Security News

KidsGuard stalkerware leaks data on secretly surveilled victims
2020-02-24 13:28

KidsGuard comes from a company called ClevGuard that promises that its "Excellent products" will deliver "All the information" from a targeted device, including real-time location, text messages, browser history, photos, videos, recordings of phone calls, keylogger data for every keystroke entered and the app where it came from, and all the data from all the social apps - hopping over the end-to-end encryption of, for example, WhatsApp. ClevGuard says the app can also be used for iPhones without access to the device if you give it the target's iCloud credentials.

Samsung cops to data leak after unsolicited '1/1' Find my Mobile push notification
2020-02-24 13:20

Samsung has admitted that what it calls a "Small number" of users could indeed read other people's personal data following last week's unexplained Find my Mobile notification. Several Register readers wrote in to tell us that, after last Thursday's mystery push notification, they found strangers' personal data displayed to them.

Trump 'Offered Pardon' to Assange If He Denied Russia Leak, Court Hears
2020-02-20 05:07

US President Donald Trump promised to pardon WikiLeaks founder Julian Assange if he denied Russia leaked emails of his 2016 election rival's campaign, a London court was told on Wednesday. The White House quickly issued a denial that Trump had dangled a pardon in exchange for help in the Russia controversy, which has cast a shadow over his first term in office.

New 'CacheOut' Attack Leaks Data from Intel CPUs, VMs and SGX Enclave
2020-01-28 08:36

If your computer is running any modern Intel CPU built before October 2018, it's likely vulnerable to a newly discovered hardware issue that could allow attackers to leak sensitive data from the OS kernel, co-resident virtual machines, and even from Intel's secured SGX enclave. Dubbed CacheOut a.k.a. L1 Data Eviction Sampling and assigned CVE-2020-0549, the new microarchitectural attack allows an attacker to choose which data to leak from the CPU's L1 Cache, unlike previously demonstrated MDS attacks where attackers need to wait for the targeted data to be available.

Hacker Leaks More Than 500K Telnet Credentials for IoT Devices
2020-01-21 11:57

Bad actor obtained passwords for servers, home routers, and smart devices by scanning internet for devices open to the Telnet port. A hacker has published a list of credentials for more than 515,000 servers, home routers and other Internet of Things devices online on a popular hacking forum in what's being touted as the biggest leak of Telnet passwords to date, according to a published report.

Mitsubishi Electric discloses data breach, possible data leak
2020-01-21 11:40

Japanese multinational Mitsubishi Electric has admitted that it had suffered a data breach some six months ago, and that "Personal information and corporate confidential information may have been leaked." According to several reports from Japanese daily newspapers, the company discovered the data breach in late June, when they detected suspicious activities on a server at its Information Technology R&D Center in Kamakura, Kanagawa Prefecture, Japan.

Unprotected Database Leaks Data of Wyze Users
2020-01-02 17:05

An unprotected database was found to have exposed the data of all Wyze users who created an account before December 26, 2019. Following a report last week of an exposed database containing a great deal of information on Wyze users, the company stepped forward and confirmed the leak, while also revealing that it had launched an investigation into the matter.

IoT Company Wyze Leaks Emails, Device Data of 2.4M
2019-12-30 16:53

The Internet of Things vendor confirmed that customer data was left unsecured on an Elasticsearch database.

Honda Leaks Data of 26K North American Customers
2019-12-19 15:45

The leaky database was online for about a week, exposing customers' vehicles information and personal identifiable information.