Content Tagged ‘vulnerability’

Google Wallet PINs easily stolen from rooted devices

February 9, 2012 - A researcher at zvelo has discovered that he can recover the PIN used to make payments with Google Wallet in just seconds on a rooted Android device. Read more

Is Digital Pearl Harbor THE most tasteless term in IT security?

February 9, 2012 - Can hackers really cause as much bloodshed as 353 Imperial Japanese Navy fighters, bombers and torpedo planes launched from six aircraft carriers? Can hackers really kill 2,402 U.S. citizens, leave 1,282 wounded, lose 65 of their own attackers in the process, (continue reading...) Read more

Endpoint Security Webinar: Protecting your network at the sharp end

February 8, 2012 - I have a theory that says improving information system security–the security of our operating systems, network connections, and applications–just means the bad guys will focus more attention on our endpoints, the digital devices we use to access the information and (continue reading...) Read more

Security 101: Attack Vectors Take Advantage of User Interaction

February 8, 2012 - Welcome back to Security 101. Our New Year’s recess is over, and it’s time to offer another lesson. So far we have discussed vulnerabilities and some types of low-interaction attack vectors. In this lesson we shall continue with (continue reading...) Read more

Why is a 14-month-old patched Microsoft vulnerability still being exploited?

February 7, 2012 - While the media just looove zero-day exploits, the security industry sees a lot more exploits designed to take advantage of patched vulnerabilities. Question is why don't many of us get around to installing the patches? (continue reading...) Read more

VeriSign admits it was hacked repeatedly in 2010, staff didn’t tell senior management

February 2, 2012 - Internet giant VeriSign was admitted it was hacked repeatedly during 2010, but its IT staff only informed senior management in September 2011. Read more

Apple OS X users – it’s Security Update time again!

February 1, 2012 - Apple's latest large-scale OS X security updates are out. In tech-speak, there are 39 fixes, covering 52 CVE identifiers, and including 19 fixes for vulnerabilities potentially allowing arbitrary code execution. That's a lot! (continue reading...) Read more

TinKode arrested for suspected hack of NASA and Pentagon servers

January 31, 2012 - Police believe that they may have apprehended the notorious hacker TinKode, who in the past has hacked into government and military websites, exposing their poor security. Read more

Facebook sues alleged clickjacking firm

January 27, 2012 - Facebook has filed a law suit a firm who, they say, bombarded users with clickjacking scams that earned $1.2 million a month. Read more

Symantec: Stop using pcAnywhere, right now

January 25, 2012 - Symantec has admitted that blueprints for current versions of its pcAnywhere software were stolen in 2006 and that all users are at risk of attack and should pull the plug. Read more

Sophos Security Threat Report 2012 – seeing through the hype

January 25, 2012 - We know you're probably sceptical of "state of the world" reports from vendors. For all you can tell, they'll turn out to be thinly-digsuised advertorial, unreconstructed product brochures, or worse. We like to do things differently. Find out how! (continue reading...) Read more

Hacking boardroom videoconferencing systems

January 25, 2012 - Videoconferencing equipment is often left wide open for hackers to creep in and peep around organizations. Read more

DreamHost warns customers of possible password breach

January 23, 2012 - A database server at DreamHost is illegally accessed by a hacker, and the passwords of some customers may have been compromised. Read more

Apple iPad 2 and iPhone 4S finally fall to jailbreakers

January 22, 2012 - Apple's most hacker-resistant hardware to date - the iPad 2 and the iPhone 4S, which are built around the Apple A5 chip - can now be jailbroken. Should you rush to slither free of Apple's fiscal tentacles? (continue reading...) Read more

Hacker exposes Grindr users’ intimate information and explicit photos

January 20, 2012 - A popular smartphone app used by the gay community to hook-up with similarly-minded people in their vicinity suffers from a serious security vulnerability that could expose personal information and explicit photos that they have been sent. (continue reading...) Read more

Hackers snatch $6.7m in South African cyber bank robbery

January 20, 2012 - A mere three years after a South African bank spent $1.8 million on a new fraud-detection system, hackers managed to swindle $6.7 million out from under that system's nose. Although customer funds are thought to be safe, would you actually (continue reading...) Read more

Click on an Anonymous link, and you could be DDoS’ing the US government

January 20, 2012 - Anonymous seems to want revenge after the arrest of Megaupload's founders on piracy charges. Take care what links you click on, you could be launching a denial-of-service attack against the US government and entertainment industry. (continue reading...) Read more

Has TechCrunch been hacked?

January 18, 2012 - One of TechCrunch's web servers is serving up pages which definitely don't belong at TechCrunch! But it may not be the result of malicious hacking.. Read more

Trojan may have stolen data from Japanese space agency

January 18, 2012 - A data-stealing Trojan horse may have smuggled out login information to gain access to a cargo shuttle that carries food and equipment to the International Space Station (ISS). Read more

Great Expectations and the Grim Reaver

January 16, 2012 - Just published in SC Magazine's Cybercrime Corner, expanding on a conversation I had recently with Kevin Townsend, is an article on "Great Expectations" that discusses WPS, "Whoops!!!," the Grim Reaver, and what you can expect from anti-virus. In terms (continue reading...) Read more

Copyright © 2012 The Security Blog. All rights reserved.