Security News

Bitwarden adds passkey support to log into web password vaults
2024-01-11 19:21

The open-source Bitwarden password manager has announced that all users can now log into their web vaults using a passkey instead of the standard username and password pairs. "This technology sources an encryption key from a passkey in relation to a particular site, which can then be used to reliably encrypt and decrypt data" - Bitwarden.

Facebook, Instagram now mine web links you visit to fuel targeted ads
2024-01-08 07:27

Link history stores records for 30 days, can be used to recall pages previously read, and excludes links sent in messages. Less prominently mentioned on help pages describing the feature on Facebook and Instagram is, of course, perhaps the real reason for the capability: "We may use link history information from our browser to improve your ads across Meta technologies."

DoJ Charges 19 Worldwide in $68 Million xDedic Dark Web Marketplace Fraud
2024-01-08 06:15

The U.S. Department of Justice (DoJ) said it charged 19 individuals worldwide in connection with the now-defunct xDedic Marketplace, which is estimated to have facilitated more than $68 million in...

Microsoft kills off Windows app installation from the web, again
2024-01-04 00:02

Microsoft has disabled a protocol that allowed the installation of Windows apps after finding that miscreants were abusing the mechanism to install malware. The move came just before Christmas, and seemingly mimicked issues first reported in December 2021, to address a Windows AppX Installer vulnerability in which an attacker could spoof App Installer into installing malicious software.

German Authorities Dismantle Dark Web Hub 'Kingdom Market' in Global Operation
2023-12-21 10:03

German law enforcement has announced the disruption of a dark web platform called Kingdom Market that specialized in the sales of narcotics and malware to "tens of thousands of users."...

New Web injections campaign steals banking data from 50,000 people
2023-12-19 20:36

A new malware campaign that emerged in March 2023 used JavaScript web injections to try to steal the banking data of over 50,000 users of 40 banks in North America, South America, Europe, and Japan. Once the victim visits the attackers' compromised or malicious sites, the malware injects a new script tag with a source attribute pointing to an externally hosted script.

Bug or Feature? Hidden Web Application Vulnerabilities Uncovered
2023-12-15 11:08

Web Application Security consists of a myriad of security controls that ensure that a web application: Functions as expected. Cannot be exploited to operate out of bounds. Cannot initiate...

Organizations can’t ignore the surge in malicious web links
2023-11-30 04:00

Despite the rising adoption of collaboration and instant messaging software, email remains a significant area of concern regarding cyber attacks, particularly the increasing threat of cybercriminals employing harmful web links in emails, according to Hornetsecurity. Its use increased by nearly 4 percentage points this year, rising from 39.6% to 43.3% of all email attacks.

How Continuous Pen Testing Protects Web Apps from Emerging Threats
2023-11-29 15:02

This article describes why threat actors target web apps and highlights the value of continuous monitoring in securing modern web apps. One of the key attractions of web apps from a hacker's perspective is how easy they are to target.

Discover Why Proactive Web Security Outsmarts Traditional Antivirus Solutions
2023-11-29 09:21

In a rapidly evolving digital landscape, it's crucial to reevaluate how we secure web environments. Traditional antivirus-approach solutions have their merits, but they're reactive. A new report...