Nethammer—Exploiting DRAM Rowhammer Bug Through Network Requests

Last week, we reported about the first network-based remote Rowhammer attack, dubbed Throwhammer, which involves the exploitation a known vulnerability in DRAM through network cards using remote direct memory access (RDMA) channels.

However, a separat… Continue reading Nethammer—Exploiting DRAM Rowhammer Bug Through Network Requests

Another severe flaw in Signal desktop app lets hackers steal your chats in plaintext

For the second time in less than a week, users of the popular end-to-end encrypted Signal messaging app have to update their desktop applications once again to patch another severe code injection vulnerability.

Discovered Monday by the same team of se… Continue reading Another severe flaw in Signal desktop app lets hackers steal your chats in plaintext

Hackers Reveal How Code Injection Attack Works in Signal Messaging App

After the revelation of the eFail attack details, it’s time to reveal how the recently reported code injection vulnerability in the popular end-to-end encrypted Signal messaging app works.

As we reported last weekend, Signal has patched its messaging … Continue reading Hackers Reveal How Code Injection Attack Works in Signal Messaging App

Here’s How eFail Attack Works Against PGP and S/MIME Encrypted Emails

With a heavy heart, security researchers have early released the details of a set of vulnerabilities discovered in email clients for two widely used email encryption standards—PGP and S/MIME—after someone leaked their paper on the Internet, which was a… Continue reading Here’s How eFail Attack Works Against PGP and S/MIME Encrypted Emails

Critical Flaws in PGP and S/MIME Tools Can Reveal Encrypted Emails in Plaintext

Note—the technical details of the vulnerabilities introduced in this article has now been released, so you should also read our latest article to learn how the eFail attack works and what users can do to prevent themselves.

An important warning for pe… Continue reading Critical Flaws in PGP and S/MIME Tools Can Reveal Encrypted Emails in Plaintext

Severe Bug Discovered in Signal Messaging App for Windows and Linux

Security researchers have discovered a severe vulnerability in the popular end-to-end encrypted Signal messaging app for Windows and Linux desktops which could allow remote attackers to execute malicious code on recipients system just by sending a mess… Continue reading Severe Bug Discovered in Signal Messaging App for Windows and Linux

7 Chrome Extensions Spreading Through Facebook Caught Stealing Passwords

Luring users on social media to visit lookalike version of popular websites that pop-up a legitimate-looking Chrome extension installation window is one of the most common modus operandi of cybercriminals to spread malware.

Security researchers are ag… Continue reading 7 Chrome Extensions Spreading Through Facebook Caught Stealing Passwords

5 Powerful Botnets Found Exploiting Unpatched GPON Router Flaws

Well, that did not take long.

Within just 10 days of the disclosure of two critical vulnerabilities in GPON router at least 5 botnet families have been found exploiting the flaws to build an army of million devices.

Security researchers from Chinese-… Continue reading 5 Powerful Botnets Found Exploiting Unpatched GPON Router Flaws

Self-destructing messages received on ‘Signal for Mac’ can be recovered later

It turns out that macOS client for the popular end-to-end encrypted messaging app Signal fails to properly delete disappearing (self-destructing) messages  from the recipient’s system, leaving the content of your sensitive messages at risk of getting e… Continue reading Self-destructing messages received on ‘Signal for Mac’ can be recovered later

Microsoft Patches Two Zero-Day Flaws Under Active Attack

It’s time to gear up for the latest May 2018 Patch Tuesday.

Microsoft has today released security patches for a total of 67 vulnerabilities, including two zero-days that have actively been exploited in the wild by cybercriminals, and two publicly disc… Continue reading Microsoft Patches Two Zero-Day Flaws Under Active Attack