Month: August 2017

IndependentKrebs

Beware of Hurricane Harvey Relief Scams

Credit to Author: BrianKrebs| Date: Tue, 29 Aug 2017 14:55:10 +0000

U.S. federal agencies are warning citizens anxious to donate money for those victimized by Hurricane Harvey to be especially wary of scam artists. In years past we’ve seen shameless fraudsters stand up fake charities and other bogus relief efforts in a bid to capitalize on public concern over an ongoing disaster. Here are some tips to help ensure sure your aid dollars go directly to those most in need.

Read More
IndependentSecuriteam

SSD Advisory – Oracle Java and Apache Xerces PDF/Docx Server Side DoS

Credit to Author: SSD / Maor Schwartz| Date: Wed, 30 Aug 2017 19:11:43 +0000

Vulnerabilities Summary The following advisory describes two (2) vulnerabilities found in Oracle Java JDK/JRE (1.8.0.131 and previous versions) packages and Apache Xerces (2.11.0) The vulnerabilities are: Oracle JDK/JRE Concurrency-Related Denial of Service java.net.URLConnection (with no setConnectTimeout) Concurrency-Related Denial of Service Credit An independent security researcher has reported this vulnerability to Beyond Security’s SecuriTeam Secure Disclosure … Continue reading SSD Advisory – Oracle Java and Apache Xerces PDF/Docx Server Side DoS

Read More
IndependentSecuriteam

SSD Advisory – Remote Command Execution in Western Digital with Dropbox App

Credit to Author: SSD / Maor Schwartz| Date: Wed, 30 Aug 2017 02:39:13 +0000

Vulnerability summary The following advisory describes an unauthenticated Remote Command Execution vulnerability in My Cloud products with that has Dropbox App installed. The My Passport, My Book, and My Cloud (Single-Bay) drives allow users to backup their data to an existing Dropbox account using WD SmartWare Pro, WD Backup. The My Cloud Dropbox App (Available … Continue reading SSD Advisory – Remote Command Execution in Western Digital with Dropbox App

Read More
ComputerWorldIndependent

Microsoft patch alert: Outstanding problems with recent updates

Credit to Author: Woody Leonhard| Date: Wed, 30 Aug 2017 12:36:00 -0700

August has seen a flurry of buggy patches:

Win10 1607KB 4033637, which arrived last Friday via Auto Update, is still undocumented. A Reddit thread credits Microsoft as saying it’s a July security patch for Flash. Abbodi86 on AskWoody has a different view: it’s an update to the Compatibility Appraiser, which is the software that scans a PC to see whether it’s ready to move to the next version. Günter Born concurs with Abbodi86. (I wonder if it’s a precursor to the Fall Creators Update.) There’s no explanation about why Microsoft refuses to document it, or talk about it.

To read this article in full or to leave a comment, please click here

Read More
MalwareBytesSecurity

Malware vaccination tricks: blue pills or red pills

Credit to Author: Pieter Arntz| Date: Wed, 30 Aug 2017 18:00:10 +0000

Malware vaccination tricks are offered for various sorts and families of malware, but can and should we use them? What are the pros and cons? Read all about it.

Categories:

Tags:

(Read more…)

The post Malware vaccination tricks: blue pills or red pills appeared first on Malwarebytes Labs.

Read More