Researchers found a security flaw in OneDrive File Picker that grants apps access to any and all files in the account when the user grants permission for just one file upload, with the language governing this process cited as too "vague" and "unclear" to communicate what is actually happening.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
A security flaw in Titan, Microsoft’s analytics platform, could have enabled a 16-year-old researcher to access over 17 trillion records after gaining access to 17 databases.
Reported security risks in U.S. online voting system OmniBallot have added to the mounting concern over vote manipulation during 2020 US presidential election.
When athletes arrive at the 2022 Winter Olympics they will be required to download an app called MY2022. Meant for contact tracing purposes, it will be packed with some unexpected extras: security flaws and possible censorship features.
Rapidly evolving botnet Dark Nexus is threatening IoT security as the dependency on connected devices grows with remote working during COVID-19 pandemic.
As the IoT revolution brings changes to society, it is introducing new classes of risk requiring IoT security to adapt to the changing threat landscape.
Financial institutions are 300 times as likely as other companies to be targeted by a cyberattack. Unfortunately, the systems designed to help (such as alerting or security monitoring tools) can overwhelm a bank’s IT department.
Second largest data leak in history exposed First American’s 900 million customer information just by raising or lowering a single digit in the document URL.
Study on security priorities found that 90% of IT and security decision-makers believed their organizations failed to address cybersecurity risks.
A new report finds that security professionals are receptive to the idea of more regulation by the federal government in the interest of improving cyber defenses. 99% feel that federal agencies are not doing enough to protect their own data and systems.










