TikTok Flaw Allows Threat Actors to Plant Forged Videos in User Feeds

The popular video-sharing apps’s use of HTTP to download media content instead of a secure protocol could lead to the spread of misinformation on the platform. Continue reading TikTok Flaw Allows Threat Actors to Plant Forged Videos in User Feeds

Zoom Taps Ex-Facebook CISO Amid Security Snafus, Lawsuit

The online videoconferencing service added Alex Stamos to the team and has also formed an expert advisory board to grapple with the pains of its COVID-19 growth spurt. Continue reading Zoom Taps Ex-Facebook CISO Amid Security Snafus, Lawsuit

Official Government COVID-19 Mobile Apps Hide a Raft of Threats

Android apps launched for citizens in Iran, Colombia and Italy offer cyberattackers new attack vectors. Continue reading Official Government COVID-19 Mobile Apps Hide a Raft of Threats

Spearphishing Campaign Exploits COVID-19 To Spread Lokibot Infostealer

The attack discovered uses World Health Organization trademark to lure users with info related to coronavirus. Continue reading Spearphishing Campaign Exploits COVID-19 To Spread Lokibot Infostealer

Emerging MakeFrame Skimmer from Magecart Sets Sights on SMBs

Attacks using a brand-new card-harvesting code is targeting small- to medium-sized businesses, claiming 19 sites so far. Continue reading Emerging MakeFrame Skimmer from Magecart Sets Sights on SMBs

Top Email Protections Fail in Latest COVID-19 Phishing Campaign

An effective spoofing campaign promises users important information about new coronavirus cases in their local area, scooting past Proofpoint and Microsoft Office 356 ATPs. Continue reading Top Email Protections Fail in Latest COVID-19 Phishing Campaign

Apple Unpatched VPN Bypass Bug Impacts iOS 13, Warn Researchers

The vulnerability can be exploited to reveal limited traffic data including a device’s IP address. Continue reading Apple Unpatched VPN Bypass Bug Impacts iOS 13, Warn Researchers