Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2892628 times)

0 Members and 7 Guests are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5475 on: September 28, 2017, 01:04:03 PM »
Activist attacked by advanced targeted PHISHING: https://www.eff.org/deeplinks/2017/09/phish-future

Scary, are Big Brother agents fighting free expression that does not fits them well?

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5476 on: September 29, 2017, 02:53:01 PM »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5477 on: September 30, 2017, 02:36:46 PM »
Apple computers are at risk from flawed updates, researchers find
https://www.cnet.com/news/apple-macbook-vulnerable-firmware-updates/



Quote
Apple may not be alone
Smith said Windows computers likely have similar (or worse) problems, but he doesn't yet have data to support that suspicion.





Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5478 on: October 01, 2017, 03:42:09 PM »
Internet wide security update on hold: https://lists.dns-oarc.net/pipermail/dns-operations/2017-September/016766.html

Quote
There are a number of reasons why systems may not be ready to accept the new KSK key:

An old configuration with the 2010 key written into the code itself.
A failure to implement the RFC 5011 protocol that will automatically update the key.
Flaws or conflicts in software that prevent the automatic rollover from happening, or accepting the change when it does happen.
No matter what the reason, it is an indication of how incredibly difficult it is to update the internet on a network-wide basis. Just look at IPv6.

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5479 on: October 03, 2017, 10:28:14 AM »
Three new zero-days being abused in Word Press plug-ins:

https://www.wordfence.com/blog/2017/10/3-zero-day-plugin-vulnerabilities-exploited-wild/

PHP-based CMS, a disaster in the hands of the unsavvy!

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5481 on: October 06, 2017, 01:02:12 PM »
Win7 kernel security to be applied to Win10 kernel as well?

That is what Google wants: https://googleprojectzero.blogspot.nl/2017/10/using-binary-diffing-to-discover.html

polonus

P.S. See attached code txt attached, copyright 1989 by Dave Angel,  providing a mem-dump for fuzzers. (pol)
« Last Edit: October 06, 2017, 01:06:45 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5482 on: October 07, 2017, 07:59:10 PM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48568
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5483 on: October 07, 2017, 08:09:50 PM »
Security Alert: User Info Breach
https://blog.disqus.com/security-alert-user-info-breach
Ouch. Would be nice if they informed their users.  :(
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5484 on: October 09, 2017, 12:02:13 PM »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5485 on: October 09, 2017, 12:21:24 PM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5486 on: October 09, 2017, 01:13:13 PM »
Microsoft silently fixes security holes in Windows 10 – dumps Win 7, 8 out in the cold
http://www.theregister.co.uk/2017/10/06/researchers_say_windows_10_patches_punch_holes_in_older_versions/



Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89062
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5487 on: October 09, 2017, 03:01:46 PM »
Microsoft silently fixes security holes in Windows 10 – dumps Win 7, 8 out in the cold
http://www.theregister.co.uk/2017/10/06/researchers_say_windows_10_patches_punch_holes_in_older_versions/

The only thing is that I'm not surprised about what MS gets up to or in this case doesn't get up to.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5488 on: October 09, 2017, 03:12:40 PM »
Microsoft silently fixes security holes in Windows 10 – dumps Win 7, 8 out in the cold
http://www.theregister.co.uk/2017/10/06/researchers_say_windows_10_patches_punch_holes_in_older_versions/

The only thing is that I'm not surprised about what MS gets up to or in this case doesn't get up to.
Yepp you have to trust that your AV vendor has those exploits blocked
https://googleprojectzero.blogspot.no/2017/10/using-binary-diffing-to-discover.html



Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5489 on: October 09, 2017, 04:35:04 PM »
SS7 (Signalling System 7) protocol, is as holed as holed can be. Do no longer use SMS authentication!

Read: http://anonymous-news.com/how-hackers-can-use-two-factor-authentication-to-hack-your-gmail-empty-bitcoin-wallet/

polonus

P.S. Related threat -usb-cable with inbuilt-sim-card... https://secure.dshield.org/forums/diary/Whats+in+a+cable+The+dangers+of+unauthorized+cables/22904/

Damian
« Last Edit: October 09, 2017, 09:03:29 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!