Facebook Stops Facial Recognition and Deletes Billions of Records

Meta, facebook’s newly rebranded parent company on Tuesday announced plans to stop its decade-old “Face Recognition” system and would also delete more than a billion users’ facial recognition templates as part of a wider initiative to limit the use of the technology across its products. This shutdown would take effect over the coming weeks and […]

Facebook Stops Facial Recognition and Deletes Billions of Records Read More »

Google Releases Patches for a New Android 0-Day Vulnerability

Monthly security patches have been released by Google for Android, fixing 39 flaws inclusive of a zero-day vulnerability which is actively being exploited in the wild in limited targeted attacks. The zero-day bug tracked as CVE-2021-1048 is described as a use-after-free vulnerability in the kernel which could be exploited for local privilege escalation. Use-after-free could

Google Releases Patches for a New Android 0-Day Vulnerability Read More »

Chinese Payment-Terminal Company Raided By The FBI

In furtherance of a federal investigation the FBI has searched the Florida premises of a Chinese payment-terminal provider. This comprised of the warehouse and offices belonging to Pax Technology. Pax was founded two decades ago and is headquartered in Shenzhen. According to its website, the company has delivered over 57 million terminals to more than

Chinese Payment-Terminal Company Raided By The FBI Read More »

Trojan Source: A New Technique Allowing Hackers Hide Vulnerabilities in Source Code

Dubbed “Trojan Source attacks,” the technique “exploits subtleties in text-encoding standards such as Unicode to produce source code whose tokens are logically encoded in a different order from the one in which they are displayed, which eventually leads to a vulnerability which could not have been perceived by direct human code review. The vulnerability affects

Trojan Source: A New Technique Allowing Hackers Hide Vulnerabilities in Source Code Read More »

Millions of Android Users are Currently Targets of Premium Scam Apps

Attackers are leveraging on 151 malicious Android apps with 10.5 million downloads in order to rope users into premium subscription service without consent and knowledge. This attack has been dubbed “UltimaSMS” and is believed to have commenced in May 2021. This attacker took advantage of apps covering wide range of categories including keyboards, QR code

Millions of Android Users are Currently Targets of Premium Scam Apps Read More »

Google Releases Emergency Update Patching Exploited Bugs

An emergency update for Chrome web browser fixing two zero-day vulnerabilities has been released. The vulnerability is tracked as CVE-2021-38000 and CVE-2021-38003 and relates to insufficient validaton of untrusted input in a feature called Intents and inappropriate implentation in V8 JavaScript and WebAssembly engine. This flaw was discovered and reported by Threat Analysis Group (TAG)

Google Releases Emergency Update Patching Exploited Bugs Read More »

Microsoft Cautions on TodayZoo Phishing Kit Used in Credential Stealing Attacks

An extensive series of credential phishing campaigns has been discovered and disclosed by Microsoft on Thursday. This campaign is taking advantage of custom phishing kit that stitched together components from at least five different circulated ones with the aim of siphoning user login information. This discovery was first made in December 2020 and dubbed the

Microsoft Cautions on TodayZoo Phishing Kit Used in Credential Stealing Attacks Read More »