Security News

None of our apps (except those 3) could secretly slurp Facebook user details, devs rage to High Court of England and Wales
2020-11-03 17:20

Mobile app developers accused by Facebook of deploying "Malicious" SDKs to scrape users' data from the social network have hit back, telling London's High Court that nearly all their apps were "Not capable" of harvesting data from Facebook itself. Haltas has now hit back, claiming that all but three of his apps couldn't possibly scrape data from Facebook because they didn't use the Login with Facebook feature.

China reveals audit of 320,000 local apps, with 34 booted from app stores and hundreds of devs warned they could suffer same fate
2020-10-23 04:27

Through most of 2020 bans on Chinese apps have meant geopolitical strife, but China yesterday revealed it has started banning some of its own apps. A ban on 34 apps was among the nuggets of news revealed, with their banishment from local app stores the result of a departmental trawl of 320,000 apps offered in local download-marts.

Old and busted: Targeting servers and web bugs. New hotness: Pwning devs with targeted poisoned stacks
2020-09-04 11:15

Speaking at the 2020 Disclosure conference, Jones outlined how the trust many developers put in their software stacks and shared code, paired with a disturbing lack of online savvy, can make them easy pickings for hackers. "Systems are generally hardened - they have patches, they have firewalls, they have monitoring," Jones explained, "But [some] developers will run literally any bullshit they find on Stack Overflow. They keep credentials lying about, they're obviously going to have the source code and some production data sitting on their hardware as well."

Microsoft Announces New Security Features for Devs, Customers
2020-05-21 08:41

At this week's Build virtual event, Microsoft announced new Identity and Azure features meant to improve security for both application developers and enterprise customers. This week, Microsoft announced two new additions to Azure Security Center: the availability of Azure Secure Score API to customers, and the public availability of suppression rules for Azure Security Center alerts, which are meant to reduce alerts fatigue.

OpenBSD devs patch authentication bypass bug
2019-12-06 11:31

One of the internet's most popular free operating systems allowed attackers to bypass its authentication controls.

Facebook confesses 100 devs may have accessed leaked Groups data
2019-11-07 12:48

It shut down that access in April 2018, or at least thought it did. At least 11 improperly accessed data in the last two months.

Chrome devs tell world that DNS over HTTPS won't open the floodgates of hell
2019-10-29 18:02

Well, their version of it won't, they claim Chrome devs have had a little rant about "misinformation", repeating that DNS-over-HTTPS (DoH) won't yet be introduced by default in upcoming builds of...

Google warns devs as it tightens Chrome cookie security: Stuff will break if you're not clued up
2019-10-24 14:15

You'll have to tag those for cross-site use from February Google is asking developers to get ready for more secure cookie settings to be implemented in Chrome 80 that is planned for release in...

Too bad, so sad, exploit devs: Google patches possibly several million dollars' worth of security flaws in Android
2019-09-05 23:43

Except one – a 'your phone is now my phone' bug reported months ago and still not fixed Google this week emitted the September edition of its monthly Android security updates – and has left at...

No REST for the wicked: Ruby gem hacked to siphon passwords, secrets from web devs
2019-08-20 21:21

Developer account cracked due to credential reuse, source tampered with and released to hundreds of programmers An old version of a Ruby software package called rest-client that was modified and...