Security News > 2021

Beware: AOL phishing email states your account will be closed
2021-02-28 17:45

An AOL mail phishing campaign is underway to steal users' login name and password by warning recipients that their account is about to be closed. While most people are using Gmail, Outlook, or other modern free mail services, many older people continue to use AOL simply because they are used to the service and find it too complicated to switch to a new email service.

What are these suspicious Google GVT1.com URLs?
2021-02-28 16:52

The domains *.gvt1.com and *.gvt2.com, along with their subdomains, are owned by Google and typically used to deliver Chrome software updates, extensions, and related content. The GVT in the gvt1.com domain stands for Google Video Transcoding, and is used as a cache server for content and downloads used by Google services and applications.

Recent Google Voice outage caused by expired certificates
2021-02-28 14:25

In an incident report published on Friday, Google said that a Google Voice outage affecting a majority of the telephone service's users earlier this month was caused by expired TLS certificates. During regular operation, voice calls made through Google Voice are controlled using the Session Initiation Protocol, with client devices immediately retrying their connection to the service once it breaks.

Google Voice silenced by expired TLS certificate in February outage
2021-02-28 14:25

In an incident report published on Friday, Google said that a Google Voice outage affecting a majority of the telephone service's users earlier this month was caused by expired TLS certificates. During regular operation, voice calls made through Google Voice are controlled using the Session Initiation Protocol, with client devices immediately retrying their connection to the service once it breaks.

Week in review: Kali Linux 2021.1, CNAME-based tracking, VMware vCenter Servers under attack
2021-02-28 08:55

Attackers are looking to exploit critical VMware vCenter Server RCE flaw, patch ASAP!The day after VMware released fixes for a critical RCE flaw found in a default vCenter Server plugin, opportunistic attackers began searching for publicly accessible vulnerable systems. Kali Linux 2021.1 released: Tweaked DEs and terminals, new tools, Kali ARM for Apple Silicon MacsOffensive Security has released Kali Linux 2021.1, the latest version of its popular open source penetration testing platform.

The Windows 10 Sun Valley design refresh - Here's what's coming
2021-02-27 20:46

Windows 10 21H2 will be released in the fall of 2021 after Windows 10 21H1 is released in the spring followed by Windows 10X. Codenamed "Sun Valley." Windows 10 21H2 will be a full-featured update that includes numerous new features and improvements for the Start Menu, Taskbar, Action Center, and more, which we have outlined below. Since Windows 10 version 21H1 will be a minor release, native support for DNS over HTTPS will likely be introduced with Windows 10 Sun Valley update.

Windows 10 Sun Valley design refresh — here's what you need to know
2021-02-27 20:46

Windows 10 21H2 will be released in the fall of 2021 after Windows 10 21H1 is released in the spring followed by Windows 10X. Codenamed "Sun Valley." Windows 10 21H2 will be a full-featured update that includes numerous new features and improvements for the Start Menu, Taskbar, Action Center, and more, which we have outlined below. Since Windows 10 version 21H1 will be a minor release, native support for DNS over HTTPS will likely be introduced with Windows 10 Sun Valley update.

Judge Approves $650M Facebook Privacy Lawsuit Settlement
2021-02-27 20:05

A federal judge on Friday approved a $650 million settlement of a privacy lawsuit against Facebook for allegedly using photo face-tagging and other biometric data without the permission of its users. U.S. District Judge James Donato approved the deal in a class-action lawsuit that was filed in Illlinois in 2015.

NSA, Microsoft promote a Zero Trust approach to cybersecurity
2021-02-27 17:03

The National Security Agency and Microsoft are advocating for the Zero Trust security model as a more efficient way for enterprises to defend against today's increasingly sophisticated threats. Google implemented zero-trust security concepts following Operation Aurora in 2009 for an internal project that became BeyondCorp. Zero Trust defense for critical networks.

Microsoft fixes Windows 10 drive corruption bug — what you need to know
2021-02-27 15:34

Microsoft has fixed a Windows 10 bug that could cause NTFS volumes to become corrupted by merely accessing a particular path or viewing a specially crafted file. Windows then prompts the user to reboot the computer and run chkdsk to fix the corruption.