#security-vulnerability

[ follow ]
fromZDNET
2 days ago

Popular Neon app that pays users to share call recordings remains down for now - here's why

People trying to earn money by sharing their personal phone conversations with the new Neon app will have to find another way to generate income, at least for now. On Thursday, the service was taken down by its developer after the discovery of a serious security flaw that let Neon users access the call recordings and other data of fellow users.
Privacy technologies
fromThe Verge
2 days ago

Tile's lack of encryption could make tracker owners vulnerable to stalking

Security researchers are shining the spotlight on a serious security vulnerability that could enable stalkers to track victims using their own Tile tags, as well as other unwanted violations of security and privacy. Research outlined by Wired shows that Tile's anti-theft mode, which makes its trackers "invisible" on the Tile network, counteracts measures to prevent stalking. Bad actors could also potentially intercept unencrypted information sent from the tags, like their unique IDs and MAC addresses,
Privacy professionals
fromZDNET
3 days ago

Serious security flaw prompts take-down of popular call recording app Neon

While making test phone calls, TechCrunch's Zack Whittaker said he saw a list of his recent calls and how much money each call earned. That's the way the app is supposed to work. But using a network analysis tool, Whittaker uncovered details not available through the app, including a transcript of the call and a URL to the audio files, information anyone could view as long as they had the link.
Privacy technologies
Privacy professionals
fromDataBreaches.Net
1 week ago

No Need to Hack When It's Leaking: App for outing Charlie Kirk's critics leaked its users' personal data - DataBreaches.Net

Cancel the Hate, an app for reporting alleged critics of Charlie Kirk, leaked users' personal data including emails and phone numbers and was taken offline.
fromTheregister
1 week ago

Entra ID bug could have granted access to every tenant

"If you are an Entra ID admin," wrote Mollema, "that means complete access to your tenant."
Information security
fromTechCrunch
1 month ago

A new security flaw in TheTruthSpy phone spyware is putting victims at risk | TechCrunch

Independent security researcher Swarang Wade found the vulnerability, which allows anyone to reset the password of any user of the stalkerware app TheTruthSpy and its many companion Android spyware apps, leading to the hijacking of any account on the platform. Given the nature of TheTruthSpy, it's likely that many of its customers are operating it without the consent of their targets, who are unaware that their phone data is being siphoned off to somebody else.
Information security
Information security
fromDataBreaches.Net
1 month ago

Intel Websites Compromised, Allowing Hackers Access to Employee and Confidential Data - DataBreaches.Net

Security flaws in Intel's internal web infrastructure exposed over 270,000 employees' details and potentially allowed attackers administrative access to corporate and supplier information.
fromThe Hacker News
1 month ago

Microsoft Discloses Exchange Server Flaw Enabling Silent Cloud Access in Hybrid Setups

In an Exchange hybrid deployment, an attacker who first gains administrative access to an on-premises Exchange server could potentially escalate privileges within the organization's connected cloud environment without leaving easily detectable and auditable traces.
Privacy professionals
Privacy professionals
fromThe Verge
1 month ago

Microsoft's plan to fix the web with AI has already hit an embarrassing security flaw

A critical vulnerability in Microsoft's NLWeb protocol allows remote users to access sensitive files.
fromTechzine Global
2 months ago

SharePoint vulnerability actively exploited: Microsoft rolls out emergency patches

Microsoft has issued an urgent warning about a critical zero-day vulnerability in SharePoint Server, registered as CVE-2025-53770, allowing remote code execution.
Privacy professionals
fromThe Hacker News
2 months ago

Hackers Exploit Critical CrushFTP Flaw to Gain Admin Access on Unpatched Servers

"CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS."
Information security
#cisco
fromThe Hacker News
2 months ago

ServiceNow Flaw CVE-2025-3648 Could Lead to Data Exposure via Misconfigured ACLs

The vulnerability, tracked as CVE-2025-3648 (CVSS score: 8.2), has been described as a case of data inference in Now Platform through conditional access control list (ACL) rules.
Information security
Privacy technologies
fromMail Online
3 months ago

Update your browser NOW: Google Chrome hit by serious security flaw

Google Chrome users must update their browser immediately to protect against a high-severity security vulnerability exploited by hackers.
Privacy technologies
fromZDNET
3 months ago

Your Brother printer might have a critical security flaw - how to check and what to do next

Brother printers have a serious unpatchable security flaw that exposes devices to potential attacks.
#google
fromZDNET
3 months ago
Privacy technologies

Google Chrome hit by another serious security flaw - update your browser ASAP

Google has patched a critical security vulnerability in Chrome, requiring users to update immediately.
fromTheregister
3 months ago
Privacy technologies

Google brute-force attack exposes phone numbers in minutes

A flaw in Google's authentication systems leaves users' phone numbers vulnerable to brute-force attacks.
fromZDNET
3 months ago
Privacy technologies

Google Chrome hit by another serious security flaw - update your browser ASAP

NYC parents
from6abc Philadelphia
3 months ago

2 of 4 detainees who escaped Delaney Hall immigration detention center back in custody: FBI Newark

Two of the four detainees who escaped an immigration detention center in New Jersey are back in custody, search ongoing for the others.
Privacy technologies
fromTechzine Global
3 months ago

AMD releases security update for Ryzen CPUs with TPM vulnerability

A new vulnerability in Ryzen processors allows unauthorized access to TPM data, with a CVSS score indicating medium risk, requiring physical access to exploit.
Information security
fromZDNET
3 months ago

Is your Asus router part of a botnet? How to check - and what you can do

Asus routers faced a significant security breach, impacting thousands as cybercriminals exploited vulnerabilities and established persistent backdoors.
fromTheregister
4 months ago

OpenPGP.js bug enables encrypted message spoofing

The vulnerability discovered in OpenPGP.js enables spoofing of both signed and encrypted messages, undermining the purpose of public key cryptography.
Privacy professionals
fromTechzine Global
4 months ago

Chrome vulnerability allowing account takeover fixed

Google has released an emergency update for the Chrome browser to fix a serious security vulnerability that allowed an account takeover.
Privacy technologies
Information security
fromTechzine Global
5 months ago

Commvault vulnerability poses serious risk to company data

Commvault's Command Center has a serious vulnerability (CVE-2025-34028) that allows remote code execution.
Organizations must ensure their systems are updated to version 11.38.20 to mitigate the risk.
Information security
fromSecuritymagazine
5 months ago

Devices exposed to remote hacking via Erlang/OTP SSH vulnerability

Erlang/OTP's SSH implementation has a critical vulnerability allowing remote code execution without authentication, requiring urgent attention and action from security teams.
fromZDNET
5 months ago

That Google email look real? Don't click - it might be scam. Here's how to tell

The sophisticated phishing scam uses Google’s own infrastructure to create deceptive emails and landing pages that appear legitimate, making attacks harder to identify.
Privacy professionals
[ Load more ]