Security researchers have discovered an arbitrary account takeover flaw in Subaru's Starlink service that could let attackers track, control, and hijack vehicles in the United States, Canada, and Japan using just a license plate.
Curry says Subaru patched the vulnerability within 24 hours of the researchers' report and was never exploited by an attacker.
A North Korean threat group has been using a technique called RID hijacking that tricks Windows into treating a low-privileged account as one with administrator permissions.
The CloudSEK researchers disrupted the botnet by utilizing hard-coded API tokens and a built-in kill switch to uninstall the malware from infected devices.
To safeguard against such attacks, it's advised to monitor suspicious processes, events, and network traffic spawned by the execution of any untrusted binary/scripts. It's also recommended to apply firmware updates and change the default username and password.
A malicious package named 'pycord-self' on the Python package index (PyPI) targets Discord developers to steal authentication tokens and plant a backdoor for remote control over the system.
New research has pulled back the curtain on a "deficiency" in Google's "Sign in with Google" authentication flow that exploits a quirk in domain ownership to gain access to sensitive data.
The ambitious final executive order requires 52 agency actions to bolster cyber protections and counter adversaries, including a new plan to address spiraling digital identity theft.
Link Actions
The ambitious final executive order requires 52 agency actions to bolster cyber protections and counter adversaries, including a new plan to address spiraling digital identity theft.
The documents provide never-been-seen insight into the current cat-and-mouse game between forensics companies and phone manufacturers Apple and Google.
The webpage discusses leaked documents revealing the capabilities of Graykey, a phone unlocking and forensics tool utilized by law enforcement globally. According to the documents obtained by 404 Media, Graykey can retrieve only partial data from modern iPhones running iOS 18 and iOS 18.0.1. There is no information on its functionality with the recently released iOS 18.1. This leak is significant for Grayshift, the company behind Graykey, especially since it has been acquired by Magnet Forensics, another player in the digital forensics field. Unlike its competitor Cellebrite, which has experienced similar leaks, this is the first detailed disclosure of the specific phones Graykey can and cannot access. The documents also provide insights into Graykey's capabilities with Android devices. Overall, this situation highlights the ongoing struggle between forensics tools and phone manufacturers like Apple and Google. The informati