Showing only posts by Thomas Claburn. Show all posts.

Story of the creds-leaking Exchange Autodiscover flaw – the one Microsoft wouldn't fix even after 5 years

Source

Redmond reckoned protocol weakness is not a security vulnerability Microsoft Exchange clients like Outlook have been supplying unprotected user credentials if you ask in a particular way since at least 2016. Though aware of this, Microsoft's advice continues to be that customers should communicate only with servers they trust …

Suex to be you: Feds sanction cryptocurrency exchange for handling payments from 8+ ransomware variants

Source

Russia-based biz targeted in Uncle Sam's crack down on cyber-extortion The US Treasury on Tuesday sanctioned virtual cryptocurrency exchange Suex OTC for handling financial transactions for ransomware operators, an intervention that's part of a broad US government effort to disrupt online extortion and related cyber-crime.... [...]

Can WhatsApp moderators really read your encrypted texts? Yes ... if you forward them to the abuse dept

Source

Where did people think spam and harassment reports were going? Facebook's WhatsApp states its messages are protected by the Signal encryption protocol. A report published today by investigative non-profit ProPublica contends that WhatsApp communication is less private than users understand or expect.... [...]

38 million records exposed by misconfigured Microsoft Power Apps. Redmond's advice? RTFM

Source

Low-code platform comes with high expectations that folks understand security Forty-seven government entities and privacy companies, including Microsoft, exposed 38 million sensitive data records online by misconfiguring the Windows giant's Power Apps, a low-code service that promises an easy way to build professional applications.... [...]

« newer articles | page 14 | older articles »