FreshRSS

πŸ”’
☐ β˜† βœ‡ ZDNet | security RSS

Chrome OS to block USB access while the screen is locked

December 23rd 2018 at 13:34
Google takes steps to protect Chromebooks from some types of physical access attacks.
☐ β˜† βœ‡ Paul's Security Weekly

Know Where You're Putting Your Tool - Paul's Security Weekly #587

By paul@securityweekly.com β€” December 22nd 2018 at 10:00

This week, we welcome Vaughn Adams, Enterprise Sales Engineer at LogRhythm! Vaughn will be talking about using freely available tools and logs you are already collecting to detect attacker behavior! In our second segment, we have a Round Table discussion entitled "What the Heck Are Security Basics?", to talk about what should organizations be doing to meet the basic security requirements, and much more! In our final segment, we air a pre-recorded interview with Mandy Logan on "Hacking the Brainstem", her trip through recovery, and how she came to love Information Security!

Β 

Full Show Notes: https://wiki.securityweekly.com/Episode587

Visit https://www.securityweekly.com/psw for all the latest episodes!

To get involved with LogRhythm, go to: www.securityweekly.com/logrhythm

Support Mandy by going to her GoFundMe Page: https://www.gofundme.com/hacking-recovery-brainstem-stroke

Β 

Visit https://www.activecountermeasures/psw to sign up for a demo or buy our AI Hunter!

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

☐ β˜† βœ‡ ZDNet | security RSS

Researcher publishes proof-of-concept code for creating Facebook worm

December 22nd 2018 at 01:21
One group has already been abusing this issue to post spam on users' Facebook walls.
☐ β˜† βœ‡ ZDNet | security RSS

India authorizes 10 agencies to intercept, monitor, and decrypt citizens' data

December 21st 2018 at 23:43
Order sparks outrage in India with citizens, privacy advocates, and political opponents accusing the government of trying to establish a "surveillance state."
☐ β˜† βœ‡ ZDNet | security RSS

Chinese websites have been under attack for a week via a new PHP framework bug

December 21st 2018 at 20:16
PoC for ThinkPHP security flaw sparks furious scans for vulnerable sites, most of which are based in China.
☐ β˜† βœ‡ Paul's Security Weekly

My Comfort Blanket - Enterprise Security Weekly #120

By paul@securityweekly.com β€” December 21st 2018 at 17:36

This week, Paul, John Strand, and Matt Alderman talk the Enterprise News, which includes TPG in early talks to sell McAfee to Thoma Bravo, Bitdefender offers new managed threat monitoring service, Symantec and Fortinet partner to deliver robust and comprehensive Cloud Security Service, and Untangle partners with Malwarebytes to bring Layered Security to SMBs! In our final segment of the year, Paul brings you his personal Top Ten List for 2018 including his favorite acquisitions, breaches, vulnerabilities, interviews, attack tools, news articles, and more!

Β 

Full Show Notes: https://wiki.securityweekly.com/ES_Episode120

Visit https://www.securityweekly.com/esw for all the latest episodes!

Visit https://www.activecountermeasures/esw to sign up for a demo or buy our AI Hunter!

Β 

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

☐ β˜† βœ‡ ZDNet | security RSS

Five other countries formally accuse China of APT10 hacking spree

December 21st 2018 at 15:44
Australia, Canada, Japan, New Zealand, and the UK also point the finger at the Beijing government. Germany expected as well.
☐ β˜† βœ‡ ZDNet | security RSS

Caribou Coffee chain announces card breach impacting 239 stores

December 20th 2018 at 23:36
Almost 40 percent of the company's coffee stores impacted by breach of its POS system.
☐ β˜† βœ‡ ZDNet | security RSS

Law enforcement shut down DDoS booters ahead of annual Christmas DDoS attacks

December 20th 2018 at 18:56
Law enforcement launch preemptive strike to shut down some of the DDoS services that may be abused to attack gaming services over the Christmas holiday.
☐ β˜† βœ‡ ZDNet | security RSS

US charges two Chinese nationals for hacking cloud providers, NASA, the US Navy

December 20th 2018 at 16:38
The two Chinese nationals were members of the infamous APT10 cyber-espionage group, DOJ said.
☐ β˜† βœ‡ ZDNet | security RSS

Nokia denies leaking internal credentials in server snafu

December 20th 2018 at 14:00
Security researcher finds treasure trove of passwords and API keys on an internet-accessible etcd database.
☐ β˜† βœ‡ ZDNet | security RSS

Researcher publishes PoC for new Windows zero-day

December 20th 2018 at 13:53
This is the third Windows zero-day the researcher dumps online in the last five months.
☐ β˜† βœ‡ ZDNet | security RSS

Hacker spoofing bypasses 2FA security in Gmail, targets secure email services

December 20th 2018 at 09:50
Updated: Google, Yahoo, and ProtonMail accounts are being targeted in a new wave of phishing attacks.
☐ β˜† βœ‡ ZDNet | security RSS

Microsoft releases security update for new IE zero-day

December 19th 2018 at 20:06
Microsoft releases out-of-band security update for Internet Explorer zero-day discovered by Google threat analysts.
☐ β˜† βœ‡ ZDNet | security RSS

Chinese hackers tap into EU diplomatic communications network

December 20th 2018 at 06:50
The critical COREU network in the bloc has been reportedly compromised by a state-sponsored Chinese hacking group, leading to the theft of internal cables.
☐ β˜† βœ‡ ZDNet | security RSS

Shamoon data-wiping malware believed to be the work of Iranian hackers

December 20th 2018 at 05:16
Researchers say the Iranian hacker group APT33 is responsible for recent attacks in the Middle East and Europe.
☐ β˜† βœ‡ ZDNet | security RSS

New attack intercepts keystrokes via graphics libraries

December 19th 2018 at 17:22
Attack can guess text input from both hardware and on-screen keyboards alike.
☐ β˜† βœ‡ ZDNet | security RSS

This business email scam spreads Trojans through Google Cloud storage

December 19th 2018 at 14:00
Financial firms and services are being actively targeted in the UK and US.
☐ β˜† βœ‡ ZDNet | security RSS

Hackers have earned $1.7 million so far from trading data stolen from US gov payment portals

December 19th 2018 at 13:23
User payment data was stolen from local Click2Gov government systems in US cities.
☐ β˜† βœ‡ ZDNet | security RSS

Facebook defends giving tech giants access to extensive user data

December 19th 2018 at 12:01
In a story which unfortunately just keeps giving, Facebook has yet again awarded us with a privacy scandal worthy of note.
☐ β˜† βœ‡ ZDNet | security RSS

Watch researchers remotely brick a server by corrupting its BMC and UEFI firmware

December 19th 2018 at 11:30
Attack is only a proof-of-concept, but one that can be as damaging as ransomware or disk-wiping malware.
☐ β˜† βœ‡ Paul's Security Weekly

In Flames - Application Security Weekly #44

By paul@securityweekly.com β€” December 19th 2018 at 10:00

This week, Keith and Paul interview Harry Sverdlove, CTO and Founder of Edgewise! Harry joins us to discuss what Edgewise does in the AppSec world, segmentation, cloud migration, trying different architectures, and more! In the Application Security News, Facebook bug exposed private photos of 6.8 million users, thousands of Jenkins servers will let anonymous users become admins, Signal app can't include a backdoor for the Australian government, WordPress plugs bug that led to Google indexing some user passwords, and more!

Β 

Full Show Notes: https://wiki.securityweekly.com/ASW_Episode44

To get involved with Edgewise, go to: https://www.edgewise.net/securityweekly

Β 

Visit https://www.securityweekly.com/asw for all the latest episodes!

Visit https://www.activecountermeasures/asw to sign up for a demo or buy our AI Hunter!

Visit our website: https://www.securityweekly.com

Β 

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

Follow us on Twitter: https://www.twitter.com/securityweekly

☐ β˜† βœ‡ ZDNet | security RSS

NASA discloses data breach

December 19th 2018 at 01:55
Hack took place in October 2018. Agency still doesn't know the number of impacted employees.
☐ β˜† βœ‡ Paul's Security Weekly

Hack Naked News #201 -Β December 18, 2018

By paul@securityweekly.com β€” December 18th 2018 at 21:56

This week, when meme's attack, how Google's taking steps to secure Kubernetes, suggestions for last minute Holiday IT gifts, Twitter fixes bug that exposed data, and how WordPress was targeted with clever SEO Injection Malware! Ed Sattar from Quickstart joins us for expert commentary on how to optimize your cyber security investment to maximize ROI, and more!

Β 

Full Show Notes: https://wiki.securityweekly.com/HNNEpisode201

Visit https://www.securityweekly.com/hnn for all the latest episodes!

Visit https://www.activecountermeasures/hnn to sign up for a demo or buy our AI Hunter!

Β 

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

☐ β˜† βœ‡ ZDNet | security RSS

DOD doesn't keep track of duplicate or obsolete software

December 18th 2018 at 19:38
July 2018 memorandum says DOD has yet to report over 30 percent of its software inventory.
☐ β˜† βœ‡ ZDNet | security RSS

Researchers slam Hola VPN over absent encryption, user IP leaks

December 18th 2018 at 13:09
Updated: Trend Micro users will now receive a warning over the use of Hola as "unwanted" and risky software.
☐ β˜† βœ‡ Paul's Security Weekly

The Mistake People Make - Business Security Weekly #111

By paul@securityweekly.com β€” December 18th 2018 at 10:00

This week, Matt and Paul interview Bob Ackerman, a legend in venture capital investing, and is referred to as one of "Cyber's Money Men". Bob is also the Founder and Managing Director of venture capital firm AllegisCyber! In the Leadership Articles, Matt and Paul discuss how to be productive during the holiday season, how to work from home without losing your mind, how to talk to your boss when you’re underperforming, selling your product as you build it, and more!

Β 

Full Show Notes: https://wiki.securityweekly.com/BSWEpisode111

Visit https://www.securityweekly.com/bsw for all the latest episodes!

Visit https://www.activecountermeasures/bsw to sign up for a demo or buy our AI Hunter!

Β 

Visit our website: https://www.securityweekly.com

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

☐ β˜† βœ‡ Paul's Security Weekly

Nuggets of Learning - Paul's Security Weekly #586

By paul@securityweekly.com β€” December 17th 2018 at 19:23

This week, how Taylor Swift used Facial Recognition to thwart stalkers, unlocking Android phones with a 3D printed head, Ticketmaster fails to take responsibility for malware, and it's December of 2018, to Hell with it, just patch your stuff already! In our first interview, we welcome back Ed Skoudis, Founder of the Counter Hack Challenge and Kringle Con 2018! Ed joins us on the show to talk about this years challenge and what's in store! In our final interview, we welcome back Don Murdoch, the Assistant Director at Regent University Cyber Range! Don joins us this week to discuss his book, "Blue Team Handbook: Incident Response Edition", and more!

Β 

Full Show Notes: https://wiki.securityweekly.com/Episode586

Visit https://www.securityweekly.com/psw for all the latest episodes!

Join KringleCon 2018: www.kringlecon.com

Β 

Visit https://www.activecountermeasures/psw to sign up for a demo or buy our AI Hunter!

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

☐ β˜† βœ‡ ZDNet | security RSS

New machine learning algorithm breaks text CAPTCHAs easier than ever

December 18th 2018 at 05:49
Algorithm tested against the text CAPTCHA systems used on 33 popular websites.
☐ β˜† βœ‡ ZDNet | security RSS

Google announces crackdown on Play Store ratings and reviews

December 18th 2018 at 03:10
Company said it removes millions of Play Store reviews and ratings on a weekly basis.
☐ β˜† βœ‡ ZDNet | security RSS

WSJ website defaced by PewDiePie fan in ongoing YouTube subscribers battle

December 18th 2018 at 01:52
Hacker posts apology on WSJ site and then urges users to follow the YouTube star.
☐ β˜† βœ‡ ZDNet | security RSS

Twitter discloses suspected state-sponsored attack

December 18th 2018 at 01:38
Twitter says data leak occurred after an attack targeting a vulnerability in its support form system.
☐ β˜† βœ‡ ZDNet | security RSS

Insider awarded $10,000 bounty for reporting enterprise software piracy

December 17th 2018 at 07:38
It is no longer just the average consumer that might wind up in court for using pirated software.
☐ β˜† βœ‡ ZDNet | security RSS

PewDiePie printer hacker strikes again: subscribe and sort out your security

December 17th 2018 at 06:18
The attacker told users to sort out their printer security -- and subscribe to the vlogger "overlord," too.
☐ β˜† βœ‡ ZDNet | security RSS

US ballistic missile systems have very poor cyber-security

December 17th 2018 at 01:21
DOD report finds no antivirus, no data encryption, no multifactor authentication.
☐ β˜† βœ‡ ZDNet | security RSS

Thousands of Jenkins servers will let anonymous users become admins

December 16th 2018 at 15:27
Two vulnerabilities discovered and patched over the summer expose Jenkins servers to mass exploitation.
☐ β˜† βœ‡ ZDNet | security RSS

'Bomb threat' scammers are now threatening to throw acid on victims

December 15th 2018 at 14:51
Bomb threat extortion campaign yielded less than $1 for the spammers.
☐ β˜† βœ‡ ZDNet | security RSS

SQLite bug impacts thousands of apps, including all Chromium-based browsers

December 14th 2018 at 23:49
New 'Magellan' vulnerability will haunt the app ecosystem for years to come.
☐ β˜† βœ‡ ZDNet | security RSS

Facebook bug exposed private photos of 6.8 million users

December 14th 2018 at 16:00
Up to 1,500 apps built by 876 developers could have had accessed the private photos of 6.8 million users.
☐ β˜† βœ‡ ZDNet | security RSS

Signal: We can't include a backdoor in our app for the Australian government

December 14th 2018 at 15:09
The Signal app's design and open source code policy makes this impossible.
☐ β˜† βœ‡ ZDNet | security RSS

Fancy Bear exploits Brexit to target government groups with Zebrocy Trojan

December 14th 2018 at 13:41
A number of former USSR nation states are also on the target list.
☐ β˜† βœ‡ Paul's Security Weekly

Cigarettes & Malleable Toothbrushes - Enterprise Security Weekly #119

By paul@securityweekly.com β€” December 14th 2018 at 10:00

This week, Paul and John Strand interview John Bradshaw, Senior Director and Solutions Engineer at Acalvio Technologies, to talk about 5 Tenets of Enterprise Deception! In the Enterprise News this week, NopSec announces the latest release of its flagship product, Minerva Labs Anti-Evasion Platform Achieves VMware Ready Status, SecurityScorecard Announces Partnership with Cybernance to Drive Holistic View of Cyber Risk Across the Enterprise, and we have some acquisition and funding updates from Venafi, WhiteFox, and Pindrop!

Β 

Full Show Notes: https://wiki.securityweekly.com/ES_Episode119

Visit https://www.securityweekly.com/esw for all the latest episodes!

Visit https://www.activecountermeasures/esw to sign up for a demo or buy our AI Hunter!

Β 

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

☐ β˜† βœ‡ ZDNet | security RSS

Trump, Google, United Nations are among 2018's worst password offenders

December 14th 2018 at 08:51
Some of the biggest names in politics and tech are responsible for this year's worst security gaffes.
☐ β˜† βœ‡ ZDNet | security RSS

Save the Children Foundation duped by hackers into paying out $1 million

December 14th 2018 at 07:27
The fraudsters broke into an email account to launch an elaborate scheme designed to scam the charity.
☐ β˜† βœ‡ ZDNet | security RSS

Logitech app security flaw allowed keystroke injection attacks

December 14th 2018 at 05:50
Google security researchers shame Logitech into releasing security update for insecure app.
☐ β˜† βœ‡ ZDNet | security RSS

Extortion emails carrying bomb threats cause panic across the US

December 13th 2018 at 22:18
Police in New York, Chicago, Detroit, San Francisco, and Washington tell Americans to stay calm.
☐ β˜† βœ‡ ZDNet | security RSS

Twitter says it receives half a million of spam reports per month

December 13th 2018 at 16:48
Twitter's latest Transparency Report also shows a rise in government requests for user data.
☐ β˜† βœ‡ ZDNet | security RSS

Shamoon malware destroys data at Italian oil and gas company

December 13th 2018 at 13:33
About a tenth of Saipem's IT infrastructure infected with infamous data-wiping Shamoon malware.
☐ β˜† βœ‡ ZDNet | security RSS

AriseBank execs forced to pay $2.7 million to settle SEC charges of cryptocurrency fraud

December 13th 2018 at 10:57
The organization claimed to operate a unique, decentralized bank via the blockchain.
☐ β˜† βœ‡ ZDNet | security RSS

WordPress plugs bug that led to Google indexing some user passwords

December 13th 2018 at 09:06
WordPress 5.0.1 also fixes seven security vulnerabilities.
☐ β˜† βœ‡ ZDNet | security RSS

Bug allowed full takeover of Samsung user accounts

December 12th 2018 at 23:34
Samsung awards researcher a $13,300 reward for finding three CSRF issues on its user portal.
☐ β˜† βœ‡ ZDNet | security RSS

Rhode Island sues Google after latest Google+ API leak

December 12th 2018 at 22:02
Google sued within a day after announcing latest Google+ API leak.
☐ β˜† βœ‡ ZDNet | security RSS

Many of 2018's most dangerous Android and iOS security flaws still threaten your mobile security

December 12th 2018 at 21:50
Bypassing passcodes, malware-laden apps, and inherent design flaws exposing almost all known mobile devices made up part of the security problems found in iOS and Android.
☐ β˜† βœ‡ ZDNet | security RSS

Ships infected with ransomware, USB malware, worms

December 12th 2018 at 18:21
Ships are the victims of cyber-security incidents more often than people think. Industry groups publish cyber-security guidelines to address issues.
☐ β˜† βœ‡ ZDNet | security RSS

Former Mt. Gox CEO could face 10 years behind bars in embezzlement case

December 12th 2018 at 11:10
Prosecutors are gunning for a lengthy prison sentence. Mark Karpeles has denied stealing investor funds.
☐ β˜† βœ‡ Paul's Security Weekly

Top Secret - Application Security Weekly #43

By paul@securityweekly.com β€” December 12th 2018 at 10:00

This week, Keith and Paul interview Chris Elgee, the Technical Engineer at Counter Hack Challenges! Chris joins Keith and Paul this week to talk about the Counter Hack Challenge, how it’s been working on the challenge vs. playing it, and more! In the Application Security News, Kubernetes instances are being hijacked worldwide, malicious sites abuse 11-year old Firefox bug that Mozilla failed to fix, Google is on a Witch Hunt for Internal Leakers, and more!

Β 

Full Show Notes: https://wiki.securityweekly.com/ASW_Episode43

Visit https://www.securityweekly.com/asw for all the latest episodes!

Visit https://www.activecountermeasures/asw to sign up for a demo or buy our AI Hunter!

Β 

Visit our website: https://www.securityweekly.com

Follow us on Twitter: https://www.twitter.com/securityweekly

Like us on Facebook: https://www.facebook.com/secweekly

☐ β˜† βœ‡ ZDNet | security RSS

China blamed for Marriott data breach

December 12th 2018 at 07:47
500 million customers were impacted. Investigators believe that state-sponsored Chinese hackers are to blame.
☐ β˜† βœ‡ ZDNet | security RSS

Firefox 64 released with a Windows-like task manager

December 12th 2018 at 01:45
Firefox 64 also comes with support for multi-tab selections and final distrust of all Symantec SSL certificates.
☐ β˜† βœ‡ ZDNet | security RSS

US border agents aren't deleting travelers' data after device searches

December 12th 2018 at 00:11
In addition, CBP agents also didn't carry out any software-assisted searches for more than seven months because a manager forgot to renew a license agreement.
❌