Twitter admits to raid on users’ phone numbers

Credit to Author: John E Dunn| Date: Wed, 05 Feb 2020 11:20:13 +0000

It relates to Twitter’s contact upload feature, which allows users to find others via contact info such as email or phone number.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/JjUJFBQ-IaQ” height=”1″ width=”1″ alt=””/>

Read more

HorseDeal Riding on The Curveball!

Credit to Author: Jayesh kulkarni| Date: Wed, 05 Feb 2020 06:17:49 +0000

It’s surprising to see how quickly attackers make use of new vulnerabilities in malware campaigns. Microsoft recently patched a very interesting vulnerability in their monthly Patch Tuesday update for January 2020. It’s a spoofing vulnerability in Windows CryptoAPI (Crypt32.dll) validation mechanism for Elliptic Curve Cryptography (ECC) certificates. An attacker could…

Read more

Iowa Caucus chaos likely to set back mobile voting

Credit to Author: Lucas Mearian| Date: Tue, 04 Feb 2020 12:51:00 -0800

A coding flaw and lack of sufficient testing of an application to record votes in Monday’s Iowa Democratic Presidential Caucus will likely hurt the advancement and uptake of online voting.

While there have been hundreds of tests of mobile and online voting platforms in recent years – mostly in small municipal or corporate shareholder and university student elections – online voting technology has yet to be tested for widespread use by the general public in a national election.

“This is one of the cases where we narrowly dodged a bullet,” said Jeremy Epstein, vice chair of the Association for Computing Machinery’s US Technology Policy Committee (USTPC). “The Iowa Democratic Party had planned to allow voters to vote in the caucus using their phones; if this sort of meltdown had happened with actual votes, it would have been an actual disaster. In this case, it’s just delayed results and egg on the face of the people who built and purchased the technology.”

To read this article in full, please click here

Read more

Washington Privacy Act welcomed by corporate and nonprofit actors

Credit to Author: David Ruiz| Date: Tue, 04 Feb 2020 16:35:25 +0000

The Washington Privacy Act would extend new data rights of access, correction, and deletion to Washington residents, with new rules on facial recognition.

Categories:

Tags:

(Read more…)

The post Washington Privacy Act welcomed by corporate and nonprofit actors appeared first on Malwarebytes Labs.

Read more

NIST tests methods of recovering data from smashed smartphones

Credit to Author: John E Dunn| Date: Tue, 04 Feb 2020 12:54:30 +0000

Criminals have found to their cost that reducing a device to a pile of rubble means nothing if the internal chips are still in working order.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/DhhD2UVxfZU” height=”1″ width=”1″ alt=””/>

Read more

Google’s Super Bowl ad will make you cry. Or wince.

Credit to Author: Lisa Vaas| Date: Tue, 04 Feb 2020 10:44:29 +0000

Google’s Super Bowl ad featured an elderly man’s voice as he asked Google Assistant to help him remember details about his late wife.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/a63Ljbmk14I” height=”1″ width=”1″ alt=””/>

Read more

A sloppy click can exfiltrate your important data!

Credit to Author: Anant Pulgam| Date: Mon, 03 Feb 2020 09:17:12 +0000

Phishing email still remains one of the top malware propagation medium. Recently, we came across an interesting phishing email containing couple of Jumpshare links pointing to malicious components. Jumpshare is an online file sharing service and often cyber criminals abuse these kind of file sharing services. Upon clicking on one of the links in…

Read more

UN hacked via unpatched SharePoint server

Credit to Author: Danny Bradbury| Date: Fri, 31 Jan 2020 13:04:44 +0000

UN staffers: the “entire domain” was probably compromised by an attacker who was lurking on the UN’s networks.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/RonIAIVbyIQ” height=”1″ width=”1″ alt=””/>

Read more

Financial tech firms disagree on ban of customer data screen-scraping

Credit to Author: Lisa Vaas| Date: Fri, 31 Jan 2020 12:05:49 +0000

They use it to offer things like budgeting apps. It puts passwords and privacy at risk, but some say they can’t afford to build APIs instead.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/p33_Z7ZunMU” height=”1″ width=”1″ alt=””/>

Read more

Facebook to pay $550m to settle face-tagging suit

Credit to Author: Lisa Vaas| Date: Fri, 31 Jan 2020 10:14:22 +0000

A class-action lawsuit against Facebook for the use of its tag suggestions feature looks like it’s finally done churning through the courts.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/-vpu7yQz3I0″ height=”1″ width=”1″ alt=””/>

Read more