Uncategorized

Microsoft accounts can go passwordless, making “password123” a thing of the past

Enlarge (credit: Getty Images) Microsoft has been working to make passwordless sign-in for Windows and Microsoft accounts a reality for years now, and today those efforts come to fruition: The Verge reports that…

Anonymous leaks gigabytes of data from alt-right web host Epik

Enlarge (credit: Tom Roberts) Hacktivist collective Anonymous claims to have obtained gigabytes of data from Epik, which provides domain name, hosting, and DNS services for a variety of clients. These include the Texas…

Security researchers at Wiz discover another major Azure vulnerability

Enlarge / This isn't how the OMIGOD vulnerability works, of course—but lightning is much more photogenic than maliciously crafted XML. (credit: Aurich Lawson | Getty Images) Cloud security vendor Wiz—which recently made news…

Apple patches “FORCEDENTRY” zero-day exploited by Pegasus spyware

Enlarge (credit: Aurich Lawson | Getty Images) Apple has released several security updates this week to patch a "FORCEDENTRY" vulnerability on iOS devices. The "zero-click, zero-day" vulnerability has been actively exploited by Pegasus,…

Travis CI flaw exposed secrets of thousands of open source projects

Enlarge (credit: Getty Images) A security flaw in Travis CI potentially exposed the secrets of thousands of open source projects that rely on the hosted continuous integration service. Travis CI is a software-testing…

Infosec researchers say Apple’s bug-bounty program needs work

Enlarge / If you don't maintain good relationships with bug reporters, you may not get to control the disclosure timeline. (credit: mhatzapa via Getty Images / Jim Salter) The Washington Post reported earlier today…

WhatsApp “end-to-end encrypted” messages aren’t that private after all

Enlarge / The security of Facebook's popular messaging app leaves several rather important devils in its details. (credit: WhatsApp) Yesterday, independent newsroom ProPublica published a detailed piece examining the popular WhatsApp messaging platform's privacy…

Microsoft Outlook shows real person’s contact info for IDN phishing emails

Enlarge (credit: Drew Angerer | Getty Images) If you receive an email from someone@arstechnіca.com, is it really from someone at Ars? Most definitely not—the domain in that email address is not the same…

ProtonMail removed “we do not keep any IP logs” from its privacy policy

Enlarge / ProtonMail offers end-to-end encryption and a stated focus on privacy for its email service—which offers a user interface quite similar to those of more mainstream services such as Gmail. (credit: Jim…

Why ransomware hackers love a holiday weekend

Enlarge / Gah, don't you miss unstressed travel? (credit: Klaus Vedfelt / Getty Images) On the Friday heading into Memorial Day weekend this year, it was meat-processing giant JBS. On the Friday before…