Independent

IndependentSecuriteam

SSD Advisory – NCurses 5.9 Local Privilege Escalation

Vulnerability Summary The following advisory describes an Local Privilege Escalation vulnerability in NCurses, version 5.9. Credit An independent security researcher Dawid Golunski (https://legalhackers.com/) has reported this vulnerability to Beyond Security’s SecuriTeam Secure Disclosure program Vendor Responses NCurses has released a patch to address the vulnerability. Thomas Dickey has also added the following statement “I don’t … Continue reading SSD Advisory – NCurses 5.9 Local Privilege Escalation

Read More
IndependentSecuriteam

SSD Advisory – IBM WebSphere Portal Cross-Site Scripting (XSS)

Vulnerabilities Summary The following advisory describes a Cross-Site Scripting (XSS) vulnerability found in WebSphere Portal version 8.0.0.1. IBM WebSphere Portal products provide enterprise web portals that help companies deliver a highly-personalized, social experience for their customers. WebSphere Portal products give users a single point of access to the applications, services, information and social connections they … Continue reading SSD Advisory – IBM WebSphere Portal Cross-Site Scripting (XSS)

Read More
ComputerWorldIndependent

Police lost 8 years of evidence in ransomware attack

Police in Cockrell Hill, a community in southwest Dallas, admitted to losing digital evidence from as far back as 2009 after the department’s server was compromised with ransomware.

Cockrell Hill Police Department Chief Stephen Barlag said, “As a result, all bodycam video, some photos, some in-car video, and some police department surveillance video were lost.”

Immediately, the police blamed Russian hackers, but Barlag later told WFAA that experts told him it “more likely originated in Ukraine.” The official press release, however, states, “It is unknown for certain where the virus originated from.”

To read this article in full or to leave a comment, please click here

Read More

(Insider Story)

Read More
ComputerWorldIndependent

Ransomware disrupts Washington DC's CCTV system

Around 70 percent of the cameras hooked up to the police’s closed-circuit TV (CCTV) system in Washington were reportedly unable to record footage for several days before President Donald Trump’s inauguration due to a ransomware attack.

The attack affected 123 of the 187 network video recorders that form the city’s CCTV system, The Washington Post reported Saturday. Each of these devices is used to store video footage captured by up to four cameras installed in public spaces.

To read this article in full or to leave a comment, please click here

Read More
ComputerWorldIndependent

German consumer groups sue WhatsApp over privacy policy changes

WhatsApp’s privacy policy change allowing Facebook to target advertising at its users has landed the company in a German court.

The Federation of German Consumer Organizations (VZBZ) has filed suit against WhatsApp in the Berlin regional court, alleging that the company collects and stores data illegally and passes it on to Facebook, the federation said Monday.

Facebook acquired WhatsApp in October 2014, but it wasn’t until August 2016 that WhatsApp said it would modify its privacy policy to allow it to share lists of users’ contacts with Facebook. The move made it possible to match WhatsApp accounts with Facebook ones where users had registered a phone number, giving the parent company more data with which to make new friend suggestions and another way to target advertising.

To read this article in full or to leave a comment, please click here

Read More