Security News > 2020

Security in 2020: Revisited
2020-02-07 18:50

Computers become temporary; user backup becomes irrelevant. The general-purpose computer is dying and being replaced by special-purpose devices.

Chrome Will Block Insecure Downloads on HTTPS Pages
2020-02-07 18:39

In an attempt to improve the security of its users, the Chrome browser will soon start blocking insecure downloads on HTTPS pages, Google announced. The announcement comes just days after the release of Chrome 80, which by default blocks mixed audio and video resources if they cannot be automatically upgraded to HTTPS. The same will happen with image files in Chrome 81, which is expected to be released to the stable channel in March 2020.

IoT Devices at Major Manufacturers Infected With Malware via Supply Chain Attack
2020-02-07 18:04

Three of the world's largest manufacturers had some IoT devices running Windows 7 infected with a piece of malware in what experts believe to be a supply chain attack. TrapX Security reported this week that it had identified a cryptocurrency miner on several IoT devices at some major manufacturers, including automatic guided vehicles, a printer and a smart TV. Ori Bach, the CEO of TrapX, told SecurityWeek that the attacks appeared to be part of the same campaign.

Barr: US Should Invest in Nokia, Ericsson
2020-02-07 17:48

U.S. Attorney General William Barr says the United States and its allies should take a "Controlling stake" in Huawei's chief competitors, Findland's Nokia and Sweden's Ericsson, to help make them more viable and improve the security of emerging 5G networks. Speaking at a conference in Washington Thursday organized by the Center for Strategic and International Studies, Barr said that China's unchecked dominance in producing technologies to support 5G networks could pose a "Monumental danger" to U.S. national security.

Organizations Quick to Patch Critical Citrix ADC Vulnerability
2020-02-07 17:48

More than 80 percent of organizations impacted by CVE-2019-19781, a critical vulnerability in the Citrix Application Delivery Controller and Gateway, have already taken steps to secure their deployments. The security bug impacts multiple versions of Citrix ADC and Gateway, but Citrix has already released permanent patches for all of them, as attacks started to ramp up.

Google Chrome To Bar HTTP File Downloads
2020-02-07 17:03

Google Chrome will soon restrict certain files, like PDFs or executables, from being downloaded via an HTTP connection, if they are loaded on HTTPS webpages. With Chrome 68's 2018 release, Google started to label HTTP websites with an "Insecure" warning label in the navigation bar.

Robbin Hood – the ransomware that brings its own bug
2020-02-07 16:35

Crooks such as the gang behind the Cryptolocker ransomware were able to make millions, perhaps even hundreds of millions, of dollars by infecting hundreds of thousands of users and businesses, and then demanding $300 a time to unlock each user's files. System services often keep critical files in permanent use, meaning that they can't easily be deleted or modified, which stops the crooks from scrambling them in a ransomware attack.

Uncle Sam tells F-35B allies they'll have to fly the things a lot more if they want to help out around South China Sea
2020-02-07 16:24

British F-35Bs deploying to the South China Sea next year may not meet key reliability metrics set by an American government watchdog, its annual report has revealed. On top of that, the supersonic stealth jet project's move towards Agile methodology for "Minimum viable product"-phased development of critical flight and weapons software every six months is a "High risk" strategy, according to DOTE. The F-35B fleet worldwide needs to rack up 75,000 flight hours before DOTE thinks it has gathered enough data to meet the contract spec.

UK's Brexit Transition Period: Keep Complying With GDPR
2020-02-07 16:18

During the Brexit transition period, "It will be business as usual for data protection," which means mandatory compliance with the EU's General Data Protection Regulation remains in effect, the U.K. Information Commissioner's Office said in a Jan. 29 blog post. What happens after the transition period is over? From a privacy standpoint, that remains the million-dollar - or rather, pounds-sterling - question, and "Depends on negotiations during the transition period," as noted in a Brexit FAQ issued by the ICO. Odds are good that after 2020, U.K. organizations will have to continue to comply with GDPR. Otherwise, they could be shut out of easy trading with the EU, leaving Britain at a competitive disadvantage.

How Shadow IT could put your organization at risk
2020-02-07 16:08

Employees who create external accounts but use them internally pose a risk to your security, says password manager company 1Password. The IT professionals at your organization likely put a lot of effort into making sure your internal accounts, logins, passwords, and systems are secure and protected.