It’s 2018: Time to assess your cyberrisk
Credit to Author: Nikolay Pankov| Date: Tue, 23 Jan 2018 16:36:22 +0000
The newest threats you should know about, and measures worth taking to keep your business and clients safe.
Read MoreRSS Reader for Computer Security Articles
Credit to Author: Nikolay Pankov| Date: Tue, 23 Jan 2018 16:36:22 +0000
The newest threats you should know about, and measures worth taking to keep your business and clients safe.
Read More
Credit to Author: Chris McCormack| Date: Tue, 23 Jan 2018 16:18:53 +0000
It’s not about the individuals, it’s about the team<img src=”http://feeds.feedburner.com/~r/sophos/dgdY/~4/BceIojSkiEA” height=”1″ width=”1″ alt=””/>
Read MoreCredit to Author: Jeffrey Esposito| Date: Tue, 23 Jan 2018 12:00:16 +0000
On this podcast, Brian Bartholomew of Kaspersky Lab’s GReAT gives a preview of his training session at SAS 2018.
Read MoreCredit to Author: Trend Micro| Date: Tue, 23 Jan 2018 14:00:04 +0000
Every device sooner or later begins to run slower and slower. Even the Mac, which is a highly-efficient Apple product, starts to slow down and becomes a real pain to use over time. If you are a heavy Mac user this is especially true and you are more likely to experience performance issues. There…

Credit to Author: John Maddison| Date: Tue, 23 Jan 2018 14:00:59 +0000
The successful rollout of icare’s new cloud-based business model can be attributed to Fortinet’s proactive account management, our technical expertise and our wide range of security solutions certified for AWS environments.
Read MoreCredit to Author: Alex Drozhzhin| Date: Tue, 23 Jan 2018 14:00:22 +0000
Do border agents have the right to search your devices? How can you protect your data from searches at the border? We have 11 tips covering this topic.
Read MoreCredit to Author: Prashant Kadam| Date: Tue, 23 Jan 2018 06:38:43 +0000
Cryptocurrencies like Bitcoin, Monero, Ethereum, Litecoin, and Tezos are in full swing. And they have exponentially increased cryptocurrency mining (or cryptomining) activities. Previously, cryptomining was carried out by powerful and dedicated mining hardware or by utilizing distributed computing because the entire process requires a lot of computation. However, there has been an observable change in the mining trends. Now, web browsers are taking part in cryptomining and its activity is growing because…
Read More
Credit to Author: SSD / Maor Schwartz| Date: Mon, 22 Jan 2018 12:07:17 +0000
漏洞概要 以下安全公告描述两个未经身份验证的命令注入漏洞。 希捷个人云家庭媒体存储设备是“存储,整理,流式传输,共享所有音乐,电影,照片和重要文档的最简单的方式”。 漏洞提交者 一位独立的安全研究人员Yorick Koster向 Beyond Security 的 SSD 报告了该漏洞。 厂商响应 希捷在10月16日被告知该漏洞,虽然已确认收到漏洞信息,但拒绝回应(我们给出的)技术细节,也没有给出确定的修复时间或是协调报告。 CVE:CVE-2018-5347 漏洞详细信息 Seagate Media Server使用Django Web框架并映射到.psp扩展名。 任何以.psp结尾的URL都会使用FastCGI协议自动发送到Seagate Media Server应用程序。 /etc/lighttpd/conf.d/django-host.conf: [crayon-5a666358f0897494367467/] URL被映射到文件/usr/lib/django_host/seagate_media_server/urls.py中特定的views。 有两个views受到未经认证的命令注入漏洞的影响。 受影响的views是: uploadTelemetry getLogs 这些views从GET参数获取用户输入,并将这些未经验证/解析的参数传递给Python模块相应的函数。 这允许攻击者注入任意的系统命令,这些命令将以root权限执行。 /usr/lib/django_host/seagate_media_server/views.py: [crayon-5a666358f08a3012049689/] /usr/lib/django_host/seagate_media_server/views.py: [crayon-5a666358f08a8093835846/] 请注意,这两个views都包含csrf_exempt decorator,它会禁用Django的默认开启的CSRF保护。 因此,这些问题可以通过跨站请求伪造来进行利用。 漏洞证明 下面的漏洞验证代码将尝试启用SSH服务,并更改root密码。 如果成功,则可以使用新密码通过SSH登录设备。 [crayon-5a666358f08ae242951493/]
Read More