Security News > 2021 > January

Apple Removes macOS Feature That Allowed Apps to Bypass Firewall Security
2021-01-17 22:42

Apple has removed a controversial feature from its macOS operating system that allowed the company's own first-party apps to bypass content filters, VPNs, and third-party firewalls. Called "ContentFilterExclusionList," it included a list of as many as 50 Apple apps like iCloud, Maps, Music, FaceTime, HomeKit, the App Store, and its software update service that were routed through Network Extension Framework, effectively circumventing firewall protections.

Windows 10X: A closer look at Microsoft's new operating system
2021-01-17 15:41

Unlike Windows 10 or Windows 8, Windows 10X doesn't come with traditional live tiles. In the leaked build, Windows 10X is using ChromeOS like static icons for Microsoft Store apps and Microsoft Edge-powered Progressive Web Apps.

Windows 10 bug crashes your PC when you access this location
2021-01-17 15:21

A bug in Windows 10 causes the operating system to crash with a Blue Screen of Death simply by opening a certain path in a browser's address bar or using other Windows commands. Today, we look at the second bug that causes Windows 10 to perform a BSOD crash by merely attempting to open an unusual path.

Windows 10 bug causes a BSOD crash when opening a certain path
2021-01-17 15:21

A bug in Windows 10 causes the operating system to crash with a Blue Screen of Death simply by opening a certain path in a browser's address bar or using other Windows commands. Today, we look at the second bug that causes Windows 10 to perform a BSOD crash by merely attempting to open an unusual path.

Privacy-focused search engine DuckDuckGo grew by 62% in 2020
2021-01-17 11:39

The privacy-focused search engine DuckDuckGo continues to grow rapidly as the company reached 102M daily search queries for the first time in January. DuckDuckGo is a search engine that builds its search index using its DuckDuckBot crawler, indexing WikiPedia, and through partners like Bing.

Week in review: Pen testing, Sunspot malware, Microsoft plugs Defender zero-day
2021-01-17 10:20

SolarWinds hack investigation reveals new Sunspot malwareCrowdstrike researchers have documented Sunspot, a piece of malware used by the SolarWinds attackers to insert the Sunburst malware into the company's Orion software. January 2021 Patch Tuesday: Microsoft plugs Defender zero-day RCEMicrosoft has plugged 83 security holes, 10 of which are critical.

EU Regulator: Hackers ‘Manipulated’ Stolen Vaccine Documents
2021-01-16 15:47

The European Union's drug regulator said Friday that COVID-19 vaccine documents stolen from its servers by hackers have been not only leaked to the web, but "Manipulated." The European Medicines Agency said that an ongoing investigation showed that hackers obtained emails and documents from November related to the evaluation of experimental coronavirus vaccines.

Pro-Trump 'Enemies of the People' doxing site is still active
2021-01-16 15:46

Enemies of the People, the website inciting violence against U.S. officials who refused to support the President's claims to voter fraud, is still active and continues to expose personal details from more individuals. The main site went offline shortly before a report from the FBI emerged saying that Iranian actors were "Almost certainly" behind the campaign but just days after the New Year, it was back up publishing personal information.

Stolen credit card shop Joker's Stash closes after making a fortune
2021-01-16 13:40

The administrator of Joker's Stash, a popular and one of the longest-running marketplace for cybercriminals to purchase stolen credit cards, announced on Friday that they would permanently shut down the operation next month. The illegal card shop opened in 2014 and became famous for providing fresh stolen credit card data and a promise of card validity; some of the cards were touted to be exclusive to Joker's Stash.

Massive stolen credit card shop Joker's Stash shuts down
2021-01-16 13:40

The administrator of Joker's Stash, a popular and one of the longest-running marketplace for cybercriminals to purchase stolen credit cards, announced on Friday that they would permanently shut down the operation next month. The illegal card shop opened in 2014 and became famous for providing fresh stolen credit card data and a promise of card validity; some of the cards were touted to be exclusive to Joker's Stash.