![]() |
| from here and here |
Maybe you thought Internet Explorer would be ancient history by now, but unfortunately Microsoft is still making security updates for it.
![]() |
| from here and here |
Maybe you thought Internet Explorer would be ancient history by now, but unfortunately Microsoft is still making security updates for it.
![]() |
| from here and here |
It's hard to believe, but the year is 2023 and people are still creating products with SQL injection vulnerabilities. I can only guess that the Q in QNAP doesn't stand for quality. It might stand for quick, because that's how fast you can get pwned with a vulnerability like that.
![]() |
| from here and here |
Thanks to Microsoft's misguided efforts to make their inferior browser an integral part of the Windows platform, the IE rendering engine was stuck into all sorts of things - and now, even though the browser has long since been deprecated, governmental hackers are still using IE exploits to break into systems because IE is embedded into MS Office products. Thanks for nothing, Microsoft.
| from here |
It seems that when it comes to privacy and security, the government's position seems to be that, instead of it being a right, we have to EARN IT. Of course we never actually will earn it in their eyes, so there's little reason for us to go along with them on this.
| from here |
This is your irregular reminder to check your network to see if there are any servers on it that don't need to be there anymore. One less server is one less thing to patch and one less thing that could be exploited in the absence of a patch (and if it's been running for 21 years you've got to think it's missing a few patches)..
![]() |
| from here |
I can't believe it's 2021 and we still have to worry about Internet Explorer and ActiveX controls. That technology is over 20 years old.
![]() |
| from here |
I kid you not, I was holding up photos in front of face recognition cameras 20 years ago, and I'm pretty sure I wasn't the first person to think of it. This recent finding may have a novel way of presenting the captured image to the system, but it's still just feeding a captured image to the system. Since the only real tricky bit was the fact that the system required an infrared image, I suspect a photo printed with infrared ink might have done the trick without needing to rely on any camera funny-business.
20 years and face rec is still being bypassed in fundamentally the same way. Is it any wonder I have no faith in biometrics?
![]() |
| from here |
Telling users to disable their antivirus was a shady thing software vendors advised their customers decades ago, before the malware problem exploded. It's mind boggling to learn that some are still doing it, and worse they're makers of remote administration software that is used by managed service providers who remotely administer the systems of hundreds of organizations - with a fairly predictable outcome.
There are better ways of dealing with false alarms on the software you make than getting your customers to disable their security or worse getting them to disable their own customers security.
![]() |
| from here |
If we were talking about days it would be days that end in Y, but because we're talking about years it's years that start with 2.
Yes, Facebook had yet another breach. You should probably head over to Have I Been Pwned to see if you're affected by this (or any other) breach
![]() |
| from here |
You'd think with all the extra free time people had this year they'd have finally worked out how to use a password manager to keep track of their passwords so they wouldn't need to use ridiculous ones like "123456" and "password" anymore.
![]() |
| from here |
![]() |
| from here |
![]() |
| from here |
![]() |
| from here |
![]() |
| from here |
![]() |
| from here |
![]() |
| from here and here |