Is Traffic Mirroring for NDR Worth the Trouble? We Argue It Isn’t

Blog WriterThe Hacker News - Original news source is thehackernews.com

Network Detection & Response (NDR) is an emerging technology developed to close the blind security spots left by conventional security solutions, which hackers exploited to gain a foothold in target …

FTC Bans Stalkerware App SpyFone; Orders Company to Erase Secretly Stolen Data

Blog WriterThe Hacker News - Original news source is thehackernews.com

The U.S. Federal Trade Commission on Wednesday banned a stalkerware app company called SpyFone from the surveillance business over concerns that it stealthily harvested and shared data on people’s physical …

Cybercriminals Abusing Internet-Sharing Services to Monetize Malware Campaigns

Blog WriterThe Hacker News - Original news source is thehackernews.com

Threat actors are capitalizing on the growing popularity of proxyware platforms like Honeygain and Nanowire to monetize their own malware campaigns, once again illustrating how attackers are quick to repurpose and …

Linphone SIP Stack Bug Could Let Attackers Remotely Crash Client Devices

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity researchers on Tuesday disclosed details about a zero-click security vulnerability in Linphone Session Initiation Protocol (SIP) stack that could be remotely exploited without any action from a victim to …

QNAP Working on Patches for OpenSSL Flaws Affecting its NAS Devices

Blog WriterThe Hacker News - Original news source is thehackernews.com

Network-attached storage (NAS) appliance maker QNAP said it’s currently investigating two recently patched security flaws in OpenSSL to determine their potential impact, adding it will release security updates should its products turn out …

Researchers Propose Machine Learning-based Bluetooth Authentication Scheme

Blog WriterThe Hacker News - Original news source is thehackernews.com

A group of academics has proposed a machine learning approach that uses authentic interactions between devices in Bluetooth networks as a foundation to handle device-to-device authentication reliably. Called “Verification of …

New Microsoft Exchange ‘ProxyToken’ Flaw Lets Attackers Reconfigure Mailboxes

Blog WriterThe Hacker News - Original news source is thehackernews.com

Details have emerged about a now-patched security vulnerability impacting Microsoft Exchange Server that could be weaponized by an unauthenticated attacker to modify server configurations, thus leading to the disclosure of …

CISA Adds Single-Factor Authentication to the List of Bad Practices

Blog WriterThe Hacker News - Original news source is thehackernews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added single-factor authentication to the short list of “exceptionally risky” cybersecurity practices that could expose critical infrastructure as well as government and …