#ZDNet | security RSS
Explore tagged Tumblr posts
goodbytegroupglobal · 1 year ago
Tumblr media
Apple issues emergency security updates for iPhone, iPad, and Apple Watch - ZDNet https://news.google.com/rss/articles/CBMiZmh0dHBzOi8vd3d3LnpkbmV0LmNvbS9hcnRpY2xlL2FwcGxlLWlzc3Vlcy1lbWVyZ2VuY3ktc2VjdXJpdHktdXBkYXRlcy1mb3ItaXBob25lLWlwYWQtYW5kLWFwcGxlLXdhdGNoL9IBcWh0dHBzOi8vd3d3LnpkbmV0LmNvbS9nb29nbGUtYW1wL2FydGljbGUvYXBwbGUtaXNzdWVzLWVtZXJnZW5jeS1zZWN1cml0eS11cGRhdGVzLWZvci1pcGhvbmUtaXBhZC1hbmQtYXBwbGUtd2F0Y2gv?oc=5&utm_source=dlvr.it&utm_medium=tumblr
0 notes
sneaksite · 4 years ago
Google researcher discovers new iOS security system  ZDNet
Apple Urges iPhone and iPad Users to Update Devices amid ‘Remote Attacker’ Security Threat  PEOPLE
iOS 14 Features New 'BlastDoor' Messages Security System  MacRumors
Apple is still in the 'early innings' amid strong 5G iPhone sales  MarketWatch
What the Tech? Apple releases iOS14 update to tighten security against potential hacking  WRCB Chattanooga
View Full Coverage on Google News
from Top stories - Google News https://news.google.com/__i/rss/rd/articles/CBMiUmh0dHBzOi8vd3d3LnpkbmV0LmNvbS9hcnRpY2xlL2dvb2dsZS1yZXNlYXJjaGVyLWRpc2NvdmVycy1uZXctaW9zLXNlY3VyaXR5LXN5c3RlbS_SAV1odHRwczovL3d3dy56ZG5ldC5jb20vZ29vZ2xlLWFtcC9hcnRpY2xlL2dvb2dsZS1yZXNlYXJjaGVyLWRpc2NvdmVycy1uZXctaW9zLXNlY3VyaXR5LXN5c3RlbS8?oc=5
0 notes
giaitritonghop123 · 4 years ago
Công ty bảo mật nổi tiếng bị tin tặc tấn công
Tumblr media
Nhóm tin tặc nhắm mục tiêu vào các công cụ thử nghiệm an ninh nội bộ của FireEye nhằm tiến hành thâm nhập các công ty khác.
Ngày 8/12, Kevin Mandia, CEO của FireEye, cho biết ngoài việc đánh cắp công cụ Red Team nội bộ của hãng, nhóm hacker đã tìm kiếm thông tin liên quan đến một số khách hàng chính phủ của công ty.
Mandia mô tả nhóm thực hiện vụ tấn công là "một tổ chức rất tinh vi, có kỷ luật và bảo mật hoạt động cao. Kỹ thuật tấn công này khiến chúng tôi tin rằng đây là một cuộc tấn công mạng do một nhà nước bảo trợ".
Tumblr media
FireEye cung cấp dịch vụ bảo mật cho nhiều khách hàng khác nhau trong lĩnh vực an ninh ở Mỹ và nước ngoài. Ảnh: Reuters.
"Dựa trên 25 năm kinh nghiệm trong lĩnh vực an ninh mạng và ứng phó sự cố, tôi có thể đưa ra kết luận rằng FireEye đang hứng chịu một cuộc tấn công gây ra bởi một quốc gia có năng lực tấn công hàng đầu thế giới hiện nay. Cuộc tấn công này khác với hàng chục nghìn vụ việc mà chúng tôi từng ứng phó nhiều năm qua", Mandia nói.
"Những kẻ tấn công dường như đã tạo ra một kỹ thuật hoàn toàn mới và hoàn hảo nhắm trực tiếp vào các điểm yếu FireEye. Tổ chức hacker này chắc chắn được đào tạo chuyên sâu về hoạt động bảo mật và chuyên nghiệp trong tác phong kỷ luật. Chúng hoạt động một cách bí mật, sử dụng thành thục các công cụ chống bị phát hiện và xóa dấu vết. Nhiều tổ hợp kỹ thuật mới tới mức chúng tôi và các đối tác chưa từng thấy chúng trước kia", CEO của công ty nói thêm.
Microsoft xác nhận có yếu tố nhà nước bảo trợ
Đại diện của FireEye cho biết đánh giá ban đầu của hãng đã được Microsoft xác nhận và đang tìm kiếm sự giúp đỡ điều tra từ phía Cục Điều tra Liên bang Mỹ (FBI).
FireEye tin những kẻ tấn công đã lấy được các công cụ kiểm tra thâm nhập nội bộ của hãng. Công ty đang chia sẻ một số manh mối dữ liệu (hay dấu vết IOC) cũng như các biện pháp đối phó trên tài khoản GitHub của hãng. Dữ liệu từ GitHub sẽ giúp các công ty khác phát hiện xem tin tặc có sử dụng công cụ bị đánh cắp từ FireEye để xâm phạm mạng của họ hay không.
FireEye không phải là công ty bảo mật lớn đầu tiên bị tấn công bởi các hacker do một nhà nước đứng đầu. Trước đó, Kaspersky công bố sự cố tương tự vào năm 2015. RSA Security cũng từng bị tấn công năm 2011 bởi một tổ chức được cho có liên hệ với Trung Quốc. Avast bị tấn công hai lần vào năm 2017 và 2019.
Trên Twitter, hầu hết các chuyên gia an ninh mạng đều thể hiện sự ủng hộ đối với FireEye và khen ngợi công ty vì đã công bố sự việc cùng các biện pháp khắc phục nhanh chóng.
"Tôi hoan nghênh FireEye đã kịp thời công khai tin tức này và tôi hy vọng quyết định tiết lộ vụ xâm nhập này của công ty sẽ giúp thúc đẩy những người khác đang đối mặt với các vụ xâm nhập tương tự", thượng nghị sĩ Mỹ Mark R. Warner, phó Chủ tịch Ủy ban Đặc biệt về Tình báo Thượng viện chia sẻ.
"Chúng tôi đã yêu cầu các công ty thực hiện các bước phòng tránh nghiêm túc để bảo mật hệ thống của họ, nhưng trường hợp này cũng cho thấy khó khăn trong việc ngăn chặn các tổ chức hacker quốc gia", ông Warner cho biết.
Đăng Thiên (theo Zdnet)
from Tin mới nhất - VnExpress RSS https://ift.tt/3gv8gVJ via IFTTT
0 notes
cyberparse · 8 years ago
Unbreakable Locky ransomware is on the march again
http://cyberparse.co.uk/2017/01/20/unbreakable-locky-ransomware-is-on-the-march-again/ https://i0.wp.com/cyberparse.co.uk/wp-content/uploads/2016/04/security-binary-pd-898757.jpg?fit=3888%2C2592
Necrus botnet wakes up and starts fresh malware-cano Cisco is warning of possible return of a massive ransomware spam campaign after researchers noticed traces of traffic from the hitherto dormant Necrus botnet. The attacks are tiny: Cisco’s security team has so far found fewer than a thousand Necrus spam messages.
Those numbers pale in comparison to attacks when Necrus’ payload, Locky, first surfaced in early 2016, infecting hospitals across the US and Japan, and outpacing the Dridex banking trojan for email-borne malware. But researchers warn it’s entirely possible there’s worse to come, because the infamous Necrus botnet once controlled nearly half a million machines devoted to pumping out spam. Many of the messages the network sent distributed the still-unbreakable Locky ransomware. Researchers say attacks both from Necrus and delivering Locky have quietly increased over the last week. “Since late December we haven’t seen the typical volume of Locky, however, a couple of days ago we finally started seeing some spam campaigns start delivering Locky again,” Cisco’s researchers say. “The key difference here is around volume. We typically would see hundreds of thousands of Locky spam, [and now] we are currently seeing campaigns with less than a thousand messages. “With both of these campaigns being relatively low volume these could be one offs or indicators of changes to come to the campaigns in the future.” One of the attacks delivers Locky through a twice-zipped attachment in emails with no subject or body text. Those who execute the malware will also receive the Kovter advertising click fraud trojan. Malware writers seemed to remember to type something in their emails a day later as they sent fake transaction failure messages bearing a doc_details javascript file wrapped into a rar file. “Crimeware is a lucrative endeavor with revenue rapidly approaching a billion dollars annually,” Cisco’s boffins say. “This doesn’t come without significant risk and we may be entering a period where adversaries are increasingly cashing out from this activity early, to avoid severe penalties.” ® Sponsored: Next gen cybersecurity.Visit The Register’s security hub
Source ZDNet | securify-this RSS
1 note · View note
jones240 · 5 years ago
Setting up a locked room at home for confidential work projects
There’s a clause in many business agreements and non-disclosures called “the locked room” clause. It mandates providing a secure space for confidential materials. With many now working from home, we take a look at how to comply with the locked room requirement at home.
from ZDNet | diy-it RSS https://ift.tt/34Pz1QI via Rosanne Rams ZdNet Blog post
from WordPress https://ift.tt/3jwdiBo
0 notes
shah2323-madtitan · 5 years ago
Microsoft fixes issue blocking some Surface devices from the May 2020 feature update - ZDNet
Microsoft fixes issue blocking some Surface devices from the May 2020 feature update  ZDNet
Windows 10 May 2020 Update is causing big problems for some Lenovo laptops  TechRadar
Windows 10 warning: If you've missed this update, your PC is in serious danger  Express
Eternal Darkness flaw in Windows 10 sounds scary as hell, best to patch it now  PC Gamer
Windows 10 security alert - users warned over 'wormable' bug  TechRadar
View Full coverage on Google News
source https://news.google.com/__i/rss/rd/articles/CBMic2h0dHBzOi8vd3d3LnpkbmV0LmNvbS9hcnRpY2xlL21pY3Jvc29mdC1maXhlcy1pc3N1ZS1ibG9ja2luZy1zb21lLXN1cmZhY2UtZGV2aWNlcy1mcm9tLXRoZS1tYXktMjAyMC1mZWF0dXJlLXVwZGF0ZS_SAX5odHRwczovL3d3dy56ZG5ldC5jb20vZ29vZ2xlLWFtcC9hcnRpY2xlL21pY3Jvc29mdC1maXhlcy1pc3N1ZS1ibG9ja2luZy1zb21lLXN1cmZhY2UtZGV2aWNlcy1mcm9tLXRoZS1tYXktMjAyMC1mZWF0dXJlLXVwZGF0ZS8?oc=5 Microsoft fixes issue blocking some Surface devices from the May 2020 feature update - ZDNet Technology via exercisesfatburnig.blogspot.com https://ift.tt/2XQ256O
0 notes
skyanfeeds · 4 years ago
Windows 11 is getting an LTSC version, but not yet  XDA Developers
Microsoft is already messing up Windows 11, and I'm worried  TechRadar
Windows “HiveNightmare” bug could leak passwords – here’s what to do!  Naked Security
Microsoft just published a workaround for this important Windows 10 flaw  ZDNet
Windows 10 bug that’s dropping frame rates hasn’t been fixed after all  Techradar
View Full Coverage on Google News
0 notes
delhi-architect2 · 5 years ago
Journal - How the Architecture and Design Community Is Helping Combat COVID-19
Architects: Showcase your next project through Architizer and sign up for our inspirational newsletter.
The COVID-19 pandemic has completely encircled the world, impacting nearly everyone. On the front lines of this crisis has been the medical industry, which is facing immense strain as cases rise around the globe. With governmental responses being highly varied, support for those working hands-on against the coronavirus has been heavily reliant on the grass roots efforts of local communities and private companies.
In particular, many individuals and firms within the creative industries are using their innovative and entrepreneurial qualities to support the fight against COVID-19. To raise awareness of these efforts, we’ve  assembled some of the news stories, fundraisers and volunteer opportunities that relate to the architecture  and design communities during this turbulent time. Check out the round up below, and click on the relevant links for further information.
Architectural and Design Solutions
Jupe’s portable hospital set up; image via Tech Crunch
A humanitarian startup has developed rapidly deployable, pop-up recovery units 
Jupe Health, a humanitarian startup, has developed a new type of affordable, shippable hospital room that can be quickly distributed to crisis zones amidst the COVID-19 pandemic. They also cost about 1/30th of what it takes to operate a single room in a standard hospital. (via Dwell)
A Chinese 3D-printing company has developed a 3D-printed buckle that makes face masks more comfortable to wear
Chinese 3D-printer manufacturing company, Creality, is creating thousands of buckles that make face masks less uncomfortable to wear for medical workers facing the COVID-19 pandemic. They’ve made the buckle design free to download, so anyone with a suitable 3D printer can fabricate their own to use or donate. (via Dezeen)
Materialise’s hands-free door opener; image via Archinect/Materialise
A Belgian manufacturing company has created a 3D-printed, hands-free door opener
To curb the spread of COVID-19, a Belgian manufacturing company named Materialise has released free design files for a 3D-printed, hands-free door opener that makes you use your wrist instead of your bare hands to touch door handles. (via Archinect News)
CURA seeks to convert shipping containers into COVID-19 treatment centers
An international task force led by architecture studio Carlo Ratti Associati, Humanitas Healthcare and University, and the World Economic Forum, among others, is developing Connected Units for Respiratory Ailments (CURA). It is a non-profit, open source, design and build initiative that is seeking to convert shipping containers to operate as biocontainment pods. Read more here.
Face Shields
image via NYU/Getty Images
NYU makes face shield design for healthcare workers that can be built in under a minute
New York University has developed an open-source face-shield design. It is a low cost, medical face shield that can be made using almost any flat material fabrication equipment, such as laser cutters, rule dies, drag knives, or scissors and an office hole punch, for example. It requires no hardware or 3D printed parts, just two pieces of flexible clear plastic and an elastic band. The design has been made available on their site, and NYU is offering production services as well. (via TechCrunch)
HP Inc. and Partners use 3D printing solutions to combat COVID-19
HP Inc. and partners have mobilized to create 3D printed face masks, face shield solutions, and other personal protection equipment (PPE). They have distributed more than 1000 3D-printed parts to hospitals near their 3D R&D centers in Barcelona, Spain, Corvallis, Oregon, San Diego, California, and Vancouver, Washington. They made their and other company’s 3D PPE models free to download here. (via HP)
Swedish 3D-printing company has developed and shared simple design for a face shield
Erik Cederberg of Swedish 3D-printing company 3DVerkstan has designed a 3D-printed protective visor. The simple design consists of a laser-cut clear plastic shield and a printed visor band. The company has provided links to the print files and a print settings guide. Many architects across America are basing their 3D-printed face shields on 3DVerkstan’s files. (via 3DVerkstan)
Major fashion brands have joined the fight against COVID-19
Multiple fashion brands, including the likes of Prada, COS and Louis Vuitton, have joined the fight against COVID-19 by manufacturing surgical face masks. Many other brands, including Yves Saint Laurent and Balenciaga, have also committed to making surgical masks with luxury conglomerate LVMH promising to donate millions of masks and medical-grade respirators to replenish low supplies. (via Dezeen)
A researcher at the University of Alberta is developing a face mask that can kill the coronavirus
An assistant professor in the Department of Chemical and Materials Engineering at the University of Alberta named Choi Hyo-jick has been developing a surgical mask with an antiviral coating that can kill viruses like the coronavirus. The key ingredient is salt. (via Fortune)
Breathing Aids and Ventilators
Dyson’s new ventilator design attaches to the side of a hospital bed; image courtesy of Dyson
Dyson has developed its own ventilator for COVID-19 patients
British technology company Dyson, commonly known for their innovative vacuum cleaners, has invented a new ventilator to address the growing shortage of these essential devices. Called the CoVent, it was designed in just 10 days by leveraging Dyson’s existing digital motor. (via Architectural Digest)
University of College London and Mercedes Formula One have collaborated to build a breathing aid
University College London engineers worked with clinicians at University College London Hospitals and Mercedes Formula One to build a breathing aid, which can deliver oxygen to the lungs without needing a ventilator. They were created in under a week, and they can help keep COVID-19 patients out of intensive care. (via BBC)
Tesla will manufacture and supply FDA-approved ventilators free of charge
Chief Executive Elon Musk said on Tuesday the company has extra FDA-approved ventilators that can be shipped free of cost to hospitals within regions where the electric carmaker delivers. “Device & shipping cost are free. Only requirement is that the vents are needed immediately for patients, not stored in a warehouse,” Musk said in a tweet. (via Reuters)
MIT has developed a cheap ventilator design 
The Massachusetts Institute of Technology (MIT) has developed a portable ventilator that only costs $100. Named E-Vent or Emergency Ventilator, its design has been released to the open source community. (via ZDNet)
Fundraisers and Volunteer Opportunities
1. COVID-19 Supplies NYC is currently producing face shields for New York City medical workers. The site provides options to those in need of the equipment and those that are seeking to volunteer their efforts to produce the face shields or component parts for them. For volunteers, COVID-19 Supplies NYC has made their design of the face shields available to download. They are also accepting donations via this Go Fund Me.
2. COVID Emergency PPE + Supplies Volunteer Initiative is a platform formed to pool together collective networks and resources to aid in the production of emergency PPE supplies.
3. A Los Angeles fine art printing studio named POV is manufacturing medical protective equipment to assist in the fight against the COVID-19 pandemic. The company is seeking donations to help secure more materials to continue the production of much needed medical supplies.
Architects: Showcase your next project through Architizer and sign up for our inspirational newsletter.
Top image: Connected Units for Respiratory Ailments (CURA); image via Dezeen
The post How the Architecture and Design Community Is Helping Combat COVID-19 appeared first on Journal.
from Journal https://architizer.com/blog/inspiration/industry/architecture-and-design-community-combat-covid-19/ Originally published on ARCHITIZER RSS Feed: https://architizer.com/blog
0 notes
miscsecurity · 5 years ago
0 notes
giaitritonghop123 · 5 years ago
Hàng loạt siêu máy tính bị hack để đào tiền ảo
Tumblr media
Hơn 10 siêu máy tính đang đặt tại một số nước châu Âu bị nhiễm mã độc khai thác tiền ảo. 
Theo Zdnet, các sự cố an ninh xảy ra đã được xác nhận tại Anh, Đức và Thụy Sĩ. Bên cạnh đó, một vụ xâm nhập siêu máy tính tương tự cũng nhằm vào trung tâm điện toán hiệu năng cao ở Tây Ban Nha, nhưng đang trong quá trình điều tra.
Tumblr media
Sức mạnh của siêu máy tính đang được ứng dụng để nghiên cứu nhiều lĩnh vực về khoa học, công nghệ. Ảnh: Cnet.
Đại học Edinburgh (Anh), nơi đặt siêu máy tính Archer, bị tấn công đầu tiên vào hôm 11/5. Hiện cỗ máy này chuyển sang hoạt động ngoại tuyến, đồng thời được đặt lại mật khẩu và cấu hình lại hệ thống đăng nhập để ngăn chặn sự cố tương tự trong tương lai. Archer đang được dùng để chạy mô phỏng sự lây lan của Covid-19.
Đức là nơi có nhiều siêu máy tính bị tấn công nhất với ít nhất 10 trường hợp. BwHPC, tổ chức điều phối các dự án nghiên cứu trên siêu máy tính tại thành phố Baden-Wurmern, cho biết, năm cụm máy tính hiệu năng cao tại Đại học Stuttgart, Viện Công nghệ Karlsruhe (KIT), Đại học Ulm và Đại học Tübingen đã ngừng hoạt động do "sự cố bảo mật" như Archer.
Ngày 14/5, Trung tâm điện toán Leibniz (LRZ), Cơ quan thuộc Viện hàn lâm Khoa học Bavaria, xác nhận đã ngắt kết nối một cụm máy tính khỏi Internet do bị tấn công. Một ngày sau thông báo của LRZ, ba siêu máy tính ở thị trấn Julich buộc phải đặt chế độ ngoại tuyến do "sự cố bảo mật". Đại học Kỹ thuật Dresden cũng tuyên bố đóng cửa siêu máy tính Taurus, trong khi một cụm máy tính hiệu năng cao tại Khoa Vật lý tại Đại học Ludwig-Maximilians ở Munich không thể hoạt động do "bị lây nhiễm phần mềm độc hại".
Báo cáo từ nhà nghiên cứu bảo mật Felix von Leitner hôm 13/5 cũng cho biết, một siêu máy tính được đặt ở Barcelona (Tây Ban Nha) bị ảnh hưởng bởi vấn đề an ninh nhưng đang điều tra trước khi đưa ra kết luận chính thức. Ngoài ra, Trung tâm tính toán khoa học Thụy Sĩ (CSCS) cũng cho ngoại tuyến siêu máy tính sau "sự cố mạng" cho đến khi khôi phục toàn bộ hệ thống.
Chưa có tổ chức hoặc cá nhân nào đứng ra nhận trách nhiệm về các cuộc tấn công.
Theo phân tích của Nhóm ứng phó sự cố an ninh máy tính (CSIRT) cho Cơ sở hạ tầng mạng lưới châu Âu (EGI) - một tổ chức nghiên cứu về siêu máy tính tại châu Âu - và công ty an ninh mạng Cado Security có trụ sở tại Mỹ, kẻ tấn công đã giành được quyền truy cập hệ thống của siêu máy tính thông qua các khóa SSH (Secure Socket Shell) - một giao thức mạng được sử dụng để đăng nhập vào máy tính từ xa. Thông tin đăng nhập dường như đã bị hacker đánh cắp từ những thành viên được cấp quyền truy cập vào siêu máy tính để chạy các phân tích điện toán, chủ yếu ở Canada, Trung Quốc và Ba Lan.
Chris Doman, đồng sáng lập Cado Security, nói rằng, chưa có bằng chứng cho thấy tất cả các cuộc tấn công được thực hiện bởi một nhóm hacker. Tuy nhiên, cách thức tấn công và tệp độc hại được sử dụng gần như tương tự nhau. Chuyên gia này cũng cho biết hacker đã tận dụng lỗ hổng CVE-2019-15666 trong nhân Linux 5.0.19 trở về trước để có quyền truy cập root, sau đó chèn vào ứng dụng khai thác tiền điện tử Monero (XMR). "Nhiều tổ chức đang sử dụng siêu máy tính để nghiên cứu Covid-19. Nhiều công đoạn có thể đã bị cản trở bởi các cuộc tấn công", Doman nói.
Đây không phải là lần đầu tiên siêu máy tính bị lợi dụng để đào tiền ảo. Tháng 2/2018, Nga đã bắt nhóm kỹ sư thuộc Trung tâm hạt nhân quốc gia vì lợi dụng siêu máy tính để đào tiền ảo. Tại Australia, một số nhân viên tại Cục khí tượng nước này cũng làm điều tương tự, nhưng bị bắt sau đó.
Bảo Lâm
from Tin mới nhất - VnExpress RSS https://ift.tt/3cHnW5j via IFTTT
0 notes
jamesmsolari · 6 years ago
Some airlines are banning Apple’s MacBook Pros even if they weren’t recalled
TechMyBiz for all things “IT”
In June, Apple recalled the 2015 MacBook Pro with Retina Display, sold between September 2015 and February 2017, because the battery “may pose a fire safety risk,” and the FAA soon reminded airlines not to carry those laptops with defective batteries on board. But some airlines are now banning Apple laptops whether they’ve got a bad battery or not, as reported by Bloomberg. Virgin Australia isn’t taking any chances: it’s banning every single MacBook from being carried in checked baggage. In a notice on its “Dangerous Goods” page, the company doesn’t differentiate by shape, screen size, or the year it was made: all “Apple MacBooks” can only be brought onto planes in carry-on baggage. That may sound extreme, as the large majority of Apple laptops have not been recalled. The policy does make it sound like you can still use your laptops once on the flight, though. Lots of MacBooks are being banned that weren’t part of the recall But if you’re flying Qantas Airways with a 15-inch MacBook Pro, that last part may not be true. Not only is the carrier banning every single 15-inch MacBook Pro from checked baggage, it won’t let you use them in flight. “Until further notice, all 15-inch Apple MacBook Pros must be carried in cabin baggage and switched off for flight following a recall notice issued by Apple,” a Qantas spokesperson told ZDNet. While it’s understandable that Quantas might not be able to easily tell whether a 2015 15-inch MacBook Pro has one of the recalled batteries or not — that’d require looking up a serial number online — it’d be nice if they exempted the 2016-and-later MacBook Pro with Touch Bar, which has several pretty easily distinguishable visual characteristics and hasn’t had a battery recall that we know of. If you have an affected 15-inch MacBook Pro, Apple says it will replace your battery for free, but you’ll have to send your laptop to an Apple repair center. You can check if your unit is eligible for a replacement here.
Source: http://tz2d.me/?c=t73
Related Posts:
Mario Kart Tour is coming out on September 25th Nintendo’s long-awaited and delayed Mario Kart smartphone game is almost…
10 new trailers you should watch this week Photo: Warner Bros. I was excited to watch Cold War,…
Steve Wozniak says Apple should have broken up years ago Photo by Lachlan Cunningham/Getty Images for Discovery Apple co-founder Steve…
Apple warns you may permanently discolor your Apple… Image: Apple Apple’s new Goldman Sachs-backed credit card launched to…
SimpliSafe’s new $99 smart lock automatically bolts… We’ve called SimpliSafe the best home security system you can…
The post Some airlines are banning Apple’s MacBook Pros even if they weren’t recalled appeared first on TekMyBiz.
Source: https://tekmybiz.com/tech/some-airlines-are-banning-apples-macbook-pros-even-if-they-werent-recalled/?utm_source=rss&utm_medium=rss&utm_campaign=some-airlines-are-banning-apples-macbook-pros-even-if-they-werent-recalled
from TekMyBiz https://tekmybiz.wordpress.com/2019/08/29/some-airlines-are-banning-apples-macbook-pros-even-if-they-werent-recalled/
0 notes
boilthefrogradio · 6 years ago
via Techmeme
0 notes
jones240 · 5 years ago
Abode: Smartly integrated security and home automation
We look at the Abode Smart Security Kit. On the surface, it’s another alarm system. But, under the hood (or inside the app), it’s quite a bit more.
from ZDNet | diy-it RSS https://ift.tt/3gR5jxF via Rosanne Rams ZdNet Blog post
from WordPress https://ift.tt/3gUjBgY
0 notes
shah2323-madtitan · 5 years ago
New phishing attack targeting Microsoft Teams users aims to steal Office 365 credentials - Neowin
New phishing attack targeting Microsoft Teams users aims to steal Office 365 credentials  Neowin
Look out - that Microsoft Teams alert might be a phishing scam  TechRadar
Fake Microsoft Teams notification emails are hitting inboxes  Help Net Security
As Microsoft touts Teams growth, Slack CEO says it's not a competitor  ZDNet
Slack CEO isn't impressed by Microsoft Teams' growth and says the app “is not a competitor”  OnMSFT
View Full coverage on Google News
source https://news.google.com/__i/rss/rd/articles/CBMidWh0dHBzOi8vd3d3Lm5lb3dpbi5uZXQvbmV3cy9uZXctcGhpc2hpbmctYXR0YWNrLXRhcmdldGluZy1taWNyb3NvZnQtdGVhbXMtdXNlcnMtYWltcy10by1zdGVhbC1vZmZpY2UtMzY1LWNyZWRlbnRpYWxzL9IBdGh0dHBzOi8vd3d3Lm5lb3dpbi5uZXQvYW1wL25ldy1waGlzaGluZy1hdHRhY2stdGFyZ2V0aW5nLW1pY3Jvc29mdC10ZWFtcy11c2Vycy1haW1zLXRvLXN0ZWFsLW9mZmljZS0zNjUtY3JlZGVudGlhbHMv?oc=5 New phishing attack targeting Microsoft Teams users aims to steal Office 365 credentials - Neowin Technology via exercisesfatburnig.blogspot.com https://ift.tt/2ysBMK6
0 notes
skyanfeeds · 4 years ago
Latest Hack Attack Boosts Cybersecurity Stocks' Prospects. Here Are Some to Consider.  Barron's
How a ransomware attack works  The Washington Post
Hundreds of Virginia Tech computers targeted in global ransomware attack  myfox8.com
These are the top five dangerous cybercriminal organisations that are holding the world to ransom  Scroll.in
Scam artists exploit Kaseya security woes to deploy malware  ZDNet
View Full Coverage on Google News
0 notes
cyberparse · 8 years ago
Researchers work to save trusted computing apps from keyloggers
http://cyberparse.co.uk/2017/01/05/researchers-work-to-save-trusted-computing-apps-from-keyloggers/ https://i0.wp.com/cyberparse.co.uk/wp-content/uploads/2016/04/security-binary-pd-898757.jpg?fit=3888%2C2592
SGX needs I/O protection, Austrian boffins reckon Intel’s Software Guard Extensions started rolling in Skylake processors in October 2015, but it’s got an Achilles heel: insecure I/O like keyboards or USB provide a vector by which sensitive user data could be compromised. A couple of boffins from Austria’s Graz University of Technology reckon they’ve cracked that problem, with an add-on that creates protected I/O paths on top of SGX.
Instead of the handful of I/O technologies directly protected by SGX – most of which have to do with DRM rather than user security – the technology proposed in Samuel Weiser and Mario Werner’s Arxiv paper, SGXIO, is a “generic” trusted I/O that can be applied to things like keyboards, USB devices, screens and so on. And we’re not talking about a merely esoteric technology that might soothe the fears of people running cloud apps on multi-tenant infrastructure. The Weiser/Werner proposal would create an SGX-supported trusted path all the way to a remote user’s browser to protect (for example) an online banking session – and provide “attestation mechanisms to enable the bank as well as the user to verify that trusted paths are established and functional.” SGXIO as a way to protect a banking app
The shortcoming SGXIO is trying to fix is that SGX’s threat model considers everything outside itself a threat (which isn’t a bad thing, in context). The usual approach for trusted paths is to use encrypted interfaces. The paper mentions the Protected Audio Video Path (PAVP) – but that’s a DRM-specific example, and most I/O devices don’t encrypt anything. Hence SGXIO, an attempt to add a generic trusted path to the SGX environment – and with that trusted path reaching to the end user environment, it’s an attempt to protect an application from nasties like keyloggers that a miscreant might have installed on a victim’s box. The key architectural concepts in SGXIO are:
A trusted stack – which contains a security hypervisor, secure I/O drivers, and the trusted boot (TB) enclave; and The virtual machine – hosting an untrusted operating system that runs secure user applications.
A user application communicating with the end user:
1. Opens an encrypted channel to the secure I/O driver; 2. This tunnels through the untrusted operating system, and establishes secure communication with the “generic” user I/O device. The hypervisor binds user devices exclusively to I/O; I/O on unprotected devices passes directly through the hypervisor; the trusted path names both the encrypted user-app-to-driver communication; and the exclusive driver-to-device binding; The TB enclave provides assurance of the trusted path setup, by attesting the hypervisor. The paper illustrates this process like this: SGXIO’s trusted stack components
An implementation wouldn’t be seamless: the SGXIO paper devices a fair chunk of copy to application design, enclave programming (fortunately something Intel provides resources for), driver design, and hypervisor choice. Application developers, for example, have to work out a key exchange mechanism (Diffie-Hellman is supported, and SGXIO offers its own lightweight key protocol). For hypervisors, the paper suggests the seL4 microkernel. Originally developed by Australia’s NICTA and now handled by the CSIRO Data61 project, seL4 is a mathematically verified software kernel that was published as open source software in 2014. SGXIO will get its first public airing at the CODASPY’17 conference in March, being held in Scottsdale Arizona. ®
Sponsored: Customer Identity and Access Management
Source ZDNet | securify-this RSS
0 notes