Security News

Authentication Bypass Vulnerability Found in SoftNAS Cloud
2019-03-20 19:48

A security firm's Vulnerability Research Team (VRT) found and reported a vulnerability in SoftNAS Cloud data storage. SoftNAS fixed the vulnerability last week, and details of the vulnerability...

Vulnerability in SoftNAS Cloud allows attackers to bypass authentication
2019-03-20 14:00

The vulnerability allows attackers to run arbitrary commands as root, which clearly undermines the security of the SoftNAS Cloud platform and data stored on it.

Attackers are exploiting IMAP to bypass MFA on Office 365, G Suite accounts
2019-03-20 12:21

Where possible, and especially for important accounts such as Office 365 and G Suite accounts, the prevailing advice for users is to enable two-factor authentication. Unfortunately, that security...

Hackers Bypass MFA on Cloud Accounts via IMAP Protocol
2019-03-15 15:50

Over the past several months, threat actors have been increasingly targeting Office 365 and G Suite cloud accounts that are using the legacy IMAP protocol, in an attempt to bypass multi-factor...

Bug Allows Bypass of WhatsApp Face ID, Touch ID Protection
2019-02-22 18:06

The Face ID and Touch ID authentication feature introduced recently to WhatsApp for iOS can be easily bypassed, but a patch has been released. read more

Flash “security bypass” list hidden in Microsoft Edge browser
2019-02-22 12:20

Until this month, the Edge browser could bypass its own warnings about Flash content on 58 websites, thanks to a hidden list.

Thousands of Android apps bypass Advertising ID to track users
2019-02-19 13:23

Six years after it was introduced, it looks as if Android’s Advertising ID (AAID) might no longer be the privacy forcefield Google claimed it would be.

Hackers Using RDP Are Increasingly Using Network Tunneling to Bypass Protections
2019-01-25 16:21

Threat actors conducting Remote Desktop Protocol (RDP) attacks are increasingly using network tunneling and host-based port forwarding to bypass network protections, FireEye reports.  read more

Phishers Use Zero-Width Spaces to Bypass Office 365 Protections
2019-01-11 21:03

A recently addressed vulnerability in Office 365 allowed attackers to bypass existing phishing protections and deliver malicious messages to victims’ inboxes.  read more

Yet Another Bypass: Is 2FA Broken? Authentication Experts Weigh In
2019-01-11 15:44

A penetration testing tool called Modlishka can defeat two-factor authentication in the latest 2FA security issue. We asked a roundtable of experts what it all means.