Security News

MFA vs 2FA: Which Is Best for Your Business?
2024-03-15 15:17

The terms 2FA and MFA are sometimes used interchangeably. This is because 2FA is really a subset of MFA. 2FA involves only one additional authentication factor.

McDonald's IT systems outage impacts restaurants worldwide
2024-03-15 14:42

McDonald's restaurants are suffering global IT outages that prevent employees from taking orders and accepting payments, causing some stores to close for the day. The outages started overnight and are impacting restaurants globally, including those in the USA, Japan, Australia, Canada, the Netherlands, Italy, New Zealand, and the UK. "We are aware of a technology outage, which impacted our restaurants; the issue is now being resolved," McDonald's said in a statement to BleepingComputer.

6 Best VPNs for Gaming in 2024
2024-03-15 14:15

Why we chose CyberGhost VPN. I selected CyberGhost for its easy-access For Gaming server list that saves gaming businesses the hassle of looking for optimal servers for gaming. Choosing the best VPN for gaming will largely depend on what type of gaming business you have and your particular circumstances.

Cop shop rapped for 'completely avoidable' web form blunder
2024-03-15 11:34

The London Mayor's Office for Policing and Crime is being rapped by regulators for untidy tech practices that made public the personal data of hundreds of people who filed complaints against the Metropolitan Police Service. Between November 11-14 2022, an unnamed employee of the GLA had meant to permit four colleagues access to data shared via the web forms but instead made both forms open to anyone on the internet.

Third-Party ChatGPT Plugins Could Lead to Account Takeovers
2024-03-15 11:34

Cybersecurity researchers have found that third-party plugins available for OpenAI ChatGPT could act as a new attack surface for threat actors looking to gain unauthorized access to sensitive...

Improving C++
2024-03-15 11:05

C++ guru Herb Sutter writes about how we can improve the programming language for better security. The immediate problem "Is" that it's Too Easy By Defaultâ„¢ to write security and safety vulnerabilities in C++ that would have been caught by stricter enforcement of known rules for type, bounds, initialization, and lifetime language safety.

Google Introduces Enhanced Real-Time URL Protection for Chrome Users
2024-03-15 07:50

Google has introduced an updated Safe Browsing feature for Chrome on desktop and iOS, offering real-time protection against malicious sites while preserving user privacy. This enhancement allows Chrome to compare site URLs against Google's server-side database of known threats in real time, potentially blocking 25% more phishing attempts. Previously, Chrome relied on a locally-stored database updated every 30 to 60 minutes.The shift to server-side checks, announced in September 2023, aims to address the rapid growth of harmful websites and the brief existence of phishing domains. The new system checks URLs against cached safe URLs and previous Safe Browsing results. For URLs not in the cache,

Malicious Ads Targeting Chinese Users with Fake Notepad++ and VNote Installers
2024-03-15 06:18

Chinese users looking for legitimate software such as Notepad++ and VNote on search engines like Baidu are being targeted with malicious ads and bogus links to distribute trojanized versions of...

Key MITRE ATT&CK techniques used by cyber attackers
2024-03-15 06:00

The classic tools and techniques adversaries deploy remain consistent-with some notable exceptions. Detections for malicious email forwarding rules rose by nearly 600%, as adversaries compromised email accounts, redirected sensitive communications to archive folders and other places users are unlikely to look, and attempted to modify payroll or wire transfer destinations, rerouting money into the criminal's account.

90% of exposed secrets on GitHub remain active for at least five days
2024-03-15 05:30

12.8 million new secrets occurrences were leaked publicly on GitHub in 2023, +28% compared to 2022, according to GitGuardian. Remarkably, the incidence of publicly exposed secrets has quadrupled since the company started reporting in 2021.