from Reuters: Technology News http://ift.tt/2xDTlSm
Brazil watchdog urges quick solution to Oi's license issue
from Reuters: Technology News http://ift.tt/2xDTlSm
'La La Land''s Chazelle partners with Netflix for Paris TV musical
from Reuters: Technology News http://ift.tt/2epZDws
Thyssenkrupp steps up 3D printing operations
from Reuters: Technology News http://ift.tt/2iOeCoZ
Microsoft pushes 'mixed reality' features with Windows 10 update
from Reuters: Technology News http://ift.tt/2gvNwlv
TippingPoint Threat Intelligence and Zero-Day Coverage – Week of August 28, 2017
The only topic I can bring up this week is the devastation in Texas caused by Hurricane Harvey. Many cities have been completely destroyed and to add insult to injury, Harvey moved back to the Gulf of Mexico and made landfall again in Louisiana. Catastrophic flooding has left tens of thousands without their homes and most major highways impassable. I have several family members that are dealing with the after effects of this storm along the Texas coast. It’s the worst feeling in the world when you want to help, but all you can do is watch from the sidelines. There’s nothing worse than texting your immediate family at 3am to make sure they’re alive and not flooded out of their house.
I’ve lived in Austin, Texas for almost 18 years, but Houston is my home. I was born there, attended college there, and have several family members and even more friends in the area. Harvey may have destroyed homes but it can’t destroy the spirit of Houston. All I can ask for at this point is to find it in your heart to make a small donation to the charity of your choice to help those who will have a long road ahead of them to rebuild their lives after this catastrophe. Or do something to help first responders who are rescuing others while they deal with the effects of Harvey at home. This native Houstonian thanks you for your generosity.
Mobile Pwn2Own
Earlier this week, the Zero Day Initiative (ZDI) announced the sixth annual Mobile Pwn2Own competition, which returns to the PacSec conference in Tokyo on November 1-2, 2017. There is more than $500,000 USD available in the prize pool, and we’re giving add-on bonuses for exploits that meet a higher bar of difficulty. This year’s contest will target the Apple iPhone 7, the Google Pixel, the Samsung Galaxy S8, and the Huawei Mate9 Pro handsets. One category has researchers targeting the web browsers on the phones. The second category involves attacks happening over Bluetooth, NFC or WiFi. The third category will have attacks demonstrated by viewing or receiving MMS or SMS messages. The final category will cover attacks where the target device communicates with a rogue base station. Full details about the event can be here on the ZDI blog. Follow ZDI on Twitter for the latest news and information.
Trend Micro Business Support Portal (BSP)
Trend Micro TippingPoint has completed the migration over to the Trend Micro Business Support Portal (BSP). The Trend Micro BSP enhances case management and collaboration by guiding customers to product specific solutions, self-help and technical assistance. Customers can access the BSP from the Threat Management Center (TMC) website by looking under Support→Business Support Portal (BSP) or directly by accessing this URL: http://ift.tt/2wY0akz.
Any Trend Micro TippingPoint customer contact who has created a case in the past two years will be automatically enabled for the new support portal (BSP). You can expect to receive an email from Trend Micro Technical Support within the next 72 hours with the relevant information. If you are unable to locate this email, please check your spam folders. The email will have the subject line of “Welcome to Trend Micro Business Support!” Please note that if you did not receive the email within 72 hours, you can register for the portal directly. You will need to have a current Trend Micro TippingPoint device certificate number (CERT) to complete your registration process. If you need assistance finding your CERT number, you can contact Trend Micro TippingPoint Technical Assistance Center (TAC) for additional information. Customers in Japan will migrate to the BSP in late November.
Zero-Day Filters
There are four new zero-day filters covering three vendors in this week’s Digital Vaccine (DV) package. A number of existing filters in this week’s DV package were modified to update the filter description, update specific filter deployment recommendation, increase filter accuracy and/or optimize performance. You can browse the list of published advisories and upcoming advisories on the Zero Day Initiative website.
Adobe (1)
|
|
Dell (1)
|
|
Trend Micro (2)
|
|
Missed Last Week’s News?
Catch up on last week’s news in my weekly recap.
from Trend Micro Simply Security http://ift.tt/2wXdCoR
This Week in Security News
Welcome to our weekly roundup, where we share what you need to know about the cybersecurity news and events that happened over the past few days.
Below you’ll find a quick recap of topics followed by links to news articles and/or our blog posts providing additional insight. Be sure to check back each Friday for highlights of the goings-on each week!
Petya Expands its Scope as a Global Ransomware Threat
Petya first garnered more recent attention in June 2017 when security researchers and investigators discovered that it was responsible for several large-scale attacks in Ukraine. According to Microsoft, before the end of June, Petya had spread to 65 countries total, impacting more than 12,500 machines.
IRS Issued Urgent Warning about Ransomware Email Scam
The Internal Revenue Service (IRS) has issued an urgent warning about a new scheme targeting taxpayers. The scam email uses the emblems of both the IRS and the FBI, and urges recipients to click on a link to download a questionnaire allegedly from the FBI.
Recent Phishing Attacks Capitalize on Office 365 Security Holes
There are two ways phishers are evading MicrosoftOffice 365 Security protections: one using “hexidecimal escape characters” to conceal coding and links, and the other by compromising SharePoint files. Researchers suspect that this phishing campaign may be the work of Chinese cybercriminals.
FDA Issued Recall of 465,000 St. Jude Pacemakers to Patch Security Holes
In particular, Abbott’s pacemakers, formerly of St. Jude Medical, have been “recalled” by the US Food and Drug Administration (FDA) on a voluntary basis. An estimated 465,000 pacemakers must be given a firmware update to protect them against a set of critical vulnerabilities.
Hackers Have Improved Their BEC Attack Methods
Business email compromise (BEC) attacks increased by 45 percent in the last three months of 2016. As email is increasingly used for notifications and interpersonal connections in company and consumer settings, it will be essential to evaluate its security capabilities and protect it appropriately.
CeX Hack Puts as Many as 2 Million Accounts at Risk
Second-hand gaming retailer, CeX, confirmed an “online security breach” may have put as many as two million customer accounts at risk. In an email to customers, the company said that personal information – including first names, surnames, addresses, email addresses and phone numbers – was stolen.
Bitpaymer Ransomware Attack Highlights Need for Better IT Security in Hospitals
The UK hospital group, NHS Lanarkshire, was forced to cancel several patient appointments after a new variant of Bitpaymer ransomware was detected in its IT systems last Friday. The hackers demanded the hospital pay 50 Bitcoins, or about $218,000.
New Cybersecurity Regulations Now in Force in New York
Earlier this year, the State of New York introduced a new set of regulations requiring banks, insurance companies and other financial services to establish and maintain cyber security programs that meet specific standards. The first of four transition periods ended on Monday.
Trend Micro Announces Support for VMware Cloud on AWS
Trend Micro’s Deep Security server security product is now available to customers of VMware Cloud on AWS. This means customers can take advantage of agile cloud infrastructure, while maintaining their familiar VMware tools, skill sets and architecture framework investments.
4 Principles to Follow for Hybrid Cloud Success
The future is cloud. At this point in its evolution it’s undeniable. Success in the hybrid cloud starts with these four principles; (1) one process regardless of environment, (2) tools must scale automatically, (3) tools must be programmable, and (4) tools must take smart decisions on your behalf.
It’s Back to School Time, Keep Your Children Safe Online
The truth is that today, there aren’t many kids on the school campus that don’t have a laptop or mobile device. Just as we’d teach them how to cross the road safely and why they shouldn’t talk to strangers, so we must do the same for their digital lives.
Please add your thoughts in the comments below or follow me on Twitter; @JonLClay.
from Trend Micro Simply Security http://ift.tt/2wXBUPA
Expedia names Alan Pickerill CFO
from Reuters: Technology News http://ift.tt/2vQ6C7S
Microsoft pushes AR/VR features with October Windows 10 update
from Reuters: Technology News http://ift.tt/2epgpM7
Norway tightens IT security to prevent ballot tampering
from Reuters: Technology News http://ift.tt/2govXQL
Just smile: In KFC China store, diners have new way to pay
from Reuters: Technology News http://ift.tt/2eoUtR3
Norway tightens IT security, vote count procedures in run-up to election
from Reuters: Technology News http://ift.tt/2iN8s8p
Western Digital CEO apologized to Toshiba for friction over chip unit sale
from Reuters: Technology News http://ift.tt/2vwoQAm
Western Digital CEO apologizes to Toshiba for friction over chip unit sale
from Reuters: Technology News http://ift.tt/2vOydqj
FDA Recalls Nearly Half a Million Pacemakers Over Hacking Fears
from The Hacker News http://ift.tt/2enURze
Hewlett Packard Enterprise to complete software spin-off
from Reuters: Technology News http://ift.tt/2iLG1aS
Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading
Cybersecurity researchers have uncovered a new phishing campaign that exploits social media private messages to propagate malicious payloads...
-
Original release date: November 08, 2018 Summary JBoss Verify and EXploitation tool (JexBoss) is an open-source tool used by cybersecurity...
-
Original release date: May 21, 2018 The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded b...
-
Original release date: January 29, 2018 The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been record...
-
It's no secret that learning how to code is one of the most important things you can do when it comes to the beginning or furthering pra...
-
Original release date: February 12, 2018 The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recor...
-
Original release date: October 26, 2020 The CISA Weekly Vulnerability Summary Bulletin is created using information from the NIST NVD . In...
-
Original release date: February 26, 2018 The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recor...
-
Os estragos causados pelo ataque com ransomware ao Superior Tribunal de Justiça (STJ) ainda não são totalmente conhecidos. A Polícia Federa...
-
Original release date: March 9, 2020 The CISA Weekly Vulnerability Summary Bulletin is created using information from the NIST NVD . In som...
-
Original release date: January 08, 2018 The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been record...