Posts From CCME

While around a third of 18-year-olds have been accepted for a university place through UCAS, new opportunities have been opened for cybersecurity experience. Although statistics from UCAS show that 28.5% of the 18-year-old population have been accepted through UCAS, with

Hackers claim to have stolen 700,000 customer records from Choice Hotels thanks to an exposed MongoDB instance, it has emerged. The US-based chain, which runs franchised outlets in over 40 countries worldwide, is now being held to ransom after the

Security researchers discovered the biggest data breach in Biometric Security Platform BioStar 2 that leaks millions of users facial recognition records, fingerprints, log data, and other personal information. BioStar 2, a web-based biometric security smart lock platform by world’s biggest

Researchers discovered a severe privilege escalation vulnerability in Bluetooth let unauthenticated attackers intercept and monitor the encryption traffic between two paired devices. The bug discovered in Bluetooth BR/EDR encryption connection, in which an attacker reduces the encryption key length and

Apparently financially-motivated threat actors carried out a long-term campaign against the Balkans involving a backdoor and a RAT to compromise the targets. Security experts from ESET uncovered a long-running campaign carried out by a financially-motivated threat actor. The attackers combined

Cloud-based back-end services are letting mobile app developers down, according to research announced this week. Even when app developers are careful about their own code, the online services that they use introduce vulnerabilities on a regular basis. The research, from

Anti-malware company Trend Micro has patched a flaw in its password manager that could have enabled an attacker to run their own code on a user’s computer with the highest possible access privileges. Available for the iOS, Android, Windows and

A biometric building access system used by thousands of companies around the world has exposed 23 gigabytes of data, representing over 27.8 million records, researchers revealed today. The BioStar 2 product, used by such organizations as the UK Metropolitan Police,

SAP Patches Highest Number of Critical Flaws Since 2014 SAP released Security Patch Day updates for August 2019 that address three critical vulnerabilities in the company’s products. SAP has released the Security Patch Day for August, this month the company

Researchers discovered a new Android malware “Cerberus” that is being rented (Malware-as-a-service) on underground forums for the last two year and the malware used for various private operation. Unlike other banking trojans such as Anubis that derives the code from

Microsoft has patched 93 unique CVEs this month, and although there are no zero-days or publicly disclosed flaws, there’s plenty to keep sysadmins busy, according to experts. Top of the list are two wormable RDP flaws CVE-2019-1181/1182) similar to the

British Airways has come under fire from the security community again, this time after a vulnerability in its e-ticketing system was found to be exposing passenger’s personal information (PII). Security firm Wandera claimed in a blog post yesterday that the

The UK’s financial regulator has agreed to give the country’s payments and e-commerce providers more time to comply with new user authentication rules mandated by PSD2. The Financial Conduct Authority (FCA) said yesterday that it would provide card issuers, payments

Microsoft released new security updates under Patch Tuesday for August and fixed more than 90 vulnerabilities including 2 Bluekep based “wormable “remote code execution vulnerabilities that reside in the windows remote desktop services. Same as Bluekeep RDP flaw, newly discovered

Canada has launched a cybersecurity certification program to try and get small to midsize enterprises (SMEs) up to speed with a basic level of protection. Launched at the University of New Brunswick’s Canadian Institute for Cybersecurity by Minister of Finance

Just as exploits for Microsoft’s BlueKeep bug make it into the wild, the company has announced another set of vulnerabilities in Windows that is equally dangerous – and this time, it also affects Windows 10 systems. Microsoft announced the bugs,