passwords
Metasploit identifies IPv6 security risks
Rapid7 announced that the new version of Metasploit 4.2 allows users to fully test whether IPv6 addresses on their network are vulnerable to cyber attacks. This is …
Users don’t bother changing default passwords
Most people working with sensitive information want stricter security policies but rarely bother changing default, automatically generated and assigned passwords. To collect …
Self-selected PINs aren’t that hard to guess
Four-digit banking PINs are usually randomly assigned by banks after the issuing of credit and debit cards, but there are still some out there that let its customers choose …
Open source password manager gets two-factor authentication
Yubico announced a successful implementation of YubiKey two-factor authentication with the free, open source password manager software Password Safe. The joint solution offers …
Twitter turns on HTTPS by default
Twitter has finally taken the plunge and made HTTPS on by default for all users. The option to always use HTTPS was made available to users back in March 2011, but they had to …
Best practices for online banking security
There are two common misconceptions about online banking security which are holding financial institutions back from offering their customers the best services possible. …
Apple iWork passwords cracked
ElcomSoft can now recover passwords protecting Apple iWork documents. This makes Distributed Password Recovery the first tool to recover passwords for Numbers, Pages and …
HTC Android phones allow apps to harvest users’ Wi-Fi password
A bug in the way some Android-running HTC smartphones handle requests for password allows some applications to send the user’s Wi-Fi network username, password and SSID …
Security breaches driving authentication changes
Recent security breaches and deployment of new technologies are driving organizations to re-evaluate incumbent authentication vendors and re-think their authentication …
Multi-factor authentication for mobile users
DigitalPersona announced the newest version of DigitalPersona Pro Enterprise has support for a variety of new authentication credentials. With the software, organizations can …
DreamHost hacker accessed pool of unencrypted passwords
DreamHost, one of the world’s most popular and well-known web hosting providers, has sent a warning out to its customers saying that one of their databases containing …
Mozilla offers alternative to OpenID
Mozilla has been working for a while now on a new browser-based system for identifying and authenticating users it calls BrowserID, but its only this month that all of its …
Featured news
Resources
Don't miss
- Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940)
- Detained ShinyHunters hacker reportedly helping FBI track down fellow members
- AI slop submissions force Google to freeze its open-source bug bounty
- Three questions a hospital CISO should ask a healthcare fintech vendor
- Keyorix: Open-source secrets management for teams that can’t use SaaS