Monday, November 9, 2009

…iPhone. iPhone Gets First Worm

If you’re an Australian and you’ve gone against Apple and jailbroken your iPhone, well, karma is coming to get you. There is a worm on the loose that at this point is only affecting Australian iPhone users. This one replaces the phone’s wallpaper with a picture of Rick Astley.

The vector of attack is via the SSH application where the user has not changed the default password (more karma).

Experts say this likely is the first of many.

CIO Zone
Sophos

Friday, October 16, 2009

Microsoft exposes Firefox users to drive-by malware downloads | Zero Day | ZDNet.com

Microsoft exposes Firefox users to drive-by malware downloads | Zero Day | ZDNet.com

This is great, now Microsoft is recommending that you unistall the add-on they so kindly installed without your knowledge.

Monday, October 5, 2009

National Cyber Security Awareness Month

“National Cyber Security Awareness Month (NCSAM), conducted every October since 2001, is a national public awareness campaign to encourage everyone to protect their computers and our nation’s critical cyber infrastructure.

The success of National Cyber Security Awareness Month rests on all of us doing what we can to engage in awareness activities. There are opportunities for everyone from home users to major corporations and government entities to get involved.”

How To Get Involved

…PII. U.S. Government Suffers 'Largest Release Of Personally Identifiable Information Ever'

While this likely isn’t as bad as it sounds, it is still unbelievable to me that this is still happening. It very clearly shows that there is a lack of interest in keeping this information secure. American voters should be making this a priority for any new elections because eventually no one is going to have any personally identifiable information. The government is going to have carelessly let it all out into the public.

Dark Reading

Tuesday, September 15, 2009

…Infrastrucutre. SANS Top Threats Revealed

SANS has released their Top Cyber Security Risks report. Top two priorities: Unpatched internal systems and vulnerable websites.

“Featuring attack data from TippingPoint intrusion prevention systems protecting 6,000 organizations, vulnerability data from 9,000,000 systems compiled by Qualys, and additional analysis and tutorial by the Internet Storm Center and key SANS faculty members.”

SANS: The Top Cyber Security Risks

Tuesday, September 8, 2009

…Windows O/S. 0-Day BSOD Vulnerability

Word today that there is a 0-Day exploit targeting a flaw in SMB2 that can allow a single packet to crash a Windows Vista/7/2008 machine. Not too many details yet but the code is out and there is a Metasploit module available.

SANS ISC
Metasploit

Thursday, September 3, 2009

…OS X. Snow Leopard; vulnerabilities pre-installed.

image

So it seems OS X 10.6 has an old version of Flash bundled with it and it won’t keep your updated version if you’re upgrading. Somehow in the rush to get 10.6 out the door, Apple didn’t update to the newest version and doesn’t during the install.

We all know that Flash is a significant vector for attack so you need to make sure you update it as soon as you have installed your new breed of Leopard.

Engadget
Daily Tech