Sat.Oct 17, 2020

article thumbnail

Four npm packages found opening shells and collecting info on Linux, Windows systems

Security Affairs

On Thursday, four JavaScript packages have been removed from the npm portal because they have been found containing malicious code. NPM staff removed four JavaScript packages from the npm portal because were containing malicious code. Npm is the largest package repository for any programming language. The four packages, which had a total of one thousand of downloads, are: plutov-slack-client nodetest199 nodetest1010 npmpubman . “Any computer that has this package installed or running sh

Libraries 138
article thumbnail

Police get access to people told to self-isolate by NHS test and trace

The Guardian Data Protection

Fears move may deter people from getting tested for Covid-19 if forces get data Coronavirus – latest updates See all our coronavirus coverage People who have been told to self-isolate through NHS test and trace could have their contact details passed to police, a move some fear could deter people from being tested for coronavirus. Police forces will be able to access information about people “on a case-by-case” basis, so they can learn whether an individual has been told to self-isolate, the Dep

Access 132
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

UK NCSC recommends organizations to fix CVE-2020-16952 SharePoint RCE flaw asap

Security Affairs

The U.K. National Cyber Security Centre (NCSC) issued an alert to urge organizations to patch CVE-2020-16952 RCE vulnerability in MS SharePoint Server. The U.K. National Cyber Security Centre (NCSC) issued an alert to warn of the risks of the exploitation for the CVE-2020-16952 remote code execution (RCE) vulnerability in Microsoft SharePoint Server and urges organizations to address the flaw.

article thumbnail

You've heard of tax havens. After Brexit, the UK could become a 'data haven' | Carissa Véliz

The Guardian Data Protection

If Britain were to host data acquired in unlawful ways, the financial and reputational damage would be huge The United Kingdom is at a crossroads. On the verge of Brexit, it has to decide where it stands in relation to privacy: will it loosen data protection regulation, moving more towards China’s model, or will it guarantee its citizens’ right to privacy, moving more towards a Californian approach and securing a data adequacy agreement with the EU?

Privacy 91
article thumbnail

Get Better Network Graphs & Save Analysts Time

Many organizations today are unlocking the power of their data by using graph databases to feed downstream analytics, enahance visualizations, and more. Yet, when different graph nodes represent the same entity, graphs get messy. Watch this essential video with Senzing CEO Jeff Jonas on how adding entity resolution to a graph database condenses network graphs to improve analytics and save your analysts time.

article thumbnail

Google warned users of 33,015 nation-state attacks since January

Security Affairs

Google delivered over 33,000 alerts to its users during the first three quarters of 2020 to warn them of attacks from nation-state actors. Google delivered 33,015 alerts to its users during the first three quarters of 2020 to warn them of phishing attacks, launched by nation-state actors, targeting their accounts. Google sent 11,856 government-backed phishing warnings during Q1 2020, 11,023 in Q2 2020, and 10,136 in Q3 2020.

More Trending

article thumbnail

Google Offers Fresh Details on China-Linked Hacking Group

Data Breach Today

Analysis Shines Light on Group that Targeted Biden's Campaign Offices A report from Google's Threat Analysis Group is offering fresh details about the hacking group that targeted Joe Biden's campaign earlier this year with phishing emails. The attacks were linked to a little known hacking group called APT31, which has connections to China.

Phishing 293
article thumbnail

TikTok launched a public bug bounty program

Security Affairs

Chinese video-sharing social networking service TikTok announced this week the launch of a public bug bounty program in collaboration with HackerOne. The popular Chinese video-sharing social networking service TikTok has launched this week a public bug bounty program through the HackerOne platform. White hat hackers are invited to report security flaws in TikTok websites, including several subdomains, and both Android and iOS apps.