Critical ThroughTek Flaw Opens Millions of Connected Cameras to Eavesdropping

Blog WriterThe Hacker News - Original news source is thehackernews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday issued an advisory regarding a critical software supply-chain flaw impacting ThroughTek’s software development kit (SDK) that could be abused by …

Experts Shed Light On Distinctive Tactics Used by Hades Ransomware

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity researchers on Tuesday disclosed “distinctive” tactics, techniques, and procedures (TTPs) adopted by operators of Hades ransomware that set it apart from the rest of the pack, attributing it to …

Apple Issues Urgent Patches for 2 Zero-Day Flaws Exploited in the Wild

Blog WriterThe Hacker News - Original news source is thehackernews.com

Apple on Monday shipped out-of-band security patches to address two zero-day vulnerabilities in iOS 12.5.3 that it says are being actively exploited in the wild. The latest update, iOS 12.5.4, comes …

Google Workspace Now Offers Client-side Encryption For Drive and Docs

Blog WriterThe Hacker News - Original news source is thehackernews.com

Google on Monday announced that it’s rolling out client-side encryption to Google Workspace (formerly G Suite), thereby giving its enterprise customers direct control of encryption keys and the identity service …

NoxPlayer Supply-Chain Attack is Likely the Work of Gelsemium Hackers

Blog WriterThe Hacker News - Original news source is thehackernews.com

A new cyber espionage group named Gelsemium has been linked to a supply chain attack targeting the NoxPlayer Android emulator that was disclosed earlier this year. The findings come from a systematic …

Cybersecurity Executive Order 2021: What It Means for Cloud and SaaS Security

Blog WriterThe Hacker News - Original news source is thehackernews.com

In response to malicious actors targeting US federal IT systems and their supply chain, the President released the “Executive Order on Improving the Nation’s Cybersecurity (Executive Order).” Although directed at Federal …

Mozilla Says Google’s New Ad Tech—FLoC—Doesn’t Protect User Privacy

Blog WriterThe Hacker News - Original news source is thehackernews.com

Google’s upcoming plans to replace third-party cookies with a less invasive ad targeted mechanism have a number of issues that could defeat its privacy objectives and allow for significant linkability …

Hackers Can Exploit Samsung Pre-Installed Apps to Spy On Users

Blog WriterThe Hacker News - Original news source is thehackernews.com

Multiple critical security flaws have been disclosed in Samsung’s pre-installed Android apps, which, if successfully exploited, could have allowed adversaries access to personal data without users’ consent and take control …