Independent

ComputerWorldIndependent

Microsoft yanks bad Outlook patches-of-patches KB 3191849, 3213654, 401042

Credit to Author: Woody Leonhard| Date: Sat, 15 Jul 2017 13:16:00 -0700

Read More
ComputerWorldIndependent

Restricting Firefox to TLS version 1.2 makes browsing safer

Credit to Author: Michael Horowitz| Date: Thu, 13 Jul 2017 19:43:00 -0700

Although its common to think of a secure website as the opposite of an insecure one, the choice is not, in fact, binary. For a website to be truly secure, there are about a dozen or so ducks that all need to be lined up in a row.

Seeing HTTPS does not mean that the security is well done, secure websites exist in many shades of gray. Since web browsers don’t offer a dozen visual indicators, many sites that are not particularly secure appear, to all but the most techie nerds, to be secure nonetheless. Browser vendors have dumbed things down for non-techies.

Last September, I took Apple to task for not having all their ducks in a row, writing that some of their security oversights allowed Apple websites to leak passwords.

To read this article in full or to leave a comment, please click here

Read More
IndependentSecuriteam

SSD Advisory – OrientDB Code Execution

Credit to Author: SSD / Maor Schwartz| Date: Thu, 13 Jul 2017 06:49:26 +0000

Vulnerability Summary The following advisory reports a vulnerability in OrientDB which allows users of the product to cause it to execute code. OrientDB is a Distributed Graph Database engine with the flexibility of a Document Database all in one product. The first and best scalable, high-performance, operational NoSQL database. Credit An independent security researcher, Francis … Continue reading SSD Advisory – OrientDB Code Execution

Read More
IndependentKrebs

Thieves Used Infrared to Pull Data from ATM ‘Insert Skimmers’

Credit to Author: BrianKrebs| Date: Thu, 13 Jul 2017 15:28:08 +0000

A greater number of ATM skimming incidents now involve so-called “insert skimmers,” wafer-thin fraud devices made to fit snugly and invisibly inside a cash machine’s card acceptance slot. New evidence suggests that at least some of these insert skimmers — which record card data and store it on a tiny embedded flash drive are — equipped with technology allowing it to transmit stolen card data wirelessly via infrared, the same technology built into a television remote control.

Read More
IndependentSecuriteam

SSD Advisory – 360 Total Security Privileged Escalation

Credit to Author: SSD / Maor Schwartz| Date: Wed, 12 Jul 2017 10:55:43 +0000

Vulnerability Summary The following advisory describes an Privileged Escalation vulnerability found in 360 Total Security. 360 Total Security offers your PC complete protection from Viruses, Trojans and other emerging threats. Whether you are shopping online, downloading files or chatting with your friends you can be sure that 360 Total Security is there to keep you … Continue reading SSD Advisory – 360 Total Security Privileged Escalation

Read More
ComputerWorldIndependent

Mingis on Tech: The language of malware

Credit to Author: Ken Mingis, Fahmida Y. Rashid| Date: Wed, 12 Jul 2017 03:00:00 -0700

Sometimes, how you say something can be as important as what you say — especially when’s there been a cyberattack and law enforcement officials are trying to figure out who you are.

That’s what CSO senior writer Fahmida Rashid found when she looked into how cybersecurity firms go about tracking down the bad actors behind malware campaigns. While linguistics may not be the first thing companies worry about when trying to protect — or retrieve access to — their data, it can help pinpoint an attack’s origin, Rashid told Computerworld Executive Editor Ken Mingis.

To read this article in full or to leave a comment, please click here

Read More