Dec 20, 2023 | Podcast
Ubiquiti users were reporting last week that they were seeing other people’s notification and had access to their devices. The incident was first reported on Reddit, where a user received a notification from UniFi Protect, including an image from someone...
Dec 18, 2023 | Podcast
It’s been almost 3 years since the critical Log4j vulnerability was disclosed and there are still approximately 38% of applications using vulnerable versions of the Apache Log4j library. Despite patches being available shortly after vulnerability disclosure,...
Dec 15, 2023 | Podcast
Apple will soon be introducing a Stolen Device Protection feature which is aimed at enhancing security if an iPhone is stolen, particularly in scenarios where thieves obtain the device passcode. The feature is currently in beta testing and relies on biometrics via...
Dec 14, 2023 | Podcast
Over 50% of insider attacks involve exploiting elevation of privilege flaws. A research study, based on data from January 2021 to April 2023, shows a rise in insider threats, with 55% relying on privilege escalation exploits and the remaining 45% introducing risks by...
Dec 13, 2023 | Podcast
In a significant update, Meta has announced the rollout of default end-to-end encryption for personal messages and calls on Messenger and Facebook. This means that private chats and calls across Messenger will now be automatically encrypted by default, enhancing...
Dec 12, 2023 | Podcast
A set of 14 security vulnerabilities named “5Ghoul” has been discovered in the firmware implementation of 5G mobile network modems from major chipset vendors like MediaTek and Qualcomm. The flaws impact USB and IoT modems, along with hundreds of smartphone...
Dec 11, 2023 | Podcast
Atlassian has issued an email warning customers of four critical vulnerabilities, each rated 9.0 or higher. Confluence, Jira, and Bitbucket servers, as well as a companion app for macOS are affected. The vulnerabilities, rated at least 9.0 out of 10, include a...
Dec 8, 2023 | Podcast
A Bluetooth authentication bypass vulnerability, tracked as CVE-2023-45866, has been discovered to be impacting Apple, Android, and some Linux devices. The bug allows attackers to connect to devices and inject keystrokes to execute arbitrary commands. It doesn’t...
Dec 7, 2023 | Podcast
WordPress administrators are being targeted by a fake security advisory email campaign that exploits a fictitious vulnerability (CVE-2023-45124) to install a malicious plugin on their websites. According to security researchers, the attackers sent deceptive emails to...
Dec 6, 2023 | Podcast
WhatsApp has introduced a new Secret Code feature, allowing users to add an extra layer of security to their locked chats by setting a custom password. This code is independent of the device unlock code and can include emojis. The feature helps hide the Locked Chats...