Vulnerability
SSD Encryption from Crucial and Samsung is not secure Exposes Data

The researchers examined multiple SSDs, including Crucial and Samsung, some of which they found could be unlocked with any password if the password validation routine in RAM was modified through a standard JTAG debugging interface.

Read more
General Security
Information Commissioner Calls for Regulation of Social Media Following Cambridge Analytica scandal

Information commissioner calls for regulation of social media following Cambridge Analytica scandal

Read more
Vulnerability & Threat Report
Ruby2.3 Security Update - CVE-2018-16395 CVE-2018-16396

Several vulnerabilities have been discovered in the interpreter for the Ruby language. The Common Vulnerabilities and Exposures project identifies the following problems:

Read more
General Security
UK's Information Commissioner’s Office (ICO) Slap Fines on Facebook and Equifax

Facebook was fined £500,000 by the UK's Information Commissioner’s Office (ICO) for its role in the Cambridge Analytica data scandal.

Read more
Vulnerability
Cisco WebEx Meetings Server XML External Entity (CVE-2018-18895)

Cisco Webex Meetings Server includes a version of Castor XML that is affected by XXE. Because of that Cisco WebEx Meetings Server prior to versions 2.8MR3 and 3.0MR2 patch 1 are affected from XXE vulnerability.

Read more
Vulnerability
U-Boot verified boot bypass vulnerabilities (CVE-2018-18439, CVE-2018-18440)

Multiple techniques have been identified that allow to execute arbitrary code, within a running U-Boot instance, by means of externally provided unauthenticated data.

Read more
Vulnerability
New PortSmash Side-Channel Vulnerability (CVE-2018-5407)

A new vulnerability being called PortSmash, (CVE-2018-5407) has been discovered impacting all CPUs that use a Simultaneous Multithreading (SMT) architecture. SMT is a technology that allows multiple computing threads to be executed simultaneously on a CPU core.

Read more
Hack
Eurostar Customers Reset Passwords After Security Breach

Eurostar forced all of its customers to reset their passwords after indications of a possible breach by hackers attempted to access user accounts.

Read more
Education
Continuous Monitoring : Academic Paper

The Federal Information Security Act (FISMA) of 2002 requires that government agencies report on their Information Technology Security Status annually to the Office of Management and Budget (OMB).

Read more
Vulnerability
Armis Discovers "BLEEDINGBIT," Two Critical Chip-Level Vulnerabilities

Armis, the enterprise IoT security company, today announced the discovery of two critical vulnerabilities related to the use of Bluetooth Low Energy (BLE) chips made by Texas Instruments (TI), and used in Cisco, Meraki and Aruba wireless access points, called "BLEEDINGBIT."

Read more