FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayYour RSS feeds

Guilty of your roots: Why Kaspersky believes tech nationalism is on our doorstep

The answer lies in why Kaspersky has now moved core systems from Russia to Switzerland.
  • November 14th 2018 at 14:58

Researchers discover seven new Meltdown and Spectre attacks

Experiments showed that processors from AMD, ARM, and Intel are affected.
  • November 14th 2018 at 14:44

Boston Accent - Application Security Weekly #39

By paul@securityweekly.com

This week, Keith and Paul interview Brian Kelly, Head of Conjur Engineering at CyberArk! Brian focuses on creating products that add much-needed security and identity management to the landscape of DevOps tools and cloud systems. In the Application Security News, DJI Drone Vulnerability, Hackers are increasingly destroying logs to hide attacks, Adobe ColdFusion servers under attack from APT group, understanding Open Source Code use in your business, and more!

Β 

Full Show Notes: https://wiki.securityweekly.com/ASW_Episode39

To learn more about Conjur, go to: www.conjur.org/asw

Β 

Visit https://www.securityweekly.com/asw for all the latest episodes!

Visit https://www.activecountermeasures/asw to sign up for a demo or buy our AI Hunter!

Visit our website: https://www.securityweekly.com

Β 

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

  • November 14th 2018 at 10:00

Card skimming malware removed from Infowars online store

Infowars online store hit by brief Magecart incident that lasted around 24 hours. Less than 1,600 users may have been affected.
  • November 14th 2018 at 00:51

Microsoft patches Windows zero-day used by multiple cyber-espionage groups

Kaspersky: Windows zero-day exploited by multiple cyber-espionage groups.
  • November 13th 2018 at 20:44

Hack Naked News #196 - November 13, 2018

By paul@securityweekly.com

Vulnerabilities in SSD Encryption, Bypassing Windows UAC, Botnet Pwns over 100,00 routers w/ ancient security flaw, Google hit with IP Hijack, and 1 thing you can do to make your internet safer and faster! Jason Wood from Paladin Security joins us for expert commentary to discuss how Phineas Fisher got away with hacking Team Hacker!

Β 

Full Show Notes: https://wiki.securityweekly.com/HNNEpisode196

Visit https://www.securityweekly.com/hnn for all the latest episodes!

Visit https://www.activecountermeasures/hnn to sign up for a demo or buy our AI Hunter!

Β 

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

  • November 13th 2018 at 20:36

Facebook patches another bug that could have allowed mass-harvesting of user data

Imperva security researcher publicly discloses bug today, but Facebook patched the issue back in May.
  • November 13th 2018 at 14:27

Crawl to the Office - Business Security Weekly #106

By paul@securityweekly.com

This week, Matt and Paul interview Dario Forte, Chief Executive Officer and Founder of DFLabs! Dario explains his journey to the position he is in now, DFLabs recent press release about Open Integration Framework, and what it allows people to do when it comes to the DFLabs platform addressing SOAR! In the Article Discussion, Matt and Paul talk the key to better focus and higher productivity, living your life on purpose, why people are willing to do more meaningful work for less money, the fundamentals of leadership, and more on this episode of Business Security Weekly!

Β 

Full Show Notes: https://wiki.securityweekly.com/BSWEpisode106

Check out Sponsor's website: www.dflabs.com/securityweekly

Visit https://www.securityweekly.com/bsw for all the latest episodes!

Visit https://www.activecountermeasures/bsw to sign up for a demo or buy our AI Hunter!!

Β 

Visit our website: https://www.securityweekly.com

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

  • November 13th 2018 at 10:00

Google traffic hijacked via tiny Nigerian ISP

A large chunk of the hijacked traffic passed through the network of a controversial Chinese state-owned telecom provider that was previously accused of intentionally misdirecting internet traffic.
  • November 13th 2018 at 12:00

How Magecart groups are stealing your card details from online stores

New report sheds light on Magecart groups and their respective tactics.
  • November 13th 2018 at 11:02

Google launches VisBug, a Chrome extension for point-and-click web design

Google's new VisBug extension lets you make small tweaks to website's text and images.
  • November 13th 2018 at 00:16

US, Russia, China don't sign Macron's cyber pact

New cyber peace pact signed by 51 other countries, 224 companies, and 92 non-profits and advocacy groups.
  • November 12th 2018 at 22:45

Internet Explorer scripting engine becomes North Korean APT's favorite target in 2018

North Korean hacking group focuses attacks on aging and soon-to-be-deprecated technology.
  • November 12th 2018 at 19:29

HTTP-over-QUIC to be renamed HTTP/3

IETF agrees to base the next major iteration of HTTP on Google's QUIC protocol
  • November 12th 2018 at 14:48

Cloudflare launches Android and iOS apps for its 1.1.1.1 service

Company makes it easy for mobile users to hide their DNS traffic from nosy ISPs.
  • November 11th 2018 at 15:08

A Million Voices - Paul's Security Weekly #582

By paul@securityweekly.com

This week, we welcome Corin Imai, Senior Security Advisor for DomainTools! She joins Paul and the crew to talk about DNS, phishing tools, and tease what DomainTools has in store for 2019! In our Technical Segment, we welcome back Eyal Neemany, Senior Security Researcher at Javelin Networks to talk about securing remote administration, remote credentials, why Jump Servers aren’t as good, and he shows that you have to connect to remote machines using AD! In the Security News, Cisco accidentally released Dirty Cow exploit code, Apache Struts Vulnerabilities, Zero Day exploit published for VM Escape flaw, Spam spewing IoT botnet infects 100,000 routers, some of these vibrating apps turn your phone into a sex toy, and more on this episode of Paul's Security Weekly!

Β 

Full Show Notes: https://wiki.securityweekly.com/Episode582

Visit https://www.securityweekly.com/psw for all the latest episodes!

Visit https://www.activecountermeasures/psw to sign up for a demo or buy our AI Hunter!

Β 

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweeklyΒ 

  • November 10th 2018 at 10:00

Deserialization issues also affect Ruby, not just Java, PHP, and .NET

Java, .NET, PHP, and now Ruby. Python, are you next?
  • November 10th 2018 at 09:35

Zero-day in popular WordPress plugin exploited in the wild to take over sites

Attacks started around three weeks ago and are still going on. Users should update the WP GDPR Compliance plugin to version 1.4.3 to protect their sites.
  • November 9th 2018 at 20:53

Linux cryptocurrency miners are installing rootkits to hide themselves

Rootkit component hides the crypto-mining process that causes high CPU usage from local, built-in Linux process monitoring utilities.
  • November 9th 2018 at 15:38

Threat Stack acquires Bluefyre in cloud infrastructure security push

The company will use Bluefyre's portfolio to assist developers in building secure cloud-native applications.
  • November 9th 2018 at 13:26

ForeScout Technologies snaps up SecurityMatters in $113 million deal

The deal is designed to strengthen ForeScout's enterprise and industrial security offerings.
  • November 9th 2018 at 13:05

South Korea will make young cryptojackers stand trial for infecting PCs

It is believed this is the first time the country has had to deal with the emerging problem of cryptojacking.
  • November 9th 2018 at 12:19

Adobe ColdFusion servers under attack from APT group

A cyber-espionage group appears to have reverse engineered an Adobe security patch and is currently going after unpatched ColdFusion servers.
  • November 9th 2018 at 05:50

Chrome 71 will warn users about websites with shady phone subscription forms

Google plans to show full-page warning for sites that fail to list all mobile subscription information in a proper and clearly visible manner.
  • November 8th 2018 at 22:51

Google: Newer Android versions are less affected by malware

Android devices that only download apps from Google Play are 9 times less likely to get malware than devices that download apps from other sources.
  • November 8th 2018 at 21:20

Steam bug could have given you access to all the CD keys of any game

Bug affected a Steam API and was patched in August. Downgrading your Steam client won't help you get free games.
  • November 8th 2018 at 18:46

DerpTrolling game server DoS attacker pleads guilty

The man has pleaded guilty to attacks against companies including Sony.
  • November 8th 2018 at 13:27

Canada Post leaked personal data, orders of thousands of cannabis smokers

The rollout of legal weed in Ontario is now beset by potential privacy issues.
  • November 8th 2018 at 10:51

Locked Up - Enterprise Security Weekly #114

By paul@securityweekly.com

This week, Paul and Matt Alderman interview Harry Sverdlove, Chief Technology Officer at Edgewise to talk about Zero Trust Segmentation! In the Enterprise News this week, Symantec boosts security with Javelin Networks, ThreatQuotient integrates Verified Breach Intelligence from Visa, FireMon delivers hybrid cloud security with new visibility and orchestration, StackPath partners with Sectigo, and we have some acquisition & funding updates from Veracode, Shape Security, Thoma Bravo, and more!

Β 

Full Show Notes: https://wiki.securityweekly.com/ES_Episode114

Visit https://www.securityweekly.com/esw for all the latest episodes!

Visit https://www.activecountermeasures/esw to sign up for a demo or buy our AI Hunter!

Β 

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

  • November 8th 2018 at 10:00

Cambodia's ISPs hit by some of the biggest DDoS attacks in the country's history

EZECOM, SINET, Telcotech, and Digi confirmed to have been affected.
  • November 8th 2018 at 06:45

US Cyber Command starts uploading foreign APT malware to VirusTotal

USCYBERCOM said it plans to regularly upload "unclassified malware samples" to VirusTotal.
  • November 8th 2018 at 00:43

Cisco removed its seventh backdoor account this year, and that's a good thing

Seventh backdoor account discovered in Cisco Small Business Switches firmware.
  • November 7th 2018 at 21:00

Dutch police snoop on criminal chats by intercepting encryption server

Law enforcement says they were able to read over 250,000 messages.
  • November 7th 2018 at 16:10

IoT botnet infects 100,000 routers to send Hotmail, Outlook, and Yahoo spam

Botnet infects routers and uses them to relay connections to webmail services.
  • November 7th 2018 at 16:07

University shuts down network to thwart Bitcoin cryptojacking scheme

The network and the university's power were used covertly to mine for cryptocurrency.
  • November 7th 2018 at 12:23

WordPress, WooCommerce flaws combine to allow website hijacking

A problem in how WordPress handles privileges can be exploited to take control of domains.
  • November 7th 2018 at 11:11

This is how artificial intelligence will become weaponized in future cyberattacks

Real-time, autonomous decisions are only some of the techniques AI can bring to the table.
  • November 7th 2018 at 10:00

Ultimate Nirvana - Application Security Weekly #38

By paul@securityweekly.com

This week, Keith and Paul interview Daniel Cuthbert, Global Head of Security Research for Banco Santander! In the Application Security News, a nasty DHCPv6 packet can Pwn vulnerable Linux Boxes, 'Stalkerware' website let anyone intercept texts of tens of thousands of people, twelve malicious Python libraries found and removed from PyPI, the U.S. Department of Defense Guide for "Detecting Agile BS", and more!

Β 

Full Show Notes: https://wiki.securityweekly.com/ASW_Episode38

Visit https://www.securityweekly.com/asw for all the latest episodes!

Visit https://www.activecountermeasures/asw to sign up for a demo or buy our AI Hunter!

Β 

Visit our website: https://www.securityweekly.com

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

  • November 7th 2018 at 10:00

Microsoft, Google apps feature in the top 20 vulnerabilities in enterprise environments

The most severe web browser bugs have the potential to disrupt up a third of enterprise environments.
  • November 7th 2018 at 09:00

VirtualBox zero-day published by disgruntled researcher

Russian researcher publishes detailed write-up for VirtualBox zero-day on GitHub after Oracle took 15 months to fix a previous similar issue.
  • November 7th 2018 at 08:58

Google's automated fuzz bot has found over 9,000 bugs in the past two years

Google improves OSS-Fuzz service, plans to invite new open source projects to join.
  • November 7th 2018 at 00:56

Hackers breach StatCounter to hijack Bitcoin transactions on Gate.io exchange

StatCounter has fixed the issue and Gate.io has removed the script from its site.
  • November 6th 2018 at 16:54

HSBC discloses security incident

Bank appears to have fallen victim to credential stuffing attack.
  • November 6th 2018 at 14:28

Ahead of US midterms, Facebook removes 30 accounts and 85 Instagram profiles

Facebook says it acted after a tip it received on Sunday from US law enforcement.
  • November 6th 2018 at 13:45

BGP attacks hijack Telegram traffic in Iran

With so many users in Iran, it's unsurprising that potentially state-sponsored groups would want an access point into the banned app.
  • November 6th 2018 at 11:44

Evernote for Windows patch resolves stored XSS vulnerability

The severe flaw permitted attackers to create a persistent XSS issue.
  • November 6th 2018 at 10:18

Cookin' Some Stuff Up - Business Security Weekly #105

By paul@securityweekly.com

This week, Paul and Matt interview CISO Alex Wood! He joins us to talk about the business mind set, how to be an effective CISO, and the vulnerabilities in the business that you have to watch out for! In the Article Discussion on Leadership, Communication, and Innovation, Matt and Paul talk how getting fired can be good for your career, a powerful planning routine that puts you in control, how to get better with sales execution, why you need a theme, not goals, and more on this episode of Business Security Weekly!

Β 

Full Show Notes: https://wiki.securityweekly.com/BSWEpisode105

Visit https://www.securityweekly.com/bsw for all the latest episodes!

Visit https://www.activecountermeasures/bsw to sign up for a demo or buy our AI Hunter!!

Β 

Visit our website: https://www.securityweekly.com

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

  • November 6th 2018 at 10:00

Back Together - Business Security Weekly #101

By paul@securityweekly.com

This week, Michael and Paul interview Jason Albuquerque, CISO at Carousel Industries! Jason explains how to run your security team as in a 'fish bowl', and how to apply this technique to your clients and their business! In our second segment, they discuss how to develop empathy for someone who annoys you, separating the quality of the outcome and quality of the decision, and much more!

Β 

Full Show Notes: https://wiki.securityweekly.com/BSWEpisode101

Visit https://www.securityweekly.com/bsw for all the latest episodes!

Visit https://www.activecountermeasures/bsw to sign up for a demo or buy our AI Hunter!!

Β 

Visit our website: https://www.securityweekly.com

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

  • October 8th 2018 at 09:00

Oracle confirms China Telecom internet traffic 'misdirections'

Oracle's Internet Intelligence division partially confirms controversial US Naval War College research paper.
  • November 6th 2018 at 06:00

States activate National Guard cyber units for US midterm elections

National Guard cyber units activated in Washington, Illinois, and, more recently, Wisconsin.
  • November 5th 2018 at 22:44

Google Chrome 71 will continue crackdown on sites with abusive ads

Google says previous ad blocking protections only blocked half of the abusive sites it wanted to block.
  • November 5th 2018 at 18:41

Flaws in self-encrypting SSDs let attackers bypass disk encryption

Master passwords and faulty standards implementations allow attackers access to encrypted data without needing to know the user-chosen password.
  • November 5th 2018 at 17:05

Microsoft working on porting Sysinternals to Linux

Microsoft engineers have already ported the ProcDump utility and are currently working on porting ProcMon as well. More tools to follow.
  • November 5th 2018 at 12:18

Republican rival puts Georgia's Democratic Party under investigation for 'cyber crimes'

Hacking claims don't seem to hold water when considering the state's previous accusations.
  • November 4th 2018 at 22:34

Android news and kids apps contain the most third-party trackers

Over 20 child advocacy groups have sent a letter to the FTC regarding advertising in kids apps.
  • November 3rd 2018 at 16:28

Buckle Up! - Paul's Security Weekly #581

By paul@securityweekly.com

This week, we welcome Aleksei Tiurin, Senior Security Researcher at Acunteix for a Technical Segment on Insecure Deserialization in Java/JVM! In our second Technical Segment, we welcome Matt Toussain, Security Analyst at Black Hills Information Security to talk about RAS! In the security news, Bleedingbit Vulnerabilities, Cisco Zero-Day exploited in the wild, Researchers find Flaws in chips used in hospitals, US Governments network infected with Russian Malware, and the Weird Trick that turns your Google Home Hub into a Doorstep!

Β 

Full Show Notes: https://wiki.securityweekly.com/Episode581

Visit https://www.securityweekly.com/psw for all the latest episodes!

Β 

β†’Visit https://www.activecountermeasures/psw to sign up for a demo or buy our AI Hunter!!

β†’Follow us on Twitter: https://www.twitter.com/securityweekly

β†’Like us on Facebook: https://www.facebook.com/secweekly

  • November 3rd 2018 at 09:00

Two botnets are fighting over control of thousands of unsecured Android devices

Researchers spot Trinity and Fbot botnets trying to infect Android devices via the ADB interface.
  • November 2nd 2018 at 22:29

Hackers are increasingly destroying logs to hide attacks

According to a new report, 72 percent of incident response specialists have came across hacks where attackers have destroyed logs to hide their tracks.
  • November 2nd 2018 at 16:36

Intel CPUs impacted by new PortSmash side-channel vulnerability

Vulnerability confirmed on Skylake and Kaby Lake CPU series. Researchers suspect AMD processors are also impacted.
  • November 2nd 2018 at 12:19

Magecart claims fresh victim in electronics kit seller Kitronik

Kitronik says a recent data breach is the work of the same group which hacked British Airways and Newegg.
  • November 2nd 2018 at 12:14
❌