Security News

Hacking Digitally Signed PDF Files
2021-03-08 12:10

Interesting paper: "Shadow Attacks: Hiding and Replacing Content in Signed PDFs":. Abstract: Digitally signed PDFs are used in contracts and invoices to guarantee the authenticity and integrity of their content. A user opening a signed PDF expects to see a warning in case of any modification.

Shadow Attacks Let Attackers Replace Content in Digitally Signed PDFs
2021-02-23 02:46

Researchers have demonstrated a novel class of attacks that could allow a bad actor to potentially circumvent existing countermeasures and break the integrity protection of digitally signed PDF documents. To carry out the attack, a malicious actor creates a PDF document with two different contents: one which is the content that's expected by the party signing the document, and the other, a piece of hidden content that gets displayed once the PDF is signed.

Hacker leaks full database of 77 million Nitro PDF user records
2021-01-20 12:17

The 14GB leaked database contains 77,159,696 records with users' email addresses, full names, bcrypt hashed passwords, titles, company names, IP addresses, and other system-related information. Nitro is an application that helps create, edit, and sign PDFs and digital documents, an app that Nitro Software claims to have over 10,000 business customers and roughly 1.8 million licensed users.

New Injection Technique Exposes Data in PDFs
2020-12-10 17:13

Security researchers on Thursday documented and described a new injection technique capable of extracting sensitive data from PDF files. The new code-injection technique essentially allows hackers to inject code to launch dangerous XSS attacks within the bounds of a PDF document.

Here's how to enable Google Chrome's new modern PDF reader
2020-11-23 12:09

Hidden behind a flag is a much-anticipated PDF reader that users can enable right now. The PDF reader or viewer within Google Chrome has always been relatively simple, especially compared to other browsers, like Microsoft Edge.

Foxit Patches Code Execution Vulnerabilities in PDF Software
2020-10-14 10:22

PDF software developer Foxit has released patches to address several high-risk vulnerabilities affecting both Windows and macOS applications. Last week, the company released security updates for both Foxit PhantomPDF Mac and Foxit Reader Mac, to address a vulnerability that could result in code injection or information disclosure.

Researchers Disclose New Methods for Replacing Content in Signed PDF Files
2020-07-23 14:12

A team of researchers from the Ruhr University Bochum in Germany has disclosed a series of new attack methods against signed PDF files. Dubbed Shadow Attacks, the new techniques allow a hacker to hide and replace content in a signed PDF document without invalidating its signature.

Foxit PDF Reader, PhantomPDF Open to Remote Code Execution
2020-04-20 18:18

Foxit Software has released patches for dozens of high-severity flaws impacting its PDF reader and editor platforms. Overall, Foxit Software patched flaws tied to 20 CVEs in Foxit Reader and Foxit PhantomPDF for Windows.

Foxit PDF Reader Vulnerable to 8 High-Severity Flaws
2019-10-03 16:23

Eight high-severity vulnerabilities exist in the Foxit Reader tool for editing PDF files.

PDF encryption standard weaknesses uncovered
2019-10-03 12:12

Researchers have discovered weaknesses in PDF encryption which could be exploited to reveal the plaintext contents of a file to an attacker.