TDM Digital Signage PC Player 4.1 – Insecure File Permissions
from Exploit-DB.com RSS Feed https://ift.tt/31MYl7B
via IFTTT
TDM Digital Signage PC Player 4.1 – Insecure File Permissions
from Exploit-DB.com RSS Feed https://ift.tt/31MYl7B
via IFTTT
You probably back yourself not to be flattered or scared by a voice scammer – but what about vulnerable friends or relatives?
from Naked Security https://ift.tt/3dZRtsp
via IFTTT
For the second time in as many years, Google is working to fix a weakness in its Widevine digital rights management (DRM) technology used by online streaming sites like Disney, Hulu and Netflix to prevent their content from being pirated.

The latest cracks in Widevine concern the encryption technology’s protection for L3 streams, which is used for low-quality video and audio streams only. Google says the weakness does not affect L1 and L2 streams, which encompass more high-definition video and audio content.
“As code protection is always evolving to address new threats, we are currently working to update our Widevine software DRM with the latest advancements in code protection to address this issue,” Google said in a written statement provided to KrebsOnSecurity.
In January 2019, researcher David Buchanan tweeted about the L3 weakness he found, but didn’t release any proof-of-concept code that others could use to exploit it before Google fixed the problem.
This latest Widevine hack, however, has been made into an extension for Microsoft Windows users of the Google Chrome web browser and posted for download on the software development platform Github.
Tomer Hadad, the researcher who developed the browser extension, said his proof-of-concept code “was done to further show that code obfuscation, anti-debugging tricks, whitebox cryptography algorithms and other methods of security-by-obscurity will eventually by defeated anyway, and are, in a way, pointless.”
Google called the weakness a bug that would be fixed. But Hadad took issue with that characterization.
“It’s not a bug but an inevitable flaw because of the use of software, which is also why L3 does not offer the best quality,” Hadad wrote in an email. “L3 is usually used on desktops because of the lack of hardware trusted zones.”
Media companies that stream video online using Widevine can select different levels of protection for delivering their content, depending on the capabilities of the device requesting access. Most modern smartphones and mobile devices support much more robust L1 and L2 Widevine protections that do not rely on L3.
Further reading: Breaking Content Protection on Streaming Websites
from Krebs on Security https://ift.tt/2G4YprS
via IFTTT
Typically, blocklists are used to prevent users from picking easily guessable patterns, but a small neural network can do the same job and suggests that complex password requirements are not necessary.
from Dark Reading: https://ift.tt/2Hyd9zQ
via IFTTT
An attacker is running a Tor site to leak the session notes of 300 patients at Vastaamo, a Finnish psychotherapy facility.
from Dark Reading: https://ift.tt/34vQrBl
via IFTTT
Cybersecurity startup helps enterprises to understand their digital risk and exposure.
from Dark Reading: https://ift.tt/3dXosxu
via IFTTT
Threatpath release addresses proliferation of endpoints and credential protection challenges.
from Dark Reading: https://ift.tt/35B2Q6r
via IFTTT
Some have also created the role of chief sustainability officer, according to Kaspersky.
from Dark Reading: https://ift.tt/3dWatrY
via IFTTT
ReQuest Serious Play F3 Media Server 7.0.3 – Remote Code Execution (Unauthenticated)
from Exploit-DB.com RSS Feed https://ift.tt/3kvkxL3
via IFTTT
ReQuest Serious Play F3 Media Server 7.0.3 – Remote Denial of Service
from Exploit-DB.com RSS Feed https://ift.tt/3dWFiwJ
via IFTTT