Security Vulnerability of HTML Emails
April 8 2024This is a newly discovered email vulnerability:
The email your manager received and forwarded to you was something completely innocent, such as a potential customer asking a few questions....
Read more
Friday Squid Blogging: SqUID Bots
April 6 2024They’re AI warehouse robots. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Read my blog posting guidelines...
Read moreIt seems that the FCC might be fixing the vulnerabilities in SS7 and the Diameter protocol:
On March 27 the commission asked telecommunications providers to weigh in and detail...
Read more
Surveillance by the New Microsoft Outlook App
April 4 2024The ProtonMail people are accusing Microsoft’s new Outlook for Windows app of conducting extensive surveillance on its users. It shares data with advertisers, a lot of data:
The window...
Read more
Class-Action Lawsuit against Google’s Incognito Mode
April 3 2024The lawsuit has been settled:
Google has agreed to delete “billions of data records” the company collected while users browsed the web using Incognito mode, according to documents...
Read more
XZ Utils Backdoor
April 3 2024The cybersecurity world got really lucky last week. An intentionally placed backdoor in XZ Utils, an open-source compression utility, was pretty much accidentally discovered by a Microsoft engineer—weeks...
Read moreDeclassified NSA Newsletters
April 3 2024Through a 2010 FOIA request (yes, it took that long), we have copies of the NSA’s KRYPTOS Society Newsletter, “Tales of the Krypt,” from 1994 to 2003.
There are...
Read moreMagic Security Dust
April 1 2024Adam Shostack is selling magic security dust. It’s about time someone is commercializing this essential technology.
Read more
Recent Comments