Infosec News

InfoSec News 20230706

  • Publicado: Qui, 06/07/2023 - 12:58

Top News


  • Android July security updates fix three actively exploited bugs

"Google has released the monthly security updates for Android operating system, which comes with fixes for 46 vulnerabilities. Three of the issues are likely actively exploited in the wild.
“There are indications that the following [vulnerabilities] may be under limited, targeted exploitation,” reads Google’s bulletin, highlighting CVE-2023-26083, CVE-2021-29256, and CVE-2023-2136."

InfoSec News 20230705

  • Publicado: Qua, 05/07/2023 - 14:28

Top News


  • Google Analytics data transfer to U.S. brings $1 million fine to Swedish firms

"The Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten – IMY) has fined two companies with 12.3 million SEK (€1 million/$1.1 million) for using Google Analytics and warned two others about the same practice.
In a decision published yesterday, the agency explains that by using Google Analytics to generate web statistics the firms were breaching European Union's General Data Protection Regulation (GDPR).

InfoSec News 20230704

  • Publicado: Ter, 04/07/2023 - 12:48

Top News


  • Hackers stole millions of dollars worth of crypto assets from Poly Network platform

"Poly Network platform suspended its services during the weekend due to a cyber attack that resulted in the theft of millions of dollars in crypto assets.
Threat actors have stolen millions of dollars worth of crypto assets from the Poly Network platform during the weekend.
The platform suspended its services due to the cyber attack to investigate the security breach and assess the extent of the incident."

InfoSec News 20230703

  • Publicado: Seg, 03/07/2023 - 13:46

Top News


  • Twitter now forces you to sign in to view tweets

"Starting today, Twitter is no longer accessible on web and mobile apps if you don’t have an account, forcing all users to log in if they want to get access to the platform.
If you're not already logged in, you will get redirected to a "Sign in to Twitter" screen, where you're prompted to either sign into your account or sign up for one.

InfoSec News 20230630

  • Publicado: Sex, 30/06/2023 - 12:33

Top News


  • Proton launches open-source password manager with some limitations

"Proton AG has announced the global availability of Proton Pass, an open-source and free-to-use password manager available as a browser extension or mobile app on Android and iOS.manager.
Proton has been offering various privacy-focused products and services for some time, including the end-to-end encrypted Proton Mail email service, the Proton VPN service, and the Proton Drive cloud storage service.

InfoSec News 20230629

  • Publicado: Qui, 29/06/2023 - 13:47

Top News


  • Experts published PoC exploits for Arcserve UDP authentication bypass issue

"Data protection vendor Arcserve addressed a high-severity bypass authentication flaw, tracked as CVE-2023-26258, in its Unified Data Protection (UDP) backup software. Threat actors can exploit the vulnerability to bypass authentication and gain admin privileges.

InfoSec News 20230628

  • Publicado: Qua, 28/06/2023 - 12:15

Top News


  • Hundreds of devices found violating new CISA federal agency directive

"Censys researchers have discovered hundreds of Internet-exposed devices on the networks of U.S. federal agencies that have to be secured according to a recently issued CISA Binding Operational Directive.
An analysis of the attack surfaces of more than 50 Federal Civilian Executive Branch (FCEB) organizations led to the discovery of more than 13,000 individual hosts exposed to Internet access, distributed across over 100 systems linked to FCEB agencies.

InfoSec News 20230627

  • Publicado: Ter, 27/06/2023 - 13:26

Top News


  • Fortinet Patches Critical RCE Vulnerability in FortiNAC

"Fortinet has released patches to address a critical vulnerability in its FortiNAC network access control solution.
The zero trust access solution allows organizations to view devices and users on the network and provides granular control over network access policies.
Tracked as CVE-2023-33299 (CVSS score of 9.6), the critical flaw is described as an issue related to deserialization of untrusted data that can lead to remote code execution (RCE).

InfoSec News 20230626

  • Publicado: Seg, 26/06/2023 - 12:23

Top News


  • Trojanized Super Mario game used to install Windows malware

"A trojanized installer for the popular Super Mario 3: Mario Forever game for Windows has been infecting unsuspecting players with multiple malware infections.
Super Mario 3: Mario Forever is a free-to-play remake of the classic Nintendo game developed by Buziol Games and released for the Windows platform in 2003.

InfoSec News 20230623

  • Publicado: Sex, 23/06/2023 - 13:33

Top News


  • More than a million GitHub repositories potentially vulnerable to RepoJacking

"A study conducted by Aqua researchers revealed that millions of GitHub repositories are potentially vulnerable to RepoJacking.
In the RepoJacking attack, attackers claim the old username of a repository after the legitimate creator changed the username, then publish a rogue repository with the same name to trick users into downloading its content."

Páginas