FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayYour RSS feeds

Good Ol' Days - Application Security Weekly #41

By paul@securityweekly.com

This week, Keith and Paul interview Brent Dukes! Brent is a hacker, and Director of Information Security for an established manufacturing company. He joins Keith and Paul this week to talk about WAF’s, Pentesting, Burp Suite, and more! In the Application Security News, Hackers use Drupalgeddon 2 and Dirty COW exploits to take over web servers, second WordPress hacking campaign underway, USPS took a year to fix a vulnerability that exposed all 60 million users' data, this JavaScript can snoop on other Browser Tabs to work out what you're visiting, and more!

Β 

Full Show Notes: https://wiki.securityweekly.com/ASW_Episode41

Visit https://www.securityweekly.com/asw for all the latest episodes!

Visit https://www.activecountermeasures/asw to sign up for a demo or buy our AI Hunter!

Β 

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

  • November 28th 2018 at 10:00

FBI dismantles gigantic ad fraud scheme operating across over one million IPs

DOJ also charged eight suspects. Three suspects have already been arrested.
  • November 28th 2018 at 05:49

Hack Naked News #198 - November 27, 2018

By paul@securityweekly.com

This week, disastrous Rowhammer bitflips, malicious developer steals Bitcoin with NodeJS module, Germany proposes router security guidelines, Uber fined 148$ Million for data breach cover-up, Microsoft yanks two buggy Office patches, and a malware advertising campaign that impacts millions of iOS users! Jason Wood from Paladin Security joins us for Expert Commentary to discuss how the FBI created a fake FedEx website to unmask a cybercriminal, and more on this episode of Hack Naked News!

Β 

Full Show Notes: https://wiki.securityweekly.com/HNNEpisode198

Visit https://www.securityweekly.com/hnn for all the latest episodes!

Visit https://www.activecountermeasures/hnn to sign up for a demo or buy our AI Hunter!

Β 

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

  • November 27th 2018 at 23:20

Seven GDPR complaints filed against Google over user location tracking

GDPR complaints have been filed today against Google in the Netherlands, Poland, the Czech Republic, Greece, Norway, Slovenia, and Sweden.
  • November 27th 2018 at 20:33

Android adware has plagued the Google Play Store in the past two months

Security researchers unearth several adware campaigns distributed via apps available through the official Google Play Store.
  • November 27th 2018 at 17:27

This worm spreads a fileless version of the Trojan Bladabindi

The malware is capable of keylogging, spying, and far more.
  • November 27th 2018 at 13:45

Evidence of Absence - Business Security Weekly #108

By paul@securityweekly.com

This week, we welcome Richard Seiersen, former Chief Information Security Officer at Lending Club and Twilio to talk about his CISO experience, and the book Richard co-authored called, "How to Measure Anything in Cybersecurity Risk"! In the Leadership and Communications segment, the million-dollar question of cyber-risk, risk assessments essential to secure third-party vendor management, how digital tech is transforming business ecosystem, and more!

Β 

Full Show Notes: https://wiki.securityweekly.com/BSWEpisode108

Β 

Visit https://www.securityweekly.com/bsw for all the latest episodes!

Visit https://www.activecountermeasures/bsw to sign up for a demo or buy our AI Hunter!

Β 

Visit our website: https://www.securityweekly.com

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

  • November 27th 2018 at 10:00

US iOS users targeted by massive malvertising campaign

A malvertising campaign deployed via a high-profile ad platform targeted iOS users across the US. Crooks hijacked over 300 million web sessions.
  • November 27th 2018 at 00:05

Hacker backdoors popular JavaScript library to steal Bitcoin funds

Users of BitPay's Copay desktop and mobile wallet apps are affected. An update has been released earlier today that doesn't contain the malicious code.
  • November 26th 2018 at 20:31

UK cops won't go after researcher who reported security issue to York city officials

York city officials face backlash after reporting security researcher who found a bug in one of their mobile apps to law enforcement.
  • November 26th 2018 at 17:14

UK gov't seizes documents Facebook wanted to keep private in Cambridge Analytica battle

It appears that the UK parliament will not stand for being ignored by Mark Zuckerberg any longer.
  • November 26th 2018 at 09:16

Germany proposes router security guidelines

German government would like to regulate what kind of routers are sold and installed across the country.
  • November 26th 2018 at 05:25

New Linux crypto-miner steals your root password and disables your antivirus

Trojan also installs a rootkit and another strain of malware that can execute DDoS attacks.
  • November 23rd 2018 at 19:19

Ukrainian police arrest hacker who infected over 2,000 users with DarkComet RAT

Suspect was most likely hosting the RAT's command and control server on his home computer.
  • November 23rd 2018 at 12:33

Rowhammer attacks can now bypass ECC memory protections

Attack works against ECC memory included with DDR3 memory, but researchers believe DDR4 is also vulnerable.
  • November 22nd 2018 at 15:11

SIM-swapping 21-year-old scores $1 million by hijacking a phone

The man reportedly targeted well-known business leaders, making off with one victim's life savings.
  • November 22nd 2018 at 12:54

How Dropbox's red team discovered an Apple zero-day exploit chain by accident

The zero-day vulnerabilities were accidentally uncovered while researchers were looking for ways to break into Dropbox.
  • November 22nd 2018 at 10:54

Shutting the Brain Off - Enterprise Security Weekly #116

By paul@securityweekly.com

This week, John Strand makes his triumphant return to join Paul and interview Rick Fernandez, Senior Sales Engineer at LogRhythm to talk about Choosing the Best Option for MSSPS! In the Enterprise News this week, Israeli cybersecurity company Tufin plans Nasdaq IPO, F-Secure boosts endpoint detection and response, Mimecast joins IBM Security app exchange community, and Awake Security debuts Network Traffic Analysis Platform to detect risks! In the Final Segment, we air some interviews we recorded at DEF CON and Black Hat 2018 with Irdeto, Venafi, and HP!

Β 

Full Show Notes: https://wiki.securityweekly.com/ES_Episode116

To learn more about LogRhythm, go to: www.LogRhythm.com

For the Full DefCon18 Playlist, go to: https://securityweekly.com/summercamp18

Β 

Visit https://www.securityweekly.com/esw for all the latest episodes!

Visit https://www.activecountermeasures/esw to sign up for a demo or buy our AI Hunter!

Β 

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

Β 

  • November 22nd 2018 at 10:00

Facebook appeals Β£500,000 penalty over Cambridge Analytica scandal

The fine, imposed by the ICO, was the maximum permitted under old data protection laws.
  • November 22nd 2018 at 09:05

Emotet malware runs on a dual infrastructure to avoid downtime and takedowns

Researchers spot unique design in the server infrastructure propping up the Emotet malware.
  • November 22nd 2018 at 06:00

City of Valdez, Alaska admits to paying off ransomware infection

City IT network was infected by Hermes ransomware, a strain that researchers previously tied to other North Korean malware and hacking tools.
  • November 21st 2018 at 23:23

Facebook entices researchers with $40,000 reward for account takeover vulnerabilities

It's not surprising considering Facebook's recent run-ins with account security problems.
  • November 21st 2018 at 17:21

German eID card system vulnerable to online identity spoofing

Vulnerability in web library lets attackers spoof electronic ID card identities.
  • November 21st 2018 at 16:59

Amazon leaks users' email addresses due to 'technical error'

Company has notified today all impacted customers.
  • November 21st 2018 at 15:00

L0rdix becomes the new Swiss Army knife of Windows hacking

The new tool combines data theft and cryptocurrency mining as a go-to product for attacking Windows machines.
  • November 21st 2018 at 12:27

Buffet Overflow - Application Security Weekly #40

By paul@securityweekly.com

This week, Keith and Paul interview John Kinsella, Vice President of Container Security at Qualys! John discusses Qualys’ Container Security, continuous discovery, and tracking for containers and images! In the Application Security News, Instagram leaks passwords to the public, Clickjacking on Google MyAccount Worth $7,500, James Wickett's thread on Open Source SAST options, an advanced search tool for sensitive information stored in GitHub repos, and more!

Β 

Full Show Notes: https://wiki.securityweekly.com/ASW_Episode40

Visit https://www.securityweekly.com/asw for all the latest episodes!

Visit https://www.activecountermeasures/asw to sign up for a demo or buy our AI Hunter!

Β 

Visit our website: https://www.securityweekly.com

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

  • November 21st 2018 at 10:00

Magecart group hilariously sabotages competitor

...but it's still stealing your card data.
  • November 20th 2018 at 23:41

Hack Naked News #197 - November 20, 2018

By paul@securityweekly.com

This week, what happens when support won't change your password, Gmail glitch Phishing Attacks, stopping the Infiltration of Things, Make-A-Wish website serves a Cryptojacking Script, Instagram exposes user passwords, and DirtyCOW is back in backdoor attack targeting Drupal Web Servers! Jason Wood from Paladin Security joins us for expert commentary to discuss how Ford is eyeing the use of customers personal data to boost profits!

Β 

Full Show Notes: https://wiki.securityweekly.com/HNNEpisode197

Visit https://www.securityweekly.com/hnn for all the latest episodes!

Visit https://www.activecountermeasures/hnn to sign up for a demo or buy our AI Hunter!

Β 

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

  • November 20th 2018 at 21:36

Cyber-security firm doxxes hacker who sold MySpace and Dropbox databases in 2016

Recorded Future claims Tessa88's identity is a 29-year-old Russian named Maksim Vladimirovich Donakov.
  • November 20th 2018 at 20:57

Second WordPress hacking campaign underway, this one targeting AMP for WP plugin

After targeting WP GDPR Compliance plugin, hackers are now going after sites using the AMP for WP plugin.
  • November 20th 2018 at 16:38

IRS failed to apply consumer protections for 11,406 taxpayers

IRS operators failed to record data of US taxpayers inside an IRS fraud detection system.
  • November 20th 2018 at 14:37

Fake Google Android driving apps claim half a million victims

The illegitimate apps include luxury car and motocross simulations.
  • November 20th 2018 at 13:45

Better Connected - Business Security Weekly #107

By paul@securityweekly.com

This week, we welcome Michael Pleasant, Chief Executive Officer and Founder at Open Security for an interview! They discuss transferring from Marine training to a business environment, and his company Open Security! In the Article Discussion, Special Guest Co-Host Jason Alburquerque joins me in studio to discuss Six ways you can establish which goals are important, How to diversify your professional network, the impact of perception and bias on leadership, and more on this episode of Business Security Weekly!!

Β 

Full Show Notes: https://wiki.securityweekly.com/BSWEpisode107

Visit https://www.securityweekly.com/bsw for all the latest episodes!

Visit https://www.activecountermeasures/bsw to sign up for a demo or buy our AI Hunter!

Β 

Visit our website: https://www.securityweekly.com

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

  • November 20th 2018 at 10:00

For Apple users without latest security updates, the letter 'd' is not always the letter 'd'

Apple users advised to install the company's July security updates if they don't want to fall victims to IDN homograph phishing attacks.
  • November 20th 2018 at 05:30

Hackers use Drupalgeddon 2 and Dirty COW exploits to take over web servers

Hacks could be easily avoided if people would patch their Drupal CMSs and Linux web servers.
  • November 19th 2018 at 20:51

Russia wants DNC hack lawsuit thrown out, citing international conventions

Russian Federation says it benefits from the same legal protections as the US does when carrying out military cyberattacks.
  • November 19th 2018 at 18:17

A bug in EA Origin client exposes gamers' data

Auto-login URL feature was not IP-bound and allowed anyone access to accounts' settings panels.
  • November 19th 2018 at 16:55

Vision Direct reveals customer credit card leak, fake Google script may be to blame

Updated: The personal and financial data of customers has been stolen.
  • November 19th 2018 at 13:48

Russian hacker arrested in Bulgaria for ad fraud of over $7 million

Alexander Zhukov, a supposed hacker who went online by the name of "Nastra," is currently fighting extradition to the US.
  • November 19th 2018 at 13:01

Texas hospital becomes victim of Dharma ransomware

The spread of malware through Altus Baytown Hospital systems highlights the ongoing threat ransomware poses to our healthcare.
  • November 19th 2018 at 12:12

Website geoblocking is not that widespread, study finds

Iran, Sudan, Syria, and Cuba are the most geoblocked countries.
  • November 19th 2018 at 05:45

Popular Dark Web hosting provider got hacked, 6,500 sites down

Hosting provider is still looking for the hacker's point of entry.
  • November 17th 2018 at 21:39

PCI PiΓ±ata - Paul's Security Weekly #583

By paul@securityweekly.com

This week, we welcome Jon Buhagiar, Network+ Review Course Instructor at Sybex for an interview to talk about Network Operations! In the Technical Segment, we welcome back John Moran, Senior Product Manager at DFLabs to talk about IncMan SOAR and how DFLabs Automation & Response platform helps automate, orchestrate, and measure CSIRTs and SOCs! In the Security News this week, 7 new Spectre/Meltdown attacks, Hacking ATM's for free cash is easier than Windows XP, AI can now fake fingerprints fooling ID scanners, and Japan's cybersecurity minister admits he's never used a computer!

Β 

Full Show Notes: https://wiki.securityweekly.com/Episode583

To learn more about DFLabs, go to: www.dflabs.com/securityweekly

Β 

Visit https://www.securityweekly.com/psw for all the latest episodes!

Visit https://www.activecountermeasures/psw to sign up for a demo or buy our AI Hunter!

Β 

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

  • November 17th 2018 at 10:00

Russian APT comes back to life with new US spear-phishing campaign

Cozy Bear (APT29) makes a comeback after last year's Dutch and Norwegian hacking campaigns.
  • November 16th 2018 at 23:40

Google Play Protect analyzes every Android app that it can find on the internet

Play Protect, a security service included in the Play Store app, lives up to all the hype that Google created last year.
  • November 16th 2018 at 18:28

AWS rolls out new security feature to prevent accidental S3 data leaks

New settings will prevent accidental S3 bucket leaks --if customers take the time to apply them.
  • November 16th 2018 at 15:33

Most antivirus programs fail to detect this cryptocurrency-stealing malware

Traditional antivirus software has a tough time detecting malware used in the campaign.
  • November 16th 2018 at 12:59

Winter Olympic Games hackers are back with an updated arsenal

The group behind Olympic Destroyer are back with an evolved toolkit and malware droppers.
  • November 16th 2018 at 11:58

Malicious code hidden in advert images cost ad networks $1.13bn this year

So-called steganography is rapidly becoming a favored tool of fraudsters.
  • November 16th 2018 at 10:44

Most ATMs can be hacked in under 20 minutes

Experts tested ATMs from NCR, Diebold Nixdorf, and GRGBanking.
  • November 16th 2018 at 05:30

Google to pay JavaScript frameworks to implement performance-first code

Google to create $200,000 fund to sponsor the addition of "on by default" performance-related updates in popular JavaScript frameworks.
  • November 15th 2018 at 22:40

DOD disables file sharing service due to 'security risks'

AMRDEC SAFE portal had been to handle the transfer of non-classified materials.
  • November 15th 2018 at 17:21

Japanese cybersecurity minister finds computers a mystery

The man in charge of cybersecurity not only said he does not use a PC but seemed stumped when asked about risks associated with USB drives.
  • November 15th 2018 at 11:47

A Picture of the World - Enterprise Security Weekly #115

By paul@securityweekly.com

This week, Paul and Matt Alderman interview James Wickett, Head of Research at Signal Sciences! James talks about how security is moving to the application space and web applications! In the Enterprise News this week, AlgoSec delivers Native Cloud Security Management for Azure, HP Reinvents customer experience with Ping Identity, what mid market security budgets will look like in 2019, and we have some acquisition & funding updates from ForeScout, Dragos, Netskope, Duality, and more!

Β 

Full Show Notes: https://wiki.securityweekly.com/ES_Episode115

To learn more about Signal Sciences, go to: www.signalsciences.com/psw

Β 

Visit https://www.securityweekly.com/esw for all the latest episodes!

Visit https://www.activecountermeasures/esw to sign up for a demo or buy our AI Hunter!

Β 

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

  • November 15th 2018 at 10:00

One in five Magecart-infected stores get reinfected within days

A large number of reinfections take place within a day or week. Average reinfection time is 10.5 days.
  • November 15th 2018 at 06:30

Dutch government report says Microsoft Office telemetry collection breaks GDPR

Microsoft pledges to address issues; has already released a "zero exhaust" Office telemetry setting.
  • November 14th 2018 at 23:00

Many free mobile VPN apps are based in China or have Chinese ownership

Chinese affiliation raises a sign of alarm in light of China's recent clampdown of "unauthorized" VPN services.
  • November 14th 2018 at 19:29
❌