Independent

IndependentKrebs

Patch Tuesday, January 2019 Edition

Credit to Author: BrianKrebs| Date: Wed, 09 Jan 2019 14:46:31 +0000

Microsoft on Tuesday released updates to fix roughly four dozen security issues with its Windows operating systems and related software. All things considered, this first Patch Tuesday of 2019 is fairly mild, bereft as it is of any new Adobe Flash updates or zero-day exploits. But there are a few spicy bits to keep in mind. Read on for the gory details.

Read More
ComputerWorldIndependent

Details, details

Credit to Author: Sharky| Date: Wed, 09 Jan 2019 03:00:00 -0800

It’s a few years after Y2K when the IT security team at this university gets a rude awakening, reports a pilot fish in the know.

“They discovered that persons unknown had hacked into a university server,” fish says. “It was being used to launch denial-of-service attacks against a victim somewhere outside the university.”

The team’s first job is finding the server — which turns out to be in the alumni office — and taking it offline.

Then they start digging into the security logs. That’s when they find out that the attackers have been making use of the server for more than a year.

And once they start checking on the IP addresses of whoever it is that has accessed the server, they discover it’s not just one or two hackers. It seems people from all over the world have been using this server to launch attacks.

To read this article in full, please click here

Read More
ComputerWorldIndependent

Mingis on Tech: As blockchain hype cools, a 'trough of disillusionment' for 2019?

Credit to Author: Ken Mingis| Date: Wed, 09 Jan 2019 03:00:00 -0800

Ok, so maybe blockchain isn’t ready yet to become the biggest new technology since the internet.

But the distributed ledger technology clearly made strides in 2018, when it was embraced by companies from Walmart to shipping bigwig Maersk to top tech venders like IBM, SAP, Oracle and Microsoft who see potential in blockchain-as-a-service. (Walmart’s vice president in charge of food safety, Frank Yiannas, compared his embrace of blockchain to a “religious conversaion.”)

To read this article in full, please click here

Read More
IndependentKrebs

Dirt-Cheap, Legit, Windows Software: Pick Two

Credit to Author: BrianKrebs| Date: Tue, 08 Jan 2019 15:00:33 +0000

Buying heavily discounted, popular software from second-hand sources online has always been something of an iffy security proposition. But purchasing steeply discounted licenses for cloud-based subscription products like recent versions of Microsoft Office can be an extremely risky transaction, mainly because you may not have full control over who has access to your data.

Read More
IndependentSecuriteam

SSD Advisory – SME Server Unauthenticated XSS To Privileged Remote Code Execution

Credit to Author: SSD / Ori Nimron| Date: Mon, 07 Jan 2019 13:21:59 +0000

Vulnerabilities Summary The following advisory describes a vulnerability in SME Server 9.2, which lets an unauthenticated attackers perform XSS attack that leads to remote code execution as root. SME Server is a Linux distribution for small and medium enterprises by Koozali foundation. CVE CVE-2018-18072 Credit An independent security researcher, Karn Ganeshen has reported this vulnerability … Continue reading SSD Advisory – SME Server Unauthenticated XSS To Privileged Remote Code Execution

Read More
ComputerWorldIndependent

Top 4 enterprise tech trends to watch in 2019

Credit to Author: Michelle Davidson| Date: Mon, 07 Jan 2019 03:00:00 -0800

If 2018 was the year of the data breach, the thinking among IT pros is that this will be the year companies take concrete steps to prevent future breaches.

That was the sentiment among tech professionals who took part in a recent @IDGTechTalk Twitter chat about enterprise tech trends for 2019.

In fact, a recent @IDGTechTalk poll found privacy and security to be the top enterprise tech issue for 2019 (45 percent), followed by artificial intelligence (30 percent), cloud computing (16 percent), and blockchain (9 percent).

To read this article in full, please click here

Read More

(Insider Story)

Read More
IndependentSecuriteam

SSD Advisory – Apache OpenOffice Virtual Table Corruption

Credit to Author: SSD / Ori Nimron| Date: Sun, 06 Jan 2019 07:40:33 +0000

Vulnerabilities Summary The following advisory discusses a vulnerability found in Apache OpenOffice. The vulnerability lays inside the part that responsible for parsing documents, which contains has an overflow that let attackers take control over program execution. Vendor Response “We obtained a CVE number for the vulnerability you reported: CVE-2018-11790. The release will need to undergo … Continue reading SSD Advisory – Apache OpenOffice Virtual Table Corruption

Read More