Security News

Friday Squid Blogging: Classic Gary Larson Squid Cartoon (Schneier on Security)
2015-06-26 21:32

I have always liked this one. As usual, you can also use this squid post to talk about the security stories in the news that I haven't covered....

Samsung to Patch Windows Update Issue Within Days (Threatpost)
2015-06-26 20:53

Samsung said today it will no longer automatically disable Windows updates on PCs and laptops it manufactures and will release a patch "within a few days."

IETF Officially Deprecates SSLv3 (Threatpost)
2015-06-26 18:50

The IETF, in RFC7568, declared SSLv3 "not sufficiently secure" and prohibited its use. SSLv3 fallbacks were to blame for the POODLE and BEAST attacks.

New Chrome Extension Blocks BeEF Attacks (Threatpost)
2015-06-26 17:48

An engineer has come up with a new way to help combat BeEF, or browser exploit framework attacks.

NIST Drops Weak Dual_EC RNG From Official Recommendations (Threatpost)
2015-06-26 17:35

NIST officially has removed the controversial and compromised Dual_EC_DRBG from its list of recommended algorithms for generating random numbers.

Other GCHQ News from Snowden (Schneier on Security)
2015-06-26 17:12

There are two other Snowden stories this week about GCHQ: one about its hacking practices, and the other about its propaganda and psychology research. The second is particularly disturbing: While...

Threatpost News Wrap, June 26, 2015 (Threatpost)
2015-06-26 16:44

Dennis Fisher and Mike Mimoso talk about the Cisco default SSH keys, more details of the OPM data breach, the Adobe 0-day and why we never hear about bad APT groups, only the really good ones.

Researcher tests Tor exit nodes, finds not all operators can be trusted (Help Net Security)
2015-06-26 14:44

While the Tor anonymity network conceals (relatively successfully) a user's location and Internet activity from anyone who might want to know about it, users should be aware of the fact that it does n...

Cisco SSH Key Flaw Has Echoes of Earlier Vulnerabilities (Threatpost)
2015-06-26 13:31

When Cisco released a patch for several of its security appliances Thursday that eliminated the presence of hard-coded SSH host and private keys, the advisory had a distinct air of familiarity...