Security News

Malware peddlers experimenting with BPL sideloading and masking malicious payloads as PGP keys
2024-06-26 12:34

"The LNK file triggered the first element of the novel technique used in this infection chain for distributing IDAT Loader. The LNK file was using mshta.exe to execute what appeared to be a 'PGP Secret Key,' hosted again on Bunny CDN," Kroll's threat analysts found. Static analysis of that file showed that it was not a PGP key, but a combination of junk bytes, an embedded HTA file and an embedded EXE file.

PGP Ecosystem Targeted in ‘Poisoning’ Attacks
2019-07-05 17:05

Two researchers are being singled out in what are called PGP poisoning or flood attacks that render the authentication tool unusable for victims.

Why PGP is fundamentally flawed and needs to be fixed
2018-06-28 18:51

Encryption should be the go-to standard for securing communications, such as email. Unfortunately, the user-facing technology that works with PGP is flawed. Jack Wallen explains.

Zimmerman and friends: 'Are you listening? PGP is not broken'
2018-05-25 01:57

EFAIL furore not over yet, even though it's easy to fix ProtonMail has weighed into 2018's worst branded-bug PR disaster, EFAIL with a simple statement: “PGP is not broken”.…

S/MIME artists: EFAIL email app flaws put a bomb under PGP-encrypted messages
2018-05-14 20:39

If a hacker can get into your inbox of ciphered messages, they may be able to read the content Security researchers have gone public with vulnerabilities in some secure mail apps that can be...

S/MIME, PGP, OMG! EFAIL encryption flaw leaves emails vulnerable to secret snooping
2018-05-14 20:39

Researchers punch hole in encryption classics Security researchers are going public with a vulnerability that is leaving some secure mail apps vulnerable to decryption.…

Details on a New PGP Vulnerability
2018-05-14 18:36

A new PGP vulnerability was announced today. Basically, the vulnerability makes use of the fact that modern e-mail programs allow for embedded HTML objects. Essentially, if an attacker can...

Here's How eFail Attack Against PGP and S/MIME Encrypted Emails Works
2018-05-14 18:33

With a heavy heart, security researchers have early released the details of a set of vulnerabilities discovered in email clients for two widely used email encryption standards—PGP and S/MIME—after...

Critical PGP Vulnerability
2018-05-14 14:33

EFF is reporting that a critical vulnerability has been discovered in PGP and S/MIME. No details have been published yet, but one of the researchers wrote: We'll publish critical vulnerabilities...

Critical PGP vulnerability could reveal text of your encrypted business emails
2018-05-14 12:45

The vulnerability, called EFAIL, is exploitable against encrypted email, including previously transmitted mail, according to researchers.