CISA orders agencies to set up vulnerability disclosure programs

Out of scores of federal civilian agencies, only a handful of them have official programs to work with outside security researchers to find and fix software bugs — a process that is commonplace in the private sector. Now, to put an end to the feet-dragging, the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency is giving agencies six months to set up the programs, known as vulnerability disclosure policies (VDPs). CISA on Wednesday issued a directive requiring agencies to establish VDPs that foreswear legal action against researchers who act in good faith, allow participants to submit vulnerability reports anonymously and cover at least one internet-accessible system or service. It’s the latest sign that federal officials are warming to white-hat hackers from various walks of life. “We believe that better security of government computer systems can only be realized when the people are given the opportunity to help,” CISA Assistant Director […]

The post CISA orders agencies to set up vulnerability disclosure programs appeared first on CyberScoop.

Continue reading CISA orders agencies to set up vulnerability disclosure programs

Webinar: Hacking the Extraterrestrial Internet – Where Fiction Meets Reality

Register Now to Explore the Tech Behind the Interplanetary Internet!
Normal SciFi glosses over a glaring problem with comms through the vastness of space… The Internet and TCP/IP suffer a massive self-imposed DOS attack with any disruptions for m… Continue reading Webinar: Hacking the Extraterrestrial Internet – Where Fiction Meets Reality

VMWare, Meltdown, Spectre, and Chip Hacks That Work – Paul’s Security Weekly #542

10 things in cybersecurity that you might have missed in 2017, a flaw in major browsers, a critical flaw in phpMyAdmin, beware of a VMWare VDP remote root issue, how to protect your home router, Meltdown and Spectre explain how chip hacks work, and Int… Continue reading VMWare, Meltdown, Spectre, and Chip Hacks That Work – Paul’s Security Weekly #542

VMware announces, patches critical flaw in its VDP backup product

Cloud computing technology provider VMware issued a security advisory Tuesday outlining three critical vulnerabilities in its vSphere Data Protection (VDP) backup and recovery product. “A remote attacker could exploit these vulnerabilities to take control of an affected system,” wrote the U.S. Computer Emergency Readiness Team in a warning sent out Tuesday afternoon by the National Cyber Awareness System. It advised all VMware customers to download and install the patches, which the company has publicly pushed. WMware, part of the Dell Technologies family of companies did not say how many of their 500,000-plus customers use the affected VDP product. The advisory doesn’t list when and how the vulnerabilities were discovered. A spokesman for the company told CyberScoop by email they had no further details to offer. VDP saves images of virtual machines that have spun up in an enterprise cloud environment so they can be easily restored in the event of […]

The post VMware announces, patches critical flaw in its VDP backup product appeared first on Cyberscoop.

Continue reading VMware announces, patches critical flaw in its VDP backup product

VMware Issues 3 Critical Patches for vSphere Data Protection

VMware released three patches fixing critical vulnerabilities affecting its vSphere cloud computing virtualization platform. Continue reading VMware Issues 3 Critical Patches for vSphere Data Protection