Author: admin

MalwareBytesSecurity

Fileless malware: part deux

Credit to Author: Vasilios Hioureas| Date: Fri, 05 Oct 2018 15:00:00 +0000

In part two of this series on fileless malware, our malware analyst walks readers through two demonstrations of fileless malware attacks and shows the problems with detecting them using static signatures.

Categories:

Tags:

(Read more…)

The post Fileless malware: part deux appeared first on Malwarebytes Labs.

Read More
ComputerWorldIndependent

Apple, Amazon server spy story is wake-up call to security pros

Credit to Author: Jonny Evans| Date: Fri, 05 Oct 2018 04:29:00 -0700

Apple and Amazon have strenuously deniedBloomberg’s claims of a sophisticated hardware exploit against servers belonging to themselves and numerous other entities, including U.S. law enforcement  

Chinese, Apple and chips

Put in very simple terms, the claim is that malicious chips were found inside servers used in data centers belonging to the tech firms.

These chips (it’s claimed) worked to exfiltrate data from those servers, which were themselves sourced from server manufacturer, Super Micro. That company’s server products are/were also used by Amazon, the U.S. government and 30 other organizations. The chips were (it is alleged) put in place by employees bribed by Chinese government agents.

To read this article in full, please click here

Read More
ComputerWorldIndependent

Time to lock the security team in a hotel room?

Credit to Author: Sharky| Date: Fri, 05 Oct 2018 03:00:00 -0700

IT security has laptops at this company really locked down, and that includes only limited admin rights, reports a road warrior pilot fish.

“On a recent trip, at my hotel I had to make an internet connection and open a web page to log into the hotel’s internet service before I could get a connection to the real internet,” fish says.

“Problem was, the work laptop was not going to let me use the browsers until I had established a VPN connection, which of course I could not do without the web page login.

“In a way, that was good — I took some real vacation time.

“In another way, it was bad, I have big hands and fingers, so using an iPhone and those stupid virtual keyboards is a one-finger, error-prone task. An email that could take seconds to type on a full-size keyboard takes minutes on the phone.

To read this article in full, please click here

Read More
IndependentSecuriteam

SSD Advisory – Cisco Prime Infrastructure File Inclusion and Remote Command Execution to Privileges Escalation

Credit to Author: SSD / Ori Nimron| Date: Thu, 04 Oct 2018 05:12:22 +0000

Vulnerabilities Summary Cisco Prime Infrastructure (CPI) contains two vulnerabilities that when exploited allow an unauthenticated attacker to achieve root privileges and execute code remotely. The first vulnerability is a file upload vulnerability that allows the attacker to upload and execute JSP files as the Apache Tomcat user. The second vulnerability is a privilege escalation to … Continue reading SSD Advisory – Cisco Prime Infrastructure File Inclusion and Remote Command Execution to Privileges Escalation

Read More
ScadaICSSchneider

Wi-Fi-as-a-service: An Emerging Opportunity for Telecom Provider ITS Fiber

Credit to Author: Guest Blogger| Date: Thu, 04 Oct 2018 17:28:43 +0000

“My internet is down.” “My Wi-Fi isn’t working.” Customer service reps at network providers hear these countless times per day; they naturally get blamed. ITS Fiber, however, has a record… Read more »

The post Wi-Fi-as-a-service: An Emerging Opportunity for Telecom Provider ITS Fiber appeared first on Schneider Electric Blog.

Read More