Zoom bolsters software security in latest move to reassure users

Zoom, the videoconferencing service whose popularity has soared during the coronavirus pandemic, on Wednesday said it was adding security measures to its software following scrutiny from independent researchers. The next version of Zoom, to be released this week, will have stronger encryption for data sent between participants in a meeting to prevent tampering, the Silicon Valley-based company said. The software will also allow Zoom account administrators to choose which parts of the world they route their data through. The upgrade follows a report from the University of Toronto’s Citizen Lab that found Zoom routed some meeting encryption keys through China. The updates are an effort to adapt to the unprecedented amount of people using Zoom as they work from home during the COVID-19 pandemic. Some 200 million people used the software on a daily basis in March, and the Silicon Valley company at first appeared unprepared for the privacy and […]

The post Zoom bolsters software security in latest move to reassure users appeared first on CyberScoop.

Continue reading Zoom bolsters software security in latest move to reassure users

Zoom Introduces New Update With Stronger Encryption, New Security Controls

Zoom announces Zoom 5.0 with a much stronger encryption standard, and new security features designed to protect users against Zoombombing.
The post Zoom Introduces New Update With Stronger Encryption, New Security Controls appeared first on Thurrott.c… Continue reading Zoom Introduces New Update With Stronger Encryption, New Security Controls

Foiling content-borne attacks against a remote workforce

Opening a single email with a malicious URL or attachment can threaten your organization. In this interview, Liron Barak, CEO at BitDam, discusses the cybersecurity issue related to remote work, the inadequate security of collaboration tools, and more…. Continue reading Foiling content-borne attacks against a remote workforce

Phishers exploit Zoom, WebEx brands to target businesses

Proofpoint researchers have spotted and documented email phishing campaigns targeting US companies in a variety of industries with emails impersonating Zoom and Cisco (WebEx). Phishing emails impersonating Zoom and WebEx “Video conferencing has become … Continue reading Phishers exploit Zoom, WebEx brands to target businesses

Zoom Hacked Accounts, North Korean Hackers, Facebook Senior Pictures

In episode 117 for April 20th 2020: More problems for Zoom with tens of thousands of compromised credentials and zero-day exploits, the $5 million dollar reward for information on North Korean hackers, and why it might not be the best idea to post your… Continue reading Zoom Hacked Accounts, North Korean Hackers, Facebook Senior Pictures

Finding Zoom Meeting Details in the Wild

The popular web conference platform Zoom has been in the storm for a few weeks. With the COVID19 pandemic, more and more people are working from home and the demand for web conference tools has been growing. Vulnerabilities have been discovered in the Zoom client and, based on the fact

[The post Finding Zoom Meeting Details in the Wild has been first published on /dev/random]

Continue reading Finding Zoom Meeting Details in the Wild

This Week in Security: Git, Patch Tuesday, Anti-Cheat, and Vulnerable Documentation

Git released an update on Tuesday, fixing an issue that could result in leaking credentials. The vulnerability was in how Git handles an HTTP URL containing a newline. Looking at the commits in 2.26.1, we can find an example of an attack:
url = "https://one.example.com?%0ahost=two.example.com/foo.git"

So doing a git pull …read more

Continue reading This Week in Security: Git, Patch Tuesday, Anti-Cheat, and Vulnerable Documentation