A bug left your Microsoft account wide open to complete takeover

TwitterFacebook

Bug bounty hunter Sahad Nk recently uncovered a series of vulnerabilities that left Microsoft users’ accounts — from your Office documents to your Outlook emails — susceptible to hacking.

While working as a security researcher with cybersecurity site SafetyDetective, Nk discovered that he was able to take over the Microsoft subdomain, http://success.office.com, because it wasn’t properly configured. This allowed the bug hunter to set up an Azure web app that pointed to the domain’s CNAME record, which maps domain aliases and subdomains to the main domain. By doing this, Nk not only takes control of the subdomain, but also receives any and all data sent to it. Read more…

More about Microsoft, Hacking, Office, Bugs, and Vulnerability

View More A bug left your Microsoft account wide open to complete takeover

Apple admits people weren’t hallucinating ‘Beautygate’

TwitterFacebook

Beauty is in the eye of the iPhone beholder.

Apple is fixing a bug in its smart front camera system that made for unnaturally filtered-looking selfies. Apple confirmed to The Verge that the phenomenon some iPhone users dubbed “Beautygate” was indeed a thing, and not the imagination of paranoid selfie-takers.

New Apple ‘Beautygate’ Controversy Claims iPhone XS Makes Selfies Look Too Good #applenews https://t.co/PlaPrJJKUN pic.twitter.com/aJxAt5w6qS

— iDrop News (@iDropNews) September 28, 2018

Beautygate was not the work of a filter. Apparently, the dynamic camera system was using a less detailed base frame for its composite images. That loss of detail is what gave the appearance of a smoothing filter. Read more…

More about Selfies, Bugs, Iphone Xs, Iphone Xs Max, and Tech

View More Apple admits people weren’t hallucinating ‘Beautygate’

Facebook expands bug bounty program to include third-party apps and websites

Facebook announced this morning it’s expanding its bug bounty program – which pays researchers who find security vulnerabilities within its platform – to now include issues found in third-party apps and websites. Specifically, Facebook says it will reward valid reports of vulnerabilities that relate to the improper exposure of Facebook user access tokens. Typically, when […]

View More Facebook expands bug bounty program to include third-party apps and websites

Take a blissful news vacation by visiting Facebook’s empty ‘Trending News’ tab

Pustulous Twitter politicking got you down? Look no further for a sweet escape from the 2018 news-hellscape, my friends, than Facebook’s Trending News tab.
What?! IN the news tab, you say? Isn’t that where click-hungry press organizations and ill-inf…

View More Take a blissful news vacation by visiting Facebook’s empty ‘Trending News’ tab

Facebook mistakenly switched 14 million people’s post settings to public because… oops!

Welp, Facebook screwed us again.
The advertising giant wants you to believe that you’re in control of what data you share, and who you share it with. We know that’s mostly an illusion built upon conflating the photos you upload with the information t…

View More Facebook mistakenly switched 14 million people’s post settings to public because… oops!

Download Apple’s update to protect your iPhone from the Telugu bug

TwitterFacebook

Apple issued a fix to the bug that was crashing iPhones with a single character. 

On Monday, the company released several updates, including iOS 11.2.6. If you’ve got an iPhone or iPad, you should probably download it ASAP.

Last week, a bug was discovered that crashed systems with a single character from the Telugu language, which is used in parts of India. Mashable tested the bug and found that, yes, it was a real problem

PSA: Go download iOS 11.2.6 NOW. Do it now to prevent someone from crashing your iPhone pic.twitter.com/wuOqV8NwOa

— (っ◔◡◔)っ Raymond Wong📱💾📼 (@raywongy) February 20, 2018 Read more…

More about Apple, Iphone, Ios, Bugs, and Ios 11

View More Download Apple’s update to protect your iPhone from the Telugu bug

Unlucky sister faces our biggest fear when a roach lands on her mouth

TwitterFacebook

Prepare yourself. This Snap may be your worst nightmare. 

Chloé (@clodeineee) posted a tweet of her sister’s Snapchat video with her singing and using one of their many filters, when a HUGE roach flew on her face. The three-second video was a horror movie in the making.

Goodbye world, please burn this footage and all of the evidence of the roach.

My sister was tryna make a Snapchat video and a fucking roach flew on her face I’m fucking dead lmaoooooo pic.twitter.com/YW1dTJypKA

— Chloé🌻 (@clodeineee) January 18, 2018 Read more…

More about Culture, Web Culture, Bugs, Snapchat Stories, and Roaches

View More Unlucky sister faces our biggest fear when a roach lands on her mouth

How to protect yourself from the massive macOS High Sierra security vulnerability

TwitterFacebook

So your macOS High Sierra-running machine is vulnerable to hackers. Like, really vulnerable. 

Thankfully, there’s a simple way to protect yourself — so long as you can follow a seven-step process laid out Tuesday by Apple. 

News broke Nov. 28 on Twitter that an attacker could gain root-user access to an unlocked computer simply by typing “root” into the “User Name” field, leaving the password field blank, and hitting “enter” while in the “Users & Groups” section of “System Preferences.”

You can access it via System Preferences>Users & Groups>Click the lock to make changes. Then use “root” with no password. And try it for several times. Result is unbelievable! pic.twitter.com/m11qrEvECs

— Lemi Orhan Ergin (@lemiorhan) November 28, 2017 Read more…

More about Apple, Hackers, Hacking, Macos, and Bugs

View More How to protect yourself from the massive macOS High Sierra security vulnerability