Month: January 2018

FortinetSecurity

Dr. StrangePatch or: How I Learned to Stop Worrying (about Meltdown and Spectre) and Love Security Advisory ADV180002

Credit to Author: Minh Tran| Date: Fri, 12 Jan 2018 11:39:59 +0000

  Introduction 2018 truly is starting off with a bang: fundamental CPU flaws dubbed Meltdown and Spectre were found affecting pretty much all modern processors developed since the Pentium Pro (1995). These flaws root in two critical CPU features: Out of Order Execution and Speculative Execution, which are crucial for performance. Since this is an important feature and not a bug, it is inherently hard to fix. Furthermore, for performance reasons, speculative execution is almost always implemented in hardware, so “fixes”…

Read More
FortinetSecurity

An Analysis of the OpenSSL SSL Handshake Error State Security Bypass (CVE-2017-3737)

Credit to Author: Dehui Yin| Date: Fri, 12 Jan 2018 11:39:59 +0000

OpenSSL is a widely used library for SSL and TLS protocol implementation that secures data using encryption and decryption based on cryptographic functions. However, a Security Bypass vulnerability – recently addressed in a patch by the OpenSSL Project –can be exploited to make vulnerable SSL clients or remote SSL servers send clean application data without encryption. This Security Bypass vulnerability (CVE-2017-3737) is caused by an error when the SSL_read or SSL_write function handles an "error state" during an SSL handshake….

Read More
MalwareBytesSecurity

Fake Spectre and Meltdown patch pushes Smoke Loader malware

Credit to Author: Jérôme Segura| Date: Fri, 12 Jan 2018 20:50:29 +0000

German users are being targeted with a rogue patch for the recently announced Meltdown and Spectre flaws.

Categories:

Tags:

(Read more…)

The post Fake Spectre and Meltdown patch pushes Smoke Loader malware appeared first on Malwarebytes Labs.

Read More
ScadaICSSchneider

How Renewables and Efficiency Measures Will Help Colo’s Meet Burgeoning Energy Demands

Credit to Author: Mark Bidinger| Date: Fri, 12 Jan 2018 16:00:04 +0000

Colocation companies are facing a period of tremendous opportunity for growth, but that same growth is forcing them to meet some serious challenges around energy use – for the sake… Read more »

The post How Renewables and Efficiency Measures Will Help Colo’s Meet Burgeoning Energy Demands appeared first on Schneider Electric Blog.

Read More