DUHK Attack Lets Hackers Recover Encryption Key Used in VPNs & Web Sessions

DUHK — Don’t Use Hard-coded Keys — is a new ‘non-trivial’ cryptographic implementation vulnerability that could allow attackers to recover encryption keys that secure VPN connections and web browsing sessions.

DUHK is the third crypto-related vulnerability reported this month after KRACK Wi-Fi attack and ROCA factorization attack.

The vulnerability affects products from dozens of vendors,

Continue reading DUHK Attack Lets Hackers Recover Encryption Key Used in VPNs & Web Sessions

Kaspersky Opens Antivirus Source Code for Independent Review to Rebuild Trust

Kaspersky Lab — We have nothing to hide!

Russia-based Antivirus firm hits back with what it calls a “comprehensive transparency initiative,” to allow independent third-party review of its source code and internal processes to win back the trust of customers and infosec community.

Kaspersky launches this initiative days after it was accused of helping, knowingly or unknowingly, Russian

Continue reading Kaspersky Opens Antivirus Source Code for Independent Review to Rebuild Trust

Google to add “DNS over TLS” security feature to Android OS

No doubt your Internet Service Provides (ISPs), or network-level hackers cannot spy on https communications.

But do you know — ISPs can still see all of your DNS requests, allowing them to know what websites you visit.

Google is working on a new security feature for Android that could prevent your Internet traffic from network spoofing attacks.

Almost every Internet activity starts with a

Continue reading Google to add “DNS over TLS” security feature to Android OS

Dangerous Malware Allows Anyone to Empty ATMs—And It’s On Sale!

Hacking ATM is now easier than ever before.

Usually, hackers exploit hardware and software vulnerabilities to hack ATMs and force them to spit out cash, but now anyone can simply buy a malware to steal millions in cash from ATMs.

Hackers are selling … Continue reading Dangerous Malware Allows Anyone to Empty ATMs—And It’s On Sale!

Microsoft Kept Secret That Its Bug-Tracking Database Was Hacked In 2013

It was not just Yahoo among “Fortune 500” companies who tried to keep a major data breach incident secret.

Reportedly, Microsoft had also suffered a data breach four and a half years ago (in 2013), when a “highly sophisticated hacking group” breached … Continue reading Microsoft Kept Secret That Its Bug-Tracking Database Was Hacked In 2013

How A Drive-by Download Attack Locked Down Entire City for 4 Days

We don’t really know the pain and cost of a downtime event unless we are directly touched.

Be it a flood, electrical failure, ransomware attack or other broad geographic events; we don’t know what it is really like to have to restore IT infrastructure… Continue reading How A Drive-by Download Attack Locked Down Entire City for 4 Days

Hackers Use New Flash Zero-Day Exploit to Distribute FinFisher Spyware

FinSpy—the infamous surveillance malware is back and infecting high-profile targets using a new Adobe Flash zero-day exploit delivered through Microsoft Office documents.

Security researchers from Kaspersky Labs have discovered a new zero-day remote code execution vulnerability in Adobe Flash, which was being actively exploited in the wild by a group of advanced persistent threat actors,

Continue reading Hackers Use New Flash Zero-Day Exploit to Distribute FinFisher Spyware

Israel Hacked Kaspersky, Caught Russian Spies Hacking American Spies, But…

The cold cyber war has just turned hot.

According to a story published today by the New York Times, Israeli government hackers hacked into Kaspersky’s network in 2015 and caught Russian government hackers red-handed hacking US government hackers with the help of Kaspersky.

In other words — Russia spying on America, Israel spying on Russia and America spying on everyone.

What the F^#% is

Continue reading Israel Hacked Kaspersky, Caught Russian Spies Hacking American Spies, But…

OnePlus Secretly Collects Way More Data Than It Should — Here’s How to Disable It

There is terrible news for all OnePlus lovers.

Your OnePlus handset, running OxygenOS—the company’s custom version of the Android operating system, is collecting way more data on its users than it requires.

A recent blog post published today by security researcher Christopher Moore on his website detailed the data collection practice by the Shenzhen-based Chinese smartphone maker, revealing

Continue reading OnePlus Secretly Collects Way More Data Than It Should — Here’s How to Disable It