Latest Tech News

Stay updated with the latest in technology, AI, cybersecurity, and more

Filtered by: secure Clear Filter

When root meets immutable: OpenBSD chflags vs. log tampering

Why ISO 27001 Demands Immutable Logs (Without Actually Saying So) # ISO 27001 is like that careful lawyer who never says exactly what they mean – it tells you what needs to be achieved, not how to do it. When it comes to logging, this is particularly telling: Control A.12.4.2 simply states that “logging information and logging facilities shall be protected against tampering and unauthorized access.” Period. How? That’s your problem to solve. But anyone who’s ever had to investigate a security

Topics: log logs root secure var

When Root Meets Immutable: OpenBSD Chflags vs. Log Tampering

Why ISO 27001 Demands Immutable Logs (Without Actually Saying So) # ISO 27001 is like that careful lawyer who never says exactly what they mean – it tells you what needs to be achieved, not how to do it. When it comes to logging, this is particularly telling: Control A.12.4.2 simply states that “logging information and logging facilities shall be protected against tampering and unauthorized access.” Period. How? That’s your problem to solve. But anyone who’s ever had to investigate a security

Topics: log logs root secure var

Linux and Secure Boot certificate expiration

Linux and Secure Boot certificate expiration [LWN subscriber-only content] Welcome to LWN.net The following subscription-only content has been made available to you by an LWN subscriber. Thousands of subscribers depend on LWN for the best news from the Linux and free software communities. If you enjoy this article, please consider subscribing to LWN. Thank you for visiting LWN.net! Linux users who have Secure Boot enabled on their systems knowingly or unknowingly rely on a key from Microsoft t

Samsung fixes the Secure Folder flaw that let anyone see what apps you’re hiding

Mishaal Rahman / Android Authority TL;DR Samsung has patched a Secure Folder flaw that previously allowed anyone with physical access to see your hidden apps and photos. The vulnerability existed because Secure Folder was implemented as a “work profile,” which key system components didn’t recognize as a highly secure space. One UI 8 reclassifies Secure Folder as a “private” profile, ensuring system apps now correctly hide its sensitive files and app information from view. Samsung’s Secure Fo

Try 1Password for free to save $20 (and all your unique passwords) for Prime Day

Using 1Password to remember every username and password that accumulates is easily one of the best quality-of-life improvements you can make in your digital world. In addition to saving all your passwords and secure information, 9to5Mac readers can also try 1Password free for 14 days and take home a $20 credit as a Prime Day exclusive! 1Password is hands-down the best fix for fumbling with passwords because it’s private, cross-platform, and the absolute leader in password management features. 1

One UI 8 gives you more control over where your Secure Folder apps pop up

Joe Maring / Android Authority TL;DR Samsung’s Secure Folder lets you lock files and even entire apps behind an extra layer of protection. One UI 8 has already started improving how Secure Folder is accessed, with a quick lockdown shortcut. Now we’re seeing Samsung add new settings for Secure Folder apps in your share sheet. Samsung likes to present its Galaxy smartphones as particularly secure devices, and has long leaned on its Knox security framework to highlight those features. That incl

Data-recovery firm tests $28, 500GB HDD from Amazon and gets surprising results

Fraudulent or misleading storage devices are, unfortunately, still easy to find via online marketplaces. It's also a common story that someone buys a shockingly cheap storage device from an unknown brand and ends up with a product that doesn’t perform as expected—or at all. With this in mind, data-recovery firm Secure Data Recovery recently bought a 500GB HDD from Amazon (the UnionSine HD2510) for $28 and tested it. The results were better than expected, but there are still reasons to avoid buy

Delta Chat is a decentralized and secure messenger app

Delta Chat is a decentralized and secure messenger app 💬 Reliable instant messaging with multi-profile and multi-device support ⚡️ Sign up to secure fast chatmail servers or use classic e-mail servers 🥳 Interactive web apps in chats for gaming and collaboration 🔒 Audited end-to-end encryption safe against network and server attacks 👉 FOSS software, built on Internet Standards, avoiding xkcd927 :) Download Available on mobile and desktop.

Infineon security microcontroller flaw enabled extraction of TPM secret keys

A few months ago, security researcher Thomas Roche presented his fundamental research on secure elements used in the YubiKey 5. The security element is the Infineon SLE78, which contains a proprietary implementation of the Elliptic Curve Digital Signature Algorithm (ECDSA). Using side-channel attacks and a great deal of smart research, the author discovered a vulnerability in Infineon Technologies' cryptographic library and, as a result, was able to extract the ECDSA secret key from the secure

Two exploits are threatening Secure Boot, but Microsoft is only patching one of them

Facepalm: Microsoft and the PC industry developed the Secure Boot protocol to prevent modern UEFI-based computers from being hacked or compromised during the boot process. However, just a few years later, the technology is plagued by a steady stream of serious security vulnerabilities. Cybercriminals are currently having a field day with Secure Boot. Security experts have uncovered two separate vulnerabilities that are already being exploited in the wild to bypass SB's protections. Even more co

Microsoft Edge now offers secure password deployment for businesses

Microsoft announced that a new Edge feature allowing employees to share passwords more securely in enterprise environments has reached general availability. Known as secure password deployment, this feature will be available to Microsoft Edge for Business users starting this week, minimizing the risk of unauthorized access by ensuring that employees don't accidentally share passwords with unintended recipients. The feature is available for Microsoft 365 Business Premium, E3, and E5 subscriptio

Security Service Edge(SSE): Powering the Modern Hybrid Workplace

The way we work has fundamentally shifted. Hybrid models, where employees split their time between the office and remote locations, are no longer a niche trend but a widespread reality. This evolution offers numerous benefits, including increased flexibility and improved work-life balance. However, it also presents significant challenges for IT and security teams tasked with ensuring seamless access to applications and protecting sensitive data outside the traditional corporate perimeter. Securi

Patch your Windows PC now before bootkit malware takes it over - here's how

Elyse Betters Picaro / ZDNET Windows users who don't always install the updates rolled out by Microsoft each month for Patch Tuesday will want to install the ones for June. That's because the latest round of patches fixes a flaw that could allow an attacker to control your PC through bootkit malware. Designated as CVE-2025-3052, the Secure Boot bypass flaw is a serious one, according to Binarly security researcher Alex Matrosov, who discovered the vulnerability. In a Binarly blog post publishe