This Week in Security: OpenWRT, Favicons, and Steganographia

OpenWRT is one of my absolute favorite projects, but it’s had a rough week. First off, the official OpenWRT forums is carrying a notice that one of the administrator accounts was accessed, and the userlist was downloaded by an unknown …read more

Continue reading This Week in Security: OpenWRT, Favicons, and Steganographia

This Week in Security: Ubiquiti, Nissan, Zyxel, and Dovecot

You may have been one of the many of us who received an email from Ubiquiti this week, recommending a password change. The email stated that there was an unauthorized access of Ubiquiti systems, and while there wasn’t evidence of …read more

Continue reading This Week in Security: Ubiquiti, Nissan, Zyxel, and Dovecot

This Week in Security: Android Bluetooth RCE, Windows VMs, and HTTPS Everywhere

Android has released it’s monthly round of security updates, and there is one patched bug in particular that’s very serious: CVE-2021-0316. Few further details are available, but a bit of sleuthing finds the code change that fixes this bug.

Fix potential OOB write in libbluetooth
Check event id if of
…read more

Continue reading This Week in Security: Android Bluetooth RCE, Windows VMs, and HTTPS Everywhere

This Week in Security: Deeper Dive Into SolarWinds, Bouncy Castle, and Docker Images

Merry Christmas and happy holidays! I took Christmas day off from writing the security roundup, coming in a day early with this week’s installment, dodging New year’s day. The SolarWinds story has continued to dominate the news, so lets dive into it a bit deeper.

Microsoft has published their analysis …read more

Continue reading This Week in Security: Deeper Dive Into SolarWinds, Bouncy Castle, and Docker Images

This Week in Security: SolarWinds and FireEye, WordPress DDoS, And Enhance!

The big story this week is Solarwinds. This IT management company supplies network monitoring and other security equipment, and it seems that malicious code was included in a product update as early as last spring. Their equipment is present in a multitude of high-profile networks, like Fireeye, many branches of …read more

Continue reading This Week in Security: SolarWinds and FireEye, WordPress DDoS, And Enhance!

This Week in Security: VMWare, Microsoft Teams, Python Fuzzing, and More

There’s a VMWare problem that’s being exploited in the wild, according to the NSA (PDF). The vulnerability is a command injection on an administrative console. The web host backing this console is apparently running as root, as the vulnerability allows executing “commands with unrestricted privileges on the underlying operating system.” …read more

Continue reading This Week in Security: VMWare, Microsoft Teams, Python Fuzzing, and More

This Week in Security: iOS Wifi Incantations, Ghosts, and Bad Regex

I hope everyone had a wonderful Thanksgiving last week. My household celebrated by welcoming a 4th member to the family. My daughter was born on Wednesday morning, November 25th. And thus explains what I did last week instead of writing the normal Hackaday column. Never fear, we shall catch up …read more

Continue reading This Week in Security: iOS Wifi Incantations, Ghosts, and Bad Regex

This Week in Security: SAD DNS, Incident Documentation Done Well, and TCL Responds

One of the big stories from the past few days is the return of DNS cache poisoning. The new attack has been dubbed SADDNS, and the full PDF whitepaper is now available. When you lookup a website’s IP address in a poisoned cache, you get the wrong IP address.

This …read more

Continue reading This Week in Security: SAD DNS, Incident Documentation Done Well, and TCL Responds

This Week in Security: Platypus, Git.bat, TCL TVs, and Lessons From Online Gaming

Git’s Large File System is a reasonable solution to a bit of a niche problem. How do you handle large binary files that need to go into a git repository? It might be pictures or video that is part of a project’s documentation, or even a demonstration dataset. Git-lfs’s solution …read more

Continue reading This Week in Security: Platypus, Git.bat, TCL TVs, and Lessons From Online Gaming