Goal was to see if computer-generated images that look like one person would get classified as another person.
from Dark Reading: https://ift.tt/30LCkG8
via IFTTT
Goal was to see if computer-generated images that look like one person would get classified as another person.
from Dark Reading: https://ift.tt/30LCkG8
via IFTTT
The August 2020 Patch Tuesday marks the sixth month in a row Microsoft released patches for more than 110 vulnerabilities.
from Dark Reading: https://ift.tt/31FvFg9
via IFTTT
As companies “shift left” — pushing more responsibility for security onto developers — the tools that are available are falling short, usability researchers say.
from Dark Reading: https://ift.tt/3kDSDg7
via IFTTT
Microsoft today released updates to plug at least 120 security holes in its Windows operating systems and supported software, including two newly discovered vulnerabilities that are actively being exploited. Yes, good people of the Windows world, it’s time once again to backup and patch up!
At least 17 of the bugs squashed in August’s patch batch address vulnerabilities Microsoft rates as “critical,” meaning they can be exploited by miscreants or malware to gain complete, remote control over an affected system with little or no help from users. This is the sixth month in a row Microsoft has shipped fixes for more than 100 flaws in its products.
The most concerning of these appears to be CVE-2020-1380, which is a weaknesses in Internet Explorer that could result in system compromise just by browsing with IE to a hacked or malicious website. Microsoft’s advisory says this flaw is currently being exploited in active attacks.
The other flaw enjoying active exploitation is CVE-2020-1464, which is a “spoofing” bug in virtually supported version of Windows that allows an attacker to bypass Windows security features and load improperly signed files.
Trend Micro’s Zero Day Initiative points to another fix — CVE-2020-1472 — which involves a critical issue in Windows Server versions that could let an unauthenticated attacker gain administrative access to a Windows domain controller and run an application of their choosing. A domain controller is a server that responds to security authentication requests in a Windows environment, and a compromised domain controller can give attackers the keys to the kingdom inside a corporate network.
“It’s rare to see a Critical-rated elevation of privilege bug, but this one deserves it,” said ZDI’S Dustin Childs. “What’s worse is that there is not a full fix available.”
Perhaps the most “elite” vulnerability addressed this month earned the distinction of being named CVE-2020-1337, and refers to a security hole in the Windows Print Spooler service that could allow an attacker or malware to escalate their privileges on a system if they were already logged on as a regular (non-administrator) user.
Satnam Narang at Tenable notes that CVE-2020-1337 is a patch bypass for CVE-2020-1048, another Windows Print Spooler vulnerability that was patched in May 2020. Narang said researchers found that the patch for CVE-2020-1048 was incomplete and presented their findings for CVE-2020-1337 at the Black Hat security conference earlier this month. More information on CVE-2020-1337, including a video demonstration of a proof-of-concept exploit, is available here.
Adobe has graciously given us another month’s respite from patching Flash Player flaws, but it did release critical security updates for its Acrobat and PDF Reader products. More information on those updates is available here.
Keep in mind that while staying up-to-date on Windows patches is a must, it’s important to make sure you’re updating only after you’ve backed up your important data and files. A reliable backup means you’re less likely to pull your hair out when the odd buggy patch causes problems booting the system.
So do yourself a favor and backup your files before installing any patches. Windows 10 even has some built-in tools to help you do that, either on a per-file/folder basis or by making a complete and bootable copy of your hard drive all at once.
And as ever, if you experience glitches or problems installing any of these patches this month, please consider leaving a comment about it below; there’s a better-than-even chance other readers have experienced the same and may chime in here with some helpful tips.
from Krebs on Security https://ift.tt/2PGCxEr
via IFTTT
Company behind Data Store and Object Security (DSOS) becomes public knowledge following a $3 million seed round of funding.
from Dark Reading: https://ift.tt/3kCjj0M
via IFTTT
A security researcher demonstrated multiple vulnerabilities, two of which could let an attacker read and steal user data.
from Dark Reading: https://ift.tt/2Fg68m7
via IFTTT
Educational technology is critical but can come at huge costs to student and teacher privacy and security. Are those costs too high?
from Dark Reading: https://ift.tt/2DTyGkC
via IFTTT
Fuel CMS 1.4.7 – ‘col’ SQL Injection (Authenticated)
from Exploit-DB.com RSS Feed https://ift.tt/3gPI9YH
via IFTTT
In a world that isn’t private by design, security and liability implications for US-based cloud companies are huge.
from Dark Reading: https://ift.tt/2PLGIPj
via IFTTT
“Something needs to be done,” said the court. Where do you stand? For or against, have your say in our comments.
from Naked Security https://ift.tt/30LUhnX
via IFTTT