Software bugs put nearly 100 million health records at risk of exposure

The slew of vulnerabilities – since patched – were found without the use of automated testing tools. A team of seven researchers has discovered more than 20 security vulnerabilities in OpenEMR, an open-sourceapplication used worldwide for the electronic management of the medical records of almost 100 million people. In keeping with the principles of responsible disclosure, … More Software bugs put nearly 100 million health records at risk of exposure

Fake banking apps on Google Play leak stolen credit card data

Fraudsters are using bogus apps to convince users of three Indian banks to divulge their personal data. Another set of fake banking apps has found its way into the official Google Play store. Claiming to increase the credit card limit for users of three Indian banks, the malicious apps phish for credit card details and … More Fake banking apps on Google Play leak stolen credit card data

Bluetooth bug could expose devices to snoopers

Patches have already been released or are expected to see the light of day soon. Researchers have discovered a flaw in some Bluetooth implementations that could allow an attacker to intercept or tamper with data exchanged between two vulnerable devices. The cryptographic bug, tracked as CVE-2018-5383, has been identified by scientists at the Israel Institute of … More Bluetooth bug could expose devices to snoopers

Facebook fined over data privacy scandal

Social media giant fined in the UK for failing to protect users’ personal information and for a lack of transparency. Facebook is facing its first possible financial penalty for its role in the Cambridge Analytica scandal that saw the personal data of millions of users harvested without their knowledge. The social media giant was hit with a … More Facebook fined over data privacy scandal

Certificates stolen from Taiwanese tech-companies misused in Plead malware campaign

D-Link and Changing Information Technologies code-signing certificates stolen and abused by highly skilled cyberespionage group focused on East Asia, particularly Taiwan. ESET researchers have discovered a new malware campaign misusing stolen digital certificates. We spotted this malware campaign when our systems marked several files as suspicious. Interestingly, the flagged files were digitally signed using a valid … More Certificates stolen from Taiwanese tech-companies misused in Plead malware campaign