Security News

A Hacker’s Mind is Out in Paperback
2024-02-13 20:13

The paperback version of A Hacker's Mind has just been published. This is the real reason I am posting this-Amazon has significantly discounted the hardcover to $15 to get rid of its stock.

QNAP vulnerability disclosure ends up an utter shambles
2024-02-13 20:00

Network-attached storage specialist QNAP has disclosed and released fixes for two new vulnerabilities, one of them a zero-day discovered in early November. Unit 42's assessment, on the other hand, was the polar opposite: "These remote code execution vulnerabilities affecting IoT devices exhibit a combination of low attack complexity and critical impact, making them an irresistible target for threat actors. As a result, protecting IoT devices against such threats is an urgent task."

Microsoft patches two zero-days exploited by attackers (CVE-2024-21412, CVE-2024-21351)
2024-02-13 19:56

On February 2024 Patch Tuesday, Microsoft has delivered fixes for 72 CVE-numbered vulnerabilities, including two zero-days that are being leveraged by attackers in the wild. CVE-2024-21412 allows attackers to bypass the Microsoft Defender SmartScreen security feature with booby-trapped Internet Shortcut files.

200,000 Facebook Marketplace user records leaked on hacking forum
2024-02-13 19:30

A threat actor leaked 200,000 records on a hacker forum, claiming they contained the mobile phone numbers, email addresses, and other personal information of Facebook Marketplace users. IntelBroker claims this partial Facebook Marketplace database was stolen by someone using the 'algoatson' Discord handle after hacking the systems of a Meta contractor.

Integris Health says data breach impacts 2.4 million patients
2024-02-13 19:28

Integris Health has reported to U.S. authorities that the data breach it suffered last November exposed personal information belonging to almost 2.4 million people. Unless Integris Health met the attacker's demands, the stolen data would be sold to other cybercriminals on January 5, 2024.

ALPHV blackmails Canadian pipeline after 'stealing 190GB of vital info'
2024-02-13 19:20

Canada's Trans-Northern Pipelines has allegedly been infiltrated by the ALPHV/BlackCat ransomware crew, which claims to have stolen 190 GB of data from the oil distributor. ALPHV added Trans-Northern to its blackmail site on Tuesday and said the purloined files include "All important information."

Microsoft February 2024 Patch Tuesday fixes 2 zero-days, 73 flaws
2024-02-13 19:07

Today is Microsoft's February 2024 Patch Tuesday, which includes security updates for 73 flaws and two actively exploited zero-days. The total count of 73 flaws does not include 6 Microsoft Edge flaws fixed on February 8th and 1 Mariner flaw.

Microsoft February 2024 Patch Tuesday fixes 2 zero-days, 74 flaws
2024-02-13 19:07

Today is Microsoft's February 2024 Patch Tuesday, which includes security updates for 74 flaws and two actively exploited zero-days. The total count of 74 flaws does not include 6 Microsoft Edge and 1 Mariner flaw fixed on February 8th. To learn more about the non-security updates released today, you can review our dedicated articles on the new Windows 11 KB5034765 cumulative update.

Windows 11 KB5034765 update released with Start Menu fixes
2024-02-13 18:47

Microsoft has released the KB5034765 cumulative update for Windows versions 23H2 and 22H2 to fix several bugs in the OS, including an issue that causes problems with the Start menu. As this update contains the Microsoft February 2024 Patch Tuesday security updates, KB5034765 is mandatory for all Windows 11 users unless you delay its installation.

RoboForm Review (2024): Pricing, Features, Pros, & Cons
2024-02-13 18:03

RoboForm has also undergone a third-party security audit that positively confirmed its security promises. RoboForm has its own password health dashboard called Security Center that gives you important data on the health of all your credentials.