Critical Flaws in PGP and S/MIME Tools Can Reveal Encrypted Emails in Plaintext

An important warning for people using widely used email encryption tools—PGP and S/MIME—for sensitive communication. A team of European security researchers has released a warning about a set of critical vulnerabilities discovered in PGP and S/Mime encryption tools that could Read More …

Tools like Palantir illustrate how easily big data can be misused

Data privacy has become a topic of critical concern among tech and business leaders, following revelations that Cambridge Analytica harvested the data of some 87 million Facebook users to build targeted political content. However, Cambridge Analytica is only one of perhaps many Read More …

Critical Code Execution Flaw Found in CyberArk Enterprise Password Vault

A critical remote code execution vulnerability has been discovered in CyberArk Enterprise Password Vault application that could allow an attacker to gain unauthorized access to the system with the privileges of the web application. Enterprise password manager (EPV) solutions help organizations securely manage Read More …

New MacOS Backdoor Linked to OceanLotus Found

We identified a MacOS backdoor (detected by Trend Micro as  OSX_OCEANLOTUS.D) that we believe is the latest version of a threat used by OceanLotus (a.k.a. APT 32, APT-C-00, SeaLotus, and Cobalt Kitty). OceanLotus was responsible for launching targeted attacks against human rights organizations, media Read More …

FBI: Iranian Firm Stole Data In Massive Spear Phishing Campaign

The United States Department of Justice announced charges against nine Iranians accused of stealing private data from U.S. universities, private companies and U.S. government agencies. FBI Deputy Director David Bowdich said in a statement that the state-sponsored hackers worked for more than Read More …