Google Expands End-to-End Encryption for Gmail on the Web

Google has recently announced that Gmail for the web is getting client-side encryption for more customers. Already available for some Workspace subscribers, the client-side encryption in Gmail on the web is being expanded to Workspace Enterprise Plus, Education Plus, and Education Standard customers. Worth knowing, however, is that the feature remains exclusive to customers who enroll in the beta program, with Google not yet sharing an ETA as to when the broad availability is supposed to be reached. The Mountain View-based search giant explains that with end-to-end encryption, the content of emails, including the body and the attachments, can’t be decrypted, even if they are stored on Google servers. “Using client-side encryption in Gmail ensures sensitive data in the email body and attachments are indecipherable to Google servers. Customers retain control over encryption keys and the identity service to access those keys,” Google

2022/12/19
阅读更多

“Password” Continues to Be the Most Common Password in 2022 as Well

You’d think the time spent working from home in the last two years or so helped netizens across the planet figure out how to master the world of WWW in a more efficient manner. But new research from NordPass shows that despite so many people relying on an Internet connection for their daily activities, few actually care about the security of their data when they go online. As a result, “password” continues to be the number one password out there, with the aforementioned company claiming that this particular keyword was detected close to 5 million times in a 3TB database. It takes less than one second to crack this password, the company says. “123456” is currently the second most-used password worldwide, followed by its longer sibling known as “123456789” because, you know, hackers don’t know how to count to 10. “There’s more than one way to get swindled on Tinder: using “tinder” as your password is mo...

2022/11/21
阅读更多

PayPal Officially Announces Support for Passkeys

PayPal has officially announced the support of passkeys, as the company wants to increase the security of user accounts and therefore provide customers with a more secure method of logging in. Stepping away from passwords is something that many tech companies are trying to do these days, and as a founding member of the FIDO Alliance, PayPal is obviously one of the big names investing in this direction. Numbers cited by PayPal show that 81 percent of the 2.6 billion hacked records in 2017 were powered by password stealing and guessing. As a result, replacing passwords with a more secure way to log in is essential, especially given PayPal offers financial services. “Passkeys will also help more consumers complete their purchases with PayPal - once PayPal users create a passkey, they won't have to remember their password, allowing them to check out with greater ease. According to a recent survey of U.S. consumers, 44% of consumers have abandoned an online purchase be...

2022/10/24
阅读更多

Rockstar “Extremely Disappointed” to See GTA 6 Gameplay Leaking to the Web

The next iteration of Grand Theft Auto made the headlines the past weekend following a major leak that provided the world with an early look at the highly anticipated game. Needless to say, given Rockstar barely talks about GTA 6, it’s no surprise that so many people are eager to see what the game is all about. The leak was therefore received with much enthusiasm by fans from all over the world. But according to Rockstar, the content we got to see was actually early development footage. The company claims its servers were hacked, as someone managed to break into its systems and steal the GTA content. “We recently suffered a network intrusion in which an unauthorized third party illegally accessed and downloaded confidential information from our systems, including early development footage for the next Grand Theft Auto. At this time, we do not anticipate any disruption to our live game services nor any long-term effect on the development of our ongoing projects,” ...

2022/9/19
阅读更多

Revolut Hacked, User Data Exposed

Revolut has recently been the target of a cyberattack, with the company confirming in emails sent to customers that a small number of user accounts have actually been exposed. Worth knowing is that the breach didn’t result in any theft of funds, but on the other hand, customer data has been exposed. The company, however, didn’t reveal what information has been exposed, but it says it’s now reaching out to every user to inform about the breach. “Data varied for different customers. We will contact them individually if necessary,” Revolut says. On the other hand, no card details, PINs, or passwords were accessed, Revolut explains. The company claims only 0.16 percent of the customers were affected, and at this point, no action is required on the user side to further protect accounts. “We recently received a highly targeted cyber attack from an unauthorized third party that may have ...

2022/9/19
阅读更多

LastPass Says Hackers Accessed Its Systems for Just 4 Days

LastPass has provided more information on the security incident that was discovered earlier this year, and in an update published this week, the company says that it was managed to confirm that hackers accessed its systems for just 4 days. The whole thing happened in August 2022, LastPass says, and once again, it hasn’t found any evidence that the malicious actors accessed any customer data or encrypted password vaults. By the looks of things, the breach was possible after the hackers managed to compromise the system of a developer. “Our investigation determined that the threat actor gained access to the Development environment using a developer’s compromised endpoint. While the method used for the initial endpoint compromise is inconclusive, the threat actor utilized their persistent access to impersonate the developer once the developer had successfully authenticated using multi-factor authentication,” LastPass

2022/9/18
阅读更多

LastPass Confirms Security Breach, No User Data Exposed

LastPass has publicly acknowledged a security incident, revealing that a developer account was compromised, with cybercriminals managing to access portions of the source code and some proprietary technical information. The security breach took place earlier this month, LastPass says, and after an investigation, the company was able to confirm that no user data was exposed. With the help of a cybersecurity and forensics firm, LastPass says it determined that users’ master passwords and vaults haven’t been compromised – for what it’s worth, the master passwords aren’t being stored on LastPass servers in the first place. “Two weeks ago, we detected some unusual activity within portions of the LastPass development environment. After initiating an immediate investigation, we have seen no evidence that this incident involved any access to customer data or encrypted password vaults,” Last...

2022/8/26
阅读更多

Google Chrome Gets Emergency Security Update

Google has released an emergency security update for Google Chrome, as the company is patching a 0-day vulnerability in the browser. While not too many specifics have been offered, the vulnerability is already being exploited in the wild, with Google obviously urging its users to install the latest update as soon as possible. The new version is Chrome 103.0.5060.114, and if you want to install it today, simply check for updates in the browser’ settings page. According to Google itself, the new browser update comes to resolve three different security vulnerabilities, all of which are rated with a high severity rating.   High CVE-2022-2294: Heap buffer overflow in WebRTC. Reported by Jan Vojtesek from the Avast Threat Intelligence team on 2022-07-01 High CVE-2022-2295: Type Confusion in V8. Reported by avaue and Buff3tts at S.S.L. on 2022-06-16 High CVE-2022-2296: Use after free in Chrome OS Shell. Reported by Khalil Zhani on 2022-05-19

2022/7/5
阅读更多

Mozilla Releases Firefox 100.0.2 With Critical Security Fixes

Mozilla has just released a new Firefox version, and this time, the minor revision is actually pretty big news in terms of security. This is because the new update, which brings the browser to version 100.0.2, includes two critical security fixes, so obviously, everybody is recommended to install it as soon as possible. Mozilla has flagged both security fixes with a critical severity rating, revealing they were reported by researcher Manfred Paul of Trend Micro’s Zero Day initiative. The first bug is a prototype pollution in Top-Level Audit implementation. “If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context,” Mozilla says. The second vulnerability, which is documented in CVE-2022-1529, is an untrusted input used in Javascript object inde...

2022/5/22
阅读更多

India Forces All VPN Providers to Log and Store User Data

One of the benefits of using a VPN service to connect to the web is the enhanced privacy, as such a solution basically makes it possible to stay anonymous and without revealing any information about you or your device. Of course, most people are looking for VPN services that don’t collect any data about their activity while connected to the servers, and in the last couple of years, more and more providers have been betting big on such capabilities. India, however, has had enough with no-log VPNs, as the country has passed a new law that will require all providers not only to store information about their users but also to share it with the government when required. No-log VPNs Coming into effect on June 27, the new directive forces VPN services to store the data on their servers for no less than five years, as per Neo...

2022/5/4
阅读更多

Hackers Posing as Police Convinced Apple and Meta to Share Basic Subscriber Info

A group of hackers known as Recursion Team has reportedly been involved in a 2021 scheme that convinced Meta and Apple to share basic customer data. The whole thing was possible after the hackers posed as law enforcement officials, with a report from Bloomberg revealing that both Apple and Meta shared information like customer addresses, phone numbers, and IP addresses following emergency data requests (which don’t typically require a court order). The obtained data could be used for various harassment campaigns, but needless to say, it could be employed for a wide variety of other schemes, including financial fraud. Apple hasn’t confirmed the report for Bloomberg, but Meta provided a statement suggesting it’s already working with law enforcement on the case. “We review every data request for legal sufficiency and use advanc...

2022/3/31
阅读更多

Signal Says It Wasn’t Hacked, No Attack at All

Signal has long been considered one of the most secure messaging platforms, but a few days ago, rumors circulating online indicated the service got hacked and the data of users ended up exposed to malicious actors. Clearly, this can’t be good news for a platform whose main objective is to provide users with state-of-the-art security, so Signal getting hacked was seen by many as reason enough to move to other platforms. Well, this shouldn’t happen because Signal wasn’t hacked at all, the company announced today in a tweet. In fact, the platform hasn’t even been attacked, and the rumors of a potential hack are nothing more than a misinformation campaign supposed to convince people to make the switch to other services. Signal wasn’t attacked Signal says it noticed an increase in the number of users joining the platform from Eastern Europe, and the company believes this is one of the reasons it’s the target of this fake attack campaign. “We've had a...

2022/3/1
阅读更多

Google Paid $8.7 Million in Bug Bounties Last Year

Bug bounty programs have become an essential tool in the security arsenal of every large company out there, as researchers are therefore encouraged to submit their findings in exchange for financial rewards that are often pretty compelling. Google, for example, paid no less than $8.7 million in bug bounties 2021, according to the company, as the program has reached a new record. The highest reward last year was $157,000, with Google issuing various bounties to a total of 696 researchers based in 62 countries. As far as Android itself is concerned, the operating system accounted for over $2.9 million of all rewards, with the highest bounty reaching $157,000. “The Android VRP doubled its 2020 total payouts in 2021 with nearly $3 million dollars in rewards, and awarded the highest payout in Android VRP history: an exploit chain discovered in Android receiving a reward of $157,000! Our industry leading prize of $1,500,000 for a compromise of our Titan-M Security chip...

2022/2/13
阅读更多

Hackers Can Now Bypass PIN Codes on Mastercard and Maestro Contactless Cards

Contacless Mastercard and Maestro PINs can be bypasses due to a new vulnerability discovered by Swiss College of Engineering in Zurich, according to Cybersecurity News.  The key aspect of the flaw is that it allows thieves to use a hacked Mastercard or Maestro card to make contactless payments without having to input the PIN to complete the transaction, if properly exploited. Properly in this case entails first installing dedicated software on two Android smartphones. One device is used to simulate a point of sale terminal being installed, while the other acts as a card emulator that allows the modified transaction information to be transmitted to a real point-of-sale device. Once the card initiates a transaction, it reveals all related information. To avert further attacks, security experts will not reveal the app in question  Experts from ETH Zu...

2021/8/31
阅读更多

Google, Microsoft To Invest $30B in Cybersecurity

Following sophisticated cyberattacks that targeted critical infrastructure, organizations and governments around the world, Microsoft, Amazon, Apple, IBM and Google pledged to invest a total of $30 billion in cybersecurity advances over the next 5 years, according to The Hacker News.  US plans to develop a framework to improve the supply chain technologies and broaden CISA's role in safeguarding natural gas pipelines. A meeting was held in this sense at the While House that included top representatives from various US companies who agreed to help improve cybersecurity. The pledges come following repeated high-profile cyberattacks on SolarWinds, Microsoft, Colonial Pipeline,

2021/8/31
阅读更多

Microsoft Warns of Widespread Open Redirects Phishing Attacks

Microsoft issued a warning about a huge phishing campaign that uses open email links to steal credentials, according to The Hacker News. An old idiom advises us to work smart, not hard and nobody applies it better than modern hackers. Using something as common as URLs, threat actors manage to trick numerous users into introducing sensitive information that could grant access to an organization's network, steal credit card information or personal data that can be used for blackmailing. Nowadays, some manage to perfect their campaigns to the point where they are not even detected by advanced and up-to-date anti-malware solutions. Microsoft 365 Defender Threat Intelligence Team explained in a report "Attackers co...

2021/8/31
阅读更多

Legal Consequences Possible by Cybersecurity Standards Non-Compliance

With an average cost of a data breach reaching an all-time high of $4.24 million, still some companies fail to see the full picture and don't meet modern cybersecurity standards, according to Tripwire.   Despite the fact that online threats are increasing on a daily basis, numerous firms fail to recognize the importance of proper cybersecurity. Interestingly enough, many companies are not aware that they are bound by state, industry, and international laws. Although there is no uniform national or global cybersecurity law in place, companies that fail to meet certain legislation can face legal consequences. As cybersecurity becomes more of a serious concern, the need for online defense is starting to worry more governments around the world. Aside from the potential data loss, companies that...

2021/8/31
阅读更多

Critical Cosmos Database Flaw Affecting Microsoft Azure Customers

Microsoft sent out a warning to thousands of cloud computing customers regarding threat actors that can view, modify, or even delete master databases if they gain access to their systems, according to Reuters. Wiz announced that Microsoft Azure's flagship Cosmos database contain a vulnerability that allows access to keys that control access to the databases of hundreds of companies. Unable to update those keys itself, Microsoft sent an email to its customers Thursday asking them to create new keys. The software giant compensated Wiz with $40,000 in cash for discovering and reporting the security flaw. Microsoft said, "Microsoft recently became aware of a vulnerability in Azure Cosmos DB that could potentially allow a user to gain access to another customer's resources by using the account's primary read-w...

2021/8/31
阅读更多

Chinese Developers Reveal Android Gamers' Data

A vpnMentor investigation found that a 134 GB server owned by EskyFun is exposed and user data was leaked for game titles such as Metamorph M, The Three Kingdoms Legend, Adventure Story, Rainbow Story, and Fantasy MMORPG. The aforementioned games were downloaded 1.6 million times, whereas the leaked information had more than 365 million records. An intriguing aspect is that developers increased the amount of analytics, monitoring and authorization options available for the games, some needing more permissions even before they were installed. Data disclosed includes IP and IMEI numbers, mobile device event logs, device information, phone numbers, EskyFun network passwords, current operating system, rooted or otherwise rooted phones, player acquisition and transaction reports, mailing, and support requests. Various data points were also used to identify profile individuals as well as tw...

2021/8/31
阅读更多

Kaspersky: Kanye's Upcoming Album is a Scam Magnet

Cybercriminals are launching a new scam to take advantage of the release of Kanye West's Donda album by distributing malicious fake downloads on the Internet, according to Tech Republic. Cybersecurity firm Kaspersky proactively studied the event to see if threat actors were spreading any malware across the Internet. They emphasized that one of the scams is to target the release of highly anticipated media (movies, music), as they can place the malicious code in fake files that can be easily downloaded. This particular scam attempt involves the uploading of fake malicious files to the Internet that are similar to those that were identified prior to the introduction of Black Widow. Kanye's fans are given a link to download the album and then asked to participate in a survey to confirm they are not robots. Afterwards, customers are redirected to a...

2021/8/31
阅读更多

Work from Home Increased Worldwide Phishing Attacks

Over the course of September 2019 to April 2021, Palo Alto Network's Unit 42 monitored firewall traffic and phishing sites detected by URL filters. The number of new phishing pages per week increased significantly when individuals began working from home.  Threat actors improved and intensified their phishing attacks by exploiting remote work environments where employees were not protected by corporate firewalls. Cybersecurity experts noticed a sudden and significant drop in traffic between March and April 2020, when COVID began spreading across the United States, forcing companies to switch to remote work.  Education and high-tech industries saw significant declines in traffic during this period, with the latter having the steepest drop: education (a 46% drop), most likely due to school closures, and high-tech (a 35% drop), probably because more employees starting working from home...

2021/8/28
阅读更多

Kaseya Patches New 0-Day Vulnerabilities Affecting Unitrends Servers

Two zero-day vulnerabilities affecting Unitrends backup and continuity service have been patches by Kaseya recently, according to The Hacker News.  Dutch Institute for Vulnerability Disclosure (DIVD) informed that the provider of IT infrastructure management solutions has solved server software bugs 10.5.5-2 reported on August 12. Both vulnerabilities are part of a trio of flaws discovered and reported on July 3, 2021. The issues encompass both an authenticated vulnerability to remote code execution and a privilege escalation fault on Unitrends servers from the read-only user to the administrator. Users of unpatched software should avoid connecting the affected servers to the Internet  A previously unknown client vulnerability in Kaseya Unitrends has not yet been patched. Then again, the company issues some firewall rules recommendations to...

2021/8/27
阅读更多

Engineering PCs Are Concerning Initial Access Vector in OT Attacks

A new report titled SANS 2021 OT/ICS Cybersecurity Report contains alarming information gathered from 480 individuals in various industries. Organizations that use operational technology (OT) and industrial control systems (ICS) are very concerned about cyber attacks.  The findings highlight the need for businesses to improve the ability to anticipate and respond to emerging threats and opportunities. While many are taking precautions to reduce risks, they are unaware if the breaches already occurred within their organization. To summarize the findings: Approximately 70% of respondents indicated that the risk to their operational technology environment was high or severe. With many companies concerned about cyber risk in their operating environment, 48% of respondents did not know whether they had encountered a breach of o...

2021/8/27
阅读更多

Top Linux Vulnerabilities Exploited by Hackers

Linux-based machines that are directly connected to the Internet can be targets for attackers who can quickly push potentially dangerous web-based shells, ransomware, Trojans, and other malicious software, according to The Hacker News.  Trend Micro produced a comprehensive analysis of the Linux threat landscape, highlighting the barriers and vulnerabilities that have plagued the operating system in the first half of the year. The information was gathered using honeypots, sensors and anonymous telemetry. According to the company, which has detected about 15 million malware attacks targeting Linux-based cloud environments, ransomware and coin miners account for 54% of all malware, while web shells represent 29% of all recorded events.  Researchers evaluated over 50 million events from 100,000 unique Linux servers and identified 15 separate vulnerabilities used in th...

2021/8/26
阅读更多

Personal Information of Entire Swiss Town Leaked Following Cyberattack

Following reports of personal data leaked online from the entire population, a small Swiss town revealed that it had misjudged the seriousness of the cyber attack late in the day before, according to Security Week.  Rolle, a small, lovely town on the beaches of Lake Geneva, acknowledged that it had been targeted by a ransomware attack and that sensitive information on some administrative systems had been compromised. The attack took place on May 30 and the city government said that only modest amounts of data were compromised at the time. Moreover, all information was restored from backup copies of the original files. However, according to an investigation published Wednesday by the French daily Le Temps, the attack was considerably larger. Cybercriminals stole names, residences, and social security numbers Le Temps cites an unidentified ...

2021/8/26
阅读更多

Top IT Firms CEOs to Attend White House Cybersecurity Meeting

On Wednesday, President Joe Biden will meet with top executives from some of the country's largest technology and financial companies, as the White House seeks private sector backing for a unified cyber defense against emerging threats, according to MCU Times.  The gathering comes amid an increase in ransomware attacks on critical infrastructure, extorting multi-million dollar payments from large corporations, and other illicit cyber operations linked to foreign hackers by US authorities. According to a senior government official, the purpose of the conversation is to identify the root causes of hostile cyber activity as well as ways in which the private sector may contribute to enhancing cybersecurity. The President Biden proposed an infrastructure bill would provide about $1 trillion in cybersecurity subsidies to state, local and tribal governmen...

2021/8/26
阅读更多

New SideWalk Backdoor Targeting U.S. Computer Retailers

Chinese advanced persistent threat (APT) gangs have resumed their hacking activities, with one of the attacks targeting an American computer retailer using an unknown backdoor referred to as Sidewalk, according to The Hacker News. In a report, ESET Cybersecurity Researchers Mathieu Tartare and Thibaut Passilly describe the fresh backdoor as modular, allowing the dynamic loading of additional modules from specific control and command servers. The malware is also designed to target Cloudflare workers as C&C servers and Google Docs as dead drop resolvers.  Security researchers describe SideWalk as "responsible for reading the encrypted shellcode from disk, decrypting it and injecting it into a legitimate process using the process hollowing techniqu...

2021/8/26
阅读更多

FluBot Malware Strikes Again

FluBot Android malware is back and already launched several attacks outside the regular geographical region of impact, according to Cyware.  Recently conducted research into the FluBot banking malware has revealed an upsurge in the number of dangerous distribution pages in a variety of Australian, Polish, and German financial institutions.   Numerous intriguing elements were incorporated by the threat actors in the new operations that now collected user credentials by overlaying several popular banking applications. The design of the malicious web pages is devised to disseminate text messages that appear to be voicemail notifications or shipment tracking information, but are actually scams.  It is worth noting that the cybercriminals were able to accomplish all of this while remaining undetected during the infection process thanks to a Domain Generation Algorithm (D...

2021/8/26
阅读更多

Medical Data for 12,000 Patients Leaked Following Revere Health Attack

A mistake by a health care worker resulted in the leaking of medical information of about 12,000 patients. The phishing attack took place on June 21 and lasted only 45 minutes, according to The Spectrum.  While he breach exposed medical record numbers, birth dates, procedures, and insurance provider names, provider names, the two-month investigation determined that the breach posed a negligible risk to the patients affected. Moreover, Revere Health believes that the hacker is not attempting to publish the patient medical information, but rather is using the incident as a platform to conduct more sophisticated phishing email attacks against other employees.  Bob Freeze, the director of marketing and communications, stated that the stolen data affected patients of the Heart of Dixie Cardiology Department in St. Georg...

2021/8/26
阅读更多

38 Million Records Exposed from Microsoft Power Apps

In an unexpected data leak, more than 38 million records from 47 organizations using Microsoft's gateway platform Power Apps were accidentally published online, according to The Hacker News.  The unfortunate incident resulted in the leakage of sensitive information on servers of corporations such as Microsoft, J.B. Hunt, and American Airlines along with government agencies from Indiana, Maryland, and New York City. Power Apps are mostly used for developing custom low-code applications for mobile devices as well as websites. The programs created by Microoft have a number of advantages, such as APIs that allow other applications to access data, templates as well as managing and collecting information and storage. Key information that went missing:  The misconfiguration of a port could lead to making the stored data public and this is what happened h...

2021/8/26
阅读更多