FreshRSS

πŸ”’
☐ β˜† βœ‡ Paul's Security Weekly

Good Ol' Days - Application Security Weekly #41

By paul@securityweekly.com β€” November 28th 2018 at 10:00

This week, Keith and Paul interview Brent Dukes! Brent is a hacker, and Director of Information Security for an established manufacturing company. He joins Keith and Paul this week to talk about WAF’s, Pentesting, Burp Suite, and more! In the Application Security News, Hackers use Drupalgeddon 2 and Dirty COW exploits to take over web servers, second WordPress hacking campaign underway, USPS took a year to fix a vulnerability that exposed all 60 million users' data, this JavaScript can snoop on other Browser Tabs to work out what you're visiting, and more!

Β 

Full Show Notes: https://wiki.securityweekly.com/ASW_Episode41

Visit https://www.securityweekly.com/asw for all the latest episodes!

Visit https://www.activecountermeasures/asw to sign up for a demo or buy our AI Hunter!

Β 

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

☐ β˜† βœ‡ ZDNet | security RSS

FBI dismantles gigantic ad fraud scheme operating across over one million IPs

November 28th 2018 at 05:49
DOJ also charged eight suspects. Three suspects have already been arrested.
☐ β˜† βœ‡ Paul's Security Weekly

Hack Naked News #198 - November 27, 2018

By paul@securityweekly.com β€” November 27th 2018 at 23:20

This week, disastrous Rowhammer bitflips, malicious developer steals Bitcoin with NodeJS module, Germany proposes router security guidelines, Uber fined 148$ Million for data breach cover-up, Microsoft yanks two buggy Office patches, and a malware advertising campaign that impacts millions of iOS users! Jason Wood from Paladin Security joins us for Expert Commentary to discuss how the FBI created a fake FedEx website to unmask a cybercriminal, and more on this episode of Hack Naked News!

Β 

Full Show Notes: https://wiki.securityweekly.com/HNNEpisode198

Visit https://www.securityweekly.com/hnn for all the latest episodes!

Visit https://www.activecountermeasures/hnn to sign up for a demo or buy our AI Hunter!

Β 

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

☐ β˜† βœ‡ ZDNet | security RSS

Seven GDPR complaints filed against Google over user location tracking

November 27th 2018 at 20:33
GDPR complaints have been filed today against Google in the Netherlands, Poland, the Czech Republic, Greece, Norway, Slovenia, and Sweden.
☐ β˜† βœ‡ ZDNet | security RSS

Android adware has plagued the Google Play Store in the past two months

November 27th 2018 at 17:27
Security researchers unearth several adware campaigns distributed via apps available through the official Google Play Store.
☐ β˜† βœ‡ ZDNet | security RSS

This worm spreads a fileless version of the Trojan Bladabindi

November 27th 2018 at 13:45
The malware is capable of keylogging, spying, and far more.
☐ β˜† βœ‡ ZDNet | security RSS

Uber fined Β£900,000 by UK, Dutch privacy regulators over 2016 data breach

November 27th 2018 at 11:44
The hacker responsible was paid off to keep quiet.
☐ β˜† βœ‡ Paul's Security Weekly

Evidence of Absence - Business Security Weekly #108

By paul@securityweekly.com β€” November 27th 2018 at 10:00

This week, we welcome Richard Seiersen, former Chief Information Security Officer at Lending Club and Twilio to talk about his CISO experience, and the book Richard co-authored called, "How to Measure Anything in Cybersecurity Risk"! In the Leadership and Communications segment, the million-dollar question of cyber-risk, risk assessments essential to secure third-party vendor management, how digital tech is transforming business ecosystem, and more!

Β 

Full Show Notes: https://wiki.securityweekly.com/BSWEpisode108

Β 

Visit https://www.securityweekly.com/bsw for all the latest episodes!

Visit https://www.activecountermeasures/bsw to sign up for a demo or buy our AI Hunter!

Β 

Visit our website: https://www.securityweekly.com

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

☐ β˜† βœ‡ ZDNet | security RSS

US iOS users targeted by massive malvertising campaign

November 27th 2018 at 00:05
A malvertising campaign deployed via a high-profile ad platform targeted iOS users across the US. Crooks hijacked over 300 million web sessions.
☐ β˜† βœ‡ ZDNet | security RSS

Hacker backdoors popular JavaScript library to steal Bitcoin funds

November 26th 2018 at 20:31
Users of BitPay's Copay desktop and mobile wallet apps are affected. An update has been released earlier today that doesn't contain the malicious code.
☐ β˜† βœ‡ ZDNet | security RSS

UK cops won't go after researcher who reported security issue to York city officials

November 26th 2018 at 17:14
York city officials face backlash after reporting security researcher who found a bug in one of their mobile apps to law enforcement.
☐ β˜† βœ‡ ZDNet | security RSS

UK gov't seizes documents Facebook wanted to keep private in Cambridge Analytica battle

November 26th 2018 at 09:16
It appears that the UK parliament will not stand for being ignored by Mark Zuckerberg any longer.
☐ β˜† βœ‡ ZDNet | security RSS

Germany proposes router security guidelines

November 26th 2018 at 05:25
German government would like to regulate what kind of routers are sold and installed across the country.
☐ β˜† βœ‡ ZDNet | security RSS

New Linux crypto-miner steals your root password and disables your antivirus

November 23rd 2018 at 19:19
Trojan also installs a rootkit and another strain of malware that can execute DDoS attacks.
☐ β˜† βœ‡ ZDNet | security RSS

Ukrainian police arrest hacker who infected over 2,000 users with DarkComet RAT

November 23rd 2018 at 12:33
Suspect was most likely hosting the RAT's command and control server on his home computer.
☐ β˜† βœ‡ ZDNet | security RSS

Rowhammer attacks can now bypass ECC memory protections

November 22nd 2018 at 15:11
Attack works against ECC memory included with DDR3 memory, but researchers believe DDR4 is also vulnerable.
☐ β˜† βœ‡ ZDNet | security RSS

SIM-swapping 21-year-old scores $1 million by hijacking a phone

November 22nd 2018 at 12:54
The man reportedly targeted well-known business leaders, making off with one victim's life savings.
☐ β˜† βœ‡ ZDNet | security RSS

How Dropbox's red team discovered an Apple zero-day exploit chain by accident

November 22nd 2018 at 10:54
The zero-day vulnerabilities were accidentally uncovered while researchers were looking for ways to break into Dropbox.
☐ β˜† βœ‡ Paul's Security Weekly

Shutting the Brain Off - Enterprise Security Weekly #116

By paul@securityweekly.com β€” November 22nd 2018 at 10:00

This week, John Strand makes his triumphant return to join Paul and interview Rick Fernandez, Senior Sales Engineer at LogRhythm to talk about Choosing the Best Option for MSSPS! In the Enterprise News this week, Israeli cybersecurity company Tufin plans Nasdaq IPO, F-Secure boosts endpoint detection and response, Mimecast joins IBM Security app exchange community, and Awake Security debuts Network Traffic Analysis Platform to detect risks! In the Final Segment, we air some interviews we recorded at DEF CON and Black Hat 2018 with Irdeto, Venafi, and HP!

Β 

Full Show Notes: https://wiki.securityweekly.com/ES_Episode116

To learn more about LogRhythm, go to: www.LogRhythm.com

For the Full DefCon18 Playlist, go to: https://securityweekly.com/summercamp18

Β 

Visit https://www.securityweekly.com/esw for all the latest episodes!

Visit https://www.activecountermeasures/esw to sign up for a demo or buy our AI Hunter!

Β 

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

Β 

☐ β˜† βœ‡ ZDNet | security RSS

Facebook appeals Β£500,000 penalty over Cambridge Analytica scandal

November 22nd 2018 at 09:05
The fine, imposed by the ICO, was the maximum permitted under old data protection laws.
☐ β˜† βœ‡ ZDNet | security RSS

Emotet malware runs on a dual infrastructure to avoid downtime and takedowns

November 22nd 2018 at 06:00
Researchers spot unique design in the server infrastructure propping up the Emotet malware.
☐ β˜† βœ‡ ZDNet | security RSS

City of Valdez, Alaska admits to paying off ransomware infection

November 21st 2018 at 23:23
City IT network was infected by Hermes ransomware, a strain that researchers previously tied to other North Korean malware and hacking tools.
☐ β˜† βœ‡ ZDNet | security RSS

Facebook entices researchers with $40,000 reward for account takeover vulnerabilities

November 21st 2018 at 17:21
It's not surprising considering Facebook's recent run-ins with account security problems.
☐ β˜† βœ‡ ZDNet | security RSS

German eID card system vulnerable to online identity spoofing

November 21st 2018 at 16:59
Vulnerability in web library lets attackers spoof electronic ID card identities.
☐ β˜† βœ‡ ZDNet | security RSS

Amazon leaks users' email addresses due to 'technical error'

November 21st 2018 at 15:00
Company has notified today all impacted customers.
☐ β˜† βœ‡ ZDNet | security RSS

L0rdix becomes the new Swiss Army knife of Windows hacking

November 21st 2018 at 12:27
The new tool combines data theft and cryptocurrency mining as a go-to product for attacking Windows machines.
☐ β˜† βœ‡ Paul's Security Weekly

Buffet Overflow - Application Security Weekly #40

By paul@securityweekly.com β€” November 21st 2018 at 10:00

This week, Keith and Paul interview John Kinsella, Vice President of Container Security at Qualys! John discusses Qualys’ Container Security, continuous discovery, and tracking for containers and images! In the Application Security News, Instagram leaks passwords to the public, Clickjacking on Google MyAccount Worth $7,500, James Wickett's thread on Open Source SAST options, an advanced search tool for sensitive information stored in GitHub repos, and more!

Β 

Full Show Notes: https://wiki.securityweekly.com/ASW_Episode40

Visit https://www.securityweekly.com/asw for all the latest episodes!

Visit https://www.activecountermeasures/asw to sign up for a demo or buy our AI Hunter!

Β 

Visit our website: https://www.securityweekly.com

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

☐ β˜† βœ‡ ZDNet | security RSS

Magecart group hilariously sabotages competitor

November 20th 2018 at 23:41
...but it's still stealing your card data.
☐ β˜† βœ‡ Paul's Security Weekly

Hack Naked News #197 - November 20, 2018

By paul@securityweekly.com β€” November 20th 2018 at 21:36

This week, what happens when support won't change your password, Gmail glitch Phishing Attacks, stopping the Infiltration of Things, Make-A-Wish website serves a Cryptojacking Script, Instagram exposes user passwords, and DirtyCOW is back in backdoor attack targeting Drupal Web Servers! Jason Wood from Paladin Security joins us for expert commentary to discuss how Ford is eyeing the use of customers personal data to boost profits!

Β 

Full Show Notes: https://wiki.securityweekly.com/HNNEpisode197

Visit https://www.securityweekly.com/hnn for all the latest episodes!

Visit https://www.activecountermeasures/hnn to sign up for a demo or buy our AI Hunter!

Β 

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

☐ β˜† βœ‡ ZDNet | security RSS

Cyber-security firm doxxes hacker who sold MySpace and Dropbox databases in 2016

November 20th 2018 at 20:57
Recorded Future claims Tessa88's identity is a 29-year-old Russian named Maksim Vladimirovich Donakov.
☐ β˜† βœ‡ ZDNet | security RSS

Second WordPress hacking campaign underway, this one targeting AMP for WP plugin

November 20th 2018 at 16:38
After targeting WP GDPR Compliance plugin, hackers are now going after sites using the AMP for WP plugin.
☐ β˜† βœ‡ ZDNet | security RSS

IRS failed to apply consumer protections for 11,406 taxpayers

November 20th 2018 at 14:37
IRS operators failed to record data of US taxpayers inside an IRS fraud detection system.
☐ β˜† βœ‡ ZDNet | security RSS

Fake Google Android driving apps claim half a million victims

November 20th 2018 at 13:45
The illegitimate apps include luxury car and motocross simulations.
☐ β˜† βœ‡ Paul's Security Weekly

Better Connected - Business Security Weekly #107

By paul@securityweekly.com β€” November 20th 2018 at 10:00

This week, we welcome Michael Pleasant, Chief Executive Officer and Founder at Open Security for an interview! They discuss transferring from Marine training to a business environment, and his company Open Security! In the Article Discussion, Special Guest Co-Host Jason Alburquerque joins me in studio to discuss Six ways you can establish which goals are important, How to diversify your professional network, the impact of perception and bias on leadership, and more on this episode of Business Security Weekly!!

Β 

Full Show Notes: https://wiki.securityweekly.com/BSWEpisode107

Visit https://www.securityweekly.com/bsw for all the latest episodes!

Visit https://www.activecountermeasures/bsw to sign up for a demo or buy our AI Hunter!

Β 

Visit our website: https://www.securityweekly.com

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

☐ β˜† βœ‡ ZDNet | security RSS

For Apple users without latest security updates, the letter 'd' is not always the letter 'd'

November 20th 2018 at 05:30
Apple users advised to install the company's July security updates if they don't want to fall victims to IDN homograph phishing attacks.
☐ β˜† βœ‡ ZDNet | security RSS

Hackers use Drupalgeddon 2 and Dirty COW exploits to take over web servers

November 19th 2018 at 20:51
Hacks could be easily avoided if people would patch their Drupal CMSs and Linux web servers.
☐ β˜† βœ‡ ZDNet | security RSS

Russia wants DNC hack lawsuit thrown out, citing international conventions

November 19th 2018 at 18:17
Russian Federation says it benefits from the same legal protections as the US does when carrying out military cyberattacks.
☐ β˜† βœ‡ ZDNet | security RSS

A bug in EA Origin client exposes gamers' data

November 19th 2018 at 16:55
Auto-login URL feature was not IP-bound and allowed anyone access to accounts' settings panels.
☐ β˜† βœ‡ ZDNet | security RSS

Vision Direct reveals customer credit card leak, fake Google script may be to blame

November 19th 2018 at 13:48
Updated: The personal and financial data of customers has been stolen.
☐ β˜† βœ‡ ZDNet | security RSS

Russian hacker arrested in Bulgaria for ad fraud of over $7 million

November 19th 2018 at 13:01
Alexander Zhukov, a supposed hacker who went online by the name of "Nastra," is currently fighting extradition to the US.
☐ β˜† βœ‡ ZDNet | security RSS

Texas hospital becomes victim of Dharma ransomware

November 19th 2018 at 12:12
The spread of malware through Altus Baytown Hospital systems highlights the ongoing threat ransomware poses to our healthcare.
☐ β˜† βœ‡ ZDNet | security RSS

Website geoblocking is not that widespread, study finds

November 19th 2018 at 05:45
Iran, Sudan, Syria, and Cuba are the most geoblocked countries.
☐ β˜† βœ‡ ZDNet | security RSS

Popular Dark Web hosting provider got hacked, 6,500 sites down

November 17th 2018 at 21:39
Hosting provider is still looking for the hacker's point of entry.
☐ β˜† βœ‡ Paul's Security Weekly

PCI PiΓ±ata - Paul's Security Weekly #583

By paul@securityweekly.com β€” November 17th 2018 at 10:00

This week, we welcome Jon Buhagiar, Network+ Review Course Instructor at Sybex for an interview to talk about Network Operations! In the Technical Segment, we welcome back John Moran, Senior Product Manager at DFLabs to talk about IncMan SOAR and how DFLabs Automation & Response platform helps automate, orchestrate, and measure CSIRTs and SOCs! In the Security News this week, 7 new Spectre/Meltdown attacks, Hacking ATM's for free cash is easier than Windows XP, AI can now fake fingerprints fooling ID scanners, and Japan's cybersecurity minister admits he's never used a computer!

Β 

Full Show Notes: https://wiki.securityweekly.com/Episode583

To learn more about DFLabs, go to: www.dflabs.com/securityweekly

Β 

Visit https://www.securityweekly.com/psw for all the latest episodes!

Visit https://www.activecountermeasures/psw to sign up for a demo or buy our AI Hunter!

Β 

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

☐ β˜† βœ‡ ZDNet | security RSS

Russian APT comes back to life with new US spear-phishing campaign

November 16th 2018 at 23:40
Cozy Bear (APT29) makes a comeback after last year's Dutch and Norwegian hacking campaigns.
☐ β˜† βœ‡ ZDNet | security RSS

Trump signs bill that creates the Cybersecurity and Infrastructure Security Agency

November 16th 2018 at 20:13
The US now has an official federal cybersecurity agency.
☐ β˜† βœ‡ ZDNet | security RSS

Google Play Protect analyzes every Android app that it can find on the internet

November 16th 2018 at 18:28
Play Protect, a security service included in the Play Store app, lives up to all the hype that Google created last year.
☐ β˜† βœ‡ ZDNet | security RSS

AWS rolls out new security feature to prevent accidental S3 data leaks

November 16th 2018 at 15:33
New settings will prevent accidental S3 bucket leaks --if customers take the time to apply them.
☐ β˜† βœ‡ ZDNet | security RSS

Most antivirus programs fail to detect this cryptocurrency-stealing malware

November 16th 2018 at 12:59
Traditional antivirus software has a tough time detecting malware used in the campaign.
☐ β˜† βœ‡ ZDNet | security RSS

Winter Olympic Games hackers are back with an updated arsenal

November 16th 2018 at 11:58
The group behind Olympic Destroyer are back with an evolved toolkit and malware droppers.
☐ β˜† βœ‡ ZDNet | security RSS

Malicious code hidden in advert images cost ad networks $1.13bn this year

November 16th 2018 at 10:44
So-called steganography is rapidly becoming a favored tool of fraudsters.
☐ β˜† βœ‡ ZDNet | security RSS

Most ATMs can be hacked in under 20 minutes

November 16th 2018 at 05:30
Experts tested ATMs from NCR, Diebold Nixdorf, and GRGBanking.
☐ β˜† βœ‡ ZDNet | security RSS

Google to pay JavaScript frameworks to implement performance-first code

November 15th 2018 at 22:40
Google to create $200,000 fund to sponsor the addition of "on by default" performance-related updates in popular JavaScript frameworks.
☐ β˜† βœ‡ ZDNet | security RSS

DOD disables file sharing service due to 'security risks'

November 15th 2018 at 17:21
AMRDEC SAFE portal had been to handle the transfer of non-classified materials.
☐ β˜† βœ‡ ZDNet | security RSS

Japanese cybersecurity minister finds computers a mystery

November 15th 2018 at 11:47
The man in charge of cybersecurity not only said he does not use a PC but seemed stumped when asked about risks associated with USB drives.
☐ β˜† βœ‡ Paul's Security Weekly

A Picture of the World - Enterprise Security Weekly #115

By paul@securityweekly.com β€” November 15th 2018 at 10:00

This week, Paul and Matt Alderman interview James Wickett, Head of Research at Signal Sciences! James talks about how security is moving to the application space and web applications! In the Enterprise News this week, AlgoSec delivers Native Cloud Security Management for Azure, HP Reinvents customer experience with Ping Identity, what mid market security budgets will look like in 2019, and we have some acquisition & funding updates from ForeScout, Dragos, Netskope, Duality, and more!

Β 

Full Show Notes: https://wiki.securityweekly.com/ES_Episode115

To learn more about Signal Sciences, go to: www.signalsciences.com/psw

Β 

Visit https://www.securityweekly.com/esw for all the latest episodes!

Visit https://www.activecountermeasures/esw to sign up for a demo or buy our AI Hunter!

Β 

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

☐ β˜† βœ‡ ZDNet | security RSS

One in five Magecart-infected stores get reinfected within days

November 15th 2018 at 06:30
A large number of reinfections take place within a day or week. Average reinfection time is 10.5 days.
☐ β˜† βœ‡ ZDNet | security RSS

Dutch government report says Microsoft Office telemetry collection breaks GDPR

November 14th 2018 at 23:00
Microsoft pledges to address issues; has already released a "zero exhaust" Office telemetry setting.
☐ β˜† βœ‡ ZDNet | security RSS

Many free mobile VPN apps are based in China or have Chinese ownership

November 14th 2018 at 19:29
Chinese affiliation raises a sign of alarm in light of China's recent clampdown of "unauthorized" VPN services.
❌