2FA Bypass Discovered In Web Hosting Software cPanel

An anonymous reader quotes a report from ZDNet: Security researchers have discovered a major security flaw in cPanel, a popular software suite used by web hosting companies to manage websites for their customers. The bug, discovered by security researchers from Digital Defense, allows attackers to bypass two-factor authentication (2FA) for cPanel accounts. These accounts are used by website owners to access…

Walmart-exclusive Router and Others Sold on Amazon and eBay Contain Hidden Backdoors To Control Devices

Bernard Meyer, reporting for CyberNews: In a collaboration between CyberNews Sr. Information Security Researcher Mantas Sasnauskas and researchers James Clee and Roni Carta, suspicious backdoors have been discovered in a Chinese-made Jetstream router, sold exclusively at Walmart as their new line of “affordable” wifi routers. This backdoor would allow an attacker the ability to remotely control not only the routers, but…

Mass-Produced, Librem 5 Linux Smartphone Begins Shipping to Customers

This week Purism began shipping its mass-produced Librem 5 phone to customers, according to announcement from the company: The Librem 5 is a one-of-a-kind general-purpose computer in a phone form-factor that Purism has designed and built from scratch following a successful crowdfunding campaign that raised over $2.2 million. Both the hardware and software design is focused on respecting the end user’s…

How Powerful Forces Collaborated to Peddle Misinformation about the Origins of the Coronavirus

There’s “an overwhelming body of evidence” for scientists’ belief that the coronavirus originated in an animal before making the leap to humans, reports the New York Times. (Alternate URL here.) They add that U.S. intelligence agencies also “have not found any proof” for a fringe theory it somehow leaked from a lab. Yet as recently as September, a Hong Kong researcher…

How Firefox Boosted Its JavaScript Performance

InfoWorld reports:
Firefox users can expect improved JavaScript performance in the Firefox 83 browser, with the Warp update to the SpiderMonkey JavaScript engine enabled by default. Also called WarpBuilder, Warp improves responsiveness and memory usage and speeds up page loads by making changes to JiT (just-in-time) compilers… Warp has been shown to be faster than Ion, SpiderMonkey’s previous optimizing JiT, including a…

‘Extremely Aggressive’ Internet Censorship Spreads In the World’s Democracies

Researchers from the University of Michigan used their own automated censorship tracking system to collect more than 21 billion measurements over 20 months in 221 countries. They discovered that citizens in what are considered the world’s freest countries aren’t safe from internet censorship. From a press release: [Roya Ensafi, U-M assistant professor of electrical engineering and computer science who led the…

Chrome 87 Released With Fix for NAT Slipstream Attacks, Broader FTP Deprecation

Google has released today version 87 of its Chrome browser, a release that comes with a security fix for the NAT Slipstream attack technique and a broader deprecation of the FTP protocol. From a report: Todays’ release is available for Windows, Mac, Linux, Chrome OS, Android, and iOS. Users can update to the new version via Chrome’s built-in update utility. While…

Credit Card Numbers For Millions of Hotel Guests Exposed By Misconfigured Cloud Database

“A widely used hotel reservation platform has exposed 10 million files related to guests at various hotels around the world, thanks to a misconfigured Amazon Web Services S3 bucket,” reports Threatpost. “The records include sensitive data, including credit-card details.” Prestige Software’s “Cloud Hospitality” is used by hotels to integrate their reservation systems with online booking websites like Expedia and Booking.com. The…

Simple Search Is a Browser Extension That Gives You Google Circa 2010

A group of journalists has built a browser extension, called Simple Search, to show you what Google search would look like without the information panels, shopping boxes, and search ads. The Verge reports: Introducing the extension, Maddy Varner and Sam Morris describe it as a conscious throwback to an earlier version of Google search, before the integration of the Knowledge Graph…

Net Applications Will No Longer Track the Browser Wars

Emil Protalinski, reporting for VentureBeat: For more than a decade, I’ve used Net Applications’ NetMarketShare tool to track the desktop browser and operating system markets. The monthly reports have been critical in gauging which browsers and new versions of operating systems are gaining or losing market share. Last week, Net Applications released its final NetMarketShare report. The loss could not come…