π΄ Intel Focuses on Data Center, Firmware Security Ahead of RSAC π΄
π Read
via "Dark Reading: ".
The new Intel SGX Card is intended to extend application memory security using Intel SGX in existing data center infrastructure.π Read
via "Dark Reading: ".
Dark Reading
Intel Focuses on Data Center, Firmware Security Ahead of RSAC
The new Intel SGX Card is intended to extend application memory security using Intel SGX in existing data center infrastructure.
π΄ Persistent Attackers Rarely Use Bespoke Malware π΄
π Read
via "Dark Reading: ".
Study of the Bronze Union group-also known as APT27 or Emissary Panda-underscores how most advanced persistent threat (APT) groups now use administrative tools or slight variants of well-known tools.π Read
via "Dark Reading: ".
Dark Reading
Persistent Attackers Rarely Use Bespoke Malware
Study of the Bronze Union group-also known as APT27 or Emissary Panda-underscores how most advanced persistent threat (APT) groups now use administrative tools or slight variants of well-known tools.
π΄ More Than 22,000 Vulns Were Disclosed in 2018, 27% Without Fixes π΄
π Read
via "Dark Reading: ".
As in previous years, input validation vulnerabilities accounted for a substantial proportion of total, Risk Based Security report shows.π Read
via "Dark Reading: ".
Dark Reading
More Than 22,000 Vulns Were Disclosed in 2018, 27% Without Fixes
As in previous years, input validation vulnerabilities accounted for a substantial proportion of total, Risk Based Security report shows.
π΄ IoT, APIs, and Criminal Bots Pose Evolving Dangers π΄
π Read
via "Dark Reading: ".
A pair of reports reach similar conclusions about some of the threats growing in cyberspace and the industries likely to be most affected.π Read
via "Dark Reading: ".
Dark Reading
Cyberattacks & Data Breaches recent news | Dark Reading
Explore the latest news and expert commentary on Cyberattacks & Data Breaches, brought to you by the editors of Dark Reading
β US pushed Russian troll factory offline during US midterm elections β
π Read
via "Naked Security".
The US blocked internet access to Russian trolls who, they say, were trying to spread FUD.π Read
via "Naked Security".
Naked Security
US pushed Russian troll factory offline during US midterm elections
The US blocked internet access to Russian trolls who, they say, were trying to spread FUD.
β US House and Senate debate new data privacy law β
π Read
via "Naked Security".
A steady stream of hair-raising revelations about the treatment of users' data by Facebook, et al. is pushing Congress to do *something.*π Read
via "Naked Security".
Naked Security
US House and Senate debate new data privacy law
A steady stream of hair-raising revelations about the treatment of usersβ data by Facebook, et al. is pushing Congress to do *something.*
β Thunderclap: Apple Macs at risk from malicious Thunderbolt peripherals β
π Read
via "Naked Security".
Researchers have revealed how malicious Thunderbolt and PCI Express (PCIe) peripherals could be used to compromise computers running macOS, Windows, Linux and FreeBSD.π Read
via "Naked Security".
Naked Security
Thunderclap: Apple Macs at risk from malicious Thunderbolt peripherals
Researchers have revealed how malicious Thunderbolt and PCI Express (PCIe) peripherals could be used to compromise computers running macOS, Windows, Linux and FreeBSD.
π΄ Find your New Favorite Security Tool in the Black Hat Asia Arsenal π΄
π Read
via "Dark Reading: ".
From data exfiltration over FM radio to open-source cybersecurity training suites, Black Hat Asia's Arsenal offers live demos of the latest security tools.π Read
via "Dark Reading: ".
Dark Reading
Find your New Favorite Security Tool in the Black Hat Asia Arsenal
From data exfiltration over FM radio to open-source cybersecurity training suites, Black Hat Asia's Arsenal offers live demos of the latest security tools.
β Cisco Fixes Critical Flaw in Wireless VPN, Firewall Routers β
π Read
via "Threatpost | The first stop for security news".
Cisco said that CVE-2019-1663, which has a CVSS score of 9.8, allows unauthenticated, remote attackers to execute arbitrary code.π Read
via "Threatpost | The first stop for security news".
Threat Post
Cisco Fixes Critical Flaw in Wireless VPN, Firewall Routers
Cisco said that CVE-2019-1663, which has a CVSS score of 9.8, allows unauthenticated, remote attackers to execute arbitrary code.
π΄ In 2019, Cryptomining Just Might Have an Even Better Year π΄
π Read
via "Dark Reading: ".
The practice today is so pervasive that cryptojacking scripts are said to be running on an estimated 3% of all sites that users visit.π Read
via "Dark Reading: ".
Darkreading
In 2019, Cryptomining Just Might Have an Even Better Year
The practice today is so pervasive that cryptojacking scripts are said to be running on an estimated 3% of all sites that users visit.
β Coinhive to Mine Its Last Monero in March β
π Read
via "Threatpost | The first stop for security news".
The controversial cryptomining service is shutting down.π Read
via "Threatpost | The first stop for security news".
Threat Post
Coinhive to Mine Its Last Monero in March
The controversial cryptomining service is shutting down.
π΄ European Security Firm to Offer Free Hacking Toolkit π΄
π Read
via "Dark Reading: ".
CQTools suite includes both exploit kits and information-extraction functions, its developers say.π Read
via "Dark Reading: ".
Dark Reading
Security Firm to Offer Free Hacking Toolkit
CQTools suite includes both exploit kits and information-extraction functions, its developers say.
π΄ Bots Plague Ticketing Industry π΄
π Read
via "Dark Reading: ".
Bots now account for 39.9% of all ticketing traffic, mostly originating in North America.π Read
via "Dark Reading: ".
Darkreading
Bots Plague Ticketing Industry
Bots now account for 39.9% of all ticketing traffic, mostly originating in North America.
π΄ Microsoft Debuts Azure Sentinel SIEM, Threat Experts Service π΄
π Read
via "Dark Reading: ".
New services, which are both available in preview, arrive at a time when two major trends are converging on security.π Read
via "Dark Reading: ".
Darkreading
Microsoft Debuts Azure Sentinel SIEM, Threat Experts Service
New services, which are both available in preview, arrive at a time when two major trends are converging on security.
π΄ Dow Jones Leak Exposes Watchlist Database π΄
π Read
via "Dark Reading: ".
The Watchlist, which contained the identities of government officials, politicians, and people of political interest, is used to identify risk when researching someone.π Read
via "Dark Reading: ".
Dark Reading
Dow Jones Leak Exposes Watchlist Database
The Watchlist, which contained the identities of government officials, politicians, and people of political interest, is used to identify risk when researching someone.
ATENTIONβΌ New - CVE-2018-12402
π Read
via "National Vulnerability Database".
The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when sub-resources are loaded as part of "Save Page As..." functionality. For example, a malicious page could recover a visitor's Windows username and NTLM hash by including resources otherwise unreachable to the malicious page, if they can convince the visitor to save the complete web page. Similarly, SameSite cookies are sent on cross-origin requests when the "Save Page As..." menu item is selected to save a page, which can result in saving the wrong version of resources based on those cookies. This vulnerability affects Firefox < 63.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2018-12401
π Read
via "National Vulnerability Database".
Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters following a '?' in the parsed string. This could lead to denial of service (DOS) attacks. This vulnerability affects Firefox < 63.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2018-12400
π Read
via "National Vulnerability Database".
In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode. This allows information leakage of sites visited during private browsing sessions. *Note: this issue only affects Firefox for Android. Desktop versions of Firefox are unaffected.*. This vulnerability affects Firefox < 63.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2018-12399
π Read
via "National Vulnerability Database".
When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approving a protocol handler that they otherwise would not have. This vulnerability affects Firefox < 63.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2018-12398
π Read
via "National Vulnerability Database".
By using the reflected URL in some special resource URIs, such as chrome:, it is possible to inject stylesheets and bypass Content Security Policy (CSP). This vulnerability affects Firefox < 63.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2018-12397
π Read
via "National Vulnerability Database".
A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.π Read
via "National Vulnerability Database".