Author: admin

FortinetSecurity

The Apache Struts 2 Vulnerability

Credit to Author: Aamir Lakhani| Date: Mon, 18 Sep 2017 15:20:00 +0000

It now appears that this crime was enabled through an exploit that targeted a Java vulnerability in Apache Struts 2, which is an open-source web application framework for developing Java web applications that extends the Java Servlet API to assist, encourage, and promote developers to adopt a model–view–controller (MVC) architecture.

Read More
FortinetSecurity

Adapting to the New Normal with an Informed Cybersecurity Strategy

Credit to Author: Joseph Sykora| Date: Mon, 18 Sep 2017 12:50:00 +0000

As cyberattacks become more frequent and impactful, security teams and executives across industries are taking notice. With new strains of malware being constantly reported, organizations want to make sure that their security solutions, and the vendors that provide them, are adapting to defend against this new normal. To ensure they have the capability to deal with these constantly evolving attacks, customers are turning to you, their solution providers, to answer their questions and ensure there is a structured strategy in place to deal with…

Read More
FortinetSecurity

Integrating Artificial Intelligence into Cybersecurity: Collaboration is the Key….!

Credit to Author: Jack Chan| Date: Mon, 18 Sep 2017 03:00:00 +0000

We have seen from the previous two posts on cybersecurity and AI the importance of using advanced technology to stay ahead of cybercriminals. But far too often, a threat transcends the capacity of one particular box, especially when it has been deployed in a discrete place in the network and has been functionally isolated from the rest of the network and other security devices. This is where Fortinet’s innovations around collaboration are paramount. Regardless of the physical location of a doiscovered security event, FortiGuard Labs teams…

Read More
MalwareBytesSecurity

A week in security (September 11 – September 17)

Credit to Author: Malwarebytes Labs| Date: Mon, 18 Sep 2017 22:10:42 +0000

A compilation of security news and blog posts from the 11th – 17th September. We look at 0days, more Equifax developments, our usual smattering of blog posts, and more!

Categories:

Tags:

(Read more…)

The post A week in security (September 11 – September 17) appeared first on Malwarebytes Labs.

Read More
MalwareBytesSecurity

Infected CCleaner downloads from official servers

Credit to Author: Pieter Arntz| Date: Mon, 18 Sep 2017 15:31:16 +0000

In a supply chain attack that may be unprecedented in number of downloads download servers hosting CCleaner, distributed by Avast have been delivering a version of CCleaner with malware on top.

Categories:

Tags:

(Read more…)

The post Infected CCleaner downloads from official servers appeared first on Malwarebytes Labs.

Read More
ComputerWorldIndependent

Heads up: Malware found in Piriform’s CCleaner installer

Credit to Author: Woody Leonhard| Date: Mon, 18 Sep 2017 05:22:00 -0700

If you installed the free version of CCleaner after Aug. 15, a couple of nasty programs came along for the ride. Talos Intelligence, a division of Cisco, just published a damning account of malware that it found hiding in the installer for CCleaner 5.33, the version that was released on Aug. 15 and which, according to Talos, was still the primary download on the official CCleaner page on Sept. 11.

After notifying Piriform, CCleaner was, ahem, cleaned up and version 5.34 appeared on Sept. 12.

I just checked, and the current version available from Piriform is version 5.34. (Piriform was bought by antivirus giant Avast in July.)

To read this article in full or to leave a comment, please click here

Read More
ComputerWorldIndependent

Apple’s clever strategy for forcing partners to use Face ID

Credit to Author: Evan Schuman| Date: Mon, 18 Sep 2017 03:00:00 -0700

When Apple announced the iPhone X last week, the most sophisticated (and widely predicted) feature revealed was the facial recognition approach, called Face ID. But by choosing to go all or nothing with the iPhone X — it’s only Face ID, with no support for Touch ID — the big risk for Apple was that all the companies that support Touch ID in their apps wouldn’t quickly make the move to Face ID. So Apple made the decision for them.

As the recent healthcare debate in the U.S. demonstrated, it’s extremely hard to take back something people have grown to like. Apple’s choice of biometric authentication faced the same problem. If Amazon, Chase, Fidelity or any of the other major companies whose apps use Touch ID as a way to log in without a password failed to move to Face ID, their customers would have been forced to go back to typing in long passwords. Apple, ever mindful of customer experience, chose to not permit that to happen. To make sure companies use Face ID in their apps, Apple simply didn’t give them any practical choice.

To read this article in full or to leave a comment, please click here

Read More