Security News

Researchers find critical RCE vulnerabilities in industrial VPN solutions
2020-07-28 15:49

Critical vulnerabilities in several industrial VPN implementations for remotely accessing operational technology networks could allow attackers to overwrite data, execute malicious code or commands, cause a DoS condition, and more. "Exploiting these vulnerabilities can give an attacker direct access to the field devices and cause some physical damage," Claroty researchers noted.

Researchers Warn of High-Severity Dell PowerEdge Server Flaw
2020-07-28 13:11

Researchers have disclosed details of a recently patched, high-severity Dell PowerEdge server flaw, which if exploited could allow an attacker to fully take over and control server operations. The web vulnerability was found in the Dell EMC iDRAC remote access controller, technology embedded within the latest versions of Dell PowerEdge servers.

Researchers Reveal New Security Flaw Affecting China's DJI Drones
2020-07-27 23:58

Cybersecurity researchers on Thursday revealed security issues in the Android app developed by Chinese drone-maker Da Jiang Innovations that comes with an auto-update mechanism that bypasses Google Play Store and could be used to install malicious applications and transmit sensitive personal information to DJI's servers. "Given the wide permissions required by DJI GO 4 - contacts, microphone, camera, location, storage, change network connectivity - the DJI or Weibo Chinese servers have almost full control over the user's phone."

Researchers Reveal New Security Flaw Affecting China's DJI Drones
2020-07-27 23:58

Cybersecurity researchers on Thursday revealed security issues in the Android app developed by Chinese drone-maker Da Jiang Innovations that comes with an auto-update mechanism that bypasses Google Play Store and could be used to install malicious applications and transmit sensitive personal information to DJI's servers. "Given the wide permissions required by DJI GO 4 - contacts, microphone, camera, location, storage, change network connectivity - the DJI or Weibo Chinese servers have almost full control over the user's phone."

DJI Drone App Riddled With Privacy Issues, Researchers Allege
2020-07-24 18:48

The privacy issues were discovered in the DJI GO 4 application, which is the complementary app used to control DJI drones. Researchers with Synacktiv found several concerning privacy issues,, which were then independently confirmed by researchers with GRIMM. "The DJI GO 4 application contains several suspicious features as well as a number of anti-analysis techniques, not found in other applications using the same SDKs," according to researchers with GRIMM, in a Thursday post.

Apple Offers Hackable iPhones to Security Researchers
2020-07-23 15:42

Apple this week kicked off another initiative meant to improve the security of iPhones, by offering hackable phones to security researchers. Specifically designed for security researchers, these devices feature unique code execution and containment policies and are offered as part of the company's Security Research Device program, which was initially announced in December last year.

Researchers Disclose New Methods for Replacing Content in Signed PDF Files
2020-07-23 14:12

A team of researchers from the Ruhr University Bochum in Germany has disclosed a series of new attack methods against signed PDF files. Dubbed Shadow Attacks, the new techniques allow a hacker to hide and replace content in a signed PDF document without invalidating its signature.

Researchers develop new learning algorithm to boost AI efficiency
2020-07-22 04:00

A working group led by two computer scientists Wolfgang Maass and Robert Legenstein of TU Graz has adopted this principle in the development of the new machine learning algorithm e-prop. Learning is a particular challenge for such less active networks, since it takes longer observations to determine which neuron connections improve network performance.

In addition to traditional DDoS attacks, researchers see various abnormal traffic patterns
2020-07-21 05:27

DDoS attacks have become a global risk, and as attacks continue to increase in complexity, further spurred by the pandemic, ISPs will have to strengthen their security measures. While DDoS attacks disrupt service for large companies and individuals alike, ISPs face increasing challenges to curb undetectable and abnormal traffic patterns before they evolve into uncontrollable reflection attacks.

Researchers Find More Malware Delivered via Chinese Tax Software
2020-07-14 16:00

Trustwave's security researchers have discovered another malware family delivered through tax software that Chinese banks require companies doing business in the country to use. The discovery comes only weeks after the security firm published information on GoldenSpy, a backdoor delivered via the Intelligent Tax application produced by the Golden Tax Department of Aisino Corporation.