Vulnerability
OpenSSL

OpenSSL fixes two high severity vulnerabilities

The OpenSSL Project has patched two high-severity security flaws in its open-source cryptographic library used to encrypt communication channels and HTTPS connections.The vulnerabilities (CVE-2022-3602 and CVE-2022-3786) affect OpenSSL version 3.0.0 and later and have been addressed in OpenSSL 3.0.7. Only roughly 7,000 Internet-exposed systems running vulnerable OpenSSL versions out of a total of more than 1,793,000 unique hosts spotted by Censys online […]

Surveillance

Are we living in Technofeudalism?

The technofeudalism model involves establishing a monopoly position and using sophisticated data extraction to secure it. Google, Facebook, Microsoft, and Amazon — have turned the slippery slope of digital surveillance into a hamster wheel, a new self-perpetuating system of exploitation. Not only does the tech oligopoly seamlessly record our preferences, habits, and choices, it also […]

AI Privacy

€20 million fine by CNIL for Clearview AI

CNIL fined Clearview AI with €20 Million for processing data without legal basis and orders to delete data already collected. Clearview AI is an US FacialRecognition company, providing software to companies, law enforcement, universities, and individuals. The company’s algorithm matches faces to a database of more than 20 billion images indexed from the Internet, including […]

Password management
Password management

9 out of 10 passwords are too easy to retrieve

Everyone is annoyed when coming up with, remembering and entering hard-to-guess passwords as shown in this video. 77.6% of people find passwords difficult to remember, while 89.2% have an easy-to-guess or retrieve password, with 8% of all passwords already leaked. ID Control helps you manage your usernames, passwords and other secrets (e.g. credit card details) […]

Firewall Vulnerability

Fortinet firewall and proxy exploited in the wild due to critical vulnerability

Fortinet revealed that the newly patched critical security vulnerability impacting its firewall and proxy products is being actively exploited in the wild. Tracked as CVE-2022-40684 (CVSS score: 9.6), the flaw relates to an authentication bypass in FortiOS, FortiProxy, and FortiSwitchManager that could allow a remote attacker to perform unauthorized operations on the administrative interface via […]