user avatar
Threatpost
@threatpost
Threatpost is the first stop for fast-breaking security news, conversations and analysis from around the world.
Joined January 2009
Posts
  • user avatar
    #Google is under fire after a report found that Google Home and Google Assistant records user audio, even when no wake-up word is used.
  • user avatar
    A white hat hacker reverse engineered 30 mobile financial applications and found sensitive #data buried in the underlying #code of nearly all apps examined. threatpost.com/financial-apps…
  • user avatar
    Breaking: Hundreds of millions of #Facebook records – including account names and plaintext #passwords – have been found in two separate publicly-exposed app datasets, researchers at @UpGuard found. threatpost.com/facebook-data-…
  • user avatar
    #Mozilla released an emergency patch for a critical #Firefox flaw that is being actively exploited in targeted attacks.
  • user avatar
    #Citrix warned of multiple #security flaws that could allow code injection and data theft - including four that are exploitable by unauthenticated, remote attackers. threatpost.com/citrix-bugs-al…
  • user avatar
    In in lieu of a patch... “I advise to IMMEDIATELY DISCONNECT vulnerable routers from the Internet.” bit.ly/2jhkqY6
  • user avatar
    Secure password firms (1Password, Dashlane, KeePass and LastPass) are blasting a #security report highlighting how the utilities can be cracked open to steal #passwords. threatpost.com/1password-dash…
  • user avatar
    This Office 365 #phishing attack leverages real-time Active Directory validation of credentials. #Office365 threatpost.com/office-365-phi…
  • user avatar
    Two separate attacks have targeted as many as 50,000 different #Teams users, with the goal of phishing #Microsoft Office 365 logins.
  • user avatar
    The latest #iOS and Android versions of the FinSpy #malware have been deployed in the wild. The espionage tool can eavesdrop on Signal, Telegram and WhatsApp messages and calls.
  • user avatar
    15 billion usernames and #passwords are currently for sale on underground forums - over three times the number available two years ago. (via @digitalshadows)
  • user avatar
    Researchers have released a proof-of-concept showing how a XXE #security vulnerability can be exploited to attack #Ghidra project users.
  • user avatar
    A strange glitch in #Gmail can be exploited to place emails into a person’s “Sent” folder — even if that person never sent them.
  • user avatar
    A ‘zero-click’ #MacOS exploit chain using #Microsoft Office macros was revealed at Black Hat.