week, IBM and Kaspersky caught hackers in Japan trying to spread malware through emails with links about the coronavirus outbreak that started in Wuhan, China, in January. Now, Kaspersky and Sophos have found phishing emails from cybercriminals purporting to be from the Centers for Disease Control and Prevention and the World Health Organization that are attempts to steal email credentials and other information.