Security News > 2024 > April

Millions of Malicious 'Imageless' Containers Planted on Docker Hub Over 5 Years
2024-04-30 13:36

Cybersecurity researchers have discovered multiple campaigns targeting Docker Hub by planting millions of malicious "imageless" containers over the past five years, once again underscoring how...

FCC fines major wireless carriers over illegal location data sharing
2024-04-30 12:56

The Federal Communications Commission fined the nation's largest wireless carriers for illegally sharing access to customers' location information without consent and without taking reasonable measures to protect that information against unauthorized disclosure. Wireless carriers shared access to customers' location data.

Palo Alto firewalls: CVE-2024-3400 exploitation and PoCs for persistence after resets/upgrades
2024-04-30 12:44

There are proof-of-concept techniques allowing attackers to achieve persistence on Palo Alto Networks firewalls after CVE-2024-3400 has been exploited, the company has confirmed on Monday, but they are "Not aware at this time of any malicious attempts to use these persistence techniques in active exploitation of the vulnerability." On April 12, Palo Alto Networks warned about limited attacks against internet-exposed firewalls, likely by a state-backed threat actor, who managed to install backdoors, grab sensitive data, and move laterally through target organizations' networks.

European Commission starts formal probe of Meta over election misinformation
2024-04-30 12:30

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

WhatsApp in India
2024-04-30 11:00

About Bruce Schneier I am a public-interest technologist, working at the intersection of security, technology, and people. I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.

U.S. Government Releases New AI Security Guidelines for Critical Infrastructure
2024-04-30 10:36

The U.S. government has unveiled new security guidelines aimed at bolstering critical infrastructure against artificial intelligence (AI)-related threats. "These guidelines are informed by the...

Considerations for Operational Technology Cybersecurity
2024-04-30 10:24

Operational Technology (OT) refers to the hardware and software used to change, monitor, or control the enterprise's physical devices, processes, and events. Unlike traditional Information...

Apple's 'incredibly private' Safari is not so private in Europe
2024-04-30 07:24

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

New U.K. Law Bans Default Passwords on Smart Devices Starting April 2024
2024-04-30 05:57

The U.K. National Cyber Security Centre (NCSC) is calling on manufacturers of smart devices to comply with new legislation that prohibits them from using default passwords, effective April 29,...

Triangulation fraud: The costly scam hitting online retailers
2024-04-30 05:00

Could you shed light on the severe financial losses that result from triangulation fraud and explain the intricacies of this scheme? The payments industry estimates triangulation fraud causes financial losses among merchants to range from $660 million to $1 billion monthly.