-
Mar 31, 2020
Recently in Norway a school had to stop using the Whereby video conference service because during a video lesson a man broke into the group video conference and showed himself naked.… read more »
-
Mar 30, 2020
So, let's start with the new "Weekly Cybersecurity Roundup"!… read more »
-
Mar 27, 2020
Amethyst, by Matt Sarnoff, it's a great project for a classic home computer… read more »
-
Mar 26, 2020
A recently discovered campaign that targets home and small-office routers is redirecting users to fake COVID-19 informational sites that attempt to install password stealing malware… read more »
-
Mar 25, 2020
Windows Service Accounts are the elephant in the room in the corporate environment: things that nobody ever talks about or considers to be a problem. Often, these service accounts are in the Domain Admins group, with passwords like "Service123", "Password123",… read more »
-
Mar 24, 2020
Microsoft has released a security advisory about a remote code execution vulnerabilities affecting all currently supported versions of Windows and Windows Server operating systems. … read more »
-
Mar 20, 2020
Mimikatz is famous post-exploitation tool written in C by Benjamin Delpy: it allows a local attacker to dump secrets from memory exploiting Windows single sign-on functionality. … read more »
-
Mar 19, 2020
Valerio Mulas published an interesting analysis about the security of Android-based Smart TVs. The analysis points out the default configuration of most Android-based TVs, which allows you to enable the ADB, install unsigned applications and theoretically gain full control of… read more »
-
Mar 18, 2020
Professor Douglas Leith from Trinity College in Ireland, tested six web browsers to determine what data they were sharing.… read more »
-
Mar 17, 2020
Some years ago, a team of researchers realized a security analysis of Signal protocol, still relevant and useful… read more »
-
Mar 13, 2020
Since Windows 8, Microsoft has moved to a new commercial strategy: in addition with traditional selling of OS licenses, started got revenues from searches, apps and games. But to do this, MS has started the collection of “telemetry” data, considered… read more »
-
Mar 11, 2020
Security firms inadvertently leaked info about a 0-Day 'wormable' vulnerability found in the SMBv3 protocol.
How to detect and moderate it?… read more »
-
Mar 11, 2020
Many processors made by Intel are vulnerable to a new type of attack named Load Value Injection.… read more »
-
Mar 10, 2020
Do you need a secure and private messenger? You shouldn't be use Telegram!… read more »
-
Mar 6, 2020
Cold boot attack is a type of side channel attack in which an attacker with physical access to a computer performs a memory dump of a computer's random access memory by performing a hard reset of the target machine.… read more »
-
Mar 5, 2020
A research team has recently discovered a new attack method that enables remote users to interact with voice-controlled device using ultrasonic waves transmitted through the surface on which is placed the target device… read more »
-
Mar 4, 2020
During an incident response, a fast analysis could be required, often on systems that aren't the workstation usually used by the analyst. So, I always suggest to create a small and simple toolkit that can be copied on a USB… read more »
-
Mar 3, 2020
A brief update regarding the Ghostcat vulnerability that affects Apache Tomcat servers.… read more »
-
Feb 28, 2020
A research tried to quantify how often false activations happen and what the devices hear when they do… read more »
-
Feb 26, 2020
The researchers who disclosed the #aLTEr attack last year (David Rupprecht, Thorsten Holz, and Christina Pöpper), have found new ways to exploit the lack of integrity protection on the 4G/5G user plane in a new attack called #Imp4Gt
… read more »