BleepingComputer
10.4K subscribers
41 photos
24.6K links
Latest news and stories from BleepingComputer.com

From a bleeping computer to a working computer.
Download Telegram
Golden SAML Attack Lets Attackers Forge Authentication to Cloud Apps

A new technique called "Golden SAML" lets attackers forge authentication requests and access the cloud-based apps of companies that use SAML-compatible domain controllers (DCs) for the authentication of users against cloud services. [...]

https://www.bleepingcomputer.com/news/security/golden-saml-attack-lets-attackers-forge-authentication-to-cloud-apps/
Keybase Bug Might Have Backed up Your Private Encryption Key on Google's Servers

Keybase is notifying Android users of a bug in its mobile app that might have unintentionally included the users' private key β€”used to encrypt conversations and other private dataβ€” into the automatic backups created by the Android OS and uploaded on Google's servers. [...]

https://www.bleepingcomputer.com/news/security/keybase-bug-might-have-backed-up-your-private-encryption-key-on-googles-servers/
Researchers Identify 44 Trackers in More Than 300 Android Apps

A collaborative effort between the Yale Privacy Lab and Exodus Privacy has shed light on dozens of invasive trackers that are embedded within Android applications and record user activity, sometimes without user consent. [...]

https://www.bleepingcomputer.com/news/security/researchers-identify-44-trackers-in-more-than-300-android-apps/
Top Secret US Army and NSA Files Left Exposed Online on Amazon S3 Server

Ten days after an Amazon S3 server exposed data from the US Army's CENTCOM and PACOM divisions, security researchers have identified another S3 server instance that leaked files from INSCOM, a joint US Army and NSA agency tasked with conducting intelligence, security, and information operations. [...]

https://www.bleepingcomputer.com/news/security/top-secret-us-army-and-nsa-files-left-exposed-online-on-amazon-s3-server/
Android Cryptocurrency Wallet Apps Are a Security Disaster Waiting to Happen

The vast majority of Android mobile apps available on the official Google Play Store that are meant for the management of cryptocurrencies are vulnerable to the most common and well-known vulnerabilities, according to a report published today by Swiss cyber-security firm High-Tech Bridge. [...]

https://www.bleepingcomputer.com/news/security/android-cryptocurrency-wallet-apps-are-a-security-disaster-waiting-to-happen/
Fake Windows Troubleshooting Support Scam Uploads Screenshots & Uses Paypal

A new tech support scam has been discovered that shows a fake crash on the infected computer and displays an application that pretends to be a Windows Troubleshooter. This Troubleshooter states that your computer cannot be fixed, blocks you from using Windows, and prompts you to purchase a program using PayPal to fix the "problems". [...]

https://www.bleepingcomputer.com/news/security/fake-windows-troubleshooting-support-scam-uploads-screenshots-and-uses-paypal/