PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

DUHK Attack Lets Hackers Recover Encryption Key Used in VPNs & Web Sessions

mardi 24 octobre 2017 à 19:58
DUHK — Don't Use Hard-coded Keys — is a new 'non-trivial' cryptographic implementation vulnerability that could allow attackers to recover encryption keys that secure VPN connections and web browsing sessions. DUHK is the third crypto-related vulnerability reported this month after KRACK Wi-Fi attack and ROCA factorization attack. The vulnerability affects products from dozens of vendors,

Kaspersky Opens Antivirus Source Code for Independent Review to Rebuild Trust

lundi 23 octobre 2017 à 19:42
Kaspersky Lab — We have nothing to hide! Russia-based Antivirus firm hits back with what it calls a "comprehensive transparency initiative," to allow independent third-party review of its source code and internal processes to win back the trust of customers and infosec community. Kaspersky launches this initiative days after it was accused of helping, knowingly or unknowingly, Russian

Android getting "DNS over TLS" to prevent ISPs from knowing what websites you visit

lundi 23 octobre 2017 à 10:29
No doubt your Internet Service Provides (ISPs), or network-level hackers cannot spy on https communications. But do you know — ISPs can still see all of your DNS requests, allowing them to know what websites you visit. Google is working on a new security feature for Android that could prevent your Internet traffic from network spoofing attacks. Almost every Internet activity starts with a

New Rapidly-Growing IoT Botnet Threatens to Take Down the Internet

samedi 21 octobre 2017 à 09:49
Just a year after Mirai—biggest IoT-based malware that caused vast Internet outages by launching massive DDoS attacks—completed its first anniversary, security researchers are now warning of a brand new rapidly growing IoT botnet. Dubbed 'IoT_reaper,' first spotted in September by researchers at firm Qihoo 360, the new malware no longer depends on cracking weak passwords; instead, it exploits

Unpatched Microsoft Word DDE Exploit Being Used In Widespread Malware Attacks

vendredi 20 octobre 2017 à 12:07
A newly discovered unpatched attacking method that exploits a built-in feature of Microsoft Office is currently being used in various widespread malware attack campaigns. Last week we reported how hackers could leveraging an old Microsoft Office feature called Dynamic Data Exchange (DDE), to perform malicious code execution on the targeted device without requiring Macros enabled or memory