Sun.Sep 08, 2019

article thumbnail

Experts found Joker Spyware in 24 apps in the Google Play store

Security Affairs

Security experts at Google have removed from Google Play 24 apps because they were infected with a new spyware tracked as “the Joker.” Google has removed from Google Play 24 apps because they were infected with a new spyware tracked as “the Joker.” The spyware is able to steal SMS messages, contact lists and device information along with to sign victims up for premium service subscriptions. “Over the past couple of weeks, we have been observing a new Trojan on Googl

article thumbnail

Weekly Update 155

Troy Hunt

From the emerging spring to the impending autumn, I'm back in Oslo at the beginning of another series of European events that'll take me across Norway, Denmark, Hungary and Switzerland. This week's update comes from under the glow of a warm outdoor heater at ridiculous o'clock as my sleep cycle keeps me making early starts. But it's all transient and by this time next month I'll be back to a very warm, very familiar Aussie landscape.

IT 56
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

China-linked APT3 was able to modify stolen NSA cyberweapons

Security Affairs

China-linked APT3 stole cyberweapons from the NSA and reverse engineered them to create its arsenal. In 2010, security firm FireEye identified the Pirpi Remote Access Trojan (RAT) which exploited a then 0-day vulnerability in Internet Explorer versions 6, 7 and 8. FireEye named the threat group APT3 which has also been described as TG-0100 , Buckeye , Gothic Panda , and UPS and described them as “one of the most sophisticated threat groups” being tracked at the time.

article thumbnail

Forget CCPA. COPPA Just Cost YouTube and Google $170 Million: Cybersecurity Trends

eDiscovery Daily

Sure, we’ve been talking a lot the past couple of years about Europe’s General Data Protection Regulation (GDPR), enacted in May 2018 and we’ve already seen one big fine here and another huge potential fine here. And, we’ve been talking for over a year now about the California Consumer Privacy Act, which is scheduled to take effect next January 1st.

article thumbnail

Peak Performance: Continuous Testing & Evaluation of LLM-Based Applications

Speaker: Aarushi Kansal, AI Leader & Author and Tony Karrer, Founder & CTO at Aggregage

Software leaders who are building applications based on Large Language Models (LLMs) often find it a challenge to achieve reliability. It’s no surprise given the non-deterministic nature of LLMs. To effectively create reliable LLM-based (often with RAG) applications, extensive testing and evaluation processes are crucial. This often ends up involving meticulous adjustments to prompts.

article thumbnail

WordPress 5.2.3 fixes multiple issues, including some severe XSS flaws

Security Affairs

The WordPress development team released version 5.2.3 that includes 29 fixes, enhancements, and several security patches. WordPress developers released a security and maintenance version 5.2.3 that includes 29 fixes, several enhancements and security patches. These flaws affect the versions 5.2.2 and earlier of the popular CMS. Most of the security flaws addressed with the release of the version 5.2.3 are cross-site scripting (XSS) issues.

CMS 81

More Trending

article thumbnail

Toyota Boshoku Corporation lost over $37 Million following BEC attack

Security Affairs

Toyota Boshoku Corporation announced that one of its European subsidiaries lost more than $37 million due to a business email compromise (BEC) attack. Toyota Boshoku Corporation is a Japanese automotive component manufacturer, it is a member of the Toyota Group of companies. . Toyota Boshoku Corporation has announced that one of its European subsidiaries lost more than $37 million following a business email compromise (BEC) attack, The BEC attack took place on August 14. “September 6, 2019

article thumbnail

Belarusian authorities seized XakFor, one of the largest Russian-speaking hacker sites

Security Affairs

Ministry of Internal Affairs announced that Belarusian police have seized and shutdown XakFor, one of the largest hacking forums on the internet. Belarusian police have seized the servers of XakFor (xakfor[.]net), a popular hacking forum a place frequented by hackers, malware authors, scammers and cybercriminals. The news was first reported by the Belarusian news outlet Reformation. “This resource has been revealed divisions on the fight against cybercrime and the Interior Ministry of Inte

article thumbnail

Security Affairs newsletter Round 230

Security Affairs

A new round of the weekly newsletter arrived! The best news of the week with Security Affairs. Hi folk, let me inform you that I suspended the newsletter service, anyway I’ll continue to provide you a list of published posts every week through the blog. Once again thank you! Cisco addresses CVE-2019-12643 critical flaw in virtual Service Container for IOS XE.

article thumbnail

University, Professional Certification or Direct Experience?

Security Affairs

How to improve technical skills? Would it be better a university course , a professional certification or an experience in a cybersecurity firm? Today I’d like to share a simple and personal thought about teaching models on cybersecurity. Quite often students ask me how to improve their technical skills and the most common question is: “would it be better an university course a professional certification or getting directly on the field working in a Cybersecurity company ?”.

article thumbnail

How and Why Should You Be Tracking Geopolitical Risk?

Geopolitical risk is now at the top of the agenda for CEOs. But tracking it can be difficult. The world is more interconnected than ever, whether in terms of economics and supply chains or technology and communication. Geopolitically, however, it is becoming increasingly fragmented – threatening the operations, financial well-being, and security of globally connected companies.