Carbanak Attackers Devise Clever New Persistence Trick

Hackers behind the Carbanak criminal gang have devised a clever way to gain persistence on targeted systems to more effectively pull off financially motivated crimes. Continue reading Carbanak Attackers Devise Clever New Persistence Trick

Gigabytes the Dust with UEFI Vulnerabilities

At this year’s BlackHat Asia security conference, researchers from Cylance disclosed two potentially fatal flaws in the UEFI firmware of Gigabyte BRIX small computers which allow a would-be attacker unfettered low-level access to the computer.

Gigabyte has been working on a fix since the start of 2017. Gigabyte are preparing to release firmware updates as a matter of urgency to only one of the affected models — GB-BSi7H-6500 (firmware vF6), while leaving the — GB-BXi7-5775 (firmware vF2) unpatched as it has reached it’s end of life. We understand that support can’t last forever, but if you sell products with such …read more

Continue reading Gigabytes the Dust with UEFI Vulnerabilities

Tales from the Black Hat NOC: Are We Broken?

Walking through the expo hall at Black Hat Europe was uplifting – if the vendor booths were to be believed, APT’s can be stopped in their tracks, Ransomware protection can be guaranteed, and phishing can become a term applied to lake activities again. All it requires is buying this tool! It made me wonder why people…

The post Tales from the Black Hat NOC: Are We Broken? appeared first on Speaking of Security – The RSA Blog.

Continue reading Tales from the Black Hat NOC: Are We Broken?

Week 31 In Review – 2016

Events Related The Security Summer Camp Talks I Want To See… – jerrygamblin.com I took some time tonight and read through the Security Summer Camp (BSidesLV, Blackhat and Defcon) schedules and picked the talks from this year that I think will be the best and that I do not want to miss. BlackHat/Def Con/BSides Talk Picks for 2016 […]

The post Week 31 In Review – 2016 appeared first on Infosec Events.

Continue reading Week 31 In Review – 2016

Behind the Glass Walls of the Black Hat NOC 2016: RSA Takes the Challenge

Every year, the increased sophistication of threat actors and the expanding attack surface makes it more challenging for the Black Hat NOC security teams to maintain a highly functional environment that is safe and secure but doesn’t stifle productivity and learning. When you have an assembly of the best and most advanced security experts, hackers,…

The post Behind the Glass Walls of the Black Hat NOC 2016: RSA Takes the Challenge appeared first on Speaking of Security – The RSA Blog and Podcast.

Continue reading Behind the Glass Walls of the Black Hat NOC 2016: RSA Takes the Challenge

Network Security Theatre

Summer is nearly here, and with that comes the preparations for the largest gathering of security researchers on the planet. In early August, researchers, geeks, nerds, and other extremely cool people will descend upon the high desert of Las Vegas, Nevada to discuss the vulnerabilities of software, the exploits of hardware, and the questionable activities of government entities. This is Black Hat and DEF CON, when taken together it’s the largest security conference on the planet.

These conferences serve a very important purpose. Unlike academia, security professionals don’t make a name for themselves by publishing in journals. The pecking order …read more

Continue reading Network Security Theatre