Security News > 2021

SolarWinds attack makes us distrust the software we buy
2021-03-30 20:22

Security expert says because we can't inspect the inner workings of the software we buy, we're at the mercy of software companies' security practices. TechRepublic's Karen Roby spoke with Manish Gupta, founder and CEO of ShiftLeft, a code analysis software company, about the SolarWinds attack and its effect on cybersecurity.

Trust in software security has eroded since the SolarWinds attack
2021-03-30 20:21

We're only as secure as the software we use, cybersecurity expert says.

Mozilla VPN now nudges users to put shields up on dodgy networks, adds LAN access
2021-03-30 19:35

Mozilla's attempts to augment its income continued apace with an update to the company's VPN subscription service. The update, which has landed less than a year since Mozilla first launched the service, adds two new features.

AI is Security's Best Defense
2021-03-30 19:15

Remote working is here to stay, and with this, security and safety have gained even more relevance. Security analysts are receiving thousands of alerts daily, and now with so many remote workers, these alerts could come from thousands of locations.

US govt warns that buying fake COVID-19 vaccine cards is a crime
2021-03-30 18:50

US federal agencies have warned today against making or selling fake COVID-19 vaccination record cards as this is breaking the law. Using fake vaccination record cards could also put others at risk, increasing the chance of contracting COVID-19 or infecting others.

How phishing attacks evade traditional security defenses
2021-03-30 18:44

A report issued on Tuesday by email security provider Armorblox looked at the tactics employed by three recent phishing campaigns and suggests ways to avoid these types of scams. In each case, the emails were able to get past security defenses to end up in the inboxes of their targeted victims.

PHP web language narrowly avoids “backdoor” supply chain attack
2021-03-30 18:30

Open source web programming language PHP narrowly avoided a potentially dangerous supply chain attack over the weekend. In theory, anyone who downloaded the very latest "Still in development" version of PHP on Sunday 2021-03-28, compiled it, and installed it on a real-life, internet facing web server could have been at risk.

VMware fixes bug allowing attackers to steal admin credentials
2021-03-30 18:01

VMware has published security updates to address a high severity vulnerability in vRealize Operations that could allow attackers to steal admin credentials after exploiting vulnerable servers. vRealize Operations is an AI-powered and "Self-driving" IT operations management for private, hybrid, and multi-cloud environments, available as an on-premises or SaaS solution.

Whistleblower: Ubiquiti Breach “Catastrophic”
2021-03-30 18:00

On Jan. 11, Ubiquiti Inc. [NYSE:UI] - a major vendor of cloud-enabled Internet of Things devices such as routers, network video recorders and security cameras - disclosed that a breach involving a third-party cloud provider had exposed customer account credentials. Now a source who participated in the response to that breach alleges Ubiquiti massively downplayed a "Catastrophic" incident to minimize the hit to its stock price, and that the third-party cloud provider claim was a fabrication.

Cyan Forensics Raises $6.9 Million to Combat Pedophiles and Terrorists
2021-03-30 17:22

Edinburgh, Scotland-based start-up Cyan Forensics has secured £5 million in a Series A funding round led by Par Equity. Cyan Forensics offers products designed to rapidly identify and block illegal content such as child pornography and terrorist material.