Instagram has patched a new flaw that allowed anyone to view archived posts and stories posted by private accounts without having to follow them. “This bug could have allowed a …
Apple Issues Urgent Patches for 2 Zero-Day Flaws Exploited in the Wild
Apple on Monday shipped out-of-band security patches to address two zero-day vulnerabilities in iOS 12.5.3 that it says are being actively exploited in the wild. The latest update, iOS 12.5.4, comes …
Google Workspace Now Offers Client-side Encryption For Drive and Docs
Google on Monday announced that it’s rolling out client-side encryption to Google Workspace (formerly G Suite), thereby giving its enterprise customers direct control of encryption keys and the identity service …
NoxPlayer Supply-Chain Attack is Likely the Work of Gelsemium Hackers
A new cyber espionage group named Gelsemium has been linked to a supply chain attack targeting the NoxPlayer Android emulator that was disclosed earlier this year. The findings come from a systematic …
Cybersecurity Executive Order 2021: What It Means for Cloud and SaaS Security
In response to malicious actors targeting US federal IT systems and their supply chain, the President released the “Executive Order on Improving the Nation’s Cybersecurity (Executive Order).” Although directed at Federal …
Chinese Hackers Believed to be Behind SITA, Air India Data Breach
The cyber assault on Air India that came to light last month lasted for a period of at least two months and 26 days, new research has revealed, which attributed …
Mozilla Says Google’s New Ad Tech—FLoC—Doesn’t Protect User Privacy
Google’s upcoming plans to replace third-party cookies with a less invasive ad targeted mechanism have a number of issues that could defeat its privacy objectives and allow for significant linkability …
Hackers Can Exploit Samsung Pre-Installed Apps to Spy On Users
Multiple critical security flaws have been disclosed in Samsung’s pre-installed Android apps, which, if successfully exploited, could have allowed adversaries access to personal data without users’ consent and take control …
Live Cybersecurity Webinar — Deconstructing Cobalt Strike
Organizations’ cybersecurity capabilities have improved over the past decade, mostly out of necessity. As their defenses get better, so do the methods, tactics, and techniques malicious actors devise to penetrate …
7-Year-Old Polkit Flaw Lets Unprivileged Linux Users Gain Root Access
A seven-year-old privilege escalation vulnerability discovered in the polkit system service could be exploited by a malicious unprivileged local attacker to bypass authorization and escalate permissions to the root user. …
