Independent

ComputerWorldIndependent

Microsoft Patch Alert: Major bugs introduced in May fixed, plenty of problems remain

Credit to Author: Woody Leonhard| Date: Wed, 30 May 2018 03:49:00 -0700

Once more we have a monthly Windows/Office patch scorecard that needs a guidebook. Or two. And we just got a handful of buried warnings about problems in old patches, plus a brand new way to fry your network interface card.

Thus continues the tradition of two cumulative updates per month for all of the supported Windows 10 versions – that’s eight cumulative updates in total – in addition to bobs and weaves and a very long list of acknowledged bugs introduced by recent security patches in Windows 7.

Conflicts with Remote Desktop

The strange behavior of the CredSSP update – where the Patch Tuesday fixes for all versions of Windows seemed to break Remote Desktop Protocol with a strange error message: “This could be due to CredSSP encryption oracle remediation” has been resolved.

To read this article in full, please click here

Read More
IndependentKrebs

Will the Real Joker’s Stash Come Forward?

Credit to Author: BrianKrebs| Date: Tue, 29 May 2018 16:33:34 +0000

For as long as scam artists have been around so too have opportunistic thieves who specialize in ripping off other scam artists. This is the story about a group of Pakistani Web site designers who apparently have made an impressive living impersonating some of the most popular and well known “carding” markets, or online stores that sell stolen credit cards.

Read More
ComputerWorldIndependent

WWDC: Apple’s NFC plan is a big developer opportunity

Credit to Author: Jonny Evans| Date: Tue, 29 May 2018 08:01:00 -0700

Apple will open up fresh opportunities for developers as it extends Near Field Communications (NFC) support in iOS to more uses.

NFC: Apple’s story so far

Apple introduced support for a new NFC framework called Core NFC at WWDC 2017. Developers were pleased, but the implementations were rather limited.

Core NFC let developers build apps that read NFC tags, but only for things like visitor attractions and museum exhibitions.

To read this article in full, please click here

Read More
IndependentSecuriteam

SSD Advisory – QRadar Remote Command Execution

Credit to Author: SSD / Noam Rathaus| Date: Mon, 28 May 2018 10:53:15 +0000

Vulnerability Summary Multiple vulnerabilities in QRadar allow a remote unauthenticated attackers to cause the product to execute arbitrary commands. Each vulnerability on its own is not as strong as their chaining – which allows a user to change from unauthenticated to authenticated access, to running commands, and finally running these commands with root privileges. Vendor … Continue reading SSD Advisory – QRadar Remote Command Execution

Read More
IndependentKrebs

FBI: Kindly Reboot Your Router Now, Please

Credit to Author: BrianKrebs| Date: Mon, 28 May 2018 18:54:22 +0000

The Federal Bureau of Investigation (FBI) is warning that a new malware threat has rapidly infected more than a half-million consumer devices. To help arrest the spread of the malware, the FBI and security firms are urging home Internet users to reboot routers and network-attached storage devices made by a range of technology manufacturers.

Read More
IndependentKrebs

Why Is Your Location Data No Longer Private?

Credit to Author: BrianKrebs| Date: Sat, 26 May 2018 16:18:48 +0000

The past month has seen one blockbuster revelation after another about how our mobile phone and broadband providers have been leaking highly sensitive customer information, including real-time location data and customer account details. In the wake of these consumer privacy debacles, many are left wondering who’s responsible for policing these industries? How exactly did we get to this point? What prospects are there for changes to address this national privacy crisis at the legislative and regulatory levels? These are some of the questions we’ll explore in this article.

Read More
ComputerWorldIndependent

Amazon's Echo privacy flub has big implications for IT

Credit to Author: Evan Schuman| Date: Sat, 26 May 2018 08:34:00 -0700

Amazon has confirmed a report that one of its Echo devices recorded a family’s conversation and then messaged it to a random person on the family’s contact list, who is an employee of a family member.

But Amazon, in a statement emailed to Computerworld, confirmed every privacy advocate’s worst nightmare with its explanation: “Echo woke up due to a word in background conversation sounding like ‘Alexa.’ Then, the subsequent conversation was heard as a ‘send message’ request. At which point, Alexa said out loud ‘To whom?’ At which point, the background conversation was interpreted as a name in the customer’s contact list. Alexa then asked out loud, ‘[contact name], right?’ Alexa then interpreted background conversation as ‘right.’ As unlikely as this string of events is, we are evaluating options to make this case even less likely.”

To read this article in full, please click here

Read More