Secure by Design Alert Eliminating SQL Injection Vulnerabilities in Software

SQL injection – or SQLi – vulnerabilities remain a persistent class of defect in commercial software products. Despite widespread knowledge and documentation of SQLi vulnerabilities over the past two decades, along with the availability of effective mitigations, software manufacturers have Read More …

New Golang Trojan Installs Certificate for Comms Evasion

This week, the Sonicwall Capture Labs threat research team analyzed a new Golang malware sample. It uses multiple geographic checks and publicly available packages to screenshot the system before installing a root certificate to the Windows registry for HTTPS communications Read More …

Chinese hackers targeted UK’s Electoral Commission and politicians, say security services

Chinese state-backed hackers were responsible for two “malicious” digital campaigns targeting the UK’s democratic institutions and politicians, the security services have found. The UK holds China responsible for a prolonged cyber-attack on the Electoral Commission during which Beijing allegedly accessed Read More …

High Court order will deliver ‘swift management’ of compensation claims by those affected by PSNI data breach

Claims by officers and civilian staff following a major PSNI data breach will be managed in a “swift” manner following a High Court order being granted, it has been suggested. Following the granting of a Group Litigation Order (GLO), thousands Read More …

APT29 Uses WINELOADER to Target German Political Parties

In late February 2024, Mandiant identified APT29 — a Russian Federation backed threat group linked by multiple governments to Russia’s Foreign Intelligence Service (SVR) — conducting a phishing campaign targeting German political parties. Consistent with APT29 operations extending back to Read More …

Air Europa says customer data may have been compromised in October breach

Spanish airline Air Europa said on Friday personal data of its customers may have been compromised in a security incident that was detected in October last year. The company’s investigation showed that name, ID card or passport details, date of Read More …

UK: ‘Mass surveillance’ fears over law change plans

The UK tech industry has deep concerns over government plans to amend a law dubbed a “snooper’s charter”. Ministers insist their changes to the Investigatory Powers Act is intended to keep UK citizens safe. But, in a statement, trade body techUK Read More …

UN General Assembly adopts landmark resolution on artificial intelligence

The UN General Assembly on Thursday adopted a landmark resolution on the promotion of “safe, secure and trustworthy” artificial intelligence (AI) systems that will also benefit sustainable development for all. The Assembly called on all Member States and stakeholders “to Read More …

Unpatchable vulnerability in Apple chip leaks secret encryption keys

A newly discovered vulnerability baked into Apple’s M-series of chips allows attackers to extract secret keys from Macs when they perform widely used cryptographic operations, academic researchers have revealed in a paper published Thursday. The flaw—a side channel allowing end-to-end Read More …