Independent

ComputerWorldIndependent

Apple edges closer to cursory code review for all Mac apps

Credit to Author: Gregg Keizer| Date: Wed, 24 Apr 2019 04:25:00 -0700

Apple will soon make a code review mandatory for all applications distributed outside its own Mac App Store by new developers, a first step towards requiring all Mac software to pass similar reviews.

The Cupertino, Calif. company argued that the process, which it calls “notarization,” would build a more secure macOS environment. “We’re working with developers to create a safer Mac user experience through a process where all software, whether distributed on the [Mac] App Store or outside of it, is signed or notarized by Apple,” the company stated in an April 10 message on its developer portal.

To read this article in full, please click here

Read More
ComputerWorldIndependent

Security theater, ’80s style

Credit to Author: Sharky| Date: Tue, 23 Apr 2019 03:00:00 -0700

It’s the late 1980s and pilot fish is working on business application development for an aerospace and defense contractor where physical security is surprisingly lax. There’s a guard on duty at the front desk during business hours, but that’s about the extent of it. That changes with the announcement that all personal gear will be subject to inspection on leaving the building.
Now there are guards 24/7, and everyone leaving the building is politely requested by those guards to open their briefcases and backpacks. The guards then take a look inside before waving the owners through.
Rumor has it that this security push came about because some Apple Mac computers have gone missing. And it continues for about six months, and then suddenly ceases.
What happened? Employees have to rely on rumor again, which holds that the cleaning crew had taken the Macs, which makes sense given that large, wheeled trashcans would make the job easy.
The exit checks never turned up anything, but even law-abiding pilot fish can’t help but notice that it would be pretty easy to cover any contraband in a bag with a few clothes or newspapers and never be discovered, given the cursory nature of the searches.

To read this article in full, please click here

Read More
IndependentKrebs

Who’s Behind the RevCode WebMonitor RAT?

Credit to Author: BrianKrebs| Date: Mon, 22 Apr 2019 19:43:02 +0000

The owner of a Swedish company behind a popular remote administration tool (RAT) implicated in thousands of malware attacks shares the same name as a Swedish man who pleaded guilty in 2015 to co-creating the Blackshades RAT, a similar product that was used to infect more than half a million computers with malware, KrebsOnSecurity has learned.

Read More
ComputerWorldIndependent

Here's an easier way to block the IE XXE zero day security hole

Credit to Author: Woody Leonhard| Date: Thu, 18 Apr 2019 09:57:00 -0700

The latest Internet Explorer XXE zero-day depends on you opening an infected MHT file. MHT is an old file format that’s almost always opened by IE — no matter which browser you’re using, no matter which version of Windows. Catalin Cimpanu has a good overview of this XXE vulnerability on ZDNet.

It’s a doozy of a security hole as it affects every recent version of IE, and it infects whether you’re actively browsing with IE or not.

To read this article in full, please click here

Read More
IndependentKrebs

Wipro Intruders Targeted Other Major IT Firms

Credit to Author: BrianKrebs| Date: Thu, 18 Apr 2019 17:42:46 +0000

The criminals responsible for launching phishing campaigns that netted dozens of employees and more than 100 computer systems last month at Wipro, India’s third-largest IT outsourcing firm, also appear to have targeted a number of other competing providers, including Infosys and Cognizant — two other large technology consulting companies, new evidence suggests.

Read More
IndependentKrebs

How Not to Acknowledge a Data Breach

Credit to Author: BrianKrebs| Date: Wed, 17 Apr 2019 17:56:58 +0000

I’m not a huge fan of stories about stories, or those that explore the ins and outs of reporting a breach. But occasionally it seems necessary to publish such accounts when companies respond to a breach report in such a way that it’s crystal clear that they wouldn’t know what to do with a breach if it bit them in the nose, let alone festered unmolested in some dark corner of their operations.

Read More