(7 votes, average: 5.00 out of 5)

A Security Vulnerability in WooCommerce Stripe Gateway Affects Over 900K Websites

A security vulnerability was discovered in the WooCommerce Stripe payment gateway plugin, making it possible for an attacker to collect personally identifiable information (PII) from stores using the plugin. Security analysts rated the attack a high grade of 7.5 on a rating scale of 1 to 10, and it does…
(10 votes, average: 5.00 out of 5)

What Is a Certificate Revocation List? [CRL]

The foundation of Public Key Infrastructure (PKI), which secures billions of online transactions, is the X.509 digital certificate standard. But what will happen if these certificates or the keys that go with them have an issue? They need to be revoked since it is clear that they can no longer be…
(7 votes, average: 5.00 out of 5)

Maximizing Your ROI: How Consulting Services Can Improve Your Bottom Line

Are you trying to figure out how to improve business operations to the next level? With the proper IT consulting services partner/business consulting services like Certera, you can maximize and optimize your ROI in ways that will impact how your organization works. To accomplish this, it could be essential to…
(9 votes, average: 5.00 out of 5)

OCSP vs. CRL: What is the Difference?

Browsers verify the validity of a website’s TLS certificate before connecting to it, and they display a warning message if the certificate has been revoked. OCSP, CRLs, OCSP must-staple, and OCSP stapling are revocations status-checking techniques browsers use. This article analyses and compares two techniques, named CRL vs OCSP. The…
(8 votes, average: 5.00 out of 5)

Create Code Signing Certificate using the Key Storage Provider

The following procedure will demonstrate how to generate a Code Signing Certificate request using a key generated and stored in the YubiHSM 2 using the Key Storage Provider (KSP). You can use the Microsoft “signtool tool” to digitally certify Windows binaries with this code signing certificate. Let’s take a closer…
(6 votes, average: 5.00 out of 5)

Atomic Wallet Security Glitch Leads to a $35M Cryptocurrency Theft

A security vulnerability at Atomic Wallet has stolen over $35 million in cryptocurrency assets since June 2. This desktop and mobile cryptocurrency wallet enable users to store several cryptocurrencies. Security personnel are looking into what sparked the attack. Reports indicate that the incident involved missing tokens, deleted transaction data, and…
(14 votes, average: 5.00 out of 5)

What is ACME Protocol, and How does it Work?

Welcome! This article will discover a robust protocol and explore how it functions. ACME protocol, short for Automated Certificate Management Environment, is a seamless communication channel between Certificate Authorities (CAs) and various endpoints in a company’s digital ecosystem. ACME automates the management of Public Key Infrastructure (PKI) certificates used in…
(8 votes, average: 5.00 out of 5)

What is FIPS 140-2 and How to be FIPS Compliant?

Every organization is responsible for securing highly sensitive information under all circumstances. Developers created standards, regulations, and best practices to enhance data security and expedite this process. One of these standards is the Federal Information Protection Standard or FIPS. The National Institute of Science and Technology (NIST) developed these standards…
(30 votes, average: 4.63 out of 5)

How to Fix ERR_SSL_PROTOCOL_ERROR?

Summary Do you browse the web with Google Chrome? We appreciate that! Most people who use the Internet recommend its attractive user interface. When using the Google Chrome browser for viewing SSL-secure websites, you might often see the SSL privacy issue “ERR_SSL_PROTOCOL_ERROR.” Subsequently, this problem frequently goes away by itself…
(7 votes, average: 5.00 out of 5)

What is Token Signing in Code Signing Certificate?

To prevent unauthorized access to federated resources, federation servers will enforce the use of token-signing certificates, effectively thwarting cybercriminals from tampering with or forging security tokens. The most crucial validation technique for any federated collaboration is the private/public key pairing utilized with token-signing certificates. These encryption keys verify that a…
(6 votes, average: 5.00 out of 5)

Google Plans to Delete the Accounts Inactive for 2 Years

Google to Delete Two Year Inactive Accounts after for security purposes Per Google’s inactive account policies, any Google account that has not been authenticated for a consecutive period exceeding 24 months is classified as long dormant and is eligible for permanent deletion. This policy is being enforced across all Google…
(10 votes, average: 5.00 out of 5)

Yubikey Key Generation and Certificate Attestation for FIPS 140-2 Token

The YubiKey FIPS 140-2 Token is a hardware-based authentication device that is used to protect user accounts. The device is compact enough to fit in your purse or wallet. It enables users to generate cryptographic keys (On the device, a randomly generated private and public key pair is created and…
(6 votes, average: 5.00 out of 5)

ABB discloses IT Security Breach: The Cyberattack Impacts Company Operations

ABB Ltd., a prominent Swedish-Swiss robotics and automation company, recently experienced a cybersecurity issue that affected business operations. ABB, the corporation headquartered in Zurich and formerly the largest industrial employer in Switzerland until 2020, asserts an IT security breach that has specifically affected certain sites and systems. Vigorous efforts are…
(8 votes, average: 5.00 out of 5)

How to use YubiKey FIPS versions for Code Signing Certificate?

Your code signing certificate could be kept secure and protected from hackers with the use of a YubiKey FIPS-compliant USB Token. Assuming you have a signing certificate in a .pfx format issued by a trustworthy certified certificate authority like Certera, Sectigo, or Comodo. Let’s have a look at how to use Yubikey…
(6 votes, average: 5.00 out of 5)

Western Digital Data Breach – 10 TB of Customer Data was Stolen

WD Data Breach – Attackers asked for a Huge “8-Figure” Ransomware Cybercriminals reportedly stole 10 TB of data from Western Digital, a US-based data storage provider and the market leader in data storage, saying that the data contained client information. According to news reports, hackers make a ransom demand of…