Security News

Stop us if you've heard this one: Remote code hijacking flaw in Apache Struts, patch ASAP
2018-11-07 01:49

Advisory issued over yet another critical security vulnerability The Apache Foundation is urging developers to update their Struts 2 installations and projects using the code – after a critical...

PoC Exploit Compromises Microsoft Live Accounts via Subdomain Hijacking
2018-11-01 15:44

Poor DNS housekeeping opens the door to account takeover.

China hijacking internet traffic using BGP, claim researchers
2018-10-30 11:28

Researchers claim that unusual BGP routing changes are actually man-in-the-middle surveillance.

IoT Flaw Allows Hijacking of Connected Construction Cranes
2018-10-29 20:50

An attacker can send spoofed commands to the crane's controller.

Get patching, if you can: Grave TCP/IP flaws in FreeRTOS leave IoT gear open to mass hijacking
2018-10-22 20:05

AWS-stewarded net-connected platform has multiple remote code execution vulnerabilities Serious security flaws in FreeRTOS – an operating system kernel used in countless internet-connected devices...

Popular TP-Link wireless home router open to remote hijacking
2018-10-03 10:35

By concatenating a known improper authentication flaw with a newly discovered CSRF vulnerability, remote unauthenticated attackers can obtain full control over TP-Link TL-WRN841N, a popular...

Instagram fights misinformation and account hijackings with new tools
2018-08-30 09:30

Users will soon be able to use authenticator apps for 2FA codes, request blue verified badges, and get more context about big accounts.

The single sign-on account hijacking threat and what can we do about it?
2018-08-22 14:54

Single sign-on (SSO) lets users avoid creating and managing accounts across different services, but what happens when that main, identity-providing account gets compromised? Can users remediate a...

BGP Hijacking Attacks Target US Payment Processors
2018-08-07 20:16

Several payment processing companies in the United States were targeted recently in BGP hijacking attacks whose goal was to redirect users to malicious websites, Oracle reported last week. read more

Beware this Android emulator, it's hijacking your GPU to mine cryptocurrency
2018-06-18 18:55

Users have accused Andy OS Android Emulator of secretly dropping a cryptocurrency miner on your system that runs endlessly.