A World of Vulnerabilities - InfoSec Institute
Every day, we read about cyber-attacks and data breaches, incidents that represent in many cases a disaster for private companies and governments. Technology plays a significant role in our lives; every component that surrounds us runs a piece of software that could be affected by flaws and exploited by those with ill intentions.
Was Microsoft's takedown of Citadel effective?
A posting from Naked Security: As we mentioned last week, Microsoft recently fought back against more than 1,400 Citadel botnets by sinkholing their Command and Control (C&C) infrastructure. SophosLabs has been monitoring Citadel for some time, including individual botnets such as those targeting Canadian institutions, so I decided to take a closer look at the impact of the […]
Black Hat USA 2013 Showcases NAND, Windows 8 Secure Boot Hacking Talks
A posting from Dark Reading in there Authentication Section: As July's Black Hat US in Las Vegas nears, organizers have confirmed another trio of highlighted Briefings from the show, which all focus, in some way or other, on getting under the skin of key systems. Here's the official rundown: - Technologies don't get much more ubiquitous […]
Bad SSH Key Management Leaves Databases At Risk
A posting from Dark reading in there Database Security Section: A "gaping hole" in the way enterprises govern the use of one of IT's least sexy but most used access control and encryption protocols is leaving many sensitive database servers and other network devices at serious risk. Secure Shell (SSH)--a Swiss army knife in the arsenal of […]
'Activation lock' to tighten iOS security
A posting from Cnet News in there Security and Privacy section; Apple may not be able to do anything to stop a mugger from stealing your iPhone, but changes in iOS 7 will prevent the thief from trying to sell the phone as new. At its Worldwide Developers Conference here on Monday, Apple unveiled several security enhancements. Activation Lock […]
Microsoft announces five Bulletins for Patch Tuesday, including Office for Mac
A posting from Naked Security: Midsummer Patch Tuesday (or midwinter, depending on your latitude) takes place on Tuesday 11 June 2013. As you probably already know, Microsoft publishes an official Advance Notification each month to give you early warning of what's coming. These early notifications generally don't give any details, summarising only the basics, such as: The […]
Facebook forensics? What the feds can learn from your digital crumbs
An interesting article In NBC News in there Technology section: Bits of you are all over the Internet. If you've signed into Google and searched, saved a file in your Dropbox folder, made a phone call using Skype, or just woken up in the morning and checked your email, you're leaving a trail of digital crumbs. […]
12 Endpoint Security Myths Dispelled
A posting from Dark Reading in there Endpoint Security section: It's been years now since the security pundits have taken up the mantle to dispel the myth that AV alone is enough to protect the typical endpoint. And while that misconception does hang on in certain quarters, to a large degree it has been discussed ad […]
New proof-of-concept malware demonstrates virus for OS X
A posting from Cnet News in there Security and Privacy Section: Security researchers have found a proof-of-concept attack that appears to be the first true viral malware approach for compromising OS X. The malware is called "Clampzok.A" and is a cross-platform malware package that alters the binary files on an affected system so when executed, the binary […]