Security News > 2024 > October

Roger Grimes on Prioritizing Cybersecurity Advice
2024-10-31 15:43

This is a good point: Part of the problem is that we are constantly handed lists…list of required controls…list of things we are being asked to fix or improve…lists of new projects…lists of...

Tracking World Leaders Using Strava
2024-10-31 15:16

Way back in 2018, people noticed that you could find secret military bases using data published by the Strava fitness app. Soldiers and other military personal were using them to track their runs,...

qBittorrent fixes flaw exposing users to MitM attacks for 14 years
2024-10-31 15:11

qBittorrent has addressed a remote code execution flaw caused by the failure to validate SSL/TLS certificates in the application's DownloadManager, a component that manages downloads throughout...

New LightSpy Spyware Version Targets iPhones with Increased Surveillance Tactics
2024-10-31 15:00

Cybersecurity researchers have discovered an improved version of an Apple iOS spyware called LightSpy that not only expands on its functionality, but also incorporates destructive capabilities to...

Microsoft fixes Windows 10 bug causing apps to stop working
2024-10-31 14:40

Microsoft has fixed a known issue that prevents some apps launched from non-admin accounts from starting on Windows 10 22H2 systems after installing the September preview cumulative update. [...]

LottieFiles Issues Warning About Compromised "lottie-player" npm Package
2024-10-31 14:16

LottieFiles has revealed that its npm package "lottie-player" was compromised as part of a supply chain attack, prompting it to release an updated version of the library. "On October 30th ~6:20 PM...

Sophos mounted counter-offensive operation to foil Chinese attackers
2024-10-31 13:57

Sophos conducted defensive and counter-offensive operation over the last five years with multiple interlinked nation-state adversaries based in China targeting perimeter devices, including Sophos...

Google on scaling differential privacy across nearly three billion devices
2024-10-31 13:00

In this Help Net Security interview, Miguel Guevara, Product Manager, Privacy Safety and Security at Google, discusses the complexities involved in scaling differential privacy technology across...

Over a thousand online shops hacked to show fake product listings
2024-10-31 13:00

A phishing campaign dubbed 'Phish n' Ships' has been underway since at least 2019, infecting over a thousand legitimate online stores to promote fake product listings for hard-to-find items. [...]

Lottie Player supply chain compromise: Sites, apps showing crypto scam pop-ups
2024-10-31 12:35

A supply chain compromise involving Lottie Player, a widely used web component for playing site and app animations, has made popular decentralized finance apps show pop-ups urging users to connect...