TikTok Assures U.S. Lawmakers it’s Working to Safeguard User Data From Chinese StaffThe Hacker News

Following heightened worries that U.S. users' data had been accessed by TikTok engineers in China between September 2021 and January 2022, the company sought to assuage U.S. lawmakers that it's taking steps to "strengthen data security." The admission that some China-based employees can access information from U.S. users came in a...

Read more...

Microsoft Warns About Evolving Capabilities of Toll Fraud Android Malware AppsThe Hacker News

Microsoft has detailed the evolving capabilities of toll fraud malware apps on Android, pointing out its "complex multi-step attack flow" and an improved mechanism to evade security analysis. Toll fraud belongs to a category of billing fraud wherein malicious mobile applications come with hidden subscription fees, roping in unsuspecting users to...

Read more...

Google Improves Its Password Manager to Boost Security Across All PlatformsThe Hacker News

Google on Thursday announced a slew of improvements to its password manager service aimed at creating a more consistent look and feel across different platforms. Central to the changes is a "simplified and unified management experience that's the same in Chrome and Android settings," Ali Sarraf, Google Chrome product manager, said in a blog post. The...

Read more...

Solving the indirect vulnerability enigma – fixing indirect vulnerabilities without breaking your dependency treeThe Hacker News

Fixing indirect vulnerabilities is one of those complex, tedious and, quite frankly, boring tasks that no one really wants to touch. No one except for Debricked, it seems. Sure, there are lots of ways to do it manually, but can it be done automatically with minimal risk of breaking changes? The...

Read more...

New ‘SessionManager’ Backdoor Targeting Microsoft IIS Servers in the WildThe Hacker News

A newly discovered malware has been put to use in the wild at least since March 2021 to backdoor Microsoft Exchange servers belonging to a wide range of entities worldwide, with infections lingering in 20 organizations as of June 2022. Dubbed SessionManager, the malicious tool masquerades as a module for Internet Information...

Read more...

Gdpr e dati sanitari: tutti i nodi della titolarità dei trattamentiRaffaele Conte

La configurazione dei ruoli rispetto alla titolarità nei trattamenti di dati particolari nelle sperimentazioni cliniche solleva non poche questioni. È difficile concordare sulla titolarità autonoma nel raggiungimento di una finalità condivisa. Proviamo a sciogliere qualche dubbio L'articolo Gdpr e dati sanitari: tutti i nodi della titolarità dei trattamenti proviene da...

Read more...