Independent

IndependentSecuriteam

SSD Advisory – Linux AF_LLC Double Free

Credit to Author: SSD / Noam Rathaus| Date: Mon, 30 Apr 2018 13:05:13 +0000

Vulnerability Summary A use after free vulnerability in AF_LLC allows local attackers to control the flow of code that the kernel executes, allowing them to cause it to run arbitrary code and gain elevated privileges. Vendor Response The vulnerability was reported to the Kernel Security, which asked us to contact the netdev team. A patch … Continue reading SSD Advisory – Linux AF_LLC Double Free

Read More
ComputerWorldIndependent

How to see everything Apple knows about you

Credit to Author: Jonny Evans| Date: Mon, 30 Apr 2018 04:41:00 -0700

Apple has at last introduced a new tool that lets you request and download everything the company knows about you, including all the data it gathers and retains when using the company’s retail outlets, iCloud, apps, products and services.

Why is this available?

In part, Apple has made this information available to bring it into line with Europe’s GDPR (General Data Protection Regulation) legislation, laws designed to better protect individual privacy in an online age.

To read this article in full, please click here

Read More
IndependentSecuriteam

beVX Conference Challenge – OffensiveCon

Credit to Author: SSD / Noam Rathaus| Date: Sun, 04 Mar 2018 07:27:05 +0000

During the event of OffensiveCon, we launched a reverse engineering and encryption challenge and gave the attendees the change to win great prizes. The challenge was divided into two parts, a file – can be downloaded from here: https://www.beyondsecurity.com/bevxcon/bevx-challenge-1 – that you had to download and reverse engineer and server that you had to access … Continue reading beVX Conference Challenge – OffensiveCon

Read More
IndependentKrebs

Security Trade-Offs in the New EU Privacy Law

Credit to Author: BrianKrebs| Date: Fri, 27 Apr 2018 17:27:40 +0000

On two occasions this past year I’ve published stories here warning about the prospect that new European privacy regulations could result in more spams and scams ending up in your inbox. This post explains in a question and answer format some of the reasoning that went into that prediction, and responds to many of the criticisms leveled against it.

Read More
ComputerWorldIndependent

Time to install the April Windows and Office patches, but there’s a big problem with Win7

Credit to Author: Woody Leonhard| Date: Fri, 27 Apr 2018 09:22:00 -0700

Good things come to those who wait. If you resisted the drill sergeant scream of “GET THOSE PATCHES INSTALLED AS SOON AS THEY’RE OUT, MAGGOT!” you’re about to reap your just reward.

As is so often the case, the Patch Tuesday screams are something you should consider, but they’re hardly the final word. At this point, there’s a credible threat forming for Win7 and Server 2008 R2 machines — Total Meltdown is definitely coming — but the sky hasn’t fallen. There are no known Meltdown or Spectre exploits in the wild, and all of the hell unleashed by this month’s series of patches and re-patches and pre-appended re-re-patches primarily served as demonic theater to those of us who chose to wait.

To read this article in full, please click here

Read More
ComputerWorldIndependent

Throwback Thursday: How to improve security

Credit to Author: Sharky| Date: Thu, 26 Apr 2018 03:00:00 -0700

There’s a new security policy at this biotech company, reports a pilot fish in the know: When logging in on a PC, the username field will now be blank, and everyone will have to input the name together with the password.

“The policy is announced weeks in advance,” fish says. “In spite of this, the first day is painful. A flurry of calls comes into the IT help desk regarding people not being able to log in. One is from a junior member of the payroll department who is about to leave on a two-week vacation — in fact, her flight is later that afternoon.”

“A tech tries to help her over the phone, but apparently she couldn’t tell the difference between the username box and password box, in spite of them actually being labeled as such.”

To read this article in full, please click here

Read More