PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

TikTok Assures U.S. Lawmakers it's Working to Safeguard User Data From Chinese Staff

samedi 2 juillet 2022 à 06:22
Following heightened worries that U.S. users' data had been accessed by TikTok engineers in China between September 2021 and January 2022, the company sought to assuage U.S. lawmakers that it's taking steps to "strengthen data security." The admission that some China-based employees can access information from U.S. users came in a letter sent to nine senators, which further noted that the

Microsoft Warns About Evolving Capabilities of Toll Fraud Android Malware Apps

vendredi 1 juillet 2022 à 18:18
Microsoft has detailed the evolving capabilities of toll fraud malware apps on Android, pointing out its "complex multi-step attack flow" and an improved mechanism to evade security analysis. Toll fraud belongs to a category of billing fraud wherein malicious mobile applications come with hidden subscription fees, roping in unsuspecting users to premium content without their knowledge or consent

Google Improves Its Password Manager to Boost Security Across All Platforms

vendredi 1 juillet 2022 à 18:03
Google on Thursday announced a slew of improvements to its password manager service aimed at creating a more consistent look and feel across different platforms. Central to the changes is a "simplified and unified management experience that's the same in Chrome and Android settings," Ali Sarraf, Google Chrome product manager, said in a blog post. The updates are also expected to automatically

New 'SessionManager' Backdoor Targeting Microsoft IIS Servers in the Wild

vendredi 1 juillet 2022 à 12:03
A newly discovered malware has been put to use in the wild at least since March 2021 to backdoor Microsoft Exchange servers belonging to a wide range of entities worldwide, with infections lingering in 20 organizations as of June 2022. Dubbed SessionManager, the malicious tool masquerades as a module for Internet Information Services (IIS), a web server software for Windows systems, after

Solving the indirect vulnerability enigma - fixing indirect vulnerabilities without breaking your dependency tree

vendredi 1 juillet 2022 à 11:45
Fixing indirect vulnerabilities is one of those complex, tedious and, quite frankly, boring tasks that no one really wants to touch. No one except for Debricked, it seems. Sure, there are lots of ways to do it manually, but can it be done automatically with minimal risk of breaking changes? The Debricked team decided to find out.  A forest full of fragile trees So, where do you even start?