Tag

Security

All articles tagged with #security

Netanyahu alleges Iran plotted to kill one of his sons amid renewed Iran confrontation
world5 hours ago

Netanyahu alleges Iran plotted to kill one of his sons amid renewed Iran confrontation

Israeli Prime Minister Benjamin Netanyahu alleged that Iran tried to murder one of his sons, offering no details on timing or which son, as the US-Israel campaign against Iran intensifies after a strike on Tehran that killed the Iranian supreme leader and several relatives; Netanyahu also urged around-the-clock protection for rival candidate Gadi Eisenkot amid election pressure.

Brits Backlash Over Public Security Funds for Harry and Meghan, Poll Finds
politics11 hours ago

Brits Backlash Over Public Security Funds for Harry and Meghan, Poll Finds

A Mail on Sunday poll shows Brits oppose taxpayer-funded security for Prince Harry and Meghan Markle, with 68% saying they should pay for their own protection and only 27% approving their return; 16% want them as working royals, 22% say the homecoming will weaken the monarchy, 8% say it would strengthen it, and 43% say Harry and Meghan should apologize for implying racism in the royal family.

CISA orders rapid patch for actively exploited Zimbra flaw
security17 hours ago

CISA orders rapid patch for actively exploited Zimbra flaw

CISA has ordered U.S. federal agencies to patch CVE-2026-73570 in Zimbra Collaboration Suite within three days after the flaw was actively exploited, enabling unauthenticated remote code execution via a SNMP command-injection vulnerability when SNMP notifications are enabled. Zimbra patched the vulnerability in version 10.1.20 (July 20). CERT Polska flagged exploitation in the wild; Shadowserver reports thousands of exposed Zimbra servers and hundreds of compromised instances. Authorities urge checking logs for suspicious activity and for files created by the zimbra user in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps, and /tmp over the past month. Given ZCS’s widespread use, governments and businesses remain at risk, with past campaigns tied to APT groups exploiting Zimbra flaws.

Teams introduces automatic blocking of external bots in meetings
technology21 hours ago

Teams introduces automatic blocking of external bots in meetings

Microsoft is rolling out a new Teams meeting protection policy that automatically blocks identified external bots from joining meetings, building on a June feature that tagged bots and required organizer approval. After activation in the Teams admin center under Manage bots, admins can assign the policy to specific users or groups; the setting is off by default and will be rolled out to general availability by late September following a targeted release through August. The change helps prevent third-party and potentially malicious bots from joining meetings without attendees’ knowledge and complements other security measures, with Microsoft planning additional admin controls like bot allow lists and audit logs.

Keycloak Password-Reset Flaw Enables Unauthenticated Account Takeover
security22 hours ago

Keycloak Password-Reset Flaw Enables Unauthenticated Account Takeover

Red Hat and Keycloak patched a critical vulnerability (CVE-2026-18963) in the reset-credentials flow that allowed an unauthenticated attacker to bypass email verification and reset any user’s password, potentially taking over accounts including admins. Upstream Keycloak is fixed in 26.7.2; Red Hat builds require 26.4.15/26.6.6 updates. As a temporary mitigation, disable the forgot-password feature across all realms; no public exploit evidence has been found yet.

Old tech, a quiet shield: why aging tools can beat modern hackers
technology22 hours ago

Old tech, a quiet shield: why aging tools can beat modern hackers

Some security experts argue that older technologies can be safer in certain situations because attackers chase the latest, most widely used targets. The idea, called “security by antiquity,” is illustrated by Mikko Hyppönen’s use of the Eudora email client, honeypot experiments that attract fewer attacks on older software, and the continued use of legacy navigation beacons and magnetic tape backups to resist modern threats like GPS jamming and ransomware. While keeping software updated remains best practice, these examples show that analogue or legacy tech can offer resilience in specific contexts and critical infrastructure.

Iranian State TV airs alleged $10M bounty on Barron Trump
world23 hours ago

Iranian State TV airs alleged $10M bounty on Barron Trump

Iranian state television aired a video claiming to track Barron Trump and alleging a $10 million bounty on him, including supposed details of his university and Secret Service protection; the claims could not be independently verified. The broadcast mirrors prior Iranian state-media provocations and comes amid ongoing tensions with the US, with the US Secret Service said to be reviewing the footage.

Silent Web Audio Fingerprinting Sparks Privacy Debate on AliExpress
technology1 day ago

Silent Web Audio Fingerprinting Sparks Privacy Debate on AliExpress

Researchers found a zero-volume Web Audio API script on AliExpress that taps the computer's audio hardware to generate a device fingerprint without cookies, collecting a range of signals and raising privacy concerns. Brave has blocked the script and warned fingerprinting will keep evolving, while other blockers may mitigate it at the cost of some site functionality, and the technique could even interfere with hardware like Bluetooth headphones.

Microsoft patches critical flaws across Entra ID, Arc, and Exchange Online that could enable remote code execution
security2 days ago

Microsoft patches critical flaws across Entra ID, Arc, and Exchange Online that could enable remote code execution

Microsoft has patched multiple maximum-severity vulnerabilities in Entra ID, Azure Arc, and Exchange Online that could let attackers with no privileges execute code remotely and escalate privileges. Key flaws include CVE-2026-69836 in Entra ID (deserialization of untrusted data), CVE-2026-65816 and CVE-2026-69555 in Azure Arc, CVE-2026-65801 in Exchange Online, and CVE-2026-65770 affecting an Azure Managed Instance for Apache Cassandra. Patches are in place and no action is required, with exploit code not publicly available. An August update notes CVE-2026-69836 was initially misflagged as exploited in the wild.

GrapheneOS gears up for high-end Motorola flagships priced above Pixels
news3 days ago

GrapheneOS gears up for high-end Motorola flagships priced above Pixels

GrapheneOS says its first Motorola devices will be high-end flagships arriving in 2027 and will cost more than Pixel phones; cheaper Motorola models will follow later as Qualcomm's lower-end chipsets currently lack the same level of security and long-term software support. GrapheneOS plans to host its own AOSP repositories and align updates with major Android releases, expanding beyond Pixel phones.