542 stories
·
0 followers

Zscaler takes "test environment" offline after rumors of a breach

1 Share
Zscaler says that they discovered an exposed "test environment" that was taken offline for analysis after rumors circulated that a threat actor was selling access to the company's systems. [...]
Read the whole story
NerdsToGo
5 hours ago
reply
Share this story
Delete

Critical F5 Central Manager Vulnerabilities Allow Enable Full Device Takeover

1 Share
Two security vulnerabilities have been discovered in F5 Next Central Manager that could be exploited by a threat actor to seize control of the devices and create hidden rogue administrator accounts for persistence. The remotely exploitable flaws "can give attackers full administrative control of the device, and subsequently allow attackers to create accounts on any F5 assets managed by the Next

Read the whole story
NerdsToGo
5 hours ago
reply
Share this story
Delete

Fake Online Stores Scam Over 850,000 Shoppers

1 Share
Researchers discover 75,000+ domains hosting fraudulent e-commerce sites, in a campaign dubbed BogusBazaar
Read the whole story
NerdsToGo
5 hours ago
reply
Share this story
Delete

AI-Powered Russian Network Pushes Fake Political News

1 Share
Researchers discover large-scale Russian influence operation using GenAI to influence voters
Read the whole story
NerdsToGo
5 hours ago
reply
Share this story
Delete

Cancer patients’ sensitive information accessed by “unidentified parties” after being left exposed by screening lab for years

1 Share
A medical lab that specialises in cancer screenings has admitted to an alarming data breach that left sensitive patient information exposed for years - and accessible by unauthorised parties. California-based Guardant Health is notifying affected individuals that information related to samples collected in late 2019 and 2020 was "inadvertently" left exposed online to the general public after an employee mistakenly uploaded it. Read more in my article on the Hot for Security blog.
Read the whole story
NerdsToGo
5 hours ago
reply
Share this story
Delete

Microsoft rolls out passkey auth for personal Microsoft accounts

1 Comment and 2 Shares
Microsoft announced that Windows users can now log into their Microsoft consumer accounts using a passkey, allowing users to authenticate using password-less methods such as Windows Hello, FIDO2 security keys, biometric data (facial scans or fingerprints), or device PINs. [...]
Read the whole story
NerdsToGo
17 hours ago
reply
Share this story
Delete
1 public comment
LinuxGeek
6 days ago
reply
Once again, Microsoft compromises security for convenience (details about this are in the story). Several security experts have recently written about how the concept behind passkeys is okay, but the various incompatible implementations suck so much that people might just stay with username/password.
NeonCone
1 day ago
Passkeys are much better for the majority of people for the majority of accounts. I still recommend username/password + 2fa for critical accounts like banking or your primary email account but for everything else passkeys are a big step up in usability for most people. I do agree though that having ecosystem locked implementations is going to suck if you aren't all in on either Google or Apple. The main reason I still use a physical yubikey and/or bitwarden passkeys instead.
Next Page of Stories