Skip to main content
All Stories Tagged:

Security

Cybersecurity is the rickety scaffolding supporting everything you do online. For every new feature or app, there are a thousand different ways it can break – and a hundred of those can be exploited by criminals for data breaches, identity theft, or outright cyber heists. Staying ahead of those exploits is a full-time job, and one of the most lucrative and sought-after skills in the tech industry. All too often, it’s something up-and-coming companies decide to skip out on, only to pay the price later on.

E
External Link
Google is increasing payouts for its top bug squashers.

The company now offers up to $250,000 to people who find, detail, and demonstrate remote code execution vulnerabilities in Chrome. That more than doubles Chrome’s previous top payout, which sat at $100,115.


E
External Link
An alarming number of kids say their friends generate nudes of classmates with AI.

As reported by 404 Media, a survey from the anti-human trafficking nonprofit Thorn revealed that 1 in 10 minors said they knew of peers who used AI to create nudes of other kids:

While the motivation behind these events is more likely driven by adolescents acting out than an intent to sexually abuse, the resulting harms to victims are real and should not be minimized in attempts to wave off responsibility. 

In March, two Florida teens were arrested for creating deepfake nudes of classmates.


J
External Link
Brave has laid off around 15 percent of its employees.

The web browser and search startup confirmed to TechCrunch that 27 roles have been axed, but provided no explanation for the cuts.

That’s a significant number for a company the size of Brave — just 191 staffers according to a Pitchbook estimate. The move also follows Brave laying off 9 percent of its workforce in October last year.


J
External Link
Kentucky hacker receives a six-year prison sentence for trying to fake his own death.

The Washington Post reports Jesse Kipf pleaded guilty to computer fraud and identity theft charges for using a doctor’s login to falsify a death certificate and attempting to sell access to death registry systems.

US attorney Carlton S. Shier IV called it “a cynical and destructive effort, based in part on the inexcusable goal of avoiding his child support obligations.”


J
External Link
US intelligence officials say Iran is behind hacks of the Trump campaign.

“The [intelligence community] is confident that the Iranians have through social engineering and other efforts sought access to individuals with direct access to the presidential campaigns of both political parties,” according to a joint ODNI, FBI, and CISA statement.

The Trump campaign said earlier this month that it had been hacked and claimed that Iran was responsible.


J
External Link
Google Play is axing its Security Reward Program on August 31st.

The program, which paid security researchers up to $20,000 to locate vulnerabilities in popular Android apps, is being shuttered after seven years due to “a decrease in the number of actionable vulnerabilities reported.”

Google last announced in 2019 that it had paid $265,000 in bounties via the program — a fraction of the $10 million it paid out across all vulnerability programs last year.


Chrome for Android is making screen sharing more secure.

As reported by Bleeping Computer, Google is testing a new experimental flag that can hide sensitive content while “screen sharing, screen recording and similar actions” in regular tabs — redacting the user's entire screen if things like credit card details or passwords are detected.

There’s no mention of a release date, but it should be available for testing in Chrome Canary in the coming weeks.


A screenshot of Google’s new experimental feature for redacting sensitive user data in Chrome for Android.
This should provide some additional protection against accidentally exposing sensitive data.
Image: Google / Bleeping Computer
J
External Link
T-Mobile is paying the price for bad data security.

Specifically, about $60 million — a hefty civil penalty to settle allegations that the telecom giant failed to report incidents of unauthorized access to sensitive data, violating a national security agreement it made to acquire Sprint in 2020.

It’s the largest fine ever imposed by the Committee on Foreign Investment in the US, and just one of many data breaches T-Mobile has faced in recent years.


L
External Link
Russia is hacking critics around the world, rights groups say.

Citizen Lab and Access Now linked a “sophisticated spear phishing campaign” to a group associated with the Russian Federal Security Service (FSB). The campaign has allegedly targeted exiled opposition figures as well as non-governmental organization staff in the US and Europe. Threat actors would allegedly email their targets, pretending to be a colleague or funder, the groups say.


J
External Link
The FBI is looking into purported attempts by Iran to hack the Trump and Biden-Harris campaigns.

Trump adviser Roger Stone told The Washington Post that “a couple” of his personal email accounts had been compromised.

As for phishing emails sent to three Biden-Harris campaign staffers, the publication reports that “investigators have not found evidence that those hacking attempts were successful.”


R
External Link
Thomas White reveals himself as a co-founder of Silk Road 2.0 and DDoSecrets.

Just weeks after the NYT profiled Blake Benthall about his Silk Road 2.0 role and post-prison endeavors, 404 Media has identified a co-founder, Thomas White, as its “Dread Pirate Roberts 2.0.”

Between his 2014 arrest and receiving a five-year prison sentence in 2019, White apparently launched DDoSecrets with Emma Best, which was eventually tagged a “criminal hacker group” after publishing the “BlueLeaks.”


J
External Link
Apple and Google are making changes to address the so-called “0.0.0.0 Day” security vulnerability.

The vulnerability deals with how browsers deal with queries to the IP address 0.0.0.0, as reported by Forbes and the security startup Oligo. Apple tells Forbes that it is making changes to the macOS Sequoia beta to fix the issue, while Google has plans to fix it in Chrome.


T
External Link
CrowdStrike explains root cause of its giant IT outage.

CrowdStrike blamed testing software for taking down 8.5 million Windows machines last month, but now a full root cause analysis offers more details. The main issue was a mismatch between the input fields expected by CrowdStrike’s Falcon driver and the ones supplied in a content update. CrowdStrike is now promising to better test updates and is using two independent third-party software security vendors to review its sensor code and release processes.


How far would you go to open an unsigned Mac app?

If you update to macOS Sequoia, you’ll have to go to Settings > Security & Privacy and approve the app on first open, because Apple is taking away the current right-click (ctrl-click) workaround.

The warning signifies the developer never had Apple malware scan and notarize the app. Sensible security step or not, I’ll still grumble every time I have to open Settings to run something.


A screenshot warning that an app can’t be verified.
I just want to open my apps.
Screenshot: macOS
R
External Link
Android’s August security patch fixes a zero-day flaw that may be under “targeted” attack.

BleepingComputer points out the notes for this month’s Android security patch, with fixes for flaws that could allow someone to take over your device. The 2024-08-05 patch level specifically addresses a kernel flaw tagged CVE-2024-36971 which “may be under limited, targeted exploitation” already, so be sure to update your devices ASAP.


J
External Link
Consumer Reports is naming and shaming smart home companies without proper security vulnerability reporting.

Level, Chamberlain, Moen, Aqara, and Lutron are just some of the manufacturers the publication reports lack a dedicated way for security researchers to flag vulnerabilities — meaning a malicious hacker could potentially take advantage of a flaw before the company knows about it.

Check out the full report to see who’s on the naughty list — and who made the nice list.


S
External Link
The Cybersecurity and Infrastructure Security Agency has hired its first Chief AI Officer.

This was mandated for all federal agencies back in March, so expect more of these kinds of announcements.

CISA’s general ambit means this hire is a tad bit more significant than the average Chief AI Officer — the agency deals with foreign influence operations and election cybersecurity, for instance. (In 2020, the agency’s head was yeeted by Trump for saying that the election had in fact been safe and secure.)


CISA Names First Chief Artificial Intelligence Officer | CISA

[Cybersecurity and Infrastructure Security Agency CISA]