Independent

IndependentSecuriteam

SSD Advisory – KEMP LoadMaster from XSS Pre Authentication to RCE

Credit to Author: SSD / Noam Rathaus| Date: Thu, 25 May 2017 06:01:41 +0000

KEMP’s main product, the LoadMaster, is a load balancer built on its own proprietary software platform called LMOS, that enables it to run on almost any platform: As a KEMP LoadMaster appliance, a Virtual LoadMaster (VLM) deployed on Hyper-V, VMWare, on bare metal or in the public cloud. KEMP is available in Azure, where it … Continue reading SSD Advisory – KEMP LoadMaster from XSS Pre Authentication to RCE

Read More
ComputerWorldIndependent

IDG Contributor Network: Eight steps to the GDPR countdown

Credit to Author: Sandra Henry-Stocker| Date: Thu, 25 May 2017 12:52:00 -0700

One year from today, the recently passed regulation known as “GDPR” (General Data Protection Regulation) goes into effect. While EU-specific, it can still dramatically affect how businesses that work with personal data of citizens and residents of the EU. GDPR was approved a year ago and will be going into effect in another year. It applies directly to organizations within the EU, but also applies to organizations outside the EU if they 1) offer goods and services to the EU, 2) monitor the behavior EU subjects, or 3) process or retain personal data of EU citizens and residents. And the regulation can place very serious fines and sanctions for non-compliance.

To read this article in full or to leave a comment, please click here

Read More
ComputerWorldIndependent

The WannaCry scramble

Credit to Author: Mathias Thurman| Date: Thu, 25 May 2017 10:05:00 -0700

A couple of weeks ago, possibly every security manager in the world was dealing with the repercussions of WannaCry, a ransomware worm that screamed across the internet and flooded the media. IT and security departments, placed on high alert, had to scramble — whether or not any of their systems had been infected. I was no exception.

Read More
IndependentKrebs

MolinaHealthcare.com Exposed Patient Records

Credit to Author: BrianKrebs| Date: Thu, 25 May 2017 18:08:21 +0000

Earlier this month, KrebsOnSecurity featured a story about a basic security flaw in the Web site of medical diagnostics firm True Health Group that let anyone who was logged in to the site view all other patient records. In that story I mentioned True Health was one of three major healthcare providers with similar website problems, and that the other two providers didn’t even require a login to view all patient records. Today we’ll examine such a flaw that was just fixed by Molina Healthcare, a Fortune 500 company that until recently was exposing countless patient medical claims to the entire Internet without requiring any authentication.

Read More
ComputerWorldIndependent

IDG Contributor Network: The complexity of password complexity

Credit to Author: Sandra Henry-Stocker| Date: Thu, 25 May 2017 05:47:00 -0700

Deploying password quality checking on your Debian-base Linux servers can help to ensure that your users assign reasonable passwords on their accounts, but the settings themselves can be a bit misleading. For example, setting a minimum password length of 12 characters does not mean that your users’ passwords will all have twelve or more characters. Let’s stroll down Complexity Boulevard and see how the settings work and examine some settings worth considering.

First, if you haven’t done this already, install the password quality checking library with this command:

apt-get -y install libpam-pwquality 

The files that contain most of the settings we’re going to look at will be:

To read this article in full or to leave a comment, please click here

Read More
ComputerWorldIndependent

Appeals court gives Wikimedia thumbs up to sue NSA for 'Upstream' surveillance

Credit to Author: Darlene Storm| Date: Wed, 24 May 2017 08:26:00 -0700

Well, well, well, the NSA may not waltz away legally unscathed after spying on Americans’ private communications due to the dogged determination of the Wikimedia Foundation, the ACLU, the Knight First Amendment Institute at Columbia University and eight other co-plaintiffs.

The 4th US Circuit Court of Appeals ruled to give Wikimedia a chance to legally challenge the NSA’s mass surveillance as being unconstitutional. The government has previously argued that the NSA’s Upstream warrantless spying is authorized under Section 702 of the Foreign Intelligence Surveillance Act. Thanks to Upstream surveillance, the NSA sucks up and searches through American’s international internet communications.

To read this article in full or to leave a comment, please click here

Read More
ComputerWorldIndependent

Former NSA chief weighs in on cybersecurity, cyberespionage at ZertoCon

Credit to Author: Ryan Francis| Date: Tue, 23 May 2017 14:53:00 -0700

BOSTON — Retired Gen. Michael Hayden held nothing back when speaking to cybersecurity pros today at the ZertoCon business continuity conference.

It’s been more than a decade since he led the National Security Agency (NSA), but that didn’t stop Hayden from asserting that the Russians were involved in last year’s U.S. presidential election. His view: Only two presidents doubt that the Russians were involved in the 2016 election — Donald Trump and Vladimir Putin.

“They [the Russians] had an affect on the election, there is no question that this happened,” Hayden said. “The question is if there was collaboration with the campaign.”

To read this article in full or to leave a comment, please click here

Read More
ComputerWorldIndependent

IDG Contributor Network: Wikileaks reveals potent Windows malware from the CIA

Credit to Author: Andy Patrizio| Date: Tue, 23 May 2017 14:00:00 -0700

A few days ago, Microsoft’s top lawyer took the NSA to task over WannaCry, saying that problem was the agency’s creation because it built and stockpiled such malware for its own use.

Now WikiLeaks has revealed more government-created malware and this one is a nasty piece of work.

Codenamed “Athena,” the spyware targets all version of Windows from Windows XP to Windows 10, and was released in August 2015. It was created in part by a private New Hampshire-based cyber security firm called Siege Technologies.

To read this article in full or to leave a comment, please click here

Read More