Security News

Google Chrome to let Isolated Web App access sensitive USB devices
2024-06-30 21:17

Google is working on a new Unrestricted WebUSB feature, which allows trusted isolated web apps to bypass security restrictions in the WebUSB API. WebUSB is a JavaScript API that allows web applications to access local USB devices on a computer. Google is now testing an "Unrestricted WebUSB" feature that allows Isolated Web Apps to access these restricted devices and interfaces.

New SnailLoad Attack Exploits Network Latency to Spy on Users' Web Activities
2024-06-28 09:59

A group of security researchers from the Graz University of Technology have demonstrated a new side-channel attack known as SnailLoad that could be used to remotely infer a user's web activity....

Web scraping is not just a security or fraud problem
2024-06-28 03:30

Bots compose 42% of overall web traffic, and 65% of these bots are malicious, according to Akamai. Web scraping is not just a fraud or security problem, it is also a business problem.

Dark-web kingpin puts 'stolen' internal AMD databases, source code up for sale
2024-06-18 23:01

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

Suspected bosses of $430M dark-web Empire Market charged in US
2024-06-17 20:13

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

Empire Market owners charged for enabling $430M in dark web transactions
2024-06-17 18:47

Two men have been charged in a Chicago federal court for operating "Empire Market," a dark web marketplace that facilitated over $430 million in illegal transactions between February 2018 and August 2020. Empire Market was a popular dark web marketplace that sold illegal drugs, chemicals, jewelry, credit card numbers, counterfeit money bills, malware, and other illicit goods, offering payment options including Monero, Litecoin, and Bitcoin.

Insurance giant Globe Life investigating web portal breach
2024-06-14 12:39

American financial services holding company Globe Life says attackers may have accessed consumer and policyholder data after breaching one of its web portals.The insurance company believes that taking down the affected web portal will not significantly impact its operations.

Hackers exploit 2018 ThinkPHP flaws to install ‘Dama’ web shells
2024-06-06 21:26

Chinese threat actors are targeting ThinkPHP applications vulnerable to CVE-2018-20062 and CVE-2019-9082 to install a persistent web shell named Dama. The web shell enables further exploitation of the breached endpoints, such as enlisting them as part of the attackers' infrastructure to evade detection in subsequent operations.

Owner of Incognito dark web drugs market arrested in New York
2024-05-20 19:36

The owner and operator of Incognito Market, a dark web marketplace for selling illegal narcotics online, was arrested at the John F. Kennedy Airport in New York on May 18. "LIN had ultimate control over more than one thousand vendors, more than 200,000 customers, and at least one other employee who assisted LIN in the management of the site," according to the indictment [PDF].

The 2024 Browser Security Report Uncovers How Every Web Session Could be a Security Minefield
2024-05-13 12:06

With the browser becoming the most prevalent workspace in the enterprise, it is also turning into a popular attack vector for cyber attackers. From account takeovers to malicious extensions to...