FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayYour RSS feeds

MIT invention builds memory walls to protect against Meltdown, Spectre attacks

The new system could potentially prevent similar memory-based attacks from risking our PCs and global services.
  • October 18th 2018 at 04:00

Equifax engineer who designed breach portal gets 8 months of house arrest for insider trading

SEC said engineer figured out on his own that the website he was building was for the company's security breach.
  • October 17th 2018 at 21:39

Hack Naked News #193 - October 16, 2018

By paul@securityweekly.com

This week, Millions of voter records for sale on the Dark Web, Apple passcode bypass can access pictures and contacts, how Chrome and Firefox could ruin your business, Fake Adobe updates, Microsoft Zero-Day patch for JET bug incomplete, and 5 ways attackers are targeting the Healthcare Industry! Doug White joins us for expert commentary how China used a Tiny Chip to infiltrate America's top companies, and more on this episode of Hack Naked News!

Β 

Full Show Notes: https://wiki.securityweekly.com/HNNEpisode193

Β 

Visit https://www.securityweekly.com/hnn for all the latest episodes!

Visit https://www.activecountermeasures/hnn to sign up for a demo or buy our AI Hunter!!

Β 

β†’Follow us on Twitter: https://www.twitter.com/securityweekly

β†’Like us on Facebook: https://www.facebook.com/secweekly

  • October 17th 2018 at 19:25

Tumblr discloses vulnerability but says 'no evidence that this bug was abused'

Bug hunter finds security flaw in Tumblr's "Recommended Blogs" widget.
  • October 17th 2018 at 19:11

Researcher finds simple way of backdooring Windows PCs and nobody notices for ten months

"RID Hijacking" technique lets hackers assign admin rights to guest and other low-level accounts.
  • October 17th 2018 at 15:49

Rapid7 acquires web app security developer tCell

The deal is designed to boost Rapid7's Insight platform.
  • October 17th 2018 at 09:20

Git On That - Application Security Weekly #35

By paul@securityweekly.com

This week, Keith and Paul interview Garrett Gross, Senior Solutions Engineer at Rapid7! They talk about catching bugs earlier in the process of development, what can lead to certain successes in development, and more! In the Application Security News, Git Project patches Remote Code Execution Vulnerability, Google is shutting down Google+ after 500k accounts potentially affected by a data breach, Facebook wants people to Invite its cameras into their homes, GitHub introduces user blocking notifications, DevOps producing more insecure apps than ever, and more on this episode of Application Security Weekly!

Β 

Full Show Notes: https://wiki.securityweekly.com/ASW_Episode35

Β 

Visit https://www.securityweekly.com/asw for all the latest episodes!

Β 

Visit https://www.activecountermeasures/asw to sign up for a demo or buy our AI Hunter!

Β 

β†’Visit our website: https://www.securityweekly.com

β†’Follow us on Twitter: https://www.twitter.com/securityweekly

β†’Like us on Facebook: https://www.facebook.com/secweekly

  • October 17th 2018 at 09:00

Creator of remote access tool LuminosityLink sent behind bars

The RAT software was a popular choice for cyberattackers.
  • October 17th 2018 at 08:37

Google to charge phone vendors for its Android apps in Europe

If device makers want to ship Android phones with Google apps --and especially the Play Store app-- in Europe, they'll now have to pay a licensing fee.
  • October 17th 2018 at 06:52

Security flaw in libssh leaves thousands of servers at risk of hijacking

Vulnerability not as bad as it gets, as most servers use the openssh library to support server-side SSH logins.
  • October 17th 2018 at 06:42

Oracle patches 301 vulnerabilities, including 46 with a 9.8+ severity rating

This wasn't Oracle's biggest patch ever. That title goes to the July 2018 CPU.
  • October 17th 2018 at 05:15

Keep It Tight - Business Security Weekly #102

By paul@securityweekly.com

This week, Michael and Paul talk about the Article Discussion on Leadership, Communication, and Innovation! They discuss how to automate habits and never think about them again, why it’s important to explain to employees that organizational changes are coming, how journaling can boost your leadership skills, why you need to tell them why, and more on this episode of Business Security Weekly!

Full Show Notes: https://wiki.securityweekly.com/BSWEpisode102

Β 

Visit https://www.securityweekly.com/bsw for all the latest episodes!

Β 

Visit https://www.activecountermeasures/bsw to sign up for a demo or buy our AI Hunter!!

Β 

β†’Visit our website: https://www.securityweekly.com

β†’Follow us on Twitter: https://www.twitter.com/securityweekly

β†’Like us on Facebook: https://www.facebook.com/secweekly

  • October 16th 2018 at 22:00

Chrome 70 released with revamped Google account login system

Chrome 70 also comes with support for the final version of the TLS 1.3 standard and the AV1 video format.
  • October 16th 2018 at 21:30

Zero-days, fileless attacks are now the most dangerous threats to the enterprise

These attacks cost the average organization millions and SMBs are the worst affected.
  • October 16th 2018 at 14:00

Epson reported to Texas AG for bricking third-party ink cartridges

EFF argues Epson's practice is making users avoid installing firmware updates, leaving millions of printers and companies vulnerable to cyber attacks.
  • October 16th 2018 at 12:46

GPU-Z now warns users if they have purchased fake Nvidia graphics cards

As the demand for high-power graphics cards continues to surge, some sellers are seeking to cash in on Nvidia's name.
  • October 16th 2018 at 12:42

Anthem agrees to pay $16 million in data breach privacy settlement

The insurer will shell out to settle a privacy violations case issued by the US government.
  • October 16th 2018 at 11:27

Temasek snaps up Sygnia, founded by Israel's NSA, in $250m deal

The cybersecurity consulting firm was created by former members of Israel's 8200 unit.
  • October 16th 2018 at 11:00

Hackers tamper with exploit chain to drop Agent Tesla, circumvent antivirus solutions

A new campaign is spreading information-stealing malware including Agent Tesla and Loki.
  • October 16th 2018 at 10:07

Czech intelligence service shuts down Hezbollah hacking operation

Hezbollah agents used Facebook profiles for attractive women to trick targets into installing spyware-infected apps.
  • October 16th 2018 at 05:00

US voter records from 19 states sold on hacking forum

Seller is asking $42,200 for all 19 US state voter databases.
  • October 15th 2018 at 19:00

Chrome, Edge, IE, Firefox, and Safari to disable TLS 1.0 and TLS 1.1 in 2020

UPDATE: The big four --Apple, Google, Microsoft, and Mozilla-- announce end of support for TLS 1.0 and 1.1 standards.
  • October 15th 2018 at 15:58

Octopus Trojan exploits Telegram ban fears to snag diplomatic targets across Asia

A fresh attack wave is launching Octopus at diplomatic organizations across the region.
  • October 15th 2018 at 15:05

Sony working on a fix for bug that's crashing PlayStation 4 consoles

Bug crashes and freezes PlayStation 4 consoles. The only way to recover is by performing a factory reset for the entire console.
  • October 15th 2018 at 14:44

Apple VoiceOver iOS vulnerability permits hacker access to user photos

The bug can be exploited to gain access to photos stored on a user's device.
  • October 15th 2018 at 13:14

Around 62 percent of all Internet sites will run an unsupported PHP version in 10 weeks

The highly popular PHP 5.x branch will stop receiving security updates at the end of the year.
  • October 14th 2018 at 08:00

Pentagon discloses card breach

Around 30,000 DOD civilian and military personnel are believed to be affected.
  • October 13th 2018 at 17:11

Get the Wagyu - Paul's Security Weekly #578

By paul@securityweekly.com

This week, we welcome Lee Neely, Senior Cyber Analyst at Lawrence Livermore National Lab for an interview! In the Technical Segment, Omer Yair from Javelin Networks brings us through his talk he presented at DerbyCon entitled: β€œGoodbye Obfuscation, Hello Invisi-Shell”! In the security news, new Apple and Microsoft security flaws at Black Hat Europe, CCTV makers leaves at least 9 million cameras public, upset Google+ users are suing Google, US weapons systems apparently can be easily hacked, not all multifactor authentication is created equal, and Kanye's '000000' password makes iPhone security Great again! All that and more, on this episode of Paul's Security Weekly!

Β 

Full Show Notes: https://wiki.securityweekly.com/Episode578

Visit https://www.securityweekly.com/psw for all the latest episodes!

Β 

β†’Visit https://www.activecountermeasures/psw to sign up for a demo or buy our AI Hunter!

β†’Follow us on Twitter: https://www.twitter.com/securityweekly

β†’Like us on Facebook: https://www.facebook.com/secweekly

  • October 13th 2018 at 09:00

Microsoft JET vulnerability still open to attacks, despite recent patch

Microsoft's patch for a JET database engine zero-day deemed incomplete.
  • October 13th 2018 at 07:25

Facebook downgrades breach count from 50 million to 30 million users

Company said 29 million of the 30 million also had personal data scraped by the attackers.
  • October 12th 2018 at 18:12

A mysterious grey-hat is patching people's outdated MikroTik routers

Internet vigilante claims he patched over 100,000 MikroTik routers already.
  • October 12th 2018 at 13:04

Yale alarm app debacle causes chaos across UK homes

Customers have reported that app failures left them powerless to disable or enable alarms.
  • October 12th 2018 at 11:56

GandCrab ransomware operators team up with crypter service

The hacking agreement could result in the ransomware strain becoming more difficult to spot and analyze in the future.
  • October 12th 2018 at 10:28

This Trojan masquerades as Google Play to hide on your phone in plain sight

GPlayed is a new Trojan which attacks Android devices while acting as a legitimate Google service.
  • October 12th 2018 at 09:30

The Land Down Under - Enterprise Security Weekly #110

By paul@securityweekly.com

This week, in the Enterprise News, Paul is joined by Joff Thyer to discuss WhiteHat Security's single page application scanning, Palo Alto Networks acquires RedLock to build out Cloud Security, KnowBe4 boosts security awareness training, Symantec brings workload assurance security to the cloud, and Splunk unveils first IoT platform for Customers! In our final segment, we air a Pre Recorded interview from Microsoft Ignite with Secure Digital Life host Doug White and CTO of Microsoft, Mark Russinovich!

Β 

Full Show Notes: https://wiki.securityweekly.com/ES_Episode110

Β 

Visit https://www.securityweekly.com/esw for all the latest episodes!

Β 

Visit https://www.activecountermeasures/esw to sign up for a demo or buy our AI Hunter!

Β 

β†’Follow us on Twitter: https://www.twitter.com/securityweekly

β†’Like us on Facebook: https://www.facebook.com/secweekly

  • October 12th 2018 at 09:00

IETF approves new internet standards to secure authentication tokens

New IETF standards aim to protect authentication tokens against replay attacks.
  • October 12th 2018 at 05:25

Proof-of-concept code published for Microsoft Edge remote code execution bug

The PoC can be hosted on any website and requires that users press the Enter key just once.
  • October 12th 2018 at 00:25

Facebook removes 800 accounts and pages for political spam, disinformation

Social network cracks down on spammers using political topics to drive traffic towards ad farms.
  • October 11th 2018 at 20:45

Senators demand Google hand over internal memo urging Google+ cover-up

Republican senators start inquiry in Google's handling of Google+ security breach.
  • October 11th 2018 at 17:41

FitMetrix user data exposed via passwordless ElasticSearch server cluster

Exact number of affected users is unknown but the server cluster is now secure.
  • October 11th 2018 at 14:05

Hackers breach web hosting provider for the second time in the past year

Company hacked again despite claiming to have boosted security measures and undergone a security audit.
  • October 11th 2018 at 13:53

Security researchers find solid evidence linking Industroyer to NotPetya

A web of code reuse and shared infrastructure links together a slew of famous cyber-attacks.
  • October 11th 2018 at 12:00

Arrest of top Chinese intelligence officer sparks fears of new Chinese hacking efforts

Suspect is a top official in one of China's intelligence agencies, accused of controlling China's state hacking operations.
  • October 10th 2018 at 23:47

Google's Pixel 3 is the first Android device to ship with new CFI kernel protections

Google adds Control Flow Integrity protection to the Android kernel.
  • October 10th 2018 at 19:22

Google opens up G Suite security threat alert service to businesses

The alert center's security notification system has been opened up days after Google revealed an exposure of private data to outside developers on its Google+ service.
  • October 10th 2018 at 19:15

Five years later, Italian police identify hacker behind 2013 NASA hacks

Hacker pleaded guilty to breaching and defacing sites belonging to NASA, Italian police, Italian government, and an Italian TV station.
  • October 10th 2018 at 14:10

A deep dive into the forces driving Russian and Chinese hacker forums

Profit, hacktivism, and politics are only some of the differences between Russia and China's hacking communities.
  • October 10th 2018 at 14:01

Adobe security update fixes a handful of critical bugs, ignores Flash Player

The light set of updates does not contain a single security patch for Flash, an unusual event for the company.
  • October 10th 2018 at 09:50

WhatsApp fixes bug that let hackers take over app when answering a video call

Bug only affects WhatsApp for Android and iOS, but the issue has been fixed this week.
  • October 10th 2018 at 00:08

Pentagon's new next-gen weapons systems are laughably easy to hack

Bad passwords, non-encrypted communications, and a lot of unpatched bugs.
  • October 9th 2018 at 22:22

Hack Naked News #192 - October 9, 2018

By paul@securityweekly.com

This week, Tenable researcher reveals extended MikroTik Router Vulnerability, Wi-Fi versions will get names people can actually understand, don't accept Facebook's 2nd friend request, Google Plus exposed 500,000 users data, weak passwords are being banned in California, and code execution bug in malicious repositories resolved by Git Project! Juxin Dyrmishi Brigjaj of Acunetix joins us for expert commentary to talk about the resurgence of XSS after the big British Airways and NewEgg Hack! All that and more, on this episode of Hack Naked News!

Β 

Full Show Notes: https://wiki.securityweekly.com/HNNEpisode192

Sponsor Landing Page: https://www.acunetix.com/securityweekly/

Visit https://www.securityweekly.com/hnn for all the latest episodes!

Visit https://www.activecountermeasures/hnn to sign up for a demo or buy our AI Hunter!

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweeklyΒ 

  • October 9th 2018 at 20:41

Microsoft October 2018 Patch Tuesday fixes zero-day exploited by FruityArmor APT

Microsoft also fixes 48 other security bugs, 18 of which are rated "Critical."
  • October 9th 2018 at 19:22

Panda Banker Trojan becomes part of Emotet threat distribution platform

The Zeus variant is now actively targeting organizations in the US, Canada, and Japan.
  • October 9th 2018 at 16:00

Over nine million cameras and DVRs open to APTs, botnet herders, and voyeurs

Re-branded IP cameras and DVRs sold by over 100 companies can be easily hacked, researchers say.
  • October 9th 2018 at 15:35

New Magecart hack detected at Shopper Approved

Malicious code removed after two days. Impact is smaller compared to previous incidents at Ticketmaster, Feedify, or British Airways.
  • October 9th 2018 at 13:00

Garmin's Navionics exposed data belonging to thousands of customers

An unsecured MongoDB server containing 19GB in customer and product data was exposed online.
  • October 9th 2018 at 12:18

Google restricts which Android apps can request Call Log and SMS permissions

Only apps selected as the device's default app for making calls or sending text messages will be able to access call logs and SMS data from now on.
  • October 9th 2018 at 11:50

Security researcher source in Supermicro chip hack report casts doubt on story

Updated: The explosive report "doesn't make sense," according to the expert which described hardware implant uses in theoretical attacks.
  • October 9th 2018 at 10:34

Heathrow Airport fined Β£120,000 over USB data breach debacle

In a prime example of data protection failure, a USB containing sensitive information ended up in the hands of the public.
  • October 9th 2018 at 08:47

Firefox will be able to show notifications inside the Windows 10 Action Center

New Windows 10-friendly notification system to arrive in December, with Firefox 64.
  • October 8th 2018 at 23:42
❌