More than one billion Android devices at risk of malware threats, no longer being updated

Based on Google data, two in five of Android users worldwide may no longer be receiving updates, and while these devices won’t immediately have problems, without security support there is an increased risk to the user. Our latest tests have shown how such phones and tablets, including handsets still available to buy from online marketplaces Read more about More than one billion Android devices at risk of malware threats, no longer being updated[…]

Virgin broadband ISP spills 900,000 punters’ records into wrong hands from insecure database

Virgin Media, one of the UK’s biggest ISPs, on Thursday admitted it accidentally spilled 900,000 of its subscribers’ personal information onto the internet via a poorly secured database. The cableco said it “incorrectly configured” a storage system so that at least one miscreant was able to access it and potentially siphon off customer records. The Read more about Virgin broadband ISP spills 900,000 punters’ records into wrong hands from insecure database[…]

Enable MFA: 1.2 million Azure Active Directory (Office 365) accounts compromised every month, reckons Microsoft

Microsoft reckons 0.5 per cent of Azure Active Directory accounts as used by Office 365 are compromised every month. The Window giant’s director of identity security, Alex Weinert, and IT identity and access program manager Lee Walker revealed the figures at the RSA conference last month in San Francisco. “About a half of a per Read more about Enable MFA: 1.2 million Azure Active Directory (Office 365) accounts compromised every month, reckons Microsoft[…]

Unfixable vulnerability in Intel CSME allows crypto key stealing and local access to files

An error in chipset read-only memory (ROM) could allow attackers to compromise platform encryption keys and steal sensitive information. Intel has thanked Positive Technologies experts for their discovery of a vulnerability in Intel CSME. Most Intel chipsets released in the last five years contain the vulnerability in question. By exploiting vulnerability CVE-2019-0090, a local attacker Read more about Unfixable vulnerability in Intel CSME allows crypto key stealing and local access to files[…]

EU Commission to staff: Switch to Signal messaging app

The European Commission has told its staff to start using Signal, an end-to-end-encrypted messaging app, in a push to increase the security of its communications. The instruction appeared on internal messaging boards in early February, notifying employees that “Signal has been selected as the recommended application for public instant messaging.” The app is favored by privacy Read more about EU Commission to staff: Switch to Signal messaging app[…]

Wi-Fi of more than a billion PCs, phones, gadgets can be snooped on. But you’re using HTTPS, SSH, VPNs… right?

A billion-plus computers, phones, and other devices are said to suffer a chip-level security vulnerability that can be exploited by nearby miscreants to snoop on victims’ encrypted Wi-Fi traffic. The flaw [PDF] was branded KrØØk by the bods at Euro infosec outfit ESET who discovered it. The design blunder is otherwise known as CVE-2019-15126, and Read more about Wi-Fi of more than a billion PCs, phones, gadgets can be snooped on. But you’re using HTTPS, SSH, VPNs… right?[…]

Your banks’ APIs are a major target for credential stuffing attacks

Automating connections from 3rd party providers makes it easy to access your financial data because people re-use their logins and these logins have been repeatedly leaked online. New data from security and content delivery company Akamai shows that one in every five attempts to gain unauthorized access to user accounts is now done through application Read more about Your banks’ APIs are a major target for credential stuffing attacks[…]

Clearview AI, Creepy Facial Recognition Company That Stole Your Pictures from Social Media, Says Entire Client List Was Stolen by Hackers

A facial-recognition company that contracts with powerful law-enforcement agencies just reported that an intruder stole its entire client list, according to a notification the company sent to its customers. In the notification, which The Daily Beast reviewed, the startup Clearview AI disclosed to its customers that an intruder “gained unauthorized access” to its list of Read more about Clearview AI, Creepy Facial Recognition Company That Stole Your Pictures from Social Media, Says Entire Client List Was Stolen by Hackers[…]

All that Samsung users found on UK website after weird Find my Mobile push notification was… other people’s details

In the early hours of this morning, a very large number of Samsung devices around the world received a push notification from the vendor’s Find my Mobile app. That notification simply read “1/1”. […] A handful of Reg staffers also received the notification, which caused surprise and concern at Vulture Central – not least because Read more about All that Samsung users found on UK website after weird Find my Mobile push notification was… other people’s details[…]

Shipping is so insecure we could have driven off in an oil rig, says Pen Test Partners

Penetration testers looking at commercial shipping and oil rigs discovered a litany of security blunders and vulnerabilities – including one set that would have let them take full control of a rig at sea. Pen Test Partners (PTP), an infosec consulting outfit that specialises in doing what its name says, reckoned that on the whole, Read more about Shipping is so insecure we could have driven off in an oil rig, says Pen Test Partners[…]

Facebook was repeatedly warned of security flaw that led to biggest data breach in its history

Facebook knew about a huge security flaw that let hackers to steal personal data from millions of its users almost one year before the crime, yet failed to fix it in time, the Telegraph can reveal. Legal documents show that the company was repeatedly warned by its own employees as well as outsiders about a Read more about Facebook was repeatedly warned of security flaw that led to biggest data breach in its history[…]

Plastic surgery images and invoices leak from unsecured database

Thousands of images, videos and records pertaining to plastic surgery patients were left on an unsecured database where they could be viewed by anyone with the right IP address, researchers said Friday. The data included about 900,000 records, which researchers say could belong to thousands of different patients. The data was generated at clinics around Read more about Plastic surgery images and invoices leak from unsecured database[…]

Apple’s Mac computers now outpace Windows in malware and virus

Think your Apple product is safe from malware? That only people using Windows machines have to take precautions? According to cybersecurity software company Malwarebytes’ latest State of Malware report, it’s time to think again. The amount of malware on Macs is outpacing PCs for the first time ever, and your complacency could be your worst Read more about Apple’s Mac computers now outpace Windows in malware and virus[…]

Tens of millions of biz Dell PCs smacked by privilege-escalation bug in bundled troubleshooting tool

Dell has copped to a flaw in SupportAssist – a Windows-based troubleshooting program preinstalled on nearly every one of its newer devices running the OS – that allows local hackers to load malicious files with admin privileges. The company has issued an advisory about the flaw, warning that a locally authenticated low-privilege user could exploit Read more about Tens of millions of biz Dell PCs smacked by privilege-escalation bug in bundled troubleshooting tool[…]

Software error exposes the ID numbers, birthdays and genders for 1.26 million Danish citizens, 1/5th of the population

A software error in Denmark’s government tax portal has accidentally exposed the personal identification (CPR) numbers for 1.26 million Danish citizens, a fifth of the country’s total population. The error lasted for five years (between February 2, 2015, and January 24, 2020) before it was discovered, Danish media reported last week. The software error and Read more about Software error exposes the ID numbers, birthdays and genders for 1.26 million Danish citizens, 1/5th of the population[…]

Israeli Voters: Data of All 6.5 Million Voters Leaked

A software flaw exposed the personal data of every eligible voter in Israel — including full names, addresses and identity card numbers for 6.5 million people — raising concerns about identity theft and electoral manipulation, three weeks before the country’s national election. The security lapse was tied to a mobile app used by Prime Minister Read more about Israeli Voters: Data of All 6.5 Million Voters Leaked[…]

Sorry to be blunt about this… Open AWS S3 storage bucket just made 30,000 potheads’ privacy go up in smoke

Personal records, including scans of ID cards and purchase details, for more than 30,000 people were exposed to the public internet from this unsecured cloud silo, we’re told. In addition to full names and pictures of customer ID cards, the 85,000 file collection is said to include email and mailing address, phone numbers, dates of Read more about Sorry to be blunt about this… Open AWS S3 storage bucket just made 30,000 potheads’ privacy go up in smoke[…]

Netgear leaves admin interface’s TLS cert and private key router firmware

Netgear left in its router firmware key ingredients needed to intercept and tamper with secure connections to its equipment’s web-based admin interfaces. Specifically, valid, signed TLS certificates with private keys were embedded in the software, which was available to download for free by anyone, and also shipped with Netgear devices. This data can be used Read more about Netgear leaves admin interface’s TLS cert and private key router firmware[…]

BlackVue dashcam shows anyone everywhere you are in real time and where you have been in the past

An app that is supposed to be a fun activity for dashcam users to broadcast their camera feeds and drives is actually allowing people to scrape and store the real-time location of drivers across the world. BlackVue is a dashcam company with its own social network. With a small, internet-connected dashcam installed inside their vehicle, Read more about BlackVue dashcam shows anyone everywhere you are in real time and where you have been in the past[…]

PGP keys, software security, and much more threatened by new SHA1 exploit

Three years ago, Ars declared the SHA1 cryptographic hash algorithm officially dead after researchers performed the world’s first known instance of a fatal exploit known as a “collision” on it. On Tuesday, the dead SHA1 horse got clobbered again as a different team of researchers unveiled a new attack that’s significantly more powerful. The new Read more about PGP keys, software security, and much more threatened by new SHA1 exploit[…]

More than 600 million users installed Android ‘fleeceware’ apps from the Play Store – where they don’t cancel your trial after uninstalling

Security researchers from Sophos say they’ve discovered a new set of “fleeceware” apps that appear to have been downloaded and installed by more than 600 million Android users. The term fleeceware is a recent addition to the cyber-security jargon. It was coined by UK cyber-security firm Sophos last September following an investigation that discovered a Read more about More than 600 million users installed Android ‘fleeceware’ apps from the Play Store – where they don’t cancel your trial after uninstalling[…]

Skype and Cortana audio listened in on by workers in China with ‘no security measures’

A Microsoft programme to transcribe and vet audio from Skype and Cortana, its voice assistant, ran for years with “no security measures”, according to a former contractor who says he reviewed thousands of potentially sensitive recordings on his personal laptop from his home in Beijing over the two years he worked for the company. The Read more about Skype and Cortana audio listened in on by workers in China with ‘no security measures’[…]

Checkpeople, why is a 22GB database containing 56 million US folks’ aggregated personal details sitting on the open internet using a Chinese IP address?

A database containing the personal details of 56.25m US residents – from names and home addresses to phone numbers and ages – has been found on the public internet, served from a computer with a Chinese IP address, bizarrely enough. The information silo appears to belong to Florida-based CheckPeople.com, which is a typical people-finder website: Read more about Checkpeople, why is a 22GB database containing 56 million US folks’ aggregated personal details sitting on the open internet using a Chinese IP address?[…]

Government exposes addresses of > 1000 new year honours recipients

More than 1,000 celebrities, government employees and politicians who have received honours had their home and work addresses posted on a government website, the Guardian can reveal. The accidental disclosure of the tranche of personal details is likely to be considered a significant security breach, particularly as senior police and Ministry of Defence staff were Read more about Government exposes addresses of > 1000 new year honours recipients[…]

Wyze data leak may have exposed personal data of millions of users

Security camera startup Wyze has confirmed it suffered a data leak this month that may have left the personal information of millions of its customers exposed on the internet. No passwords or financial information were exposed, but email addresses, Wi-Fi network IDs and body metrics were left unprotected from Dec. 4 through Dec. 26, the Read more about Wyze data leak may have exposed personal data of millions of users[…]