Security News

UK to replace physical biometric immigration cards with e-visas
2024-02-10 10:00

By 2025, Britain is set to ditch physical immigration status documents such as Biometric Residence Permits and Biometric Residence Cards in a bid to make its borders digital, which is in-line with developed countries like Australia. Presently, students, workers, immigrants and their dependents from non-EU countries residing in the UK are eventually issued Biometric Residence Permits, cards which are proof of their immigration status in the country.

Alert: New Stealthy "RustDoor" Backdoor Targeting Apple macOS Devices
2024-02-10 07:12

Apple macOS users are the target of a new Rust-based backdoor that has been operating under the radar since November 2023.The backdoor codenamed “RustDoor” by Bitdefender, has been found to impersonate an update for Microsoft Visual Studio and target both Intel and Arm architectures.

Meet VexTrio, a network of 70K hijacked websites crooks use to sling malware, fraud
2024-02-10 03:31

More than 70,000 presumably legit websites have been hijacked and drafted into a network that crooks use to distribute malware, serve phishing pages, and share other dodgy stuff, according to researchers. In the case of VexTrio, tens of thousands of websites are compromised so that their visitors are redirected to pages that serve up malware downloads, show fake login pages to steal credentials, or perform some other fraud or cyber-crime.

Friday Squid Blogging: A Penguin Named “Squid”
2024-02-09 22:09

Amusing story about a penguin named "Squid." As usual, you can also use this squid post to talk about the security stories in the news that I haven't covered.

Ivanti discloses fifth vulnerability, doesn't credit researchers who found it
2024-02-09 21:30

In disclosing yet another vulnerability in its Connect Secure, Policy Secure, and ZTA gateways, Ivanti has confused the third-party researchers who discovered it. Researchers at watchTowr blogged today about not being credited with the discovery of CVE-2024-22024 - the latest in a series of vulnerabilities affecting Ivanti gateways as the vendor continues to develop patches for supported versions.

New Fortinet RCE bug is actively exploited, CISA confirms
2024-02-09 21:02

CISA confirmed today that attackers are actively exploiting a critical remote code execution bug patched by Fortinet on Thursday. CISA's announcement comes one day after Fortinet published a security advisory saying the flaw was "Potentially being exploited in the wild."

Canada to ban the Flipper Zero to stop surge in car thefts
2024-02-09 19:16

The Canadian government plans to ban the Flipper Zero and similar devices after tagging them as tools thieves can use to steal cars. The figures shared by the Canadian government when describing the car theft surge currently impacting Canada align with the most recent data shared by the Statistics Canada government agency, which shows an increasing number of car theft reports since 2021.

No, Toothbrushes Were Not Used in a Massive DDoS Attack
2024-02-09 18:10

The widely reported story last week that 1.5 million smart toothbrushes were hacked and used in a DDoS attack is false. Near as I can tell, a German reporter talking to someone at Fortinet got it wrong, and then everyone else ran with it without reading the German text.

Bitwarden Free vs. Premium: Which Plan Is Best For You?
2024-02-09 17:57

The Bitwarden Free plan allows you to send encrypted text only, whereas Bitwarden Premium users can attach other file types. Bitwarden Free users can enable two-step login, such as MFA, for their Bitwarden account using an authenticator app or email verification codes.

Microsoft: Outlook clients not syncing over Exchange ActiveSync
2024-02-09 17:57

Microsoft warned Outlook for Microsoft 365 users that clients might have issues connecting to email servers via Exchange ActiveSync after a January update."After updating to Version 2401 Build 17231.20182 Outlook stops connecting when using the Exchange ActiveSync protocol," Microsoft said.