This week on the podcast, we cover OpenSSH’s recent critical vulnerability and what it means for systems administrators. Before that, we discuss the CDK Global ransomware attack impacting car dealerships across the us, a Korean internet service provider delivering malware to their customers, and a takeover of a popular JavaScript library gone hostile.
Read More - OpenSSH regreSSHion Vulnerability
Introduction This research began with finding a simple malware sample to extract strings for an unrelated topic. In my day-to-day malware analysis workflow, I stumbled upon a JavaScript (JS) file with what I would call trivial obfuscation. I knew it was malware but wanted to understand the infection chain. After some cleanup, I understood it […]
Read More - Yet Another TA558 Campaign Targets South America’s Hospitality Industry With AsyncRAT
This post arrives later than usual, but as they say, “Better late than never.” Researchers and the media have highlighted various unique, interesting, or destructive vulnerabilities in the last few weeks. We decided to pick three of these vulnerabilities and talk about them. One was patched with Microsoft’s Patch Tuesday in March; another affects the […]
Read More - Cybersecurity News: A Trio of Vulnerabilities, BreachForums Admin Arrested, Hundreds of Ransomware Victims, and The Rise of AI
3CX created the desktop phone app 3CXDesktopApp and now finds itself in the middle of a supply chain attack. One that perhaps went on for too long. As a recognized company in the softphone space 3CX provides services to many large companies including Honda, Coca cola, BMW, Holiday Inn among others according to […]
Read More - 3CX Supply Chain Attack
It’s Monday, and there’s no better way to start a new week than with some cybersecurity-related news. So, if you need an excuse to procrastinate a bit more, allow us to fill that void. For this iteration, we made a few minor improvements, as always. In addition to the table of contents from last time, […]
Read More - Cybersecurity News: LastPass Incident Revealed, White House Issues Cybersecurity Strategy, FBI Purchases Leaked USHOR PII Data, and a Slew of Other Breaches
On today’s episode we cover a pair of alerts from the Cybersecurity Infrastructure and Security Agency (CISA), one detailing the tools, tactics and procedures from a prolific ransomware organization and another walking through a recent incident response engagement CISA completed with a federal agency. Before that though, we learn about what happens when you use […]
Read More - CISA Incident Response Learnings
We have seen interpolation in the news concerning a recent court case. Here we cover what interpolation does to an image, not only because of the recent news but also because face recognition uses interpolation to better recognize a face – something we have covered in the past. Interpolation means to take pixels in an image and calculate what their […]
Read More - Dangers of Bicubic Interpolation In Pictures
A recent survey of 700 SMBs (small and medium businesses) by Untangle shows an increase in cybersecurity budgets and awareness. While some companies still have users working remotely, 50% of respondents have moved back into the office or at least some form of hybrid work environment. Most companies – 64% – see breaches as the […]
Read More - How SMBs Deal With An Uptick in Breaches
Over the last week we saw 70 million AT&T customers and 53 million T-Mobile customers have their personal data leaked to hackers. While we didn’t find any connections between these two breaches the timing of the incidents is strange. AT&T has so far denied the breach involving their customers. While we don’t have confirmation from […]
Read More - Mobile Carriers Leak 123 million Customer Records in One Week
A large cyber attack has caused chaos in the New Zealand healthcare system over the past few weeks. Multiple hospitals in New Zealand became crippled due to locked phone lines and computers from a large ransomware attack. Though the ransom note didn’t contain a dollar amount the note indicates a “ransomware event” according to the […]
Read More - “The Biggest Cyber Attack In New Zealand’s History”
In response to recent cybersecurity incidences like the SolarWinds breach, Microsoft Exchange Server vulnerabilities, and the Colonial Pipeline ransomware attack, President Biden signed an executive order to increase the cybersecurity stance of the federal government and all civilian agencies it contracts with. The 34-page executive order implements minimum security standards for the government and contractors. […]
Read More - Biden Orders Massive Overhaul of Federal Agency Security
According to an article by Techdirt, the Chinese government has created “Uyghur alarms” by an explicitly biased face recognition service which they are using. China uses face recognition to identify and target Uyghur people. Under the guise of identifying the different races in China, the model used appears to specifically identify Uyghur and Tibetan face […]
Read More - China’s Explicitly Biased Face Recognition Model
Over the last few weeks, we continue to see HAFNIUM attacks against Exchange Servers through our threat intelligence. Our Firebox feed data shows Fireboxes identifying the signature almost every day over the HTTPS proxy. Yet, Many Exchange servers remain unprotected. With Exchange Outlook Web Access (OWA)servers, Fireboxes must inspect the content of HTTPS traffic […]
Read More - Fireboxes Detect HAFNIUM Attacks in the Wild
In a dynamic world, where user mobility impacts security almost 100% of the time, multi-factor authentication (MFA) has become imperative and key to deploying a zero-trust network. Why? • Users are connecting to company resources from different, unprotected networks • Working hours have become more flexible, so they could be working from early hours to […]
Read More - Identity Management and Risk Authentication: Core Technologies to Achieve Zero-Trust Security
(update 12/11/20: XRSI may not have rooted the Quest 2, see XRSI May Have Lie About Gaining Root Access The Quest 2) XRSI may have found a way around the new Oculus Quest 2 Facebook login. Technical users will sometimes root a device to gain complete control over the device. This option for users commonly occurs with most of the popular phones and tablets available so usually, it doesn’t mean much. We do find a reason […]
Read More - Researchers May Already have Compromised The Quest 2 VR
With the US elections only a week away, we’re talking election security on this week’s episode. We’ll cover what we do and don’t think attackers will target in the coming week and what we can do as a country to improve our security posture.
Read More - Top Election Security Threats
The dark web is a collection of anonymous websites that are publicly available, yet hide the IP addresses to make it impossible for users to identify the host. It’s very common that sensitive information made available by data breaches ends up becoming available illicitly for sale on the dark web. According to the 2019 Global […]
Read More - Are Your Company Credentials Exposed on the Dark Web?
The UK Cyber Security Center (NCSC) and Canada’s Communications Security Establishment (CSE) with the help of the NSA released an advisory today on attacks from APT29 (also known as ‘the Dukes’ or ‘Cozy Bear’), a group with ties to the Russian intelligence services. “APT29 is using custom malware known as ‘WellMess’ and ‘WellMail’ to target […]
Read More - UK, Canada and US All Warn of New Attacks on Covid-19 Research
Earlier this week, Citadelo published a vulnerability they found in the VMware Cloud software. Small Cloud providers use VMware Cloud software to support virtual servers and manage the environment through the Director module in the software. Citadelo found a remote execution vulnerability in this management software. Citadelo also noted they could do the following […]
Read More - VMware Cloud Server Takeover Vulnerability
Last week, researchers at Mimecast posted an article that detailed an increase in the LimeRAT malware hidden in Excel spreadsheets. If you’ve followed our quarterly security reports, you’ll remember we have also found an increase in the use of Excel spreadsheets to release malware. Find out more about this increase of malware in Excel […]
Read More - Does Your Network Box Block All Malware
Just like viruses that spread when we don’t protect ourselves, a computer virus also spreads when we don’t protect our devices. The global COVID-19 pandemic has forced much of the workforce to work remotely to help slow the spread of the disease. To keep your computer safe while working from home, take these steps. A […]
Read More - Protecting Your Devices While Working From Home
“If you have knowledge, let others light their candles in it.” – Margaret Fuller This month WatchGuard is celebrating Women’s History Month by featuring outstanding women in the cybersecurity industry on Secplicity and on our podcast The 443 – Security Simplified. Our goal is to give women in our field a platform to talk about the work they do […]
Read More - Celebrate Women’s History Month with WatchGuard
As reported by TechCrunch, an app made by ClevGuard called KidsGuard stalks spouses, employees, and children. ClevGuard advertises the app for this purpose as while highlighting the apps stealth capabilities. Lots of these types of apps, called “stalkerware,” exist but this one’s crummier than the rest. The app copies data off of the target’s […]
Read More - Creepy App Tracks its Users, Leaks its Database
A recent addition to the Emotet botnet, found by Binary Defense, enables this malware to spread through Wi-Fi networks. This differs from previous versions of Emotet where it only targeted local wired networks. The Emotet botnet started off as a banking trojan in 2014. Early on, it spread by email and would resend […]
Read More - Emotet Evolves to Gain the Wi-Fi Attribute
As the second largest access point (AP) supplier by market share, Aruba Networks, a HPE company, has worked hard to provide worldwide businesses with enterprise-grade Wi-Fi connectivity. You’ll see the company’s APs in many schools, retail locations and airports, among other places. Want a fun scavenger hunt idea? Look up at the ceiling next time […]
Read More - Pass or Fail? Aruba’s WIPS Gets Tested by Independent Lab
Welcome back to another episode of The 443 – Security Simplified. This week, we cover three major news stories from the past week including the NordVPN breach, Facebook suing a zero-day development firm, and the latest attack from North Korea’s Lazarus Group.
Read More - DTrack Damage
With the average person managing 90 accounts that require a username and password, and credential-stealing malware on the rise, your users are firmly in the crosshairs of cyber criminals. At the same time, the drive toward workplace flexibility and desire to empower people to work where they are most comfortable challenges some foundations of cyber […]
Read More - Set Employees Free with Security That Travels
Now you can pay for your drink using just your face in China, but only for some. Chinese face recognition vending machine. No cash, card, or phone needed. pic.twitter.com/tDN0pMitA4 — Matthew Brennan (@mbrennanchina) August 21, 2019 A video recently posted to Twitter shows a woman who has walked up to a vending machine press a […]
Read More - Face Recognition For Purchasing is Still a Novelty
The same security researchers that disclosed the initial five WPA3 vulnerabilities (referred to as Dragonblood) earlier this year in April, have recently disclosed two additional WPA3 vulnerabilities. Just like the initial five Dragonblood vulnerabilities, these two new ones allow attackers to either downgrade or bypass WPA3 encryption protected networks via brute force password cracking. As […]
Read More - Additional WPA3 Dragonblood Vulnerabilities
Since its inception in February 2018, the Notifiable Data Breaches scheme (NDB scheme) in Australia has delivered some very interesting results, which we can all learn from. The NDB is a legal requirement imposed by the OAIC (Office of the Australian Information Commissioner) on organizations of all sizes to notify individuals of eligible data […]
Read More - The first 18 months of Data Breach regulation in Australia: my thoughts
How much should you spend on cyber defense, recovery, and insurance? A recent research study from WEIS [PDF]—a collection of cyber security researchers—analyzes the costs of cyber crime and how it has changed over the years. While the report mostly covers world e-commerce losses and how governments can combat them, it also reports cyber security […]
Read More - $98 Million Spent Just To Replace Credit Cards in 2018
If you are a business owner (CEO, CIO, or head of a business line) you continuously need to look for ways to innovate, out-think and out-maneuver your competition. In the sharing and collaborative economy we live in, you have an unprecedented opportunity to team up with others to make what you’re good at even better, […]
Read More - Securing The API Economy
IP theft in midsized businesses – Are YOU at risk? I’d like to focus on an important topic, which is especially relevant for midsized corporates, SMBs and distributed enterprises: Intellectual Property (IP) theft. BIG business for cyber criminals. When my Team and I meet clients who are midsize, SMBs, or distributed enterprises, many do not […]
Read More - Intellectual Property Theft – Are YOU at risk ?
Social engineering is an increasingly important methodology used by fraud actors of all types to gather information and target government agencies, SMBs and enterprises – in addition to consumers. In this post, I’d like to share my strong point of view on a topic that is relevant to most of us as business professionals: sharing […]
Read More - Sharing your business destinations to the world on LinkedIn? Beware
CEO Fraud, also known as Business Email Compromise (BEC), is a sophisticated scam targeting businesses of all sizes leveraging social engineering. The ultimate objective is to get unauthorized transfers of funds to the fraud actors’ bank accounts. It’s all about hard cash and top executives being the targets of such scams. There are 3 main […]
Read More - CEO Fraud: are you at risk?
When does doing something good cross the line? That is what some security pundits may ask Google in the next few months, after they go through with some HTTPS-related changes in Chrome. On the positive side, Google is doing what they can to help change the web to all HTTPS. This change helps enforce the […]
Read More - Google & HTTPS – Daily Security Byte
Each year, Black Friday and Cyber Monday account for a whirlwind of online sales. Our CTO Corey Nachreiner joined Q13 FOX live on air this morning to discuss tips for protecting personal information when purchasing holiday gifts online. Here are some of Corey’s tips for online shopping this holiday season: Beware of email deal scams. […]
Read More - Deals Not Steals: How to Stay Safe Online This Holiday Season
I am excited to announce the upcoming launch of our redesigned and refreshed blog. Over the past six years, WatchGuard Security Center has provided IT professionals with breaking news and analysis about the most important information security (InfoSec) issues. Our mission has always been to distill the often complex topics of computer and network security […]
Read More - Exciting Blog Changes Just Around the Corner
A few stories surfaced yesterday talking about “devastating” vulnerabilities in Windows’ Kerberos. Today’s vlog explores whether or not these are new issues, how severe they really are, and where you can learn how to mitigate them. (Episode Runtime: 3:44) Direct YouTube Link: https://www.youtube.com/watch?v=yxcoqfagLfI EPISODE REFERENCES: The Register’s edited article about the “devastating” Windows Kerberos flaws – The Register A copy […]
Read More - Devastating Kerberos Flaws? – Daily Security Byte EP. 193
Unlike cyber criminals, who want to stay under the radar, Hacktivists like to make big splashy messages. The whole point of “cyber” activism is to use technology to get as many people as possible to notice your message, whatever it may be. Prediction video link: https://youtu.be/EEbqr-2XFRk Anonymous is a great example of this, with their […]
Read More - WatchGuard Security Prediction #10 – Alien Attackers Hijack Our Broadcast Signals from Space
To be honest, wireless security hasn’t changed too much in the last few years. That’s not to say it’s perfectly secure. There are still plenty of folks using legacy WEP encryption standards, and organizations that use WPA2-PSK with a horrible password. There are also many wireless networks that don’t segment clients, so attackers can sniff […]
Read More - WatchGuard Security Prediction #9 – Spies Slip Into Wireless Alliances
If you use Joomla to manage content on your website, you’re going to want to patch immediately. Today’s daily video covers a new zero day flaw in the open source content management system (CMS) that attackers are actively exploiting in the wild. (Episode Runtime: 1:42) Direct YouTube Link: https://www.youtube.com/watch?v=oLcHEBQb274 EPISODE REFERENCES: Article on Joomla new vulnerability […]
Read More - Joomla Attack in Wild – Daily Security Byte EP. 192
When a hacker hijacks a computer, gaining persistence (or making sure his malicious trojan stays on the computer) is easy. The attacker just has to load malware onto the computer’s hard drive and make sure it runs when the computer reboots. However, hijacking the Internet of Things (IoT) is a different story. Many IoT devices […]
Read More - WatchGuard Security Prediction #8 – Breaches Come to the IoT Frontier
Cybercrime; Is it out of control? Yes! When attackers hijack your news site to serve malware from your cyber crime article, it probably is a bit out of control. Watch today’s video to learn what I’m talking about, and how you might protect yourself from legitimate web sites unknowingly spreading malware. (Episode Runtime: 3:28) Direct YouTube […]
Read More - Ironic Watering Hole Attack – Daily Security Byte EP. 191
Information security is all about protecting data, because at the end of the day, stolen data is what makes the cyber criminals rich. Criminals started with the basics. Monetizing stolen credit card (CC) information was easy. You just needed the basic CC information and a few personal details to make a purchase with a stolen […]
Read More - WatchGuard Security Prediction #7 – Starfleet Academy Targeted
Can hackers knock out the Internet? Probably not, but it look like attackers tried to disrupt DNS recent by launching a distributed denial of service attack against the root DNS servers. Watch today’s video to learn how the IT community can make it harder for attackers to launch reflected attacks. (Episode Runtime: 4:04) Direct YouTube […]
Read More - Attacker DDoSes the Internet – Daily Security Byte EP. 190
Security experts have always realized that information security is a constant arms race. Attackers discover new methods to evade defenses, we update our defenses, and the cycle continues and repeats. In fact, much of our legacy defense is reactive. It relies on us having seen a particular attack, and creating a specific defense for that particular […]
Read More - WatchGuard Security Prediction #6 – Jango Fett and the Clone Army are Coming
Malware is already a pain in the neck to clean up, but it’s even worse if the malware includes a bootkit. Bootkits are becoming more popular in advanced malware targeting Windows systems. Today’s episode discusses a new bootkit called BootTrash, and how you might avoid it. (Episode Runtime: 3:36) Direct YouTube Link: https://www.youtube.com/watch?v=t2ef0p5av6I EPISODE REFERENCES: Blog post […]
Read More - BootTrash Hijacks Your MBR – Daily Security Byte EP. 189
Malvertising, the combination of the words malware and advertising, is an attack where criminals booby-trap a legitimate, trusted website with a malicious code by sneaking it in through a third party advertising network. Unfortunately, legitimate web advertising services haven’t been very discerning with the ads they allow their “customers” to upload to their networks. Prediction […]
Read More - WatchGuard Security Prediction #5 – Jar Jar Can’t Resist Ads from the Dark Side
It’s hard to call today, “Microsoft Patch Day,” when both Adobe and Apple piled on with tons of security fixes of their own. Microsoft released a dozen security bulletins today, eight rated Critical; Adobe released a Flash update fixing 78 vulnerabilities; and Apple released fixes for all their OSes and a few other products. If you […]
Read More - IT Pros Get Patches for Xmas? – Daily Security Byte EP. 188
Experts have been predicting the growth of mobile malware for years. We’ve covered how the increase in mobile device usage has led to an increase in criminal attention. We’ve predicted how the inclusion of mobile wallets, using NFV and RFID technology, would lead to attackers targeting the mobile payment vector. We’ve even talked about how […]
Read More - WatchGuard Security Prediction #4 – The iOS Menace
Internet Explorer (IE) has been around for ages, but Microsoft is ending support for older version of the popular browser on January 12, 2016, likely to focus on their new Edge browser. They’ll only support the latest version of IE in each of their supported operating systems, which basically means most people will have to use […]
Read More - No Security for Old IE – Daily Security Byte EP. 187
Security experts often focus on the latest and greatest progressions of the threat landscape. They’re most interested in sharing how threat actors have become more sophisticated and how attack technology, malware, and techniques have evolved significantly. They warn that the latest attacks bypass or evade many of the industry’s original information security defenses. Prediction video […]
Read More - WatchGuard Security Prediction #3 – SMBs Can’t Let Basic Shields Down
One of WatchGuard’s partners, Trend Micro, found that many devices are still using an older version of a common Universal Plug-n-Play (UPnP) library that suffers from a very serious vulnerability. This new research is very similar HD Moore’s UPnP disclosures a few years ago; the difference being Trend Micro specifically found the issue affecting many Internet of Things […]
Read More - UPnP Flaw Helps Pop IoT – Daily Security Byte EP. 186
Security professionals spend a lot of time trying to plug the technical security gaps in their organization’s IT infrastructure. We find and fix software vulnerabilities, tighten our network security controls, and monitor the latest malware samples and exploits to try and ensure a hacker can’t leverage them against our systems. However, if you look at […]
Read More - WatchGuard Security Prediction #2 – It's a Trap
From an attacker’s perspective, the best botnet is the one you’ve never heard of, since the authorities won’t know what to take down. Using that measure, Ponmocup—a botnet recently detailed by the security group Fox-IT—is pretty successful, considering it has hung around over nine years and infected over 15 million victims. Watch today’s episode for more on this […]
Read More - Evasive Ponmocup Botnet – Daily Security Byte EP. 185
On Monday, I highlighted the Vtech breach. A hacker was able to steal millions of records from an online kid’s toy manufacturer, which including information about children. Over the past day, we’ve learned two new updates about this story. One increases the scope of the breach, and the other explains how it happened (Spoiler: my hunch […]
Read More - Vtech Update Proves SQLi – Daily Security Byte EP. 184
At the end of each year, WatchGuard’s security team and I like to spend some time imagining what the threat landscape might look like the upcoming year. This not only gives us the opportunity to analyze the security trends we’ve followed over the past year, but also allows us to creatively extrapolate what might happen next. Though our predictions don’t always […]
Read More - WatchGuard 2016 Security Predictions: #1 Ransomware
You’ve heard me talk about the Lenovo Superfish issue, and Dell’s Superfish 2.0. Both these vendors shipped products with identical digital certificates, which makes it easier for attackers to trick these devices into trusting them, if they can get into the path of the devices’ communications. Well, the news just got even worse. Watch today’s episode to learn about the […]
Read More - Lots of Duplicate Keys – Daily Security Byte EP. 183
What’s worse than the average data breach? A breach that involves our childrens’ private information! In Monday’s episode, I talk about how a “greyhat” hacker stole over 190GBs of data from a company that makes an Internet-connected kid’s toy. Luckily, he doesn’t seem to plan on using the data with malicious intent. Nonetheless, it’s still […]
Read More - Vtech Leaks Kids Data – Daily Security Byte EP. 182
To deal hunters, Black Friday and Cyber Monday have become even more exciting than the Thanksgiving holiday that spawned them. Unfortunately, cyber criminals understand our weakness for deals, and use the time themselves to increase their phishing and web scam campaigns. Watch today’s video for some quick tips on how you might avoid any Black Friday […]
Read More - Black Friday Security Tips – Daily Security Byte EP. 181
Remember Superfish? That was when Lenovo shipped bloatware on their laptops that included the same self-signed root certificate. Once attackers extracted the private key, they could leverage this root certificate to make every HTTPS connection look good, even if it was a fake site. Apparently, Dell made the same mistake. Watch today’s video to learn more. […]
Read More - Dell Superfish 2.0 – Daily Security Byte EP. 180
Great news for Black Friday shoppers who use Amazon! The well known online retailer has finally enabled free two-factor authentication (2FA) for its customers. Watch today’s video to learn why I think you should turn it on, and why I think 2FA is important for all IT organizations. (Episode Runtime: 2:19) Direct YouTube Link: https://www.youtube.com/watch?v=xzodlmJxyrE EPISODE […]
Read More - Amazon 2FA – Daily Security Byte EP. 179
Ransomware has become a very serious threat online, and I suspect it will continue to evolve and get worse in 2016. Today’s video covers one such evolution—a Linux-based variant affecting web servers. Luckily, this ransomware story has a happy ending. Click play to learn more. (Episode Runtime: 2:24) Direct YouTube Link: https://www.youtube.com/watch?v=H4RpG0n4olw EPISODE REFERENCES: Linux ransomware targets web […]
Read More - Linux Ransomware – Daily Security Byte EP. 178
On the surface, terrorist attacks and information security (infosec) seem unrelated. However, the abhorrent terrorist attacks carried out against innocent victims in Paris have stirred up two long-running information security topics; is hactivism valuable and should governments have access to public encrypted data? Neither of these are black and white issues, but watch today’s daily video to […]
Read More - Terrorism & InfoSec – Daily Security Byte EP. 177
Last week, a Chinese security research disclosed a new zero day Android vulnerability at PacSec’s Pwn2Own competition. Watch today’s video to learn a little more about this flaw, and what to do about it until it’s patched. (Episode Runtime: 2:13) Direct YouTube Link: https://www.youtube.com/watch?v=GzE9VpfhkaE EPISODE REFERENCES: Researcher discloses Android Chrome zero day vulnerability at PacSec Pwn2Own – Security Affairs […]
Read More - Android Chrome 0day – Daily Security Byte EP. 176
Whether you’re talking about soccer in Europe, or U.S. football in the states, fantasy football leagues have become very popular lately, which is why criminal hackers have noticed and might start targeting them. Today’s video talks about how a popular UK fantasy football site has become infecting with evil malvertising. Watch below to learn how […]
Read More - Fantasy Football Malvertising – Daily Security Byte EP. 175
If you use Microsoft or Adobe products—as the majority of computer users do—it’s that time again… Patch Day. For November’s Patch Day, Microsoft released a dozen bulletins fixing many flaws in their most popular products. Watch today’s video for the quick highlights about these and Adobe’s updates. UPDATE: As gung-ho as I am about applying […]
Read More - A Dozen Microsoft Updates – Daily Security Byte EP. 174
Nowadays, each week has more information security news that we used to have each month. If you find yourself falling behind, and need a shortcut to stay informed, this is the weekly video for you. Every Monday, I summarize our daily security video from last week. Today’s episode covers a new Android malware variant, an […]
Read More - iOS Bounties, Android Auto-root, and Guy Fawkes Day – WSWiR Episode 168
Based on the masks they chose, you could probably guess that Hacktivists, like Anonymous, associate strongly with Guy Fawkes. So it’s not surprising that they also plan hacking campaigns for Guy Fawkes Day, which falls on November 5th every year. Watch today’s episode to hear about two hacktivist campaigns carried out this week, and what we can […]
Read More - Guy Fawkes Day Hacktivism – Daily Security Byte EP. 173
No one wants an attacker or malware in their systems. That’s why the information security community spends so much time and effort on prevention. We try our best to implement defenses that stop today’s threats, while imagining new safeguards to catch future ones. The problem is, complete prevention is simply an infeasible goal. We’re all human. No […]
Read More - Visibility: The Missing Layer of Information Security
Can Android malware burrow so deep that it’s impossible to remove from your device? Today’s episode covers three new Android malware samples that automatically root your device and cause a lot of mayhem. Some think you’d have to buy a new phone to get rid of these samples. Watch the video to see what I […]
Read More - Auto-rooting Android Malware – Daily Security Byte EP. 172
The creators of vBulletin are having a bad week. Not only did they have a data breach that resulted in around 400,00 stolen user records, but it sounds like the attacker leveraged a zero day vulnerability in their own software to compromise their network. Watch today’s Daily Byte to learn more about this story, and what you should […]
Read More - vBulletin Breach and 0day – Daily Security Byte EP. 171
Some happy researchers apparently claimed a one million dollar bounty by finding a remote root jailbreak vulnerability in iOS 9. Yet, as exciting as that might sound, it’s bad news for Apple users because the bounty was offered by a company that doesn’t plan to disclose the flaw to Apple. Watch today’s video to learn more about this […]
Read More - Claimed iOS Bounty is Bad News – Daily Security Byte EP. 170
A popular hosting company suffered a network breach and lost over 13M user records. Not only did the company not know about the breach until five months later, the stolen records included clear text passwords. Watch today’s video to see what you can learn from this web hoster’s mistakes; of which they made many. (Episode Runtime: […]
Read More - 000Webhost has 000 Security – Daily Security Byte EP. 169
At a small security conference in Boston, an FBI agent said that they often recommend victims to just pay the ransom associated with ransomware like Crytpowall and Cryptolocker. Watch today’s video to see what I think of this, and to get a small Halloween-themed surprise. (Episode Runtime: 3:59) Direct YouTube Link: https://www.youtube.com/watch?v=25ncoN7CDfk EPISODE REFERENCES: The FBI […]
Read More - Don’t Listen to the FBI – Daily Security Byte EP. 168
If you use Adobe Shockwave, it’s time to patch. This week, Adobe released an out-of-cycle update fixing a critical flaw in the popular multimedia player. Watch the video to learn more, including why I recommend against Shockwave. (Episode Runtime: 1:10) Direct YouTube Link: https://www.youtube.com/watch?v=LFKIM8k8nf8 EPISODE REFERENCES: Adobe releases out of cycle Shockwave update – Adobe — Corey […]
Read More - Emergency Shockwave Update – Daily Security Byte EP. 167
Last week, TalkTalk’s suffered a data breach for the third time this year. It took awhile for the details to surface, but it looks like the attackers exploited a SQL injection flaw in TalkTalk’s website to steal 4M customers’ personally identifying information. Watch today’s information to learn the latest news about this breach, and what you […]
Read More - TalkTalk Hacked by Teenager? – Daily Security Byte EP. 166
Are you feeling overwhelmed by your normal IT job, but wish you had time to keep up with information security (infosec)? No worries! Let our weekly security video fill you in. Every Monday, I quickly summarize the biggest network and information security stories from the previous week, so you can keep up with the latest […]
Read More - PWNed CIA, hacked Fitbit, and Fake Chrome- WSWiR Episode 167
This week, the media was all over a Fitbit hack that allegedly could transfer malware from an infected Fitbit to a victim computer. However, the research—though interesting—didn’t deliver on this nightmare scenario. Watch today’s video to learn what the discoverer really did, and what some news stories are overstating. (Episode Runtime: 4:58) Direct YouTube Link: https://www.youtube.com/watch?v=jHYbLgKxg6E […]
Read More - Overstated Fitbit Hack – Daily Security Byte EP. 165
Are you an Apple fan, or do you at least use Safari or iTunes for Windows? If so, yesterday was Apple patch day. If you haven’t updated yet, watch today’s video to learn what you’re missing. (Episode Runtime: 1:08) Direct YouTube Link: https://www.youtube.com/watch?v=AMSg5eyRynI EPISODE REFERENCES: Apple’s Security page with the latest October updates – Apple — Corey Nachreiner, […]
Read More - Apple’s October Updates – Daily Security Byte EP. 164
Have you installed free software lately. If so, there’s a chance you might think you’re surfing with Chrome, but in reality a look-alike browser is snooping on your web connections and forcing ads on you. In today’s video, I discuss eFast browser, a potentially unwanted program (PUP) shipping with certain free software installers. Show note: […]
Read More - Malicious Chrome Look-alike – Daily Security Byte EP. 163
Oracle follows a quarterly patch cycle, and today they released their big Critical Patch Update (CPU) for October 2015. Since they only update four times a year, they tend to release tons of patches at once. Today’s update fixes 154 vulnerabilities in a wide selection of their products—from MySQL to the Siebel CRM. Most importantly, […]
Read More - Oracle CPU for Oct. 2015 – Daily Security Byte EP. 162
Lately, the nation has been been criticizing Hilary Clinton for running an insecure personal email server. However, she’s apparently not the only government employee with insecure email practices. Today, a high school hacker claimed to hijack the personal email account of the Director of the CIA. Watch today’s episode to learn what sensitive documents the director […]
Read More - CIA Director’s Email Hacked – Daily Security Byte EP. 161
Did you miss last week’s security news since you were too busy keeping your network running? If so, you’re not alone. However, staying up to date with the latest threats is important, so let our short weekly security summary keep you informed. If you don’t have time to follow our daily security videos, I summarize […]
Read More - Patches, Drone Hacks, and Evil USB – WSWiR Episode 166
This week a research team found vulnerabilities in a remote control communication protocol that would allow them to crash or ground quadcopters. What does hacking a drone have to do with information security? Watch today’s video to find out. (Episode Runtime: 2:27) Direct YouTube Link: https://www.youtube.com/watch?v=fcCtAdYorrY EPISODE REFERENCES: Researcher post about a MAVLink vulnerability – Shellntel […]
Read More - Drone Hacking – Daily Security Byte EP. 160
Adobe just released a new Flash update Tuesday, but researchers have already found sophisticated threat actors leveraging a new zero day Flash exploit in the wild. Trend Micro, one of our security partners, found the Pawn Storm attackers leveraging this new Flash exploit. Watch today’s video to learn when the next patch will come out, and what […]
Read More - Flash 0day Surfaces – Daily Security Byte EP.159
You’ve heard me talk about USB-based malware, or malicious USB sticks that can take over your computer (Bad USB), but what about a USB device that can fry your machine. A Russian research has built just such a device, and he calls it USB Killer 2.0. Watch today’s video to learn more about it, and why […]
Read More - Computer Frying USB Stick – Daily Security Byte EP.158
As boring and repetitive as it may seem, patching is one of the most effective things you can do to improve your security. That’s why I suggest you keep up with Microsoft Patch Day on the second Tuesday of every month. Today, I quickly highlight Microsoft’s October security updates, so that you know the types of holes […]
Read More - Patch Day Improves Browser Security – Daily Security Byte EP.157
If you use a Netgear router, you’ll want to disable remote administration. In today’s video, I talk about two zero day vulnerabilities the Shellshock Labs found in a line of popular Netgear broadband routers. In a nutshell, if an attacker can access the administrative web page, she can gain complete control of your router. Press […]
Read More - 0day Root Netgear Flaw – Daily Security Byte EP.156
Can malware be good? That’s the question we explore by looking at a new Linux threat called Wifatch. This new “threat” infects consumer routers and other Linux-based IoT devices, but rather than do anything bad, it seems to plug security holes. Learn what I think about this in today’s daily video. (Episode Runtime: 4:00) Direct […]
Read More - WiFatch: “Good Guy” Malware – Daily Security Byte EP.155
Another piece of iOS malware is affecting Chinese and Taiwanese users. It works against non-jailbroken devices and uses Apple’s private APIs to hide its malicious activities. Watch today’s video to learn more about it, and what users should do to avoid it. (Episode Runtime: 3:17) Direct YouTube Link: https://www.youtube.com/watch?v=1lAUaPeiHCo EPISODE REFERENCES: Detailed YiSpecter iOS malware blog […]
Read More - YiSpecter iOS Malware – Daily Security Byte EP.154
It’s bad enough that we seem to learn about a new data breach every week, but today we learned about four new data breaches, including one that leaked 15M customer record. Watch today’s video to learn which companies were affected, what data was stolen, and what users should do about it. I also discuss how […]
Read More - Data Breachapalooza – Daily Security Byte EP.153
Today, Apple fixed a few security flaws but also suffered from a new one. A researcher has found a new way to bypass Gatekeeper—the OS X component that’s supposed to keep suspicious software off Macs. Watch the video below to learn a bit about this flaw. (Episode Runtime: 2:11) Direct YouTube Link: https://www.youtube.com/watch?v=LvZ3zN7D4Ng EPISODE REFERENCES: Research […]
Read More - Researcher Storms Gatekeeper- Daily Security Byte EP.152
A hosting and security company discovered attackers leveraging mobile devices in China to launch a DDoS attack against one of its customers. Watch today’s video to learn how this DDoS attack is unique, and what you can do to prevent your computer from becoming a pawn in some criminal’s attack. (Episode Runtime: 2:50) Direct YouTube Link: https://www.youtube.com/watch?v=iznz2iN8PRY […]
Read More - Mobile DDoS from China – Daily Security Byte EP.151
If you have no time to keep up with security news, but do want to know about the most concerning threats, our weekly video was made for you. It summarizes the biggest infosec stories each week (which I also cover in daily videos), and shares tips to protect your organization. Today’s episode includes a couple […]
Read More - Lots of Apple Hacks- WSWiR Episode 165
Criminals have infected ATMs with a new malware variant called GreenDispenser. Besides stealing cash from bank machines, this new variant adds two-factor authentication and secure delete to the malware’s arsenal. Watch today’s video to learn more. (Episode Runtime: 1:51) Direct YouTube Link: https://www.youtube.com/watch?v=NWCU-O8VQuM EPISODE REFERENCES: GreenDispenser infects Mexican ATMs – ProofPoint ATM malware dispenses cash on demand – Network World — Corey […]
Read More - GreenDispenser – Daily Security Byte EP.150
Apple’s not having a great security week. First the XcodeGhost issue, which infected their App Store with malware, now a new iOS 9 lockscreen bypass vulnerability. A Spanish speaking YouTuber disclosed a new lockscreen bypass flaw this week. Today’s episode covers how an attacker might exploit this flaw, and what you can do to mitigate it […]
Read More - iOS 9 Lockscreen Bypass – Daily Security Byte EP.149
Adobe usually follows Microsoft Patch Tuesday, and releases updates on the second Tuesday of each month. However, yesterday they released a critical, out-of-cycle Flash update fixing 23 vulnerabilities. Watch today’s video to learn how severe these vulnerabilities are, and what you should do. (Episode Runtime: 1:45) Direct YouTube Link: https://www.youtube.com/watch?v=ybNfQajHGhI EPISODE REFERENCES: Adobe’s out-of-cycle Flash advisory – Adobe […]
Read More - Critical Flash Patch – Daily Security Byte EP.148
A booby-trapped version of Xcode—Apple’s development toolkit—is spreading on Chinese forums, and adding a malicious backdoor to any app made with it. Watch today’s video to learn more about XcodeGhost, and what developers and users should do to avoid it. (Episode Runtime: 2:30) Direct YouTube Link: https://www.youtube.com/watch?v=BC_oyFg7AnA EPISODE REFERENCES: Palo Alto’s posts on XcodeGhost Original XcodeGhost post […]
Read More - XcodeGhost Pwns App Store – Daily Security Byte EP.147
A curious netizen found more than he expected while checking out his D-link webcam’s firmware. Learn how D-link accidentally leaked some sensitive digital keys, and what that means to the world at large. (Episode Runtime: 3:24) Direct YouTube Link: https://www.youtube.com/watch?v=gIUwVfKMu5k EPISODE REFERENCES: Original post about leaked D-link keys on Dutch forum – Tweakers.net D-Link spilled their private keys on […]
Read More - D-Link Leaks Key – Daily Security Byte EP.146
A new malvertising campaign went undetected for three weeks due to advertisers adopting HTTPS. Learn how secure web communications might introduce unexpected new risks in today’s daily video. (Episode Runtime: 2:57) Direct YouTube Link: https://www.youtube.com/watch?v=u3DURxAy7Lw EPISODE REFERENCES: Malvertising hiding in HTTPS – Motherboard Malvertising campaign goes undetected – MalwareBytes Malvertising campaigns triple – Riskiq — Corey Nachreiner, CISSP (@SecAdept)
Read More - HTTPS Masks Malvertising – Daily Security Byte EP.145
Today is Apple Patch Day. They released security updates for iTunes, iOS, Xcode, and OS X Server. iOS 9 is the big news, since it’s a pretty big feature update. However, it also fixes a critical AirDrop flaw. Press play below to learn about these updates, and the major AirDrop issue. (Episode Runtime: 1:39) Direct […]
Read More - Apple Patches iOS & iTunes – Daily Security Byte EP.144
Sophisticated attackers have injected malicious firmware into at least 14 Cisco routers in four continents. Watch today’s quick video to learn more about this attack, and how you should validate your devices’ firmware. (Episode Runtime: 2:07) Direct YouTube Link: https://www.youtube.com/watch?v=agcx4Xkv7Yw EPISODE REFERENCES: SYNful knock: Pwned Cisco routers – FireEye Implanted routers hard to detect – Reuters Cisco […]
Read More - SYNful Knock Pwns IOS – Daily Security Byte EP.143
Hardware security is becoming as important as software security, especially with the development of secure boot systems that require digital certificates on chips. Watch today’s video for an interesting new take on securing the data on computer chips from prying eyes. (Episode Runtime: 1:50) Direct YouTube Link: https://www.youtube.com/watch?v=aiEJAnBdaQ4 EPISODE REFERENCES: Xerox develops an exploding computer chip – Tech […]
Read More - Exploding Security Chips – Daily Security Byte EP.142
Do you have little time for security news, but wish you could keep abreast of the latest threats? In that case, our weekly summary video can help. Every Monday, we summarize last week’s infosec news for you, often in under ten minutes. This week’s show includes Microsoft and Adobe patches, some adult-themed mobile ransomware, and a sneaky new […]
Read More - Adult Ransomware and Hacked WhatsApp – WSWiR Episode 164
Attackers have always tried to hide their command and control (C&C) servers using proxies and peer-to-peer (P2P) networks, but authorities still eventually track them down. However, an advanced hacking group has found a new way to keep their malicious control servers off the radar. Watch Friday’s video to learn about this hidden communication channel. (Episode […]
Read More - Satellite C&C Channel – Daily Security Byte EP.141
Ransomware like Cryptolocker and Cryptowall are already bad enough, costing victims millions in losses. It’s about to get worse… Now there’s ransomware that targets your smartphone and takes embarrassing pictures of you associated with an adult-themed app. The good news is it’s easy to avoid. Watch today’s video to learn more. (Episode Runtime: 1:46) Direct YouTube […]
Read More - Adult Mobile Ransomware – Daily Security Byte EP.140
WhatsApp is one of the most popular messenger apps for mobiles, with over 900 million users. Unfortunately, it suffered from a critical vulnerability attackers could exploit to trick you into accidentally installing malware. Watch below for the details. (Episode Runtime: 1:38) Direct YouTube Link: https://www.youtube.com/watch?v=NJ5ploC4nzY EPISODE REFERENCES: Researcher finds critical flaw in WhatsApp web client – Checkpoint Article […]
Read More - WhatsApp Hacked – Daily Security Byte EP.139
It’s the second Tuesday of the month, which means you’re in for a pile of Microsoft and Adobe patches. Watch today’s video for a quick summary of the issues, and how WatchGuard appliances can help. (Episode Runtime: 1:42) Direct YouTube Link: https://www.youtube.com/watch?v=DvHYJGpr4rc EPISODE REFERENCES: Microsoft September Patch Day summary post – Microsoft Quick SANS summary of Microsoft Patch […]
Read More - September Patch Day – Daily Security Byte EP.138
Are you interested in the latest security news, but have no time to source it yourself? No problem! Let our weekly video summarize the latest for you in ten minutes or less. If you want to watch the video Friday, subscribe to our YouTube channel. Otherwise, we’ll post the weekly episode on the first day of […]
Read More - Apple Flaws and Cyber Sanctions – WSWiR Episode 163
Mozilla’s bug tracking system has been breached for at least a year. This means attackers have had access to zero day Firefox vulnerabilities. Watch today’s video to learn what this means, and what you should do. (Episode Runtime: 1:40) Direct YouTube Link: https://www.youtube.com/watch?v=fRVqaFgZ1uo EPISODE REFERENCES: Article about attackers spying on Mozilla bugs – The Register Mozilla’s FAQ on […]
Read More - Mozilla Hacked – Daily Security Byte EP.137
Another Apple vulnerability put passwords at risk on Thursday. This time the flaw lies in OS X’s Keychain. Watch today’s episode to learn about this vulnerability and how you might avoid it. (Episode Runtime: 1:33) Direct YouTube Link: https://www.youtube.com/watch?v=ZG8cmqQ8MjE EPISODE REFERENCES: Beirut researchers disclose zero day OS X Keychain vulnerability – Engadget Adware caught using the Keychain vulnerability – Ars […]
Read More - OS X Keychain Broken – Daily Security Byte EP.136
The bad news is a new iOS malware variant has stolen the iCloud credentials of 225,000 users. The good news is it only affects jailbroken iOS users. Watch today’s video to learn more about this new threat, and how to avoid it. (Episode Runtime: 2:07) Direct YouTube Link: https://www.youtube.com/watch?v=WgouWbav3jA EPISODE REFERENCES: KeyRaider iOS malware targets jailbroken devices […]
Read More - iOS KeyRaider – Daily Security Byte EP.135
According to unnamed sources in the Obama administration, the US government is developing sanction against foreign attackers who leverage cyber espionage to steal intellectual property. While these sorts of deterrents may be necessary to discourage cyber attacks in the age we live, they could certainly change the information security landscape. Watch today’s episode to learn more about these possible […]
Read More - Cyber Espionage Sanctions – Daily Security Byte EP.134
Did you know your medical Personally Identifiable Information (PII) is worth 50x more than your credit card information on the black market? It’s also the target of exponentially rising attacks. A recent report from Keeper Security has highlighted staggering stats informing us that 90% of all healthcare organizations have had a data breach, affecting nearly one-third of the […]
Read More - HIPAA-Compliant Wi-Fi: What You Need To Know
Cyber security has become mainstream. Nowadays, there’s more information security (infosec) stories each week than the average IT professional can keep up with. If you find yourself falling behind, let our daily and weekly videos keep you informed. If you watch my Daily Security Bytes, you can probably skip this weekly summary. However, if you […]
Read More - Backdoors and Watering Holes – WSWiR Episode 162
Today, the EFF warned the world that advanced attackers have been using their name in vain. A targeted spear phishing email is linking to a fake version of the EFF site, which forces malware via a recent cross-platform Java exploit. Learn more about this attack and how to protect yourself by watching the video below. (Episode […]
Read More - EFF Watering Hole Attack – Daily Security Byte EP.133
A few months ago, researchers found a backdoor in an LTE consumer router. Today, we learned that his hole exists in a number of DSL routers, including ones given to customers by ISPs. Watch the video to learn about this secret admin account, and what you can do to mitigate access to it. (Episode Runtime: […]
Read More - Backdoor in Multiple DSL Routers – Daily Security Byte EP.132
I’ve talked about the Ashley Madison breach before, but the news keeps coming. Today’s video covers, tragic suicides, new attack details, a CTO hacker, and criminals extorting the victims. Watch below to get the latest updates. (Episode Runtime: 3:46) Direct YouTube Link: https://www.youtube.com/watch?v=IemvDUxe7Wo EPISODE REFERENCES: Two suicides allegedly associated with AM breach – Ars Technica Biderman […]
Read More - Ashley Madison Extortion – Daily Security Byte EP.131
It’s pretty impressive to know an 18 year old Italian teenager is already finding vulnerabilities in OS X. However, I hope he learns to disclose them responsibly, and starts informing vendors first. This week, news surfaced of a zero day privileges escalation flaw in the latest version of OS X Yosemite. Click play below to learn […]
Read More - Yosemite 0day – Daily Security Byte EP.130
As if yesterday’s Ashley Madison data dump wasn’t bad enough, the attackers have released new stolen data. Learn what new information is at stake, and what you can do to protect your data in today’s video. (Episode Runtime: 1:39) Direct YouTube Link: https://www.youtube.com/watch?v=4Yk7OOST1ag EPISODE REFERENCES: Attacker dump new data from the Ashley Madison breach – Motherboard […]
Read More - Ashley Madison Hemorrhaging Data – Daily Security Byte EP.129
The latest Wi-Fi standard to hit the market is 802.11ac and it’s been split up into two flavors; Wave 1 and Wave 2. Wave 1 has been out for awhile, but Wave 2 consumer routers and business access points have recently become available. With that in mind, what do you need to know about these new standards? […]
Read More - How to Save Yourself an 802.11ac Wave 2 Headache
I missed yesterday’s daily video due to an offsite meeting, so today’s episode contains two important stories; an emergency update to fix a zero day vulnerability in Internet Explorer (IE) and the latest update to the Ashley Madison breach. If you run a Microsoft network, or you know anyone that had an account on Ashley […]
Read More - IE 0day & AM Hack Update – Daily Security Byte EP.128
The Australian 60 Minutes unveiled a piece on how attackers can track and intercept the calls from any mobile, as long as they know its number. However, others say the researchers demonstrating this attack had special access to carrier networks. Watch today’s video to learn how real this threat is, and whether or not you can […]
Read More - Global Mobile Hack – Daily Security Byte EP.127
Two weeks ago, the Black Hat and DEF CON conferences unveiled tons of new security research, which means last week was packed with interesting security stories. If you find yourself falling behind on security news, and need a “one stop shop” to keep you up to date, this weekly video does just that. Last week’s stories included […]
Read More - Black Hat & DEF CON Aftermath – WSWiR Episode 160
Cisco is warning its customers that attackers have been overwriting the iOS ROMMON firmware of some of their customers routers, replacing it with a malicious firmware trojan. Watch today’s video to learn more about this attack, and what Cisco says you can do. (Episode Runtime: 2:09) Direct YouTube Link: https://www.youtube.com/watch?v=49hPCvBygiE EPISODE REFERENCES: Cisco’s advisory on the mysterious iOS […]
Read More - Cisco iOS ROMMON hacks – Daily Security Byte EP.126
Weeks ago, I shared a story about a scary remote car hack researchers were previewing before Black Hat. Not only did those researchers release all the details about that attack, but many other researchers have also found significant automotive security flaws. Today’s video highlights a number of new car attacks disclosed in the past few […]
Read More - Car Hacking Revolution – Daily Security Byte EP.125
While there’s lots of interesting security stories I could share today, one of the most practical infosec actions you can take is to keep your software patched. Yesterday was Microsoft and Adobe patch day, and Mozilla also recently released a pretty important Firefox update. Watch the video to learn about these important fixes, and more […]
Read More - Piles of August Patches – Daily Security Byte EP.124
You probably know that USB devices can be malicious, but did you know that infected Thunderbolt devices could spread a firmware worm to all your Macbooks? In today’s security video, I cover the ThunderStrike 2 attack that researchers disclosed at this year’s Black Hat and DEF CON conferences. Watch to learn what this attack does, and how the […]
Read More - Thunder Strikes Mac Firmware Again – Daily Security Byte EP.123
UK smart phone shoppers will probably want to know about the latest security breach. This week a popular mobile retailer, Carphone Warehouse, lost 2.4 million customer records. Learn what data is at risk, and what you should do if you’re affected in today’s video. (Episode Runtime: 2:38) Direct YouTube Link: https://www.youtube.com/watch?v=YS_f-ViBDcI EPISODE REFERENCES: Attackers steal 2.4M […]
Read More - Carphone Warehouse Gets Robbed – Daily Security Byte EP.122
The most popular DNS server on the market, BIND, suffers from a new denial of service (DoS) vulnerability that’s trivial to exploit. Watch today’s episode to learn what to do. (Episode Runtime: 1:21) Direct YouTube Link: https://www.youtube.com/watch?v=ZxsRs9Ll2-g EPISODE REFERENCES: BIND suffers from easy to exploit DoS flaw – SC Magazine Another good description of the BIND […]
Read More - Critical BIND DoS – Daily Security Byte EP.121
When I started in information security, I’d never have guessed hackers would be able to cause sniper rifles to shoot off target. However, the latest research has made that idea a reality. See today’s video to learn about this interesting new hack, and why it should make you aware of the dangers of the “Internet of […]
Read More - Hacking Sniper Rifles – Daily Security Byte EP.120
Stagefright is a new Android vulnerability that’s serious enough to deserve its fancy marketing name. As one security pundit said, “It’s the Heartbleed of mobile vulnerabilities.” Attackers can leverage this dangerous flaw against 95% of Android devices simply by sending you a text message with a specially crafted file. You don’t even have to interact […]
Read More - StageFright Affects Most Androids – Daily Security Byte EP.119
Mr Robot keeps getting better. This is the first show that I’ve seen that gets hacking and technology consistently right; down to the tools they show in screen shots. I like it so much that I have partnered with GeekWire to do an article series analyzing each episode. Watch Friday’s video to learn more about […]
Read More - Mr Robot Rewind – Daily Security Byte EP.118
The IOActive researchers are at it again. In 2013, they demonstrated how you could hack a car with physical access. However, this year they found the holy grail of car hacks—a remote zero day flaw that allows them to control a car over its cellular network. Watch today’s video to learn what you should do if […]
Read More - Remote Zero Day Car Hack – Daily Security Byte EP.117
We can’t condone cyber crime, even when the hacktivists have morals. A group of attackers calling themselves The Impact Team have breached a well-known online cheating site, and threatened to expose all its customers if they don’t shutdown shop. Watch today’s video to learn about this scandalous cyber drama, and why you shouldn’t post anything online […]
Read More - Hacktivists Expose Cheaters – Daily Security Byte EP.116
Good news. A major underground cyber crime forum has been busted. However, it turns out an intern from a well known security company was actually behind a popular android exploit kit sold on the forum. Watch today’s video to learn more. (Episode Runtime: 2:14) Direct YouTube Link: https://www.youtube.com/watch?v=iZBsTM2N_Sc EPISODE REFERENCES: World-wide authorities bust Darkode underground forum […]
Read More - Darkode Busted – Daily Security Byte EP.115
This Patch Tuesday, Adobe and Oracle shared the spotlight with Microsoft, releasing updates for well over 200 vulnerabilities. Furthermore, the patches included fixes for flaws leaked during The Hacking Team fiasco. Watch today’s video for details, and be sure to update as soon as you can. Show Note: Due to continued travel, there will likely be […]
Read More - July Patch Avalanche – Daily Security Byte EP.114
Last week was another packed week of information security stories. If you’re falling behind, and don’t know what’s really important, use our weekly video to keep up to date. Last Friday’s episode covered an ironic story about a “grey hat” security company getting hacked, leaked Adobe Flash 0day, an important software update, and much more. Watch […]
Read More - Hacked Teams, Suspicious Glitches, and 0day Fixes – WSWiR Episode 159
A Finnish teenager was convicted of 50,000 incidents of cyber fraud while part of the Lizard Squad; yet he’s not going to jail. One of his victims, and the ex-chief of Sony Online Entertainment (SOE), is not happy and vents to the world. Watch Friday’s video to learn all about this InfoSec drama. (Episode Runtime: […]
Read More - Lizard Squad Drama – Daily Security Byte EP.113
Among all the embarrassing stolen data from The Hacking Team breach was a serious Adobe Flash zero day vulnerability, which is now in the hands of any blackhat criminal who knows how to use Google. If you don’t want cyber criminals exploiting this flaw against you, watch today’s video to learn what you can do. (Episode Runtime: […]
Read More - Hacked Team Flash ’Sploit Patched – Daily Security Byte EP.112
Yesterday, the New York Stock Exchange (NYSE) stopped trading, United Airlines grounded thousands of flights, and the Wall Street Journal site went down all due to computer and network related issues. The night before, an Anonymous group twitter account had predicted a bad day for Wall Street. Was this all a coordinated “cyber” attack? Watch […]
Read More - The Cyber Sky is Falling – Daily Security Byte EP.111
A group of malware researchers wants the security community to know about a recent botnet tool that has leaked on the underground. Watch today’s episode to learn about this tool, and why this leak will result in an increase in botnet activity. I also cover a few updates about the Hacking Team breach. (Episode Runtime: 2:06) […]
Read More - Botnet Tool Leaked – Daily Security Byte EP.110
A controversial Italian company, know for making spyware for governments, has suffered a data breach. Learn what the hackers disclosed in today’s daily security video. (Episode Runtime: 1:48) Direct YouTube Link: https://www.youtube.com/watch?v=Yz1TjASkMu4 EPISODE REFERENCES: Hacking Team, a spyware company, breached – Wired Hackers dump stolen Hacking Team data – CSO Online Industry chuckles over Hacking Team irony – The Register […]
Read More - Hacking Team Hacked – Daily Security Byte EP.109
Earlier Snowden leaks have already introduced us to XKeyScore. However, new documents highlighted in the latest Intercept article make it sound even worse than privacy advocates first suspected. Watch the video to learn more. As an aside: You may have noticed there was no episode on Wednesday. I was updating my production software, which prevented me from […]
Read More - XKeyScore Sniffs Our Data – Daily Security Byte EP.108
If you use Apple products—on Mac or PC—know that today is Apple Patch Day. The popular software company released six security advisories (originally five, but they had a late breaking advisory) fixing many security flaws in most of their most popular products. Watch today’s video to learn which products are affected, and what you should patch […]
Read More - June Apple Patch Day – Daily Security Byte EP.107
Last week, I talked about a Flash 0day vulnerability that attackers were only exploiting in limited, targeted attacks. This week, the vulnerability has been added to popular exploit kits, so I expect it to become more popular. Watch today’s video to learn more about it. (Episode Runtime: 1:26) Direct YouTube Link: https://www.youtube.com/watch?v=ZaI0mbo9V0Q EPISODE REFERENCES: Magnitude exploit […]
Read More - Exploit Kits Spread Flash 0day – Daily Security Byte EP.106
If you’re feeling behind on critical information security news, you’re not alone. There are so many new InfoSec stories each week that only a dedicated few can keep up with the latest. If you need a little help following what’s important, let our weekly security news summary video keep you informed. Last Friday’s episode covered […]
Read More - Grounded Airline, Snowden Leak, and Mr. Robot – WSWiR Episode 158
It’s Friday, so let’s keep today’s InfoSec news light. The last few security-related shows and movies, like Blackhat and CSI: Cyber, have sucked! However, I have good news for you; Mr. Robot rocks! Watch today’s video to learn why I love this new TV show, and watch the first episode for free below (may not […]
Read More - Mr. Robot Rocks! – Daily Security Byte EP.105
I’ve mentioned ransomware repeatedly in my videos, but today the FBI warned business how dangerous ransomware can be. Watch our video to learn how much ransomware has cost US companies this year, and how to protect yourself from it. (Episode Runtime: 2:30) Direct YouTube Link: https://www.youtube.com/watch?v=Z1WVM7_xLMQ EPISODE REFERENCES: Cyber criminal make over $18M from ransomware – […]
Read More - Ransomware Costs $18M – Daily Security Byte EP.104
You would hope our governments only spy on or hack the bad guys, but apparently they target security companies too. The latest Snowden leaks cover how the NSA and GCHQ target foreign antivirus companies, and reverse engineer their products to presumably find weaknesses. Watch today’s video to learn why I think this is bad for the security […]
Read More - Nation States Spy on AV Vendors – Daily Security Byte EP.103
Adobe released an emergency patch today to fix a zero day Flash vulnerability, which a security company found attackers exploiting in the wild. Watch today’s short video to learn how these alleged Chinese attackers delivered this exploit, and what you can do to protect yourself from it. (Episode Runtime: 2:31) Direct YouTube Link: https://www.youtube.com/watch?v=mSXb6N1k-ok EPISODE REFERENCES: Adobe […]
Read More - Spam Spreads 0day Flash Exploit – Daily Security Byte EP.102
Last Sunday, 1400 Polish LOT airline passengers were probably disappointed to learn their flights were delayed for five hours. According to the airline, hackers disrupted the ground stations responsible for sending flight plans to pilots. Watch today’s video to learn about this recent airline hack, and what it means for the industry. (Episode Runtime: 1:59) Direct […]
Read More - Hackers Ground Airline – Daily Security Byte EP.101
Do you want to know about the latest security threats, but find yourself too busy solving business critical IT problems to keep up to date? Well maybe our videos can help. This weekly video summarizes the most interesting InfoSec news from the week. Or if you prefer, you can catch the shorter dailies. Last Friday’s […]
Read More - Baseball Hacks and Mobile Threats – WSWiR Episode 157
Wow, it’s been 100 daily videos already?! I started this daily security video experiment in January of this year, and though I haven’t been able to cover every single day, we’ve had quite a ride of InfoSec related stories so far. If you find this daily post useful, or if you have suggestions on ways […]
Read More - Two Mobile Platform Threats – Daily Security Byte EP.100
We’ve heard a ton about nation state cyber espionage, but this is the first time I’ve heard of baseball teams using network attacks to spy. Watch today’s video to hear how employees from the St. Louis Cardinals allegedly broke into the Houston Astro’s network, and what you should do to protect yourself from a similar […]
Read More - Baseball Cyber Espionage – Daily Security Byte EP.99
I often recommend you use a password vault to manage your passwords, but this week a popular password vault company’s network was breached. The good news is you don’t need to panic if you’re a LastPass customer. Your passwords are probably still safe. However, you do need to change your master password and use two […]
Read More - LastPass Hacked – Daily Security Byte EP.98
Information Security is a hot topic right now; unfortunately not for all the right reasons. Nowadays, it’s not unusual to have a big data breach, new zero day malware, and a ton of security updates all in the same week. If you’re part of an IT organization that’s concerned with protecting your network, but that doesn’t […]
Read More - APTs, Updates, and OPM – WSWiR Episode 156
You thought 4 million stolen federal workers’ records was bad? Well, Friday we learned the Office of Personnel Management (OPM) breach might be even worse than first suspected. We also learned a small time cyber criminal has tried to take credit for the attack. Watch the video for these updates, and to learn why PII theft […]
Read More - OPM Breach Gets Worse – Daily Security Byte EP.97
Kaspersky, one of the most effective antivirus companies out there, admitted that its network was breached by nation state actors. Watch today’s video to learn about the advanced threat that compromised this security vendor, and what I think about nation states that attack private security companies. (Episode Runtime: 3:45) Direct YouTube Link: https://www.youtube.com/watch?v=_JHX5son-aM EPISODE REFERENCES: […]
Read More - Kaspersky Gets an APT – Daily Security Byte EP.96
It happens every month… Microsoft released their June patches on Tuesday, fixing 45 vulnerabilities in a range of popular products. If you manage a Windows network, you should watch this video to get the Patch Day highlights, and to learn which products to update first. As an aside, I recorded this video Wednesday, but was not […]
Read More - Microsoft Posts Critical Patches – Daily Security Byte EP.95
HTTPS usage has skyrocketed over the last few years, largely due to the “Snowden effect.” Today, the US government mandated that federal web sites must use HTTPS. Ultimately, this is a good thing. However, malicious actors can hide in HTTPS too. Watch today’s video to learn what you should do to secure HTTPS. (Episode Runtime: […]
Read More - US Federal Sites Use HTTPS – Daily Security Byte EP.94
If you work at a restaurant, hospitality service, or retailer—or you help support the IT needs of such organizations—you should be on the look out for Point-of-Sale (POS) malware. Today’s daily security video covers a new POS malware variant called MalumPOS, which targets Oracle MICROS POS systems. Watch it to learn how to protect yourself. […]
Read More - MalumPOS Targets Oracle MICROS – Daily Security Byte EP.93
A few years ago we’d be surprised to learn about a public data breach once a month. However, nowadays two nation states can suffer major hacks in the same week. If you have trouble keeping up with the weekly security news yourself, let our vlog help you with a short recap. This week’s episodes shares […]
Read More - US & Japan Gov. Hacked – WSWiR Episode 155
If you want to know why spear phishing is a big threat, ask the managers of Japan’s Pension System. They recently had attackers steal 1.25 million records due to a user clicking on the wrong attachment. Watch today’s video to learn more. (Episode Runtime: 2:29) Direct YouTube Link: https://www.youtube.com/watch?v=jtUGQREjjgU EPISODE REFERENCES: Cyber attackers steal 1.2M […]
Read More - Japanese Pension System Pwned – Daily Security Byte EP.92
Unfortunately, lots of security news suggests lots of cyber crime. If you want to stay protected, you need to keep up to date; but who has time? Hopefully our weekly InfoSec video can help. Last Friday’s episode covered an IRS data leak, a mysterious text message that crashed iPhones, some scary new crowd-sourced ransomware, and more. Watch […]
Read More - Hacking Nation States & Crashing iPhones – WSWiR Episode 154
Today, a North Korean (NK) defector and university professor claimed the NK’s Bureau 121 cyber attack group includes 6000 cyber warrior who could destroy cities and cause human casualties. Meanwhile, we also learned that the US government allegedly launched a failed, Stuxnet-like attack against NK back in 2010. How much of this is true, and what do […]
Read More - North Korean Cyber Killers? – Daily Security Byte EP.91
Cyber criminals are getting more creative with malware dissemination by crowd-sourcing distribution. A ransomware author is giving away his creation for free, in return for help finding new victims. Cyber criminals spread the malware far and wide, and the author gets a 30% cut of the illicit profits. Watch today’s security video to learn more about this […]
Read More - Crowd-sourced Ransomware – Daily Security Byte EP.90
High schoolers around the nation likely woke up to randomly rebooting iPhones due to pranksters exploiting a mysterious new flaw triggered by a simple text message. The news of this malicious text started on Reddit, but quickly spread as security researchers and the press jumped on the issue. Learn more about it in today’s video. (Episode […]
Read More - iOS Crash Text – Daily Security Byte EP.89
Today, the IRS admitted that criminal attackers leveraged one of their online apps to steal tax records from 100,000 victims. Watch they video to learn how they did it, and what the IRS intends to do to protect US taxpayers. (Episode Runtime: 2:21) Direct YouTube Link: https://www.youtube.com/watch?v=T1ej6xgkAjA EPISODE REFERENCES: IRS’s official warning about the Get Transcript breach – IRS.gov […]
Read More - Hackers Hit the IRS – Daily Security Byte EP.88
Are you too busy provisioning new servers and reseting your users’ Windows passwords to keep up with information security news? If so, we have a quick solution for you. Learn the most important security issues in under ten minutes with our weekly security review video. Today’s episode talks about the latest plane hacking drama, a new […]
Read More - Plane Hacking & Crypto Logjams – WSWiR Episode 153
If you date online, especially at “adult” dating sites, you may want to reconsider how much data you share with these organizations. This week, a researcher found a stolen user data dump from a very popular adult dating site. Watch the video to learn the details, and find out how to learn whether or not you […]
Read More - Adult Friend Pwner – Daily Security Byte EP.87
This week, a group of university researchers disclosed a new vulnerability affecting the Diffie-Hellman key exchange. The Diffie-Hellman (DH) key exchange is a cryptographic method for two systems to establish a shared secret over a public communication channel, which they later use to encrypt their communications. Many encryption protocols, including HTTPS, SMTPS, IPSec VPN, SSH, and other […]
Read More - WatchGuard Breaks Logjam and Protects Encrypted Connections
Are you getting sick of SSL/TLS and other cryptography related vulnerabilities? I sure am! Nonetheless, we need to keep on top of them in order to keep our communications private. In today’s daily video I cover Logjam, a new named vulnerability having to do with the Diffie-Hellman key negotiation. Watch the video to learn which of […]
Read More - Cryptography Logjam – Daily Security Byte EP.86
Last month a security researcher was detained from a flight for allegedly making a silly plane hacking joke on Twitter. The latest news suggest his research was more than a just a joke. Watch today’s video to learn what he’s accused of and why I think he was irresponsible. Quick show note: I’ll be traveling to speak at […]
Read More - Plane Hacking Hijinks – Daily Security Byte EP.85
Last week was full of a wide range of information security news; from the latest critical Microsoft updates, to a new virtualization system vulnerability, and finishing off with malware targeting a popular video game. If you find yourself falling behind with the latest security intelligence, you’re not alone. Don’t worry though, we’re here to pick up the slack. […]
Read More - VM Venom, MS Patches, & GTA V Malware – WSWiR Episode 152
I hoped to keep today’s video fun with a video game related story, but I guess if the news means gamers might have been infected with a keylogger, it’s no fun at all. Watch the the Daily Byte video to learn what “mods” GTA V PC gamers should avoid. (Episode Runtime: 1:47) Direct YouTube […]
Read More - GTAV Mod Malware – Daily Security Byte EP.84
I’ve been known to mix a bit of pop culture with my information security (InfoSec) in the past. I truly believe that people get more interested in subjects, and learn better, if you make it fun for them—and almost everyone likes pop culture, right? In my latest InfoSec/TV mashup, I decided to tackle what a […]
Read More - Want to Improve Your InfoSec? Better Call Saul
Editor’s note: I’m excited to share a cool new security site with you. Pulitzer prize winning journalist, Byron Acohido, has launched a fresh site dedicated to keeping consumers and businesses informed about emerging information security (infosec) and privacy issues. I first met Byron while he was doing a USA Today story on Java’s security risk, and I’m excited to see him […]
Read More - The Hazards of Using Public WiFi Access Points
Happy much belated New Year readers, and welcome back! Regular readers probably noticed that the blog has been down for quite awhile. Early January, we unexpectedly had to take the blog server offline during some expected web site maintenance and re-architecture. It remained down longer than planned, so we decided to move the blog back to […]
Read More - The Blog is Back!
Security FUD, Black Energy, and Tor Terror Happy Halloween! The Internet “threatscape” has changed drastically over the past few years, with many more cyber security incidents each year and tons of information security (infosec) news in the headlines. Can you keep up? If not, maybe my weekly infosec video will help. In today’s quick update, I rant […]
Read More - Evil Tor Exit Node – WSWiR Episode 127
Windows 0day, iCloud MitM, and Cryptowall Rises You’re a busy IT guy that barely has time to brush your teeth before running off to work, so who has time to follow security news too? Does this sound like you? If so, let our short weekly video inform you of the most important security news in the time […]
Read More - Cryptowall Malvertising – WSWiR Episode 126
October Patch Bonanze, Leaky Apps, and POODLE Cyber security has gone main stream, which means we’re getting a lot more security news each week than we used to. This week was even busier than usual, with updates fixing hundreds and hundreds of security vulnerabilities, as well as a significant vulnerabilities in a encryption standards. If you’re […]
Read More - POODLE Bites SSL – WSWiR Episode 125
Nine MS Bulletins, Sneaky DRM, and ATM Trojan Every week, the security community learns about new attacks, exploits, breaches, security patches, and more. However, keeping track of all this fresh information security (infosec) news can be challenging for most IT practitioners. If you need a little help separating the security wheat from the chaff, this weekly video podcast is […]
Read More - ATM Trojan – WSWiR Episode 124
iOS Trojan, BadUSB PoC, and Gamer Hackers Charged Normally, I post a weekly video that summarizes the three biggest information and network security stories every Friday. However, due to a busy travel and work schedule I couldn’t find a convenient time to shoot. But fear not… Instead, I’ll post a written summary this week, and continue with the video […]
Read More - WatchGuard Security Week in Review in Writing (Oct.3, 2014)
Serious Bash Flaw affects *nix, Mac OS X, and IoT Normally, my weekly video covers a number of important information and network security stories, in order to keep you informed of the latest threats. However, this week one story is so important I give it the primary focus. Today’s show covers the critical “Shellshock” vulnerability in […]
Read More - Shellshock – WSWiR Episode 123
Apple Patches, Kindle XSS, and Doom Printer Hack If you want to stay current with the Internet “threatscape,” our weekly video can help. It summarizes each week’s top information and network security news in one convenient place. Subscribe today! Today’s episode covers, Apple and Adobe security updates, a cross-site scripting flaw that affects Kindle users, and […]
Read More - Printer Doom Hack – WSWiR Episode 122
Patch Day, Home Depot Update, and Gmail Leak Why go searching for all the week’s information security (infosec) news when you can find it in one convenient place. This weekly vlog summarizes the important security updates, hacks, and threats so you can protect yourself. This week’s episode arrives a bit late due to my business […]
Read More - Old Gmail Leak – WSWiR Episode 121
Software Patches, Home Depot Breach, and Celebrity Selfie Hack If you need a quick source for all your information security (infosec) news, you’ve come to the right place. I summarize the most important infosec news in this weekly video, and provide links to other security stories as well. Unfortunately, today’s episode includes a pretty creepy hack. […]
Read More - Celeb Selfie Hack – WSWiR Episode 120
Gaming DDoS, Malvertising, and U.S. Banks Breached You really need to keep up with the latest attacks to learn how to adjust your defenses to survive. However, with so much infosec news and so little time, it’s hard for many administrators to stay current. This weekly videos tries to keep you in the loop by summarizing the […]
Read More - JP Morgan Hacked – WSWiR Episode 119
Healthcare, UPS, and US Nuclear Organization Breached Need to learn the latest security news so you can figure out how to protect your network from evolving threats? Well, this weekly video series will help. Every Friday I summarize the biggest security stories and share some advice in a video, as well as compile a list of other […]
Read More - Breach Trio – WSWiR Episode 118
Blackhat Summary,Lots of Patches, and MonsterMind Times have changed. Cyber attacks have increased 10-fold, causing a ton of information security (infosec) news each week. Can’t keep up with it all? Let me help out. In this weekly video summary, I highlight the biggest information and security news every week. Last week, I had meant to post a Black […]
Read More - Blackhat and More – WSWiR Episode 116
Did any of the briefings from day one sound interesting to you? Do you want to know what happened the next day? If so, check out my day two Black Hat briefing summary below: BadUSB – On Accessories that Turn Evil Topic: Infecting USB microcontrollers to create undetectable evil USB devices Speaker: Karsten Nohl, Sascha […]
Read More - Black Hat 2014 – Briefing Summary – Day 2
If you’ve never been to Black Hat, the week long security conference is separated into two parts; a four day (optional) period for technical training courses, followed by two days of security briefings, where researchers share their latest discoveries and vulnerabilities. While the trainings I’ve attended have been excellent, most of the week’s security headlines […]
Read More - Black Hat 2014 – Briefing Summary – Day 1
Android Fake ID, Backoff PoS Attack, and BadUSB With Blackhat and DEF CON only a week away, it’s not surprising to see news of new vulnerabilities and attack vectors popping up as researchers hint at their upcoming presentations. If you are interesting in this threat news, but have no time to track it down yourself, this […]
Read More - BadUSB – WSWiR Episode 115
Firefox 31, Tails 0day, and iOS Backdoor Are you curious about the latest network breaches, dangerous new zero day exploits, or breaking security research, but too busy to find all this information on your own? No worries. We summarize the most important security news for you in our weekly security video every Friday. In this week’s […]
Read More - iOS Backdoor – WSWiR Episode 114
Oracle Patches, Project Zero, and Password Problems Another week, another big batch of InfoSec news. If your IT job is already overwhelming you with tasks, leaving you no time to keep up with computer and network security, “I’ve got ya bro.” Check out our weekly security news summary for all the important action. Today’s episode covers […]
Read More - Weak Passwords are Good? – WSWiR Episode 113
Tons of Patches, Facebook Botnets, and Infected Hand Scanners After a couple weeks of hiatus, we’re finally back with our weekly security news summary video. If you want to learn about all the week’s important security news from one convenience resource, this is the place to get it. This episode covers the latest popular software security […]
Read More - Hardware Malware – WSWiR Episode 112
Among this week’s Microsoft security bulletins is one that likely only affects a small subset of Microsoft customers, and thus not worth a full security alert. Microsoft Service Bus is a messaging component that ships with server versions of Windows, providing enterprise developers with the means to create message-driven applications. According to Microsoft’s bulletin, Service […]
Read More - Microsoft Service Bus DoS Mostly Affects Enterprise Web Developers.
Patch Day, P.F. Changs Hack, and TweetDeck XSS This week delivered a lot of infosec news and a ton of software security updates. If you didn’t have time to follow it all, check out our weekly computer security video to fill in the blanks. During today’s episode, I cover the critical patches from Microsoft, Adobe and Mozilla, mention […]
Read More - TweetDeck XSS – WSWiR Episode 111
NSA Facial Recognition, OpenSSL Patch, and Zeus Takedown It’s that time again. If you have a hankering for the latest InfoSec news, this is the place to get it. You can watch me summarize all of the week’s biggest security stories in one short video. Today I talk about the NSA scanning the Internet for […]
Read More - GOZeus Down – WSWiR Episode 110
Iranian Social Hackers, XP Patch Hack, and iPhone Ransom Notes Did you have time to follow security mailings lists, check out infosec news sites, or find that latest patches this week? If not, don’t worry. This weekly video blog will cover the top three computer security news items each Friday for you. Subscribe to this blog […]
Read More - iPhone Ransom Message – WSWiR Episode 109
Ebay Data Breach, IE8 0Day, and Alleged Chinese Hackers With all the information security (InfoSec) news coming out each week, it’s hard to believe anyone can keep up with it; let alone an already busy IT professional with other things on his plate. If that sounds like you, rather than worrying about finding the most important […]
Read More - Ebay Pwned – WSWiR Episode 108
Tons of Patches, NSA Booby-Trapped Routers, and Alleged Iranian Hackers If you don’t have time to follow all the information security stories popping up each week, you can let our weekly video and blog post summarize the important stuff for you. In today’s show, I recite the big list of security patches you need to get […]
Read More - TAO Hijack Routers – WSWiR Episode 107