SMBv1, GnuPG, Trump USB, and OnePlus – Hack Naked News ##175

This week, SMBv1 is getting killed, GnuPG updates, the gift of USB, OnePlus 6 vulnerability, vulnerable Android devices, the worst 2FA, malware on macOS. Jason Wood from Paladin Security joins us for expert commentary this week, and more on this episod… Continue reading SMBv1, GnuPG, Trump USB, and OnePlus – Hack Naked News ##175

SMBv1 Windows Exploit “Fix” Problem – Why Disable Auto Updates?

New information has come to our attention that there is a specific Windows patch, which aims to address issues in the SMBv1 of Windows, more specifically removing it. SMB is in several versions and it stands for Server Message Block…Read more
The pos… Continue reading SMBv1 Windows Exploit “Fix” Problem – Why Disable Auto Updates?

Hackers Use EternalBlue Exploit to Infect 500K Computers with Cryptominer

Over the past year, a group of hackers has used the “EternalBlue” exploit to infect more than 500,000 computers from around the world and use them to mine Monero. According to researchers from security firm Proofpoint, who have been trackin… Continue reading Hackers Use EternalBlue Exploit to Infect 500K Computers with Cryptominer

U.S. Government Blames North Korea for WannaCry

The United States government is officially blaming North Korea for the WannaCry ransomware outbreak in May that infected nearly a quarter-million computers in 150 countries. Continue reading U.S. Government Blames North Korea for WannaCry

Dangerous Intel Chip Flaw Patches Becoming Available

Some computer manufacturers have started releasing patches for eight serious vulnerabilities in Intel processors or they have outlined firmware update plans for vulnerable models. Acer, Dell, Fujitsu, Hewlett Packard Enterprise (HPE), Lenovo, Panasonic… Continue reading Dangerous Intel Chip Flaw Patches Becoming Available

Equifax’s Servers Reportedly Had Glaring Holes Long Before Data Breach

Equifax reportedly took six months to take down a publicly exposed web application that could have allowed anyone on the internet to search and download sensitive personal consumer data. VICE Motherboard reported Thursday that an unnamed security researcher alerted Equifax about the exposed application in December 2016, but the company didn’t take steps to secure..

The post Equifax’s Servers Reportedly Had Glaring Holes Long Before Data Breach appeared first on Security Boulevard.

Continue reading Equifax’s Servers Reportedly Had Glaring Holes Long Before Data Breach

Samba Update Patches Two SMB-Related MiTM Bugs

Samba released three security updates, including two related to SMB connections that could be abused by an attacker already on the network to hijack connections and manipulate traffic or data sent from a client. Continue reading Samba Update Patches Two SMB-Related MiTM Bugs

Windows Search Bug Worth Watching, and Squashing

Patches are available—and should be applied—that address a critical vulnerability in Windows Search that some are calling the next WannaCry. Others aren’t so ready to do that. Continue reading Windows Search Bug Worth Watching, and Squashing

Scanner Shows EternalBlue Vulnerability Unpatched on Thousands of Machines

Data collected from the freely available scanner called EternalBlues shows that tens of thousands of computers remain vulnerable to the SMBv1 vulnerability that spawned WannaCry and ExPetr. Continue reading Scanner Shows EternalBlue Vulnerability Unpatched on Thousands of Machines