Cyber security aggregate rss news

Cyber security aggregator - feeds history

image for iOS prompts: "Allow  ...

 Privacy

So, you’ve downloaded the latest Candy Ninja: Battle Royale to while away a couple of hours on your iPhone or iPad, but the first thing you see when you open the app is a prompt: “Allow “Candy Ninja” to track your activity across other companies’ apps and websites?” What exactly   show more ...

does that mean? What’s the risk? What are the benefits? And why didn’t your friend get that notification on their iPhone? What is App Tracking Transparency? Apple is always saying how much it values user privacy and data confidentiality. Within that paradigm, in January 2021, the developers of iOS, iPadOS, and tvOS promised that version 14.5 and later of these systems would support App Tracking Transparency. For users, that means any app that uses device identifiers for advertising purposes, which Apple calls identifiers for advertisers (IDFA), must clearly explain why it does so and explicitly ask the user’s permission. That permission request looks like this: Tracking requests in iOS 14.5: “Allow App to track your activity across other companies’ apps and websites?” According to Apple, the request should clarify the relationship between app developers and device owners. If a hypothetical flashlight app or social network client collects information about your actions and passes it on to advertisers, allowing them to link it to you, you should not only know, but also be able to opt out. Opting out does not affect app performance, so there’s no downside in rejecting tracking requests. On the other hand, even if tracking is disabled, you’ll still see ads; they just won’t be personalized. Responding to app tracking requests in iOS, iPadOS, and tvOS To stop advertising networks from tracking you through iOS, iPadOS, or tvOS apps, select the Ask App Not to Track option each time you see the prompt. If for some reason you prefer personalized ads or want to support developers in that way, choose Allow. Getting rid of app tracking requests altogether If you don’t want to be bothered by tracking requests, you can turn them off completely. That is, opt out of tracking in all apps once and for all. It’s easy to do: Go to open Settings; Scroll down to Privacy; Open Tracking; Switch off the Allow Apps to Request to Track toggle. Why don’t I see tracking requests on my Apple devices? IDFA used to be handled under Apple Advertising -> Personalized Ads, which can still be found in the iOS privacy settings. If you turned off personalized ads at some point, Allow Apps to Request to Track was set to off by default. If you’re not seeing tracking requests, that’s probably why. Apple versus targeting Advertisers lie awake at night worrying about users turning off tracking. Some developers, such as those on Snapchat’s team, are already working on ways to get around App Tracking Transparency, which in theory would allow them to keep profiling devices and their owners. The changes are good for users, who can choose, among other things, whether to share private details and with whom. Another positive sign for consumers: The more platforms fret about data protection, the less likely our digital fingerprints are to fall into the wrong hands (no pun intended). For non-Apple users who don’t like nosy apps, we offer more options for safeguarding your online privacy.

 Companies to Watch

Tenable Holdings has completed its acquisition of Active Directory security startup Alsid SAS. The deal, first announced in February, was officially closed on April 26 with a cash payment of $98m.

 Threat Actors

In March, threat intelligence experts warned of a new version of the ransomware that featured a faster encryption process, VoIP calling, and modules to target virtual machines.

 Feed

This Metasploit module abuses a known default password on Micro Focus Operations Bridge Reporter. The shrboadmin user, installed by default by the product has the password of shrboadmin, and allows an attacker to login to the server via SSH. This module has been tested with Micro Focus Operations Bridge Manager 10.40.   show more ...

Earlier versions are most likely affected too. Note that this is only exploitable in Linux installations.

 Feed

Ubuntu Security Notice 4930-1 - Peter Eriksson discovered that Samba incorrectly handled certain negative idmap cache entries. This issue could result in certain users gaining unauthorized access to files, contrary to expected behaviour.

 Feed

Red Hat Security Advisory 2021-1469-01 - The Berkeley Internet Name Domain is an implementation of the Domain Name System protocols. BIND includes a DNS server ; a resolver library ; and tools for verifying that the DNS server is operating correctly.

 Feed

Microsoft researchers on Thursday disclosed two dozen vulnerabilities affecting a wide range of Internet of Things (IoT) and Operational Technology (OT) devices used in industrial, medical, and enterprise networks that could be abused by adversaries to execute arbitrary code and even cause critical systems to crash. "These remote code execution (RCE) vulnerabilities cover more than 25 CVEs and

 Feed

Perhaps due to the nature of the position, the InfoSec leadership roles tend to be solitary ones. CISOs, or their equivalent decision-makers in organizations without the role, have so many constant drains on their attention – keeping their knowledge fresh, building plans to secure their organizations further – that they often find themselves on an island. It’s even more challenging for

 Feed

Click Studios, the Australian software firm which confirmed a supply chain attack affecting its Passwordstate password management application, has warned customers of an ongoing phishing attack by an unknown threat actor. "We have been advised a bad actor has commenced a phishing attack with a small number of customers having received emails requesting urgent action," the company said in an

 Feed

An "aggressive" financially motivated threat group tapped into a zero-day flaw in SonicWall VPN appliances prior to it being patched by the company to deploy a new strain of ransomware called FIVEHANDS. The group, tracked by cybersecurity firm Mandiant as UNC2447, took advantage of an "improper SQL command neutralization" flaw in the SSL-VPN SMA100 product (CVE-2021-20016, CVSS score 9.8) that

2021-04
Aggregator history
Friday, April 30
THU
FRI
SAT
SUN
MON
TUE
WED
AprilMayJune