CES 2018: The top 9 new products for the enterprise
Credit to Author: Peter Sayer| Date: Fri, 12 Jan 2018 08:24:00 -0800

SSD Advisory – Seagate Personal Cloud Multiple Vulnerabilities

Credit to Author: SSD / Maor Schwartz| Date: Thu, 11 Jan 2018 13:45:21 +0000
Vulnerabilities summary The following advisory describes two (2) unauthenticated command injection vulnerabilities. Seagate Personal Cloud Home Media Storage is “the easiest way to store, organize, stream and share all your music, movies, photos, and important documents.” Credit An independent security researcher, Yorick Koster, has reported this vulnerability to Beyond Security’s SecuriTeam Secure Disclosure program Vendor … Continue reading SSD Advisory – Seagate Personal Cloud Multiple Vulnerabilities
Read MoreBitcoin Blackmail by Snail Mail Preys on Those with Guilty Conscience
Credit to Author: BrianKrebs| Date: Thu, 11 Jan 2018 18:25:26 +0000
KrebsOnSecurity heard from a reader whose friend recently received a remarkably customized extortion letter via snail mail that threatened to tell the recipient’s wife about his supposed extramarital affairs unless he paid $3,600 in bitcoin. The friend said he had nothing to hide and suspects this is part of a random but well-crafted campaign to prey on men who may have a guilty conscience.
Read MoreMicrosoft reinstates Meltdown/Spectre patches for some AMD processors — but which ones?

Credit to Author: Woody Leonhard| Date: Thu, 11 Jan 2018 09:38:00 -0800
As we rappel down the Patch Tuesday rabbit hole this month, Microsoft just announced that it’s going to start pushing its January Windows security patches onto AMD processors again. But it neglects to mention which ones. Per a late-night change to KB 4073707:
Microsoft has resumed updating the majority of AMD devices with the Windows operating system security update to help protect against the chipset vulnerabilities known as Spectre and Meltdown.
Windows 7 takes biggest performance hit from emergency Meltdown, Spectre updates

Credit to Author: Gregg Keizer| Date: Thu, 11 Jan 2018 05:09:00 -0800
Microsoft said Tuesday that Windows 7 PCs would run slower after receiving and installing the crash updates designed to stymie attacks that leverage the recently-disclosed vulnerabilities in virtually every in-use microprocessor.
But for Windows 10, a Microsoft executive said, “We don’t expect most users to notice a change because these [slowdown] percentages are reflected in milliseconds.”
The contrast, general though it was, came from Terry Myerson, who leads the company’s Windows group.
“With Windows 10 on newer silicon (2016-era PCs with Skylake, Kaby Lake or newer CPU), benchmarks show single-digit slowdowns,” Myerson wrote in a Tuesday post to a Microsoft blog. Skylake and Kaby Lake were the codenames for the Intel processors launched in 2015 and 2016, respectively. The bulk of new personal computers sold in 2016 and 2017 were equipped with Skylake or Kaby Lake CPUs (central processor units).
A mess of Microsoft patches, warnings about slowdowns — and antivirus proves crucial

Credit to Author: Woody Leonhard| Date: Wed, 10 Jan 2018 09:22:00 -0800
Welcome to another banner Patch Tuesday. Microsoft yesterday released 56 separately identified security patches for every supported version of Windows, Office, .Net, Internet Explorer and Edge. Out of that monstrous pile, only one patch cures a currently exploited problem — a flaw in Word’s Equation Editor that should have been fixed in November.
If you’re a “normal” user, your first priority shouldn’t be Microsoft’s patches, notwithstanding the fabulous PR job performed on Meltdown and Spectre’s behalf. Assuming you don’t open random Word docs with dicey embedded equations, your main concern right now should be getting your antivirus house in order.
Microsoft’s Jan. 2018 Patch Tuesday Lowdown

Credit to Author: BrianKrebs| Date: Wed, 10 Jan 2018 16:07:35 +0000
Microsoft on Tuesday released 14 security updates, including fixes for the Spectre and Meltdown flaws detailed last week, as well as a zero-day vulnerability in Microsoft Office that is being exploited in the wild. Separately, Adobe pushed a security update to its Flash Player software.
Read MoreMicrosoft sets novel antivirus prerequisite before offering Windows emergency updates

Credit to Author: Gregg Keizer| Date: Wed, 10 Jan 2018 05:03:00 -0800
Microsoft last week took the unprecedented step of requiring customers to have up-to-date antivirus software on their personal computers before it would hand over a critical security update.
“This was unique,” said Chris Goettl, product manager with client security and management vendor Ivanti. “But there was a danger here.”
Goettl was talking about the emergency updates Microsoft issued last week to bolster Windows’ defenses against potential attacks leveraging the vulnerabilities labeled Meltdown and Spectre by researchers. Operating system and browser makers have shipped updates designed to harden systems against the vulnerabilities, which stemmed from design flaws in modern processors from companies such as Intel, AMD and ARM.