Security News

IBM Spectrum Protect Plus Security Open to RCE
2020-09-15 19:08

IBM has issued fixes for vulnerabilities in Spectrum Protect Plus, Big Blue's security tool found under the umbrella of its Spectrum data storage software branding. IBM Spectrum Protect Plus is a data-protection solution that provides near-instant recovery, replication, reuse and self-service for virtual machines.

Schlumberger, IBM and Red Hat to accelerate digital transformation across the oil and gas industry
2020-09-10 00:00

Schlumberger, IBM and Red Hat, announced today a major collaboration to accelerate digital transformation across the oil and gas industry. Through the agreement with IBM and Red Hat, Schlumberger has committed to the exclusive use of Red Hat OpenShift.

News Wrap: AWS Cryptojacking Worm, IBM Privacy Lawsuit and More
2020-08-21 14:04

Threatpost editors discuss a cryptomining malware targeting AWS systems, a recent development in a lawsuit against the IBM-owned Weather Channel app, and more. Listen to the full podcast below or download direct here.

Shared memory vulnerability in IBM's Db2 database could let nefarious insiders wreak havoc – so get patching
2020-08-21 13:38

Security firm Trustwave said the shared memory vulnerability in Db2 - CVE-2020-4414 - was similar to the problems found with Cisco's Webex in June. According to TrustWave, "Only Db2 for LUW is affected. Db2 for other platforms like IBM mainframes and z/OS are unaffected."

IBM Settles Lawsuit Over Weather Channel App Data Privacy
2020-08-20 19:41

IBM, the owner of the Weather Channel mobile app, has reached a settlement with the Los Angeles city attorney's office after a 2019 lawsuit alleged that the app was deceiving its users in how it was using their geolocation data. The 2019 lawsuit claimed, the app's permission prompt for users to share their geolocation data did not make them aware that it was also selling that data to third-party companies.

Vulnerability in IBM Db2 Leads to Information Disclosure, Denial of Service
2020-08-20 14:43

A shared memory vulnerability that IBM addressed in its Db2 data management products could allow malicious local users to access sensitive data. Trustwave, which identified the vulnerability and reported it to IBM, says that the issue exists because the developers forgot to include explicit memory protections for the shared memory that the Db2 trace facility uses.

Bank of America, Daimler, and Apple partnering with IBM for confidential computing services
2020-08-20 13:45

For two years, IBM has been deploying confidential computing capabilities in the IBM Cloud and Rohit Badlaney, vice president of IBM Z Hybrid Cloud, said it is the only public cloud with "Production-ready confidential computing capabilities able to protect data, applications and processes." IBM's platform is now used in heavily regulated industries like healthcare and banking, with high profile customers like Bank of America and Daimler taking advantage of confidential cloud computing capabilities.

IBM AI-Powered Data Management Software Subject to Simple Exploit
2020-08-20 12:00

The IBM Db2 is a family of hybrid data-management products containing artificial intelligence, which can be used to analyze and manage both structured and unstructured data within enterprises. The lack of explicit memory protections "Allows any local users read-and-write access to that memory area," Trustwave researchers said, in their PoC exploit writeup for the bug, issued on Thursday.

Experts Reported Security Bug in IBM's Db2 Data Management Software
2020-08-20 04:59

Cybersecurity researchers today disclosed details of a memory vulnerability in IBM's Db2 family of data management products that could potentially allow a local attacker to access sensitive data and even cause a denial of service attacks. The flaw, which impacts IBM Db2 V9.7, V10.1, V10.5, V11.1, and V11.5 editions on all platforms, is caused by improper usage shared memory, thereby granting a bad actor to perform unauthorized actions on the system.

IBM finds vulnerability in IoT chips present in billions of devices
2020-08-19 15:56

A security flaw in a series of IoT connectivity chips could leave billions of industrial, commercial, and medical devices open to attackers. EHS8 modules are built for industrial IoT machines that operate in factories, the energy sector, and medical roles, and are designed to create secure communication channels over 3G and 4G networks.