Security News

5 SaaS Misconfigurations Leading to Major Fu*%@ Ups
2024-11-01 10:20

With so many SaaS applications, a range of configuration options, API capabilities, endless integrations, and app-to-app connections, the SaaS risk possibilities are endless. Critical...

Lottie Player supply chain compromise: Sites, apps showing crypto scam pop-ups
2024-10-31 12:35

A supply chain compromise involving Lottie Player, a widely used web component for playing site and app animations, has made popular decentralized finance apps show pop-ups urging users to connect...

UPS supplier's password policy flip-flops from unlimited, to 32, then 64 characters
2024-09-23 12:01

That 'third party' person sure is responsible for a lot of IT blunders, eh? A major IT hardware manufacturer is correcting a recent security update after customers complained of a password...

Collection agency FBCS ups data breach tally to 3.2 million people
2024-06-03 23:11

Debt collection agency Financial Business and Consumer Solutions now says over 3.2 million people have been impacted by a data breach that occurred in February. In late April, the firm reported that roughly 1.9 million people in the U.S. had sensitive personal information compromised in a data breach incident on February 14, 2024.

Product showcase: Block ads, cookie pop-ups, trackers with CleanWeb
2024-05-16 04:00

By eliminating intrusive ads, trackers, and cookie notifications, CleanWeb ensures a smoother, faster, and more enjoyable browsing experience that no longer comes at the cost of personal privacy. CleanWeb is part of Surfshark VPN. CleanWeb is one of many additional features you get with Surfshark VPN. It comes with a VPN subscription at no extra cost and can be accessed via a browser extension or the app.

PyPI Halts Sign-Ups Amid Surge of Malicious Package Uploads Targeting Developers
2024-03-29 05:37

The maintainers of the Python Package Index (PyPI) repository briefly suspended new user sign-ups following an influx of malicious projects uploaded as part of a typosquatting campaign....

Fortinet's week to forget: Critical vulns, disclosure screw-ups, and that toothbrush DDoS attack claim
2024-02-09 14:30

The only workaround recommended by Fortinet is to disable the SSL VPN. Disabling webmode won't mitigate the vulnerability, it said. Firstly, Fortinet backtracked and said these weren't vulnerabilities at all, instead explaining that they were issued in error and were duplicates of the single vulnerability mentioned in the aforementioned October advisory - CVE-2023-34992.

UPS Data Harvested for SMS Phishing Attacks
2023-06-23 14:55

I never click on it, because it's so obviously spam. Turns out that hackers have been harvesting actual UPS delivery data from a Canadian tracking tool for its phishing SMSs. Tags: cybercrime, phishing, phones, SMS, spam.

UPS discloses data breach after exposed customer info used in SMS phishing
2023-06-21 17:43

Multinational shipping company UPS is alerting Canadian customers that some of their personal information might have been exposed via its online package look-up tools and abused in phishing attacks. At first glance, the letters sent by UPS Canada, titled "Fighting phishing and smishing - an update from UPS," seem to be a warning to customers about the dangers of phishing.

Google changes email authentication after spoof shows a bad delivery for UPS
2023-06-09 01:02

Google says it has fixed a flaw that allowed a scammer to impersonate delivery service UPS on Gmail, after the data-hoarding web behemoth labeled the phony email as authentic. The problem stemmed from an issue in an email authentication program called Brand Indicators for Message Identification that aims to protect email users from brand spoofing and phishing attacks claiming to be from a trusted org.