Google's New .zip and .mov Domains Raise Security Concerns

The new .zip Top Level Domain (TLD) can be abused for phishing purposes using Unicode tricks. Microsoft Sharepoint is automatically trying the most common passwords to scan inside encrypted zip files, which is a concern for security researchers. Essential Addons for Elementor and possearchproducts are two web plugins with high-priority vulnerabilities that allow attackers to take over user accounts and steal credit card information. BlackLotus has broken Secure Boot on Windows, and a patch and workaround have been found. IPv6 and vm2 escapes are also causing security concerns. The Wemo Mini Smart Plug V2 has a buffer overflow vulnerability that can be leveraged for Remote Code Execution.
- This Week In Security: .zip Domains, Zip Scanning Hackaday
- Google pushes .zip and .mov domains onto the Internet, and the Internet pushes back Ars Technica
- Google released a .zip web domain and people can't decide if it's the phishing apocalypse or just as bad as any other dodgy link PC Gamer
- Google's new registered domains include .zip and .mov for a more "exciting" and insecure internet TechSpot
- Cybersecurity experts flag potential risks affecting new top-level domains SiliconANGLE News
Reading Insights
0
20
5 min
vs 6 min read
90%
1,039 → 107 words
Want the full story? Read the original article
Read on Hackaday