Security News > 2020

This WhatsApp Bug Could Have Let Attackers Access Files On Your PCs
2020-02-04 20:22

When combined together, the reported issues could have even enabled hackers to remotely steal files from the Windows or Mac computer of a victim using the WhatsApp desktop app by merely sending a specially crafted message. In a blog post published today, Weizman revealed that WhatsApp Web was vulnerable to a potentially dangerous open-redirect flaw that led to persistent cross-site scripting attacks, which could have been triggered by sending a specially crafted message to the targeted WhatsApp users.

Hackers Pose Increasing Risk to Medical Research Data
2020-02-04 20:03

The intellectual property, including research results, of biotechnology companies and other medical organizations is also increasingly a target for hackers, who sometimes dump data on hacker forums or public websites. While GBG did not identify the "Member company" impacted by the attack, media outlet Bleeping Computer on Jan. 23 reported that Medical Diagnostics Laboratory - a unit of GBG - was a victim of a Dec. 2, 2019, Maze ransomware attack that resulted in the dumping of more than 9 Gbytes of research related data on the Maze Team website.

How to sign up for Firefox breach alerts
2020-02-04 19:34

Mozilla offers users a service that will send alerts for account breaches associated with email addresses. The service compares any email address you setup to monitor against known data breaches and reports back if any of those breaches has exposed your info and how many of your passwords have been compromised across the breaches.

YouTube Takes Steps to Stop Spread of Election Disinformation
2020-02-04 19:33

YouTube is the latest social media firm to adjust its policies as the 2020 U.S. presidential election gets underway. On Monday, the company announced plans to remove misleading political content and other disinformation from its platform.

How to sign up for Firefox breach alerts
2020-02-04 19:31

Mozilla offers users a service that will send alerts for account breaches associated with email addresses. Find out how to use Firefox Monitor.

Why many security pros lack confidence in their implementation of Zero Trust
2020-02-04 19:15

Almost half of security professionals don't know where or how to use Zero Trust policies in a hybrid IT environment, says a survey commissioned by security provider Pulse Secure. The report found that confidence levels around the implementation of Zero Trust are about split down the middle.

Two Critical Android Bugs Get Patched in February Update
2020-02-04 18:51

Google has released a security update for a critical flaw in its Android operating system that allows hackers to execute remote code on affected handsets, potentially allowing an adversary to gain remote access to the device. Part of Google's February Android Security Bulletin, released Monday, also warns of a second critical flaw that could allow a remote hacker to gain access to an Android handset and obtain sensitive data.

Untested app and no training for volunteers are fatal in Iowa caucus
2020-02-04 18:36

SEE: Iowa caucus app fiasco: How it happened and lessons learned. "Inevitably, the cost of this misstep is considerably greater since damage control and ultimately training staff properly is required, as well demonstrated with the app rollout in Iowa caucuses," Jones said.

California Man Pleads Guilty to Hacking Nintendo
2020-02-04 18:33

A 21-year-old California man has pleaded guilty to repeatedly hacking gaming company Nintendo over three years to access servers and steal confidential data, including details on hardware, games and developer tools, according to the U.S. Justice Department. In 2017, FBI agents confronted Hernandez at his parents' home, and he agreed to stop hacking Nintendo in exchange for federal authorities not pressing charges, according to court documents.

Medtronic Patches Implanted Device, CareLink Programmer Bugs
2020-02-04 17:53

The medical device giant said in an advisory last week that at issue is the proprietary Medtronic Conexus radio frequency wireless telemetry protocol that the devices use for remote monitoring of a patient's implanted cardiac device. While most of the affected products are still awaiting fixes, Medtronic has now issued patches for all models of the Brava and Viva lines of CRT-D devices; and bugs in the Evera, Evera MRI, Mirro MRI and Primo MRI lines of ICDs.