President Biden Signs Executive Order Restricting Use of Commercial Spyware

28/03/2023 0 Comments 0 tags

U.S. President Joe Biden on Monday signed an executive order that restricts the use of commercial spyware by federal government agencies. The order said the spyware ecosystem “poses significant counterintelligence or security

Apple Issues Urgent Security Update for Older iOS and iPadOS Models

28/03/2023 0 Comments 0 tags

Apple on Monday backported fixes for an actively exploited security flaw to older iPhone and iPad models. The issue, tracked as CVE-2023-23529, concerns a type confusion bug in the WebKit browser

20-Year-Old BreachForums Founder Faces Up to 5 Years in Prison

27/03/2023 0 Comments 0 tags

Conor Brian Fitzpatrick, the 20-year-old founder and the administrator of the now-defunct BreachForums has been formally charged in the U.S. with conspiracy to commit access device fraud. If proven guilty, Fitzpatrick, who

New MacStealer macOS Malware Steals iCloud Keychain Data and Passwords

27/03/2023 0 Comments 0 tags

A new information-stealing malware has set its sights on Apple’s macOS operating system to siphon sensitive information from compromised devices. Dubbed MacStealer, it’s the latest example of a threat that uses

Microsoft Issues Patch for aCropalypse Privacy Flaw in Windows Screenshot Tools

27/03/2023 0 Comments 0 tags

Microsoft has released an out-of-band update to address a privacy-defeating flaw in its screenshot editing tool for Windows 10 and Windows 11. The issue, dubbed aCropalypse, could enable malicious actors to recover

Where SSO Falls Short in Protecting SaaS

27/03/2023 0 Comments 0 tags

Single sign-on (SSO) is an authentication method that allows users to authenticate their identity for multiple applications with just one set of credentials. From a security standpoint, SSO is the

U.K. National Crime Agency Sets Up Fake DDoS-For-Hire Sites to Catch Cybercriminals

25/03/2023 0 Comments 0 tags

In what’s a case of setting a thief to catch a thief, the U.K. National Crime Agency (NCA) revealed that it has created a network of fake DDoS-for-hire websites to

Microsoft Warns of Stealthy Outlook Vulnerability Exploited by Russian Hackers

25/03/2023 0 Comments 0 tags

Microsoft on Friday shared guidance to help customers discover indicators of compromise (IoCs) associated with a recently patched Outlook vulnerability. Tracked as CVE-2023-23397 (CVSS score: 9.8), the critical flaw relates to a

OpenAI Reveals Redis Bug Behind ChatGPT User Data Exposure Incident

25/03/2023 0 Comments 0 tags

OpenAI on Friday disclosed that a bug in the Redis open source library was responsible for the exposure of other users’ personal information and chat titles in the upstart’s ChatGPT

Critical WooCommerce Payments Plugin Flaw Patched for 500,000+ WordPress Sites

24/03/2023 0 Comments 0 tags

Patches have been released for a critical security flaw impacting the WooCommerce Payments plugin for WordPress, which is installed on over 500,000 websites. The flaw, if left unresolved, could enable