Security

Hacker selling Vodafone’s Ho Mobile database of 2.5M users

The database contains ICCID that can be used in SIM swapping attacks. Other information in the leaked dump includes mobile…

4 years ago

Joomla fixes ACL violation vulnerability after 2 years

Joomla! CMS project has fixed an access control violation flaw, CVE-2020-35616 nearly after 2 years of its reporting.

4 years ago

Google ‘Send Feedback’ bug could expose your sensitive data to attackers

Google Docs "Send Feedback" feature vulnerability which could expose your sensitive files to attackers earns researcher a $3,134 bounty.

4 years ago

Insecure QR codes on COVID-19 test results come with data exposure risks

Medical labs appointed by governments to test incoming international passengers for COVID-19 contain insecure QR code implementations that may lead…

4 years ago

Facebook fixes Instagram bug that leaked user’s private email address and birthday

Facebook has fixed an Instagram bug which leaked users' private email address and date of birth. The company awarded the…

4 years ago

Source code used by Central Banks and Stock Exchanges leaked online

This week, the source code of CMA, a software provider relied on by leading central banks across nations and stock…

4 years ago

Steam gamers: your Windows PC is prone to privilege escalation attacks

Multiple privilege escalation vulnerabilities in Stream gaming service that remain unpatched can make it easy for malware and malicious threat…

4 years ago

Canadian government site canada.gc.ca SSL certificate expires, breaks links

Government of Canada website canada.gc.ca is throwing SSL errors due to an expired certificate. Multiple Canadian government sites continue to…

4 years ago

DoS flaw lets attackers crash NodeJS apps via DNS lookups

NodeJS has released fixes for CVE-2020-8277, a DoS vulnerability that could be triggered via DNS requests.

4 years ago

Drupal fixes critical Remote Code Execution vulnerability, patch now

Development team behind Drupal, a popular CMS and blogging platform has issued patches for a remote code execution vulnerability, CVE-2020-13671.

4 years ago

This website uses cookies.