BleepingComputer
10.4K subscribers
41 photos
24.6K links
Latest news and stories from BleepingComputer.com

From a bleeping computer to a working computer.
Download Telegram
The Week in Ransomware - November 24th 2017 - qkG, Scarab, Necurs, and More

Not much to report this week other than Necurs starting to push the Scarab Ransomware and a new office document infecting ransomware called qkG. Otherwise, it has been a week of small variants that are in various stages of development. [...]

https://www.bleepingcomputer.com/news/security/the-week-in-ransomware-november-24th-2017-qkg-scarab-necurs-and-more/
Imgur Suffered a Small Data Breach in 2014

Late Friday night, Imgur came clean about a security breach that took place in 2014. During the incident, Imgur says an unknown attacker managed to steal details on 1.7 million users, representing about 1.13% of Imgur's total 150 million users. [...]

https://www.bleepingcomputer.com/news/security/imgur-suffered-a-small-data-breach-in-2014/
Golden SAML Attack Lets Attackers Forge Authentication to Cloud Apps

A new technique called "Golden SAML" lets attackers forge authentication requests and access the cloud-based apps of companies that use SAML-compatible domain controllers (DCs) for the authentication of users against cloud services. [...]

https://www.bleepingcomputer.com/news/security/golden-saml-attack-lets-attackers-forge-authentication-to-cloud-apps/
Keybase Bug Might Have Backed up Your Private Encryption Key on Google's Servers

Keybase is notifying Android users of a bug in its mobile app that might have unintentionally included the users' private key β€”used to encrypt conversations and other private dataβ€” into the automatic backups created by the Android OS and uploaded on Google's servers. [...]

https://www.bleepingcomputer.com/news/security/keybase-bug-might-have-backed-up-your-private-encryption-key-on-googles-servers/
Researchers Identify 44 Trackers in More Than 300 Android Apps

A collaborative effort between the Yale Privacy Lab and Exodus Privacy has shed light on dozens of invasive trackers that are embedded within Android applications and record user activity, sometimes without user consent. [...]

https://www.bleepingcomputer.com/news/security/researchers-identify-44-trackers-in-more-than-300-android-apps/
Top Secret US Army and NSA Files Left Exposed Online on Amazon S3 Server

Ten days after an Amazon S3 server exposed data from the US Army's CENTCOM and PACOM divisions, security researchers have identified another S3 server instance that leaked files from INSCOM, a joint US Army and NSA agency tasked with conducting intelligence, security, and information operations. [...]

https://www.bleepingcomputer.com/news/security/top-secret-us-army-and-nsa-files-left-exposed-online-on-amazon-s3-server/
Android Cryptocurrency Wallet Apps Are a Security Disaster Waiting to Happen

The vast majority of Android mobile apps available on the official Google Play Store that are meant for the management of cryptocurrencies are vulnerable to the most common and well-known vulnerabilities, according to a report published today by Swiss cyber-security firm High-Tech Bridge. [...]

https://www.bleepingcomputer.com/news/security/android-cryptocurrency-wallet-apps-are-a-security-disaster-waiting-to-happen/