Technology

A widespread software supply chain attack has targeted the NPM package manager at least since December 2021 with rogue modules designed to steal data entered in forms by users on websites that include them. The coordinated attack, dubbed IconBurst by ReversingLabs, involves no fewer than two dozen NPM packages that include obfuscated JavaScript, which comes
0 Comments
Vulnerability coordination and bug bounty platform HackerOne on Friday disclosed that a former employee at the firm improperly accessed security reports submitted to it for personal gain. “The person anonymously disclosed this vulnerability information outside the HackerOne platform with the goal of claiming additional bounties,” it said. “In under 24 hours, we worked quickly to
0 Comments
While manufacturers have successfully increased the water-repelling nature of smartphones, they are still far from “waterproof”. A water-resistant product can usually resist water penetration to some extent, but a waterproof product is (meant to be) totally impervious to water. Last week, Samsung Australia was fined A$14 million (roughly Rs. 76 crores) by the Australian Federal
0 Comments
Amazon, in December 2021, patched a high severity vulnerability affecting its Photos app for Android that could have been exploited to steal a user’s access tokens. “The Amazon access token is used to authenticate the user across multiple Amazon APIs, some of which contain personal data such as full name, email, and address,” Checkmarx researchers
0 Comments
Fixing indirect vulnerabilities is one of those complex, tedious and, quite frankly, boring tasks that no one really wants to touch. No one except for Debricked, it seems. Sure, there are lots of ways to do it manually, but can it be done automatically with minimal risk of breaking changes? The Debricked team decided to
0 Comments
Following heightened worries that U.S. users’ data had been accessed by TikTok engineers in China between September 2021 and January 2022, the company sought to assuage U.S. lawmakers that it’s taking steps to “strengthen data security.” The admission that some China-based employees can access information from U.S. users came in a letter sent to nine
0 Comments
Smartphone sales globally have slipped below the 100-million mark in May 2022, according to Counterpoint Research’s Market Pulse Service. The research said that the global market sales of smartphones have dropped 4 percent month-on-month (MoM) and 10 percent year-on-year (YoY) in May this year, marking the second consecutive drop in MoM sales and 11th consecutive
0 Comments
Microsoft has detailed the evolving capabilities of toll fraud malware apps on Android, pointing out its “complex multi-step attack flow” and an improved mechanism to evade security analysis. Toll fraud belongs to a category of billing fraud wherein malicious mobile applications come with hidden subscription fees, roping in unsuspecting users to premium content without their
0 Comments
OnePlus 10RT may launch in India soon, if the latest report is to be believed. The smartphone is said to have been spotted on the Bureau of Indian Standards (BIS) certification database. Citing a tipster, the report also detailed some specifications of the smartphone. The camera specifications of the OnePlus 10RT were earlier tipped with
0 Comments