Please turn on your JavaScript for this page to function normally.
Drupal
Drupal moves to fix flaws in update process

After IOActive researcher Fernando Arnaboldi publicly revealed three crucial vulnerabilities in Drupal’s update process last Thursday, the Drupal Security Team published …

GM
General Motors invites hackers to report security flaws in their cars

General Motors has started a bug bounty program and has invited security researchers to report information on security vulnerabilities affecting the company’s products …

math
Imperfect algorithms threaten democracy

Do we want algorithms that we can’t understand or question to influence how we get to live our lives? Unfortunately, as Cathy O’Neil, well-known mathematician and …

Keyboard
SLOTH attacks weaken secure protocols because they still use MD5 and SHA-1

Researchers Karthikeyan Bhargavan and Gaëtan Leurent from INRIA, the French national research institute for computer science, have discovered a new class of transcript …

Lock
After two fixes, OAuth standard deemed secure

OAuth 2.0 is one of the most used single sign-on systems on the web: it is used by Facebook, Google, Microsoft, GitHub and other big Internet companies. A group of researchers …

FBI
FBI warns Time Warner Cable of potential data breach

Time Warner Cable will soon be contacting approximately 320,000 of its customers whose accounts have likely been compromised, the company’s public relations director …

EU flag
Cyber crooks abuse legitimate EU Cookie Law notices in clever clickjacking campaign

Cyber crooks have set up a clever new clickjacking campaign that takes advantage of pop-up alerts that European users are (by now) accustomed to see: the “EU Cookie …

Fitbit
Fitbit, warranty fraud, and hijacked accounts

Online account hijackings usually end up with the account owners being the main victims, but there are fraudsters out there who are more interested in ripping off companies …

Dell
Well-informed tech support scammers target Dell users

Has Dell been breached and its databases containing customer’s personal, computer and tech support data been pilfered? Dell still won’t say yes or no, but many …

Drupal
Bugs in Drupal’s update process could lead to backdoored updates, site compromise

Drupal’s update process is deeply flawed, says IOActive researcher Fernando Arnaboldi. He recently discovered three separate flaws in it, the worst of which could be …

https
HTTPS Bicycle attack reveals password length, allows easier brute-forcing

Dutch security researcher Guido Vranken has come up with a new attack that could allow attackers to discover the length of a user’s password – and therefore make …

complex
EFF: T-Mobile breaks net neutrality rules with Binge On service

In February 2015, the FCC has approved net neutrality rules “to preserve the Internet as a platform for innovation, free, expression and economic growth.” In …

Don't miss

Cybersecurity news
Daily newsletter sent Monday-Friday
Weekly newsletter sent on Mondays
Editor's choice newsletter sent twice a month
Periodical newsletter released whent there is breaking news
Weekly newsletter listing new cybersecurity job positions
Monthly newsletter focusing on open source cybersecurity tools