FreshRSS

๐Ÿ”’
โ˜ โ˜† โœ‡ Paul's Security Weekly

Release the Edge - Paul's Security Weekly #571

By paul@securityweekly.com โ€” August 18th 2018 at 09:00

This week, our very own Larry Pesce delivers the Technical Segment on Spoofing GPS with a hackRF! In the Security News, Hacking Police Bodycams, Adobe execution flaws, Google expands to Bug Bounty Program, and if you live in Australia, you could face ten years in jail if you don't unlock your phone! In our final segment, we air our pre-recorded interview with Paul and Matt Alderman from DEF CON on Cigars and Security!

Full Show Notes: https://wiki.securityweekly.com/Episode571

ย 

Visit https://www.securityweekly.com/psw for all the latest episodes!

ย 

โ†’Visit https://www.activecountermeasures/psw to sign up for a demo or buy our AI Hunter!!

โ†’Follow us on Twitter: https://www.twitter.com/securityweekly

โ†’Like us on Facebook: https://www.facebook.com/secweekly

โ˜ โ˜† โœ‡ ZDNet | security RSS

EU considers 60-minute deadline for social networks to remove terrorist content

August 20th 2018 at 06:12
The commission says that not enough progress has been made in stamping out extremist content.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Coinbase files patent for freeze logic cryptocurrency wallet security

August 20th 2018 at 07:07
The invention aims to add a fresh layer of security to wallets used directly for merchant payments.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Alleged head of BitConnect cryptocurrency scam arrested in Dubai

August 20th 2018 at 08:35
BitConnect has been accused of operating an exit scam after duping investors out of millions of rupees.
โ˜ โ˜† โœ‡ ZDNet | security RSS

UK hacking prosecutions plummet with only 47 charges recorded last year

August 20th 2018 at 12:19
A lack of resources is believed to be partly to blame for incredibly low prosecution figures.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Philips reveals code execution vulnerabilities in cardiovascular devices

August 21st 2018 at 08:33
Only a low level of skill is required to exploit the bugs.
โ˜ โ˜† โœ‡ Paul's Security Weekly

This Magical Thing - Business Security Weekly #96

By paul@securityweekly.com โ€” August 21st 2018 at 09:00

This week, Paul and Matt Alderman interview Sharon Goldberg, CEO/Co-Founder of Commonwealth Crypto, and makes her return to Security Weekly! In our final segment, we air a pre-recorded segment with Matt Alderman and Paul live from DEF CON, discussing different vendors and CEOโ€™s they had a chance to sit down with explaining their products and marketing in the security industry!

Full Show Notes: https://wiki.securityweekly.com/BSWEpisode96

ย 

Visit https://www.securityweekly.com/bsw for all the latest episodes!

ย 

Visit https://www.activecountermeasures/bsw to sign up for a demo or buy our AI Hunter!!

ย 

โ†’Visit our website: https://www.securityweekly.com

โ†’Follow us on Twitter: https://www.twitter.com/securityweekly

โ†’Like us on Facebook: https://www.facebook.com/secweekly

โ˜ โ˜† โœ‡ ZDNet | security RSS

McAfee: Calling Bitfi unhackable may have been 'unwise' but it was great marketing

August 21st 2018 at 10:33
Updated: The "unhackable" wallet saga may have been little more than salesmanship designed to provoke controversy.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Guns are already on UK streets. 3D printing could make things far worse.

August 21st 2018 at 12:27
Opinion: With 3D gun blueprints now available for download, it's potentially too late to stop the future impact on the streets of London.
โ˜ โ˜† โœ‡ Paul's Security Weekly

Hack Naked News #185 - August 21, 2018

By paul@securityweekly.com โ€” August 21st 2018 at 21:05

This week, Hacking Blackhat Badges, USB Harpoons (not the ale), PHP attacks, privacy in Las Vegas hotels, or not, who is looking at your DNS requests?, AWS breaches. Jason Wood from Paladin Security joins us for expert commentary on Social networks getting fined for hosting terrorist content so stay tuned to this episode of Hack Naked News!

ย 

Full Show Notes: https://wiki.securityweekly.com/HNNEpisode185

ย 

Visit https://www.securityweekly.com/hnn for all the latest episodes!

Visit https://www.activecountermeasures/hnn to sign up for a demo or buy our AI Hunter!!

ย 

โ†’Visit our website: https://www.securityweekly.com

โ†’Follow us on Twitter: https://www.twitter.com/securityweekly

โ†’Like us on Facebook: https://www.facebook.com/secweekly

โ˜ โ˜† โœ‡ ZDNet | security RSS

Adobe releases out of schedule remote code execution fix

August 22nd 2018 at 08:50
The patch resolves two critical flaws which can both lead to remote code execution.
โ˜ โ˜† โœ‡ Paul's Security Weekly

Always More to Learn - Application Security Weekly #29

By paul@securityweekly.com โ€” August 22nd 2018 at 09:00

This week, Keith and Paul interview Tom McLaughlin, Founder of ServerlessOps! In the final segment, we air a Pre-Recorded segment with Paul and Matt Alderman, as they sat down at DEF CON to talk all things AppSec, vendors that were there, and companies they had briefings with from our pool cabana!

ย 

Full Show Notes: https://wiki.securityweekly.com/ASW_Episode29

ย 

Visit https://www.securityweekly.com/asw for all the latest episodes!

ย 

Visit https://www.activecountermeasures/asw to sign up for a demo or buy our AI Hunter!

ย 

โ†’Visit our website: https://www.securityweekly.com

โ†’Follow us on Twitter: https://www.twitter.com/securityweekly

โ†’Like us on Facebook: https://www.facebook.com/secweekly

โ˜ โ˜† โœ‡ ZDNet | security RSS

Hacker holds the data of 20,000 Superdrug customers to ransom

August 22nd 2018 at 09:30
Customers are being asked to change their account passwords immediately.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Mexicans served with Dark Tequila in spyware spree

August 22nd 2018 at 10:33
The campaign has been swiping bank credentials and corporate data for years through offline malware.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Turla backdoors compromise European government foreign offices

August 22nd 2018 at 15:12
The backdoors are told what to do and what to steal by email.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Critical remote code execution flaw in Apache Struts exposes the enterprise to attack

August 22nd 2018 at 15:47
The bug was found in the core infrastructure of Apache Struts 2.
โ˜ โ˜† โœ‡ ZDNet | security RSS

AppleJeus: macOS users targeted in new Lazarus attacks

August 23rd 2018 at 08:00
The campaign includes the distribution of Apple macOS malware for the first time.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Facebook's Onavo VPN app removed from Apple App Store over privacy concerns

August 23rd 2018 at 08:58
Reports suggest the app was removed based on a request from Apple.
โ˜ โ˜† โœ‡ Paul's Security Weekly

Seems So Rare - Enterprise Security Weekly #103

By paul@securityweekly.com โ€” August 23rd 2018 at 09:00

This week, Paul and John Strand interview Mike Jones, VP of Product at DomainTools! In our final segments, we air the last of our Pre-Recorded interviews with Paul and Matt Alderman LIVE from DEF CON and Black Hat, discussing different security vendors they encountered at biggest security conferences in the country!

ย 

Full Show Notes: https://wiki.securityweekly.com/ES_Episode103

ย 

Visit https://www.securityweekly.com/esw for all the latest episodes!

Visit https://www.activecountermeasures/eswย to sign up for a demo or buy our AI Hunter!

ย 

โ†’Visit our website: https://www.securityweekly.com

ย 

โ†’Follow us on Twitter: https://www.twitter.com/securityweekly

โ†’Like us on Facebook: https://www.facebook.com/secweekly

โ˜ โ˜† โœ‡ ZDNet | security RSS

Medical records of high school students leaked in 'appalling' data breach

August 23rd 2018 at 09:49
Medication, healthcare records, and conditions were all posted online for the world to see.
โ˜ โ˜† โœ‡ ZDNet | security RSS

500,000 Cheddar's Scratch Kitchen customers involved in possible credit card data theft

August 24th 2018 at 08:21
Customers of the restaurant chain need to keep an eye on their bank accounts as their information may be up for sale.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Hackers help themselves to data belonging to 2 million T-Mobile customers

August 24th 2018 at 09:17
The "international" threat actors managed to capture a set of customer data before being shut down.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Spyware firm SpyFone leaves customer data, recordings exposed online

August 24th 2018 at 10:21
Thousands of spyware users and those being monitored have had their information leaked to the public domain.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Iranian hackers target 70 universities worldwide to steal research

August 24th 2018 at 13:00
Researchers say the campaign is focused on stealing credentials and access to library systems.
โ˜ โ˜† โœ‡ Paul's Security Weekly

The Infinite Window - Paul's Security Weekly #572

By paul@securityweekly.com โ€” August 25th 2018 at 09:00

This week, Paul and the crew sit down with Tod Beardsley, Director of Research at Rapid7 for an interview! Sven Morgenroth, Security Researcher at Netsparker delivers the Technical Segment on PHP Type Juggling Vulnerabilities! In the Security News this week, The Untold story of NotPetya, New Apache Struts RCE Flaw, How door cameras are creating dilemmas for police, Google gets sued for tracking you even when your location history is off, and Artificial Whiskey is coming, and one company is betting you'll drink up! All that and more on this episode of Paulโ€™s Security Weekly!

Full Show Notes: https://wiki.securityweekly.com/Episode572

ย 

Visit https://www.securityweekly.com/psw for all the latest episodes!

ย 

โ†’Visit https://www.activecountermeasures/psw to sign up for a demo or buy our AI Hunter!!

โ†’Follow us on Twitter: https://www.twitter.com/securityweekly

โ†’Like us on Facebook: https://www.facebook.com/secweekly

โ˜ โ˜† โœ‡ ToolsWatch.org โ€“ The Hackers Arsenal Tools Portal

Blackhat Arsenal Europe 2018 CFT Open

By NJ Ouchn โ€” August 27th 2018 at 10:49
The Black Hat Arsenal team is heading to London with the very same goal: give hackers & security researchers the opportunity to demo their newest and latest code. The Arsenal tool demo area is...

[[ This is a content summary only. Visit my website for full links, other content, and more! ]]
โ˜ โ˜† โœ‡ ZDNet | security RSS

How hackers managed to steal $13.5 million in Cosmos bank heist

August 27th 2018 at 12:00
An in-depth look into the incident reveals how the 112-year-old bank may have been swindled out of millions.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Microsoft Windows zero-day vulnerability disclosed through Twitter

August 28th 2018 at 08:19
Updated: There is no known workaround for the security flaw.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Fortnite Epic Games CEO rails against Google vulnerability disclosure

August 28th 2018 at 08:36
Circumventing the Google Play Store has not gone completely to plan.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Facebook patches critical server remote code execution vulnerability

August 28th 2018 at 09:41
The exploit took advantage of instability in the server's system.
โ˜ โ˜† โœ‡ ZDNet | security RSS

WhatsApp warns free Google Drive backups are not end-to-end encrypted

August 28th 2018 at 10:23
The storage deal might be free for users, but that does not mean communications records are protected in the same way.
โ˜ โ˜† โœ‡ Paul's Security Weekly

Hack Naked News #186 - August 28, 2018

By paul@securityweekly.com โ€” August 28th 2018 at 20:13

This week, AT commands will pwn your phone, Adobe gets creative with an update, protecting your pin, why companies should use the Google Play store, 0-day Windows vulnerabilities disclosed on Twitter, and side-channel attacks that can be mitigated with tin foil. Jason Wood from Paladin Security joins us for expert commentary on an Enterprise version of Burp on the way, so stay tuned for this episode of Hack Naked News!

ย 

Full Show Notes: https://wiki.securityweekly.com/HNNEpisode186

ย 

Visit https://www.securityweekly.com/hnn for all the latest episodes!

Visit https://www.activecountermeasures/hnnย to sign up for a demo or buy our AI Hunter!!

ย 

โ†’Visit our website: https://www.securityweekly.com

โ†’Follow us on Twitter: https://www.twitter.com/securityweekly

โ†’Like us on Facebook: https://www.facebook.com/secweekly

โ˜ โ˜† โœ‡ Paul's Security Weekly

An Interesting Journey - Business Security Weekly #97

By paul@securityweekly.com โ€” August 28th 2018 at 21:00

This week, Paul is joined by Dr. Doug White to interview Todd Weller, Chief Security Officer at Bandura Systems! In the Tracking Security Innovation segment, Paul and Doug talk about updates from ย AlienVault, Cloudera, Splunk, CA, and more on this episode of Business Security Weekly!

Full Show Notes: https://wiki.securityweekly.com/BSWEpisode97

ย 

Visit https://www.securityweekly.com/bsw for all the latest episodes!

ย 

Visit https://www.activecountermeasures/bsw to sign up for a demo or buy our AI Hunter!!

ย 

โ†’Visit our website: https://www.securityweekly.com

โ†’Follow us on Twitter: https://www.twitter.com/securityweekly

โ†’Like us on Facebook: https://www.facebook.com/secweekly

โ˜ โ˜† โœ‡ Paul's Security Weekly

A Mixture of Spices - Application Security Weekly #30

By paul@securityweekly.com โ€” August 29th 2018 at 09:00

This week, Keith and Paul discuss The Apache Struts2 RCE Vulnerability! In the news, Using Signal Sciences to defend against Apache Struts, PHP flaw puts WordPress sites at risk, Oracle will charge for Java starting in 2019, how Netflix does Failovers in 7 minutes flat, Burp Suite 2.0 Beta released, even anonymous coders leave fingerprints, and more on this episode of Application Security Weekly!

ย 

Full Show Notes: https://wiki.securityweekly.com/ASW_Episode30

ย 

Visit https://www.securityweekly.com/asw for all the latest episodes!

ย 

Visit https://www.activecountermeasures/asw to sign up for a demo or buy our AI Hunter!

ย 

โ†’Visit our website: https://www.securityweekly.com

โ†’Follow us on Twitter: https://www.twitter.com/securityweekly

โ†’Like us on Facebook: https://www.facebook.com/secweekly

โ˜ โ˜† โœ‡ ZDNet | security RSS

Meet the malware which hijacks your browser and redirects you to fake pages

August 29th 2018 at 09:25
The malware is currently being distributed through the RIG exploit kit.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Defense Distributed now sells 3D gun blueprints online, 'pay what you want'

August 29th 2018 at 10:16
Founder Cody Wilson insists that a recent court injunction is still being obeyed, despite the launch.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Air Canada reveals mobile data breach, passport numbers potentially exposed

August 30th 2018 at 08:32
Passport details belonging to thousands of customers may have been exposed in the incident.
โ˜ โ˜† โœ‡ Paul's Security Weekly

Sprinkler System Twinkies - Enterprise Security Weekly #104

By paul@securityweekly.com โ€” August 30th 2018 at 09:00

This week, Paul and John Strand interview Rick Holland, CISO at Digital Shadows! In our Technical Segment, John Strand talks about Office 365 User Behavior Analytics! In the Enterprise News this week, we have updates from VMware, Caveonix, Qualys, Minerva Labs, Bitdefender, CrowdStrike, and more on this episode of Enterprise Security Weekly!

ย 

Full Show Notes: https://wiki.securityweekly.com/ES_Episode104

ย 

Visit https://www.securityweekly.com/esw for all the latest episodes!

ย 

Visit https://www.activecountermeasures/esw to sign up for a demo or buy our AI Hunter!

ย 

โ†’Visit our website: https://www.securityweekly.com

โ†’Follow us on Twitter: https://www.twitter.com/securityweekly

โ†’Like us on Facebook: https://www.facebook.com/secweekly

โ˜ โ˜† โœ‡ ZDNet | security RSS

Android 'API breaking' vulnerability leaks device data, allows user tracking

August 30th 2018 at 10:13
A vulnerability in the Android operating system can be used to track users without their knowledge.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Misfortune Cookie vulnerability returns to impact medical devices

August 30th 2018 at 11:02
The four-year-old security flaw has reared its head once again but this time medical equipment, and not routers, are at risk.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Former Qualys exec charged with insider trading after protecting brothers from financial loss

August 31st 2018 at 09:45
The former Chief Commercial Officer tipped off his family in advance of poor financial results.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Why is Google selling potentially compromised Chinese security keys?

August 31st 2018 at 19:36
Opinion: To sign up for Google's Advanced protection program, you must buy security keys from a Chinese vendor. Security questions have since been raised considering current intelligence laws in China.
โ˜ โ˜† โœ‡ Paul's Security Weekly

The Word You're Looking for Is Sodomized - Paul's Security Weekly #573

By paul@securityweekly.com โ€” September 1st 2018 at 09:00

This week, Paul and the crew sit down with Jayson Street, VP of Infosec at SphereNY for an interview! John Moran, Senior Project Manager of DFLabs delivers the Technical Segment on a new No-Script Automation Tool! In the Security News this week, 0-Day Windows exploits, How to hide sensitive files in encrypted containers, Misfortune Cookie vulnerability returns, and bank robbers faked Cosmos backend to steal 13.5$ million! All that and more, on this episode of Paulโ€™s Security Weekly!

Full Show Notes: https://wiki.securityweekly.com/Episode573

ย 

Visit https://www.securityweekly.com/psw for all the latest episodes!

ย 

โ†’Visit https://www.activecountermeasures/psw to sign up for a demo or buy our AI Hunter!!

โ†’Follow us on Twitter: https://www.twitter.com/securityweekly

โ†’Like us on Facebook: https://www.facebook.com/secweekly

โ˜ โ˜† โœ‡ ZDNet | security RSS

Meet ransomware which wears the face of former president Barack Obama

September 3rd 2018 at 09:26
The peculiar malware asks victims for a "tip" in return for a decryption key.
โ˜ โ˜† โœ‡ ZDNet | security RSS

SonarSnoop attack can steal smartphone unlock patterns

September 3rd 2018 at 09:43
SonarSnoop technique transforms smartphones into mini sonar systems to track a user's finger across the screen and steal phone unlock patterns.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Wireshark fixes serious security flaws that can crash systems through DoS

September 3rd 2018 at 10:03
Proof-of-concept code detailing related exploits has been released to the public.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Windows utility used by malware in new information theft campaigns

September 3rd 2018 at 11:06
WMIC-based payloads highlight how attackers are turning to innocuous system processes to compromise Windows machines.
โ˜ โ˜† โœ‡ ZDNet | security RSS

New Hakai IoT botnet takes aim at D-Link, Huawei, and Realtek routers

September 3rd 2018 at 14:12
Security researchers have spotted a new strain of IoT malware that has been growing in sophistication and silently infecting more and more devices online.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Premera Blue Cross accused of destroying evidence in data breach lawsuit

September 3rd 2018 at 20:07
Class-action lawsuit plaintiffs claim US health insurer Premera Blue Cross intentionally destroyed evidence despite ongoing litigation.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Bitcoin Gold delisted from major cryptocurrency exchange after refusing to pay hack damages

September 4th 2018 at 00:29
Cryptocurrency exchange Bittrex removes Bitcoin Gold trading options after BTG team refuses to pay $256,000 as reparations for May 2018 cyber-attacks
โ˜ โ˜† โœ‡ ZDNet | security RSS

Department of Labour denies server compromise in recent cyberattack

September 4th 2018 at 07:55
The government department says the attack did not expose any sensitive or confidential information.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Google open-sources internal tool for finding font-related security bugs

September 4th 2018 at 09:21
Google Project Zero releases BrokenType, a tool that found nearly 40 security bugs in Windows font rasterization components
โ˜ โ˜† โœ‡ ZDNet | security RSS

Google's campus door security blasted wide open by its own engineer

September 4th 2018 at 09:28
Malicious code sent across Google's network had some interesting results.
โ˜ โ˜† โœ‡ ZDNet | security RSS

This malware disguises itself as bank security to raid your account

September 4th 2018 at 10:00
CamuBot takes advantage of your trust in your bank to hide in plain sight.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Facebook's 'war room' hunts and destroys election meddling, fake news

September 4th 2018 at 10:47
The physical room will be tasked with protecting the network against insidious attempts to tamper with the US midterm elections.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Thousands of 3D printers may be leaking private product designs online

September 4th 2018 at 19:12
Nearly 3,800 3D printers with an OctaPrint interface were left exposed online with no password authentication, inadvertently leaking 3D models and webcam feeds.
โ˜ โ˜† โœ‡ Paul's Security Weekly

Hack Naked News #187 - September 4, 2018

By paul@securityweekly.com โ€” September 4th 2018 at 19:54

This week, Android OS API-Breaking Flaw, Thousands of MikroTik Routers Hacked, John McAfee's "unhackable" Bitcoin wallet is hackable, misconfigured 3D printers, researchers used sonar signal to steal unlock passwords, and the Linux Foundation sets to improve Open-Source code security. Ron Gula of Gula Tech Adeventures joins us for expert commentary, so stay tuned for this episode of Hack Naked News!

ย 

Full Show Notes: https://wiki.securityweekly.com/HNNEpisode187

ย 

Visit https://www.securityweekly.com/hnn for all the latest episodes!

Visit https://www.activecountermeasures/hnn to sign up for a demo or buy our AI Hunter!!

ย 

โ†’Visit our website: https://www.securityweekly.com

โ†’Follow us on Twitter: https://www.twitter.com/securityweekly

โ†’Like us on Facebook: https://www.facebook.com/secweekly

โ˜ โ˜† โœ‡ ZDNet | security RSS

MEGA.nz Chrome extension caught stealing passwords, cryptocurrency private keys

September 4th 2018 at 23:57
Tainted extension caught stealing passwords for Google, Microsoft, GitHub and Amazon accounts, but also Monero and Ethereum private keys.
โ˜ โ˜† โœ‡ ZDNet | security RSS

Chrome 69 released with new UI and random password generator

September 5th 2018 at 00:08
Google revamps Chrome main user interface with new white rounded tabs, replacing classic gray angled tabs after a decade.
โŒ