OpenDXL Ontology is intended to allow security components to interoperate right out of the box.
from Dark Reading: https://ift.tt/2PpvkIU
via IFTTT
OpenDXL Ontology is intended to allow security components to interoperate right out of the box.
from Dark Reading: https://ift.tt/2PpvkIU
via IFTTT
A developer has discovered that malicious apps could exploit the pasteboard to work out a user’s location.
from Naked Security https://ift.tt/2TmaETk
via IFTTT
Researchers have found a way to impersonate mobile devices on 4G and 5G mobile networks, and are calling on operators and standards bodies to fix the flaw that caused it.
from Naked Security https://ift.tt/32waRrb
via IFTTT
from Dark Reading: https://ift.tt/2VoZjVt
via IFTTT
Good security programs start with a mindset that it’s not about the tools, it’s what you do with them. Here’s how to get out of a reactive fire-drill mode with vulnerability management.
from Dark Reading: https://ift.tt/383qfN3
via IFTTT
ESET researchers uncover a previously unknown security flaw allowing an adversary to decrypt some wireless network packets transmitted by vulnerable devices
The post KrØØk: Serious vulnerability affected encryption of billion+ Wi‑Fi devices appeared first on WeLiveSecurity
from WeLiveSecurity https://ift.tt/2HWK4uL
via IFTTT
On Monday, networking hardware maker Zyxel released security updates to plug a critical security hole in its network attached storage (NAS) devices that is being actively exploited by crooks who specialize in deploying ransomware. Today, Zyxel acknowledged the same flaw is present in many of its firewall products.

This week’s story on the Zyxel patch was prompted by the discovery that exploit code for attacking the flaw was being sold in the cybercrime underground for $20,000. Alex Holden, the security expert who first spotted the code for sale, said at the time the vulnerability was so “stupid” and easy to exploit that he wouldn’t be surprised to find other Zyxel products were similarly affected.
Now it appears Holden’s hunch was dead-on.
“We’ve now completed the investigation of all Zyxel products and found that firewall products running specific firmware versions are also vulnerable,” Zyxel wrote in an email to KrebsOnSecurity. “Hotfixes have been released immediately, and the standard firmware patches will be released in March.”
The updated security advisory from Zyxel states the exploit works against its UTM, ATP, and VPN firewalls running firmware version ZLD V4.35 Patch 0 through ZLD V4.35 Patch 2, and that those with firmware versions before ZLD V4.35 Patch 0 are not affected.
Zyxel’s new advisory suggests that some affected firewall product won’t be getting hotfixes or patches for this flaw, noting that the affected products listed in the advisory are only those which are “within their warranty support period.”
Indeed, while the exploit also works against more than a dozen of Zyxel’s NAS product lines, the company only released updates for NAS products that were newer than 2016. Its advice for those still using those unsupported NAS devices? “Do not leave the product directly exposed to the internet. If possible, connect it to a security router or firewall for additional protection.”
Hopefully, your vulnerable, unsupported Zyxel NAS isn’t being protected by a vulnerable, unsupported Zyxel firewall product.
CERT’s advisory on the flaw rate this vulnerability at a “10” — its most severe. My advice? If you can’t patch it, pitch it. The zero-day sales thread first flagged by Holden also hinted at the presence of post-authentication exploits in many Zyxel products, but the company did not address those claims in its security advisories.
Recent activity suggests that attackers known for deploying ransomware have been actively working to test the zero-day for use against targets. Holden said the exploit is now being used by a group of bad guys who are seeking to fold the exploit into Emotet, a powerful malware tool typically disseminated via spam that is frequently used to seed a target with malcode which holds the victim’s files for ransom.
“To me, a 0day exploit in Zyxel is not as scary as who bought it,” he said. “The Emotet guys have been historically targeting PCs, laptops and servers, but their venture now into IoT devices is very disturbing.”
from Krebs on Security https://ift.tt/32tWtzI
via IFTTT
Encryption experts gave insights into the Crypto AG revelations, delved into complexities of the “right to be forgotten,” and more at RSA Conference.
from Dark Reading: https://ift.tt/2wRKsst
via IFTTT
Analysis of 92 billion rejected emails reveals a range of simple and complex attack techniques for the last quarter of 2019.
from Dark Reading: https://ift.tt/3a7x2qi
via IFTTT
Formerly preferred diplomatic app WhatsApp apparently isn’t up to snuff.
from Naked Security https://ift.tt/2VzAaHN
via IFTTT