Supermicro, Apache Struts, & HTTPS – Paul’s Security Weekly #574

In the security news, Spanish driver tests positive for every drug test, vulnerabilities found in the remote management interface of Supermicro servers, Apache Struts 2 flaw in the wild, HTTPS crypto-shame, and how to manipulate Apple’s podcast c… Continue reading Supermicro, Apache Struts, & HTTPS – Paul’s Security Weekly #574

Max Age For SSL/TLS Certificates Now Two Years

This post was authored by Jason Wood, founder of Paladin Security, a host on Security Weekly and commentator on Hack Naked News. This post is sponsored by DigiCert. Ah, the easy, old days when you could buy an SSL/TLS certificate that was valid for up … Continue reading Max Age For SSL/TLS Certificates Now Two Years

Black Hat 2018: Google’s Tabriz Talks Complex Security Landscapes

At Black Hat, Google’s Parisa Tabriz discussed how to navigate the complex security environment with long-term thinking and a policy of open collaboration. Continue reading Black Hat 2018: Google’s Tabriz Talks Complex Security Landscapes

The Shared Security Weekly Blaze – Bluetooth Vulnerabilities, Malicious Apps Removed from Twitter, Gmail Confidential Mode

This is the Shared Security Weekly Blaze for July 30th, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions and Silent Pocket.  This episode was hosted by Tom… Continue reading The Shared Security Weekly Blaze – Bluetooth Vulnerabilities, Malicious Apps Removed from Twitter, Gmail Confidential Mode

Smashing Security #088: PayPal’s Venmo app even makes your drug purchases public

Websites still using HTTP are marked as “not secure” by Chrome, 85,000 Google employees haven’t been phished for a year, and if you’re buying drugs via PayPal’s Venom app you should say goodbye to privacy.
All this and much much more is discussed in th… Continue reading Smashing Security #088: PayPal’s Venmo app even makes your drug purchases public