Leaked ShadowBrokers Attack Upgraded to Target Current Versions of Cisco ASA

Researchers at Silent Signal have ported the ShadowBrokers’ Equation Group exploit for Cisco ASA firewalls to newer versions of the product. Continue reading Leaked ShadowBrokers Attack Upgraded to Target Current Versions of Cisco ASA

New Collision Attacks Against 3DES, Blowfish Allow for Cookie Decryption

Researchers have found a new way to recover and decrypt authentication cookies from 3DES and Blowfish protected traffic. In response, OpenSSL is expected to deprecate 3DES’ designation from high to medium. Continue reading New Collision Attacks Against 3DES, Blowfish Allow for Cookie Decryption

Timing of Browser-Based Security Alerts Could Be Better

New academic research shows that security warnings should be better timed to pop up when computers users are less likely to be multitasking. Continue reading Timing of Browser-Based Security Alerts Could Be Better

Juniper Acknowledges Equation Group Exploits Target ScreenOS

Juniper Networks on Friday acknowledged that exploits contained in the ShadowBrokers data dump target NetScreen firewalls running ScreenOS. Continue reading Juniper Acknowledges Equation Group Exploits Target ScreenOS

GPG Patches 18-Year-Old Libgcrypt RNG Bug

New versions of GPG and its crypto library Libgcrypt were released on Wednesday addressing a vulnerability that could allow an attacker to predict Libgcrypt RNG output. Continue reading GPG Patches 18-Year-Old Libgcrypt RNG Bug

ShadowBrokers’ Leak Has ‘Strong Connection’ to Equation Group

Researchers at Kaspersky Lab said there is a strong connection between the ShadowBrokers cache of exploits and those belonging to the Equation Group. Continue reading ShadowBrokers’ Leak Has ‘Strong Connection’ to Equation Group

VeraCrypt Audit Under Way; Email Mystery Cleared Up

Missing emails between the parties involved in an audit of VeraCrypt, which began today, are now being blamed on errors in mail.app and GPGMail. Continue reading VeraCrypt Audit Under Way; Email Mystery Cleared Up

TCP Flaw in Linux Extends to 80 Percent of Android Devices

Researchers at Lookout said that 80 percent of Android devices remain vulnerable to a critical Linux vulnerability disclosed last week. Continue reading TCP Flaw in Linux Extends to 80 Percent of Android Devices