“On Friday (5 April), it emerged that home routers such as those manufactured by D-Link were being targeted by DNS hijacking. Security researchers at Bad Packets identified three waves which took place between December last year and the end of March this year, detailed in a blog.”
Gmail, Netflix and PayPal Users Targeted In DNS Hijacking Campaign
“On Friday (5 April), it emerged that home routers such as those manufactured by D-Link were being targeted by DNS hijacking. Security researchers at Bad Packets identified three waves which took place between December last year and the end of March this year, detailed in a blog.”
Ongoing DNS hijacking campaign targeting consumer routers
“Over the last three months, our honeypots have detected DNS hijacking attacks targeting various types of consumer routers. All exploit attempts have originated from hosts on the network of Google Cloud Platform (AS15169).”
‘Biggest breach recorded’: 982 MILLION people’s personal information exposed
“Email addresses from 982 million people were listed in what researchers are calling one of the ‘biggest and most comprehensive email database’ ever recorded. Personal information including names, gender, date of birth, address, employer and details of social media accounts were also listed.”
Researchers find 36 new security flaws in LTE protocol
“The vulnerabilities allow attackers to disrupt mobile base stations, block incoming calls to a device, disconnect users from a mobile network, send spoofed SMS messages, and eavesdrop and manipulate user data traffic.”
BitLocker hacked? Disk encryption – and why you still need it [VIDEO]
“That has led to us getting asked, “Is BitLocker cracked? Is disk encryption still worth it?” The answers are “No” and “Yes”, and this week’s Naked Security Live video explains why.”
Hackers using fake ‘Flash Player’ Google Chrome extension to steal credit card data
“Cybersecurity researchers are warning unsuspecting internet users about a year-old Chrome extension which steals credit card data from infected users via web forms on visited websites. The surreptitious extension is spread by means of JavaScript injection attacks i.e.”
Hackers using fake ‘Flash Player’ Google Chrome extension to steal credit card data
“Cybersecurity researchers are warning unsuspecting internet users about a year-old Chrome extension which steals credit card data from infected users via web forms on visited websites. The surreptitious extension is spread by means of JavaScript injection attacks i.e.”
Performance of Iodine over DNS-over-HTTPS
“Iodine is a DNS-tunnel that can be used to send TCP traffic encapsulated in DNS queries. Sometimes, this helps to bypass captive portals or otherwise restricted networks. In this blogpost I’ll test the performance of using Iodine in combination with DoH (DNS-over-HTTPS).”
Google helps make the password obsolete w/ FIDO2 support on Android, rolling out now
“Android Now FIDO2 Certified, Accelerating Global Migration Beyond Passwords Mobile apps and websites can now leverage FIDO standards to provide a simpler and secure biometric login for users on over a billion devices supporting Android 7.0+ BARCELONA, Spain, Feb.”