Showing posts with label vulnerability. Show all posts
Showing posts with label vulnerability. Show all posts

Tuesday, June 27, 2023

In OWASP We Trust mug

Product Page

If you're in software development, raise some awareness around the office of the OWASP Top 10 vulnerabilities. They're still being found in software even after all this time, which means not enough effort is being made to avoid them.

Tuesday, June 20, 2023

Moving your data into their hands

from here and here (image source)

The MOVEit vulnerability has been exploited far and wide, but this latest one involving the DMV seems particularly far reaching.

Friday, May 12, 2023

What are the chances hackers will take the year off?

from here and here

There's a security vulnerability in the secure boot feature of modern computers. While the patch for this 0-day was already released, it won't be enabled by default until Q1 2024. That's a long time to wait for a fix. In theory you can probably enable this fix sooner than that, but most people aren't even going to be aware of it, so most of the vulnerable computer population will remain vulnerable for basically a year, giving attackers ample opportunity to take advantage of it.

Never tempt fate or hackers

found on Izismile

You might think that the only way they could get into your WiFi is by guessing your super powerful secret password, but not only is your password probably not as strong as you think it is, it's also probably not the only way in. WiFi routers have vulnerabilities just like other computerized systems.

Monday, April 17, 2023

Always check for a bounty program beforehand

from here and here

I'm not saying there's anything wrong with wanting something in return for your efforts, but be honest about your motivations and be more curious about how that process works. Don't just assume everyone hands out bug bounties, because they don't, and if the company in question doesn't then it's best to not even mention it.

Frankly, when you approach a company with a report that mentions a deadline to act and payment they never agreed to, quite a few are going to interpret it as some sort of shakedown or blackmail. One of the best indicators that a company won't do that is if they do in fact have a documented bug bounty program.

Wednesday, April 5, 2023

Sometimes it's smarter to be dumb

from here and here

When the advice to deal with a vulnerable Internet of Things device is to unplug it (effectively returning you to the dumb way of doing things), that's when you know "smart" isn't worth it.

Thursday, March 16, 2023

What an unfortunate product name

from here and here

I can't resist a pun, and I suppose some attackers can't either, so keep that in mind when you're naming your products. And if you happen to be a GoAnywhere user, patch it, or your org might be the next place the attackers wind up.

Wednesday, March 15, 2023

A digital snow day

from here and here

I imagine if you can still get Internet on your phone, a digital snow day while you wait for 83 patches to be applied to your PC might actually be a good thing. No work and all play. It's almost enough to make me wish I had a phone.

Thursday, February 23, 2023

Thieves exploiting major vulnerability to steal Dodge Ram trucks


Watch on YouTube

This news report makes an excellent point. Vehicles are now computers on wheels, and need the same kind of effort to protect that more traditional computers do. Something to keep in mind when you're choosing your next vehicle.

Wednesday, February 15, 2023

How about some defense of the computers

from here and here

Withholding security patches for over a year is not a good look on anyone, regardless of how well loved your products are. 

Thursday, February 2, 2023

I just had a QNAP

from here and here

It's hard to believe, but the year is 2023 and people are still creating products with SQL injection vulnerabilities. I can only guess that the Q in QNAP doesn't stand for quality. It might stand for quick, because that's how fast you can get pwned with a vulnerability like that.

Tuesday, January 10, 2023

Suddenly beaters don't look quite so bad

from here and here

It's honestly kind of shocking how many cars are vulnerable to hackers and how much they can do to them. Makes me glad I use public transit.

Tuesday, December 20, 2022

Maybe later

from here and here

I think the people who make updates need to put more thought into the user experience of applying updates. Otherwise the updates are just going to get delayed over and over again.

Friday, December 9, 2022

Microsoft's IE, they put that shit in everything

from here and here

Thanks to Microsoft's misguided efforts to make their inferior browser an integral part of the Windows platform, the IE rendering engine was stuck into all sorts of things - and now, even though the browser has long since been deprecated, governmental hackers are still using IE exploits to break into systems because IE is embedded into MS Office products. Thanks for nothing, Microsoft.

Tuesday, December 6, 2022

We could use happy endings like that more often

from here and here

Gotta love malware that doesn't validate its own inputs. Especially when it goes out of it's way to be non-persistent, so that when it crashes it's effectively gone and the previously infected machines are now clean until someone comes along to reinfect them.

Monday, December 5, 2022

The gift that keeps on taking

from here and here

Log4j is still out there after an entire year. It's hardly the first time a vulnerability has been left unpatched within the online world, but an easy to exploit vulnerability with the highest severity possible still being unpatched after a year? That's not a good precedent to set.

Tuesday, November 29, 2022

Isn't it ironic

from here and here

There is certainly a delicious irony in Google getting called out by none other than Google for taking to long to patch their shit. Seemingly the patch has been available for more than the 90 days that Google's Project Zero usually gives vendors. They didn't even need to develop the patch themselves, just apply it to their product, but apparently it's gotten held up in testing. 

Kinda makes you wonder, if Google can't even adhere to their own 90 day policy, why is it reasonable to expect it from others?

Wednesday, November 23, 2022

Live by the hack, die by the hack

from here and here

Even though the security company that discovered the malware vulnerability aren't publishing it, I have high hopes that people less scrupulous than them will use it to take the criminals down. That's not to say that I don't want the criminals in question to face justice, but rather I have my doubts whether most of them will, and in the absence of legal consequences, the increased cost due to business disruptions could conceivably make the operation less financially viable. Also, if the hack forces them to re-infect people or to infect even more people then that probably will increase their exposure with regards to law enforcement and might be the thing that gets them caught.

Friday, October 7, 2022

The biggest target takes the most hits

from here and here

Apparently Chrome has more than twice as many vulns this year as the next leading browser. I know more vulnerabilities doesn't necessarily mean Chrome is less secure than it's competitors. It has the most market share so it gets the most attention from people trying to find vulnerabilities. However, while that doesn't make it less secure, it does make it less safe. More attention from attackers (successful attention at that it appears) means that users of the software face more attacks than users of the alternative browser - and that has been the rationale behind using alternative software for a long time. If you're using something that has a smaller target on it's back, you're less likely to fall victim.

Thursday, September 29, 2022

The cipher can't be trusted right now

from here and here

It seems that life is imitating art a weird sort of way. Matrix, an ecosystem of open source chat and collaboration clients, has vulnerabilities that subvert the protection of it's end to end encryption, but unlike the movie there's a fix that allows you to trust the cipher again if you hurry up and apply the patch.