Fortnite bugs put accounts at risk of takeover

With one click, any semi-skilled hacker could have silently taken over a Fortnite account, according to a cybersecurity firm who says the bug is now fixed. Researchers at Check Point say the three vulnerabilities chained together could have affected any of its 200 million players. The flaws, if exploited, would have stolen the account access token […]

View More Fortnite bugs put accounts at risk of takeover

Another huge database exposed millions of call logs and SMS text messages

An unprotected server storing millions of call logs and text messages was left open for months before they were found by a security researcher. If you thought you’d heard this story before, you’re not wrong. Back in November, another telecoms company Voxox exposed a database containing millions of text messages — including password resets and two-factor […]

View More Another huge database exposed millions of call logs and SMS text messages

Another server security lapse at NASA exposed staff and project data

Two months ago, NASA quietly fixed a buggy internal server that was leaking sensitive information about the agency’s staff and their work. The leaking server was — ironically — a bug reporting server, running the popular Jira bug triaging and tracking software. In NASA’s case, the software wasn’t properly configured, allowing anyone to access the […]

View More Another server security lapse at NASA exposed staff and project data

An unsecured database exposed the personal details of 202M job seekers in China

The personal details belonging to more than 202 million job seekers in China, including information like phone numbers, email addresses, driver licenses and salary expectations, were freely available to anyone who knew where to look for as long as three years due to an insecure database. That’s according to findings published by security researcher Bob Diachenko […]

View More An unsecured database exposed the personal details of 202M job seekers in China

Two-factor authentication can save you from hackers

If you find passwords annoying, you might not like two-factor authentication much. But security experts say it’s one of the best ways to protect your online accounts. Simply put, two-factor authentication adds a second step in your usual log-in process. Once you enter your username and password, you’ll be prompted to enter a code sent […]

View More Two-factor authentication can save you from hackers

At Blind, a security lapse revealed private complaints from Silicon Valley employees

Thousands of people trusted Blind, an app-based “anonymous social network,” as a safe way to reveal malfeasance, wrongdoing and improper conduct at their companies. But Blind left one of its database servers exposed without a password, making it possible for anyone who knew where to look to access each user’s account information and identify would-be […]

View More At Blind, a security lapse revealed private complaints from Silicon Valley employees

‘Donald’ debuts at No. 23 on worst passwords of 2018 list

Almost 10 percent of people on the interwebs used at least one of the 25 worst passwords on SplashData’s annual list, which was released this week. And nearly three percent of you are still using “123456,” the worst password of the entire ranking. The eighth annual list of worst passwords of the year is based […]

View More ‘Donald’ debuts at No. 23 on worst passwords of 2018 list

Want to reduce fraud? Make a better password, dummy!

Researchers at Indiana University have confirmed that stringent password policies – aside from being really annoying – actually work. The research, led by Ph.D. student Jacob Abbott, IU CIO Daniel Calarco, and professor L. Jean Camp. They published their findings in a paper entitled “Factors Influencing Password Reuse: A Case Study.” “Our paper shows that […]

View More Want to reduce fraud? Make a better password, dummy!

California passes law that bans default passwords in connected devices

Good news! California has passed a law banning default passwords like “admin,” “123456” and the old classic “password” in all new consumer electronics starting in 2020. Every new gadget built in the state from routers to smart home tech will have to come with “reasonable” security features out of the box. The law specifically calls […]

View More California passes law that bans default passwords in connected devices

UK phone giant EE hit by another security lapse

For the second time this week, U.K. phone giant EE has fixed a security lapse, which allowed a security researcher to gain access to an internal site. The researcher, who goes by the pseudonym Six, found the company’s internal training site indexed on Google. (We’re not linking to the page as it remains an active […]

View More UK phone giant EE hit by another security lapse