Scanner Shows EternalBlue Vulnerability Unpatched on Thousands of Machines

Data collected from the freely available scanner called EternalBlues shows that tens of thousands of computers remain vulnerable to the SMBv1 vulnerability that spawned WannaCry and ExPetr. Continue reading Scanner Shows EternalBlue Vulnerability Unpatched on Thousands of Machines

Google Changes How it Analyzes Misbehaving Mobile Apps

Google has a new machine-learning algorithm it uses to compare new apps to known secure apps, improving the way it classifies submissions to Google Play. Continue reading Google Changes How it Analyzes Misbehaving Mobile Apps

Telegram-Controlled Hacking Tool Targets SQL Injection at Scale

The Katyusha Scanner can find SQL injection bugs at scale, and is managed via the Telegram messenger on any smartphone. Continue reading Telegram-Controlled Hacking Tool Targets SQL Injection at Scale

Microsoft Addresses NTLM Bugs That Facilitate Credential Relay Attacks

Microsoft today addressed two NTLM-related vulnerabilities privately disclosed by Preempt Security. The flaws allow for credential relay attacks. Continue reading Microsoft Addresses NTLM Bugs That Facilitate Credential Relay Attacks

Telcos Singled Out for Prioritizing Government Requests for Data Over Privacy

The EFF’s annual Who Has Your Back report singles out giant telecommunications providers for their prioritization of government requests for data over privacy. Continue reading Telcos Singled Out for Prioritizing Government Requests for Data Over Privacy

Google to Fully Distrust WoSign/StartCom SSL Certs in Chrome 61

Google has put websites signed with WoSign/StartCom SSL certificates on notice that it will no longer trust certs from the Chinese CA starting in Chrome 61. Continue reading Google to Fully Distrust WoSign/StartCom SSL Certs in Chrome 61

New Petya Distribution Vectors Bubbling to Surface

Microsoft has made a definitive link between MEDoc and initial distribution of the Petya ransomware. Kaspersky Lab, meanwhile, has identified a Ukrainian government website used in a watering hole attack. Continue reading New Petya Distribution Vectors Bubbling to Surface