This Week in Security: The Rest of the IPv6 Story, CVE Hunting, and Hacking the TSA

We finally have some answers about the Windows IPv6 vulnerability — and a Proof of Concept! The patch was a single change in the Windows TCP/IP driver’s Ipv6pProcessOptions(), now calling …read more Continue reading This Week in Security: The Rest of the IPv6 Story, CVE Hunting, and Hacking the TSA

This Week in Security: Three Billion SS Numbers, IPv6 RCE, and Ring -2

You may have heard about a very large data breach, exposing the Social Security numbers of three billion individuals. Now hang on. Social Security numbers are a particularly American data …read more Continue reading This Week in Security: Three Billion SS Numbers, IPv6 RCE, and Ring -2

Zero-Click Exploit Concerns Drive Urgent Patching of Windows TCP/IP Flaw

Security experts are ratcheting up the urgency for Windows admins to patch a wormable, pre-auth remote code execution vulnerability in the Windows TCP/IP stack.
The post Zero-Click Exploit Concerns Drive Urgent Patching of Windows TCP/IP Flaw appeared … Continue reading Zero-Click Exploit Concerns Drive Urgent Patching of Windows TCP/IP Flaw

[SANS ISC] Do Attackers Pay More Attention to IPv6?

Today, I published the following diary on isc.sans.edu: “Do Attackers Pay More Attention to IPv6?“: IPv6 has always been a hot topic! Available for years, many ISP’s deployed IPv6 up to their residential customers. In Belgium, we were for a long time, the top-one country with IPv6 deployment because all

The post [SANS ISC] Do Attackers Pay More Attention to IPv6? appeared first on /dev/random.

Continue reading [SANS ISC] Do Attackers Pay More Attention to IPv6?