Linux users got a nasty surprise on Wednesday, as a security team at Red Hat uncovered a subtle but dangerous bug in the Bash shell, one of the most versatile and widely used utilities in Linux. It’s being called the Bash bug, or Shellshock. When accessed properly, the bug allows for an attacker’s code to Continue Reading →
Safety Security & Privacy
Posts I've written about Safety Security & Privacy. Subscribe to my newsletter to make sure you don't miss anything.
If you build it, they will come. And attack. Earlier this year, I was brainstorming with Greg Martin, the founder and chief technical officer of ThreatStream, a Google Ventures-backed security startup, about finding a way to show the global nature of attacks against industrial-control systems used in electrical grids, water systems and manufacturing plants. For Continue Reading →
There’s a lot that’s new in Apple’s just-released iPhone 6, but one feature hasn’t changed: Faked fingerprints can still fool the Touch ID fingerprint sensor. Security on the Touch ID fingerprint reader has been tightened, but only marginally, said Marc Rogers, chief security researcher at Lookout Mobile Security. “I don’t think people need to worry Continue Reading →
The risks were clear to computer experts inside Home Depot: The home improvement chain, they warned for years, might be easy prey for hackers. But despite alarms as far back as 2008, Home Depot was slow to raise its defenses, according to former employees. On Thursday, the company confirmed what many had feared: The biggest Continue Reading →
Last night, researchers at Malwarebytes noticed strange behavior on sites like Last.fm, The Times of Israel and The Jerusalem Post. Ads on the sites were being unusually aggressive, setting off anti-virus warnings and raising flags in a number of Malwarebytes systems. After some digging, researcher Jerome Segura realized the problem was coming from Google’s DoubleClick Continue Reading →
A few weeks ago, the world went crazy when reports surfaced that Facebook Messenger was snooping on you. Reporters, hackers, and users alleged that, because Messenger had the permission to use your camera, monitor your location, or (on Android) read your text messages, that it was doing so all the time. The scare was eventually Continue Reading →
Home Depot said Thursday that the security breach it reported this month allowed cyberthieves to cull information from 56 million credit and debit cards, far worse in terms of data loss than a similar attack late last year on the Target store chain. The malicious software, or malware, was placed on Home Depot point-of-sale terminals, Continue Reading →
In July, it was revealed that Goodwill Industries had suffered from a credit card data breach that affected the charitable retailer’s stores in at least 21 states. The Goodwill breach seemed by many to be just the latest case of criminals taking advantage of the weak underbelly of retailers—their point-of-sale systems. But now, as it Continue Reading →
Apple said Wednesday night that it is making it impossible for the company to turn over data from most iPhones or iPads to police — even when they have a search warrant — taking a hard new line as tech companies attempt to blunt allegations that they have too readily participated in government efforts to Continue Reading →
Apple has put fixes in place to its iCloud cloud storage service that now prevent an attacker from mining data from an iOS device backup stored in the cloud by gaining access to the user’s password—at least if that user has turned on Apple’s new two-factor authentication. As we reported last week, iCloud previously did Continue Reading →