Showing posts with label Lucian Constantin. Show all posts
Showing posts with label Lucian Constantin. Show all posts

Friday, February 23, 2018

Npm Update Crashes Linux Systems

An update for the popular Npm package manager used by many developers for JavaScript-based projects crashed Linux systems after changing the permissions for critical directories. Linux users who installed npm 5.7.0 released Feb. 21 quickly took to Twitter and GitHub to report that the update broke their filesystems by changing the permissions on critical system..

The post Npm Update Crashes Linux Systems appeared first on Security Boulevard.



from Npm Update Crashes Linux Systems

Wednesday, February 21, 2018

Spectre Patches Reach More CPUs as New Attack Variants Appear

Intel has released microcode patches to address the Spectre vulnerability on additional families of CPUs. Meanwhile, researchers have found a new way of implementing the Meltdown and Spectre attacks, but the variants are covered by existing patches. “We have now released production microcode updates to our OEM customers and partners for Kaby Lake- and Coffee..

The post Spectre Patches Reach More CPUs as New Attack Variants Appear appeared first on Security Boulevard.



from Spectre Patches Reach More CPUs as New Attack Variants Appear

Report: Software Vulnerabilities Increased 30 Percent in 2017

The number of software vulnerabilities recorded last year grew by 31 percent compared to 2016 and one-third of them have public exploits, according to a new report. Vulnerability intelligence firm Risk Based Security, which maintains its own vulnerability database called VulnDB, recorded a total of 20,832 security flaws last year. Around 7,900 of those flaws..

The post Report: Software Vulnerabilities Increased 30 Percent in 2017 appeared first on Security Boulevard.



from Report: Software Vulnerabilities Increased 30 Percent in 2017

Wednesday, February 14, 2018

Microsoft Fixes 50 Flaws in Windows, Outlook, Office and Browsers

Microsoft released patches for 50 vulnerabilities in Windows, Office, Outlook, Edge and Internet Explorer, 14 of which are rated critical. The company also released additional protections for the Meltdown and Spectre CPU vulnerabilities for older 32-bit versions of Windows 10, including Windows 10 for HoloLens. The most urgent patch is for a critical flaw (CVE-2018-0825)..

The post Microsoft Fixes 50 Flaws in Windows, Outlook, Office and Browsers appeared first on Security Boulevard.



from Microsoft Fixes 50 Flaws in Windows, Outlook, Office and Browsers

Monday, February 12, 2018

Destructive Malware Used to Attack Winter Olympics Infrastructure

The Olympic Winter Games in Pyeongchang, South Korea, started off with a cyberattack that disrupted the games’ official website and caused technical problems in the press center at the Olympic Stadium shortly before the opening ceremony Feb. 9. Winter Olympics officials confirmed that the games were hit by a cyberattack, but didn’t provide any other..

The post Destructive Malware Used to Attack Winter Olympics Infrastructure appeared first on Security Boulevard.



from Destructive Malware Used to Attack Winter Olympics Infrastructure

Sunday, February 4, 2018

Adobe Confirms Unpatched Flash Player Vulnerability Used in Attacks

Adobe Systems has confirmed that attackers are in possession of an exploit for a critical zero-day vulnerability in Flash Player that will be patched over the coming days. News of the flaw first came Jan. 31 in an alert from the South Korean Computer Emergency Response Team (KR-CERT), but researchers from security firm Hauri believe..

The post Adobe Confirms Unpatched Flash Player Vulnerability Used in Attacks appeared first on Security Boulevard.



from Adobe Confirms Unpatched Flash Player Vulnerability Used in Attacks

Friday, February 2, 2018

Hackers Use EternalBlue Exploit to Infect 500K Computers with Cryptominer

Over the past year, a group of hackers has used the “EternalBlue” exploit to infect more than 500,000 computers from around the world and use them to mine Monero. According to researchers from security firm Proofpoint, who have been tracking the botnet since May 2017, the cybercriminals behind it have used the computing power of..

The post Hackers Use EternalBlue Exploit to Infect 500K Computers with Cryptominer appeared first on Security Boulevard.



from Hackers Use EternalBlue Exploit to Infect 500K Computers with Cryptominer

Friday, January 26, 2018

Dutch Spies Monitored Russian ‘Cozy Bear’ Hackers in Real Time For Years

Intelligence services from the Netherlands reportedly had access to the computer network used by a Russian cyberespionage group known as Cozy Bear for years, watching the group break into the U.S. National Democratic Committee and other targets. Not only that, but the Dutch spies gained access to a surveillance camera outside the office used by..

The post Dutch Spies Monitored Russian ‘Cozy Bear’ Hackers in Real Time For Years appeared first on Security Boulevard.



from Dutch Spies Monitored Russian ‘Cozy Bear’ Hackers in Real Time For Years

Thursday, January 25, 2018

Apple Finally Ships Meltdown Patch for Older MacOS Systems

Apple has released new security patches for its macOS and iOS devices, managing to be both the first and the last of the major OS vendors to fix the serious Meltdown vulnerability. When the Meltdown and Spectre CPU vulnerabilities were first revealed earlier this month, people were surprised to learn that Apple had already included..

The post Apple Finally Ships Meltdown Patch for Older MacOS Systems appeared first on Security Boulevard.



from Apple Finally Ships Meltdown Patch for Older MacOS Systems

Wednesday, January 24, 2018

More OEMs Pull Spectre Patches As Intel Confirms Reboot Issues

HP and Dell, two of the largest server and enterprise workstation manufacturers, have stopped distributing BIOS/UEFI updates that include Intel’s CPU microcode patches for the Spectre vulnerability. The companies now advise customers to stop deploying the updates and wait for a new release. Days after releasing the patches two weeks ago, Intel revealed it was..

The post More OEMs Pull Spectre Patches As Intel Confirms Reboot Issues appeared first on Security Boulevard.



from More OEMs Pull Spectre Patches As Intel Confirms Reboot Issues

Monday, January 22, 2018

Triton Malware Exploited Zero-Day Flaw in Schneider Electric Safety Controllers

Schneider Electric has confirmed that a recently uncovered malware program that was used to attack industrial infrastructure exploited a vulnerability in its Triconex safety controllers. The malware, dubbed Triton, was uncovered in December by researchers from security firm FireEye after it triggered an emergency shutdown event at a critical infrastructure organization. It was the first..

The post Triton Malware Exploited Zero-Day Flaw in Schneider Electric Safety Controllers appeared first on Security Boulevard.



from Triton Malware Exploited Zero-Day Flaw in Schneider Electric Safety Controllers

Friday, January 19, 2018

Lebanon-Based Spy Group Identified in Mobile Spying Effort

Over the past six years, thousands of enterprises, educational institutions, medical professionals, activists, journalists, lawyers and military personnel from around the world have been spied on through their mobile devices by one or multiple groups that share the same malware toolset. The attacks have been discovered by researchers from mobile security firm Lookout in collaboration..

The post Lebanon-Based Spy Group Identified in Mobile Spying Effort appeared first on Security Boulevard.



from Lebanon-Based Spy Group Identified in Mobile Spying Effort

Wednesday, January 17, 2018

Oracle Fixes 200-Plus Vulnerabilities in Business-Critical Applications

Oracle has released the first quarterly security update this year to fix 237 vulnerabilities, more than half of which affect business-critical applications. The products impacted by the patched flaws include Java, MySQL, Oracle Database Server, Financial Services Applications, Fusion Middleware, Hospitality Applications, PeopleSoft, Supply Chain Products Suite, Sun Systems Products Suite, Retail Applications, Communications Applications,..

The post Oracle Fixes 200-Plus Vulnerabilities in Business-Critical Applications appeared first on Security Boulevard.



from Oracle Fixes 200-Plus Vulnerabilities in Business-Critical Applications

Sunday, January 14, 2018

Intel Investigating Reboots Caused by CPU Firmware Patches

The CPU crisis continues. After Windows and Ubuntu patches for the Meltdown and Spectre flaws caused problems for some users, Intel is now investigating reports that its CPU firmware updates are triggering system crashes and reboots. “We have received reports from a few customers of higher system reboots after applying firmware updates,” Navin Shenoy, the..

The post Intel Investigating Reboots Caused by CPU Firmware Patches appeared first on Security Boulevard.



from Intel Investigating Reboots Caused by CPU Firmware Patches

Wednesday, January 10, 2018

Microsoft Kills Old Office Equation Editor Due to New Flaw

Microsoft has removed a 17-year-old Office component called the Equation Editor after researchers found an arbitrary code execution flaw in it. This is the second serious vulnerability found in the old code that was kept around for compatibility reasons. The Microsoft Equation Editor (EQNEDT32.EXE) allows users to insert mathematical and scientific equations into Word documents...

The post Microsoft Kills Old Office Equation Editor Due to New Flaw appeared first on Security Boulevard.



from Microsoft Kills Old Office Equation Editor Due to New Flaw

Tuesday, January 9, 2018

D-Link NAS Backdoor Found Years Later in Western Digital My Cloud Boxes

A number of My Cloud network-attached storage devices from Western Digital, including some models used by businesses, were found to contain an undocumented account that could allow attackers to take over the devices. The exact same account with the same hard-coded password existed in D-Link NAS devices in the past. The backdoor account, which cannot..

The post D-Link NAS Backdoor Found Years Later in Western Digital My Cloud Boxes appeared first on Security Boulevard.



from D-Link NAS Backdoor Found Years Later in Western Digital My Cloud Boxes

Saturday, January 6, 2018

EMC Patches Serious Flaws in Data Protection Suite

EMC has released security fixes for three vulnerabilities that, when combined, can be used to take full control of products from its Data Protection Suite: the Avamar Server, the NetWorker Virtual Edition and the Integrated Data Protection Appliance. All three products contain a component called the Avamar Installation Manager (AVI), which is vulnerable to the..

The post EMC Patches Serious Flaws in Data Protection Suite appeared first on Security Boulevard.



from EMC Patches Serious Flaws in Data Protection Suite

Thursday, January 4, 2018

Major CPU Flaws Meltdown, Spectre Put Most Computers at Risk

The new year started with an announcement that has shaken the entire computer industry: Many modern processors found in servers, laptops and mobile devices are vulnerable to a new class of attacks that could expose sensitive information. The vulnerabilities were discovered independently by multiple researchers and have been reported to CPU manufacturers and all major..

The post Major CPU Flaws Meltdown, Spectre Put Most Computers at Risk appeared first on Security Boulevard.



from Major CPU Flaws Meltdown, Spectre Put Most Computers at Risk

Friday, December 29, 2017

You Can Now Help Identify Middleboxes Holding Back TLS 1.3 Adoption

TLS 1.3 promises great improvements for the encrypted Web, both in terms of security and performance. However, its adoption has been held back for the past year by SSL/TLS proxies and other load balancing and traffic monitoring middleboxes that break connections. Browser vendors have held back adding TLS 1.3 by default because tests showed that..

The post You Can Now Help Identify Middleboxes Holding Back TLS 1.3 Adoption appeared first on Security Boulevard.



from You Can Now Help Identify Middleboxes Holding Back TLS 1.3 Adoption

Hackers Infect Magento Shops With Malware Through Extension Flaw

Attackers are breaking into online shops built with Magento by exploiting a known cross-site scripting vulnerability within a popular extension used by merchants for customer support. A successful compromise results in malware being installed on the website with the goal being to intercept sensitive payment information inputted by customers. The vulnerability is located in a..

The post Hackers Infect Magento Shops With Malware Through Extension Flaw appeared first on Security Boulevard.



from Hackers Infect Magento Shops With Malware Through Extension Flaw