Security News

Loads of PostgreSQL systems are sitting on the internet without SSL encryption
2022-10-07 10:48

Only a third of PostgreSQL databases connected to the internet use SSL for encrypted messaging, according to a cloud database provider. Bit.io, which offers a drag-and-drop database as a service based on PostgreSQL, searched shodan.io to create a sample of 820,000 PostgreSQL servers connected to the internet over September 1-29.

Matrix: Install security update to fix end-to-end encryption flaws
2022-09-29 18:32

Matrix decentralized communication platform has published a security warning about two critical-severity vulnerabilities that affect the end-to-end encryption in the software development kit. A threat actor exploiting these flaws could break the confidentiality of Matrix communications and run man-in-the-middle attacks that expose message contents in a readable form.

Matrix chat encryption sunk by five now-patched holes
2022-09-28 21:22

Four security researchers have identified five cryptographic vulnerabilities in code libraries that can be exploited to undermine Matrix encrypted chat clients. "Our perspective is that these attacks together show a rich attack surface in Matrix from both a protocol and implementation perspective," Benjamin Dowling, a lecturer in cybersecurity, told The Register this week.

Meta, Twitter, Apple, Google urged to up encryption game in post-Roe America
2022-09-20 19:19

Tech companies are throwing their users to the wolves by allowing company employees, cops, and other third parties to access unprotected messages. "After the reversal of Roe v. Wade and with more rights cutbacks on the way, tech companies are throwing their users to the wolves by allowing company employees, cops, and other third parties to access unprotected messages."

TeamTNT hijacking servers to run Bitcoin encryption solvers
2022-09-18 14:07

The recent attacks bear various signatures linked to TeamTNT and rely on tools previously deployed by the gang, indicating that the threat actor is likely making a comeback. The researchers observed three attack types being used in the allegedly new TeamTNT attacks, with the most interesting one being to use the computational power of hijacked servers to run Bitcoin encryption solvers.

Ransomware makes use of intermittent encryption to bypass detection algorithms
2022-09-12 22:36

A study of BlackCat ransomware using different file sizes revealed that intermittent encryption brings significant speed benefits to threat actors. Historically, LockFile ransomware has been the first malware family to make use of intermittent encryption, in mid-2021, yet several different ransomware families are now using it.

Ransomware gangs switching to new intermittent encryption tactic
2022-09-10 14:07

These groups actively promote the presence of intermittent encryption features in their ransomware family to entice affiliates to join the RaaS operation. Agenda ransomware offers intermittent encryption as an optional and configurable setting.

Hyundai Uses Example Keys for Encryption System
2022-08-22 11:38

A developer says it was possible to run their own software on the car infotainment hardware after discovering the vehicle's manufacturer had secured its system using keys that were not only publicly known but had been lifted from programming examples. "Turns out the [AES] encryption key in that script is the first AES 128-bit CBC example key listed in the NIST document SP800-38A [PDF]".

OpenFHE: Open-Source Fully Homomorphic Encryption
2022-08-19 03:30

Fully Homomorphic Encryption (FHE) is a cryptographic primitive that enables performing computations over encrypted data without having access to the secret key. In this Help Net Security video,...

Facebook Testing Default End-to-End Encryption and Encrypted Backups in Messenger
2022-08-13 05:23

Social media company Meta said it will begin testing end-to-end encryption on its Messenger platform this week for select users as the default option, as the company continues to slowly add security layers to its various chat services. "If you're in the test group, some of your most frequent chats may be automatically end-to-end encrypted, which means you won't have to opt in to the feature," Sara Su, product management director of Messenger Trust, said.