Posts

Showing posts from May, 2024

Apple iOS 17.5: Cross-Platform Tracking Protection Tackles Bluetooth Tracker Misuse

Image
 By Nadim Kahwaji Apple has released updates for all supported devices, including iOS 17.5, iPadOS 17.5, macOS 14.5, watchOS 10.5, tvOS 17.5, and HomePod Software 17.5, introducing several new features and enhancements. These updates are now available for download. The updates include: SecurityUpdates : Each update includes a variety of security patches to enhance device protection. Cross-Platform Tracking Protection: This feature alerts users if a Bluetooth tracker they do not own is moving with them, applicable across different operating systems. It extends the anti-stalking protections previously available for AirTags to other Bluetooth devices paired with non-Apple phones. Apple News+ Enhancements: Subscribers to Apple News+ can now enjoy a new word game called Quartiles. Other games like Crossword and Mini Crossword now track player stats and win streaks. Additionally, the Today+ and News+ tabs can now load without an internet connection. These updates are expected to ...

Why Passwords Alone Aren't Enough: A Look at GitLab's Recent Security Vulnerability

Image
 By  Nadim Kahwaji In the digital age, relying solely on passwords to secure online accounts is increasingly proving to be insufficient. Even the strongest passwords, fortified with symbols and complex combinations, may fall short due to potential vulnerabilities in the security implementations of online services. This vulnerability underscores the critical weaknesses of relying solely on passwords for security, as vividly illustrated by a recent incident involving GitLab , a web-based DevOps platform similar to GitHub . GitLab, a platform supporting collaborative development across coding, testing, and deploying applications, offers both self-hosted and cloud-hosted options. However, this flexibility necessitates the implementation of robust security measures to protect against sophisticated cyberattacks. Recently, GitLab fell victim to a critical security flaw identified as CVE-2023-7028 , exploiting the password reset feature to redirect emails to unverified addresses. This...