Security News > 2018 > November

Google logins make JavaScript mandatory, Huawei China spy shock, Mac malware, Iran gets new Stuxnet, and more
2018-11-03 13:07

Plus, SystemD gets system de-bugged, again Roundup This week there were Hacked Home Hubs, buggered BBC Bits, and PortSmash privilege punch-ups.…

30 spies dead after Iran cracked CIA comms network with, er, Google search – new claim
2018-11-02 22:05

Uncle Sam's snoops got sloppy with online chat, it seems Iran managed to infiltrate the communications network of CIA agents who left their secret websites, used to exchange messages with...

Friday Squid Blogging: Eating More Squid
2018-11-02 21:08

This research paper concludes that we'll be eating more squid in the future. As usual, you can also use this squid post to talk about the security stories in the news that I haven't covered. Read...

Facebook Blames Malicious Extensions in Breach of 81K Private Messages
2018-11-02 20:39

Investigators posed as buyers and were offered the messages at 10 cents per Facebook account.

PortSmash attack punches hole in Intel's Hyper-Thread CPUs, leaves with crypto keys
2018-11-02 20:18

Side-channel timing technique exploits SMT – but you'll need to be running malware on the machine already Brainiacs in Cuba and Finland have found a new side-channel vulnerability in Intel x64...

Web domain owners paid EasyDNS to cloak their contact info from sight. It was blabbed via public Whois anyway
2018-11-02 19:33

Registrar apologies as punters wait for spam tsunami Domain name registrar EasyDNS has 'fessed up to accidentally leaking cloaked contact details for about 1,500 domain owners in Whois query...

Business Email Compromise: Must-Have Defenses
2018-11-02 19:18

David Stubley of 7 Elements Shares BEC Incident Response Lessons LearnedWant to better block business email compromise - CEO fraud - attacks outright, as well as be able to spot and respond more...

Eye Clinic Reports Quick Recovery from Ransomware Attack
2018-11-02 18:48

Despite Fast Rebound, Entity Still Reporting Data BreachAn Iowa eye clinic and its affiliated surgery center recently recovered from a ransomware attack on their common systems within one day and...

Cisco Security Appliance Zero-Day Found Actively Exploited in the Wild
2018-11-02 16:50

A high severity zero-day flaw exists in Cisco System's SIP inspection engine.