Security News

Critical Security Flaw Found in Popular LayerSlider WordPress Plugin
2024-04-03 05:11

A critical security flaw impacting the LayerSlider plugin for WordPress could be abused to extract sensitive information from databases, such as password hashes. The flaw, designated...

Microsoft slammed for lax security that led to China's cyber-raid on Exchange Online
2024-04-03 02:15

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

Microsoft slammed for lax security that led to China's cyber-raid on Exchange Online
2024-04-03 02:15

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

Winnti's new UNAPIMON tool hides malware from security software
2024-04-02 21:59

The Chinese 'Winnti' hacking group was found using a previously undocumented malware called UNAPIMON to let malicous processes run without being detected. UNAPIMON is a C++ malware delivered in DLL form, which uses Microsoft Detours for hooking the CreateProcessW API function, allowing it to unhook critical API functions in child processes.

3 UK Cyber Security Trends to Watch in 2024
2024-04-02 21:03

Staying up to date with the latest in cyber security has arguably never been more paramount than in 2024. TechRepublic consulted U.K. industry experts to identify the three most significant trends in cyber security - AI, zero days and IoT security - and provide guidance as to how businesses can best hold their fort.

Harnessing the Power of CTEM for Cloud Security
2024-04-02 11:27

Cloud solutions are more mainstream – and therefore more exposed – than ever before. In 2023 alone, a staggering 82% of data breaches were against public, private, or hybrid cloud environments....

Apple's GoFetch silicon security fail was down to an obsession with speed
2024-04-02 07:30

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

6 keys to navigating security and app development team tensions
2024-04-02 03:00

The security team's animosity toward development teams grows as they view developers as not "Taking security seriously enough." That's why I've decided to share what I've learned from managing the application security team at a large telecom with some success in balancing the tensions between developers and security.

Magic Security Dust
2024-04-01 14:19

About Bruce Schneier I am a public-interest technologist, working at the intersection of security, technology, and people. I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.

Vultur banking malware for Android poses as McAfee Security app
2024-03-30 15:56

Security researchers found a new version of the Vultur banking trojan for Android that includes more advanced remote control capabilities and an improved evasion mechanism. A report from Fox-IT, part of the NCC Group, warns that a new, more evasive version of Vultur spreads to victims through a hybrid attack that relies on smishing and phone calls that trick the targets into installing a version of the malware that masquerades as the McAfee Security app.