Remove site-map
article thumbnail

Bug in Google Maps Opened Door to Cross-Site Scripting Attacks

Threatpost

A researcher discovered a cross-site scripting flaw in Google Map's export function, which earned him $10,000 in bug bounty rewards.

89
article thumbnail

Live Coronavirus Map Used to Spread Malware

Krebs on Security

A recent snapshot of the Johns Hopkins Coronavirus data map, available at coronavirus.jhu.edu. In one scheme, an interactive dashboard of Coronavirus infections and deaths produced by John Hopkins University is being used in malicious Web sites (and possibly spam emails) to spread password-stealing malware.

Malware 364
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Why No HTTPS? The 2021 Version

Troy Hunt

He crawls the sites from a US IP address using request headers that emulate a common browser. The top million is defined by Tranco and Scott uses it to produce 2 other lists which drive this little project: The top sites that redirect to HTTPS The top sites that don't redirect to HTTPS These lists don't add up to 1 million.

VPN 359
article thumbnail

Deere John: Researcher Warns Ag Giant’s Site Provides a Map to Customers, Equipment

The Security Ledger

Software vulnerabilities in web sites operated by John Deere could allow a remote attacker to harvest information on the company’s customers including their names, physical addresses and the equipment they own. The revelation suggests the U.S. agriculture sector is woefully unprepared for disruptive cyber attacks, experts warn.

article thumbnail

Google blocks staff’s internet access to reduce attacks – but will it work?

Graham Cluley

Some employees at Google will have internet access from their desktop PCs significantly restricted, with only internal web-based tools and Google-owned sites such as Google Drive, Google Maps, and Gmail accessible. But will such an approach protect the tech giant from attacks? Read more in my article on the Hot for Security blog.

article thumbnail

The Not-so-True People-Search Network from China

Krebs on Security

Responding to a reader inquiry concerning the trustworthiness of a site called TruePeopleSearch[.]net The site offers to sell a report containing photos, police records, background checks, civil judgments, contact information “and much more! Scouring multiple image search sites reveals Ms. 03-12 15, Singapore).

Marketing 240
article thumbnail

Crooks are attempting to take over tens of thousands of WordPress sites

Security Affairs

Threat actors are launching a hacking campaign aimed at taking over tens of thousands of WordPress sites by exploiting critical vulnerabilities. One of the issues exploited in the attacks is a zero-day vulnerability that affects several plugins and that could allow hackers to create admin accounts and take over the sites.