Embedded browsers within apps can be useful if you want to use an existing account from another service -- say, your Gmail log-in -- to access their features. However, they're also really easy to weaponize for man-in-the-middle types of phishing attacks. Since Google can't differentiate between a legitimate log-in and a phishing attempt through a browser from within an application, it's blocking sign-ins from all embedded browser frameworks starting in June. . Bad actors can exploit embedded browsers, such as Chromium Embedded Framework, by intercepting communications between the user and providers like Google. The method gives them a way to steal log-in credentials, sometimes even multi-factor authentication details, in real time. Google has been implementing more security measures around log-ins in recent months in an effort to protect users' details. In late 2018, for instance, it launched a risk-assessment feature that requires JavaScript to be able to sign into your account. The link for this article located at Engadget is no longer available. . Tech giant Microsoft limits third-party app sign-ins to safeguard user data from potential hacks, promoting safer account management practices.. Embedded Browser Security, Phishing Prevention, User Authentication Issues. . LinuxSecurity.com Team
Despite all of the hand wringing over cloud security, major cloud security breaches haven't been grabbing headlines. The past year has seen major breaches, such as the ones that hit Sony and Epsilon, but we haven't heard much of an emphasis about the cloud being a weakness. . Part of this, of course, could be a simple matter of semantics. Some have emphasized Epsilon's role as a provider of email marketing services -- in other words, it's a SaaS company -- but the breach was a traditional spear-phishing attack used to gain access to email servers, not, say, an assault on hypervisor vulnerabilities. The link for this article located at PC Advisor is no longer available. . Cloud computing has changed data management, but it brings security risks. Breaches show the need for strong IAM solutions and clear security responsibilities.. Cloud Security, Data Breach Trends, Security Risks, Cloud Data Protection. . Anthony Pell
A million logins for the hugely popular YouPorn sex site appear to have been leaked after a hacker chanced upon a URL linking to a user list apparently left exposed for several years.. Smaller portions of the YouPorn database featuring user email addresses and passwords have appeared on Pastebin, many of them using recognisable first and last names. The vulnerable URL has now been taken down by the publishers of YouPorn, which still leaves a large number of the site's users at risk of having their accounts hacked of phished. The link for this article located at PC Advisor is no longer available. . Smaller portions of the YouPorn database featuring user email addresses and passwords have appeared . million, logins, hugely, popular, youporn, appear, leaked, hacker. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.