A WordPress plugin with over 100,000 active installations had a bug that could have allowed unauthorised attackers to wipe its users’ blogs clean, it emerged this week.
from Naked Security https://ift.tt/38HvvXQ
via IFTTT
A WordPress plugin with over 100,000 active installations had a bug that could have allowed unauthorised attackers to wipe its users’ blogs clean, it emerged this week.
from Naked Security https://ift.tt/38HvvXQ
via IFTTT
OpenSSH version 8.2 is out and the big news is that the world’s most popular remote management software now supports authentication using any FIDO (Fast Identity Online) U2F hardware token.
from Naked Security https://ift.tt/2wmJLH5
via IFTTT
Insecure developer accounts, legacy software, and nonstandard naming schemes are major problems, Linux Foundation and Harvard study concludes.
from Dark Reading: https://ift.tt/2HAW311
via IFTTT
Deal with private equity entity Symphony Technology Group revealed one week before the security industry’s RSA Conference in San Francisco.
from Dark Reading: https://ift.tt/2V4m5Sm
via IFTTT
The new company will focus on giving customers earlier indications of network and server compromise.
from Dark Reading: https://ift.tt/2STFlz3
via IFTTT
Make cybersecurity your top priority, moving away from addressing individual problems with Band-Aids and toward attaining a long-term cyber-fitness plan.
from Dark Reading: https://ift.tt/37BlN88
via IFTTT
Crooks are constantly dreaming up new ways to use and conceal stolen credit card data. According to the U.S. Secret Service, the latest scheme involves stolen card information embedded in barcodes affixed to phony money network rewards cards. The scammers then pay for merchandise by instructing a cashier to scan the barcode and enter the expiration date and card security code.
This phony reloadable rewards card conceals stolen credit card data written to a barcode. The barcode and other card data printed on the card have been obfuscated. Image: U.S. Secret Service.
Earlier this month, the Secret Service documented a recent fraud incident in Texas involving a counterfeit club membership card containing a barcode, and a card expiration date and CVV printed below the barcode.
“Located underneath the barcode are instructions to the cashier on the steps necessary to complete the transaction,” reads an alert the Secret Service sent to law enforcement agencies. “They instruct the cashier to select card payment, scan the barcode, then enter the expiration date and CVV. In this instance, the barcode was encoded with a VISA credit card number.”
The instructions on the phony rewards card are designed to make the cashier think it’s a payment alternative designed for use exclusively at Sam’s Club and WalMart stores. When the transaction goes through, it’s recorded as card-not-present purchase.
“This appears to be an evolution of the traditional card-not-present fraud, and early indications are linking this type of activity to criminal organizations of Asian descent,” the Secret Service memo observed.
“As a result of this emerging trend, instead of finding a large number of re-encoded credit cards during a search, a subject may only possess stickers or cards with barcodes that contain stolen card data,” the alert continues. “Additionally, the barcodes could be stored on the subject’s cell phone. If barcodes are discovered in the field, it could be beneficial to utilize a barcode scanning app to check the barcode for credit card data.”
from Krebs on Security https://ift.tt/2STaYZO
via IFTTT
Other leaked records include videos, facial and body scans, as well as a range of patients’ personal data
The post Sensitive plastic surgery photos exposed online appeared first on WeLiveSecurity
from WeLiveSecurity https://ift.tt/2SUyqFT
via IFTTT
A vulnerability in the network of marketing contractor Computer Facilities led to a breach at the South African bank.
from Dark Reading: https://ift.tt/39KTSUB
via IFTTT
A fix is available, so you may want to make sure that you run the plugin’s latest version
The post Plugin flaw leaves up to 200,000 WordPress sites at risk of attack appeared first on WeLiveSecurity
from WeLiveSecurity https://ift.tt/2Hx2VMQ
via IFTTT