Showing only posts by Gareth Halfacree. Show all posts.

Enterprise password management outfit Passwordstate patches Emergency Access bug

Source

Up to 29,000 organizations and potentially 370,000 security and IT pros affected Australian development house Click Studios has warned users of its Passwordstate enterprise password management platform to update immediately if not sooner, following the discovery of an authentication bypass vulnerability that opens the doors to an …

Boffins say tool can sniff 5G traffic, launch 'attacks' without using rogue base stations

Source

Sni5Gect research crew targets sweet spot during device / network handshake pause Security boffins have released an open source tool for poking holes in 5G mobile networks, claiming it can do up- and downlink sniffing and a novel connection downgrade attack - plus "other serious exploits" they're keeping under wraps, for …

Secure chat darling Matrix admits pair of 'high severity' protocol flaws need painful fixes

Source

Foundation warns federated servers face biggest risk, but single-instance users can take their time Updated The maintainers of the federated secure chat protocol Matrix are warning users of a pair of "high severity protocol vulnerabilities," addressed in the latest version, saying patching them requires a breaking change in servers …