Macs Not Receiving EFI Firmware Security Updates as Expected

Researchers at Duo Security are expected today at Ekoparty to reveal data and a paper that shows Mac users are not receiving EFI firmware updates at expected. Continue reading Macs Not Receiving EFI Firmware Security Updates as Expected

Windows Defender Bypass Tricks OS into Running Malicious Code

Researchers at CyberArk have devised a Windows Defender bypass that tricks the operating system into executing malicious code while Defender scans a benign file. Continue reading Windows Defender Bypass Tricks OS into Running Malicious Code

Gatekeeper Alone Won’t Mitigate Apple Keychain Attack

Apple said that macOS’ native Gatekeeper security feature would protect against a Keychain attack disclosed this week, but researcher Patrick Wardle said that won’t help against Mac malware signed with an Apple certificate. Continue reading Gatekeeper Alone Won’t Mitigate Apple Keychain Attack

Remote Wi-Fi Attack Backdoors iPhone 7

Google’s Project Zero released a proof-of-concept attack against a Wi-Fi firmware vulnerability in Broadcom chips that backdoors the iPhone 7. The flaw was patched in iOS 11. Continue reading Remote Wi-Fi Attack Backdoors iPhone 7

macOS High Sierra Available—And Vulnerable to Keychain Attack

Researcher Patrick Wardle has discovered a critical vulnerability that allows an attacker to dump passwords in plaintext from the macOS Keychain. The vulnerability is in macOS High Sierra, Sierra and El Capitan, and has yet to be patched. Continue reading macOS High Sierra Available—And Vulnerable to Keychain Attack

Mobile Stock Trading App Providers Unresponsive to Glaring Vulnerabilities

IOActive analyzed 21 mobile stock trading platforms and found vulnerabilities that put transactions and personal information at risk. Of the 13 firms notified, only two acknowledged the disclosure. Continue reading Mobile Stock Trading App Providers Unresponsive to Glaring Vulnerabilities

Adobe Private PGP Key Leak a Blunder, But It Could Have Been Worse

Adobe suffered at a minimum a PR black eye on Friday when one of its private PGP keys was inadvertently published to its Product Incident Security Response Team (PSIRT) blog. Continue reading Adobe Private PGP Key Leak a Blunder, But It Could Have Been Worse