Live Breaking News & Updates on Security Blogwatch

Stay updated with breaking news from Security blogwatch. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.

STOP: Opt out of phone numbers as authentication tokens


Richi Jennings
Industry analyst and editor, RJAssociates
 
This week brings yet more examples of poor design. Specifically: Two apps trusting phone numbers without properly authenticating the actual user.
First, a deadly denial-of-service attack on WhatsApp, in which combining two subtle side effects can lock out users from their accounts. And second, a really dumb authentication bug in a wireless provider’s app.
Watch out these things come in threes. In this week’s
Security Blogwatch, we got the 411 (ask your parents).
Your humble blogwatcher curated these bloggy bits for your entertainment. Not to mention: 
Cracking Enigma.
What’s the craic, Zak? Mister Doffman reports ....

United States , Richi Jennings , Mister Doffman , Dan Goodin , Ernesto Canales Pere , Michael Crider , Issa Asad , Artem Russakovskii , Security Blogwatch , Suddenly Whatsapp , Link Wireless , Karl Bode , Mobile Account , South Florida , Registered Coward , Experian Treatment , ஒன்றுபட்டது மாநிலங்களில் , பணக்காரர் ஜென்னிங்ஸ் , டான் குடின் , மைக்கேல் சிறுதேர் , வழங்கல் அசாத் , இணைப்பு வயர்லெஸ் , கார்ல் போட் , கைபேசி எண்ணுதல் , தெற்கு புளோரிடா ,

China stole NSA zero day—4+ years before Shadow Brokers leak


A Chinese group known as APT31 … somehow gained access to and used a Windows-hacking tool known as EpMe created by the Equation Group … widely understood to be a part of the NSA. … The Chinese hackers then used that tool … from 2015 until March 2017, when Microsoft patched the vulnerability.

APT31 had access to the … privilege escalation exploit … long before the late 2016 and early 2017 Shadow Brokers leaks. … APT31 s [version] appears to have been built by someone with hands-on access to the Equation Group s compiled program.
And Kieren McCarthy wonders if this illustrates
It could be that Beijing obtained a copy of Equation Group s EpMe, or observed it being used and recreated it, and used it while the hole in Microsoft s Windows remained unfixed. Or the Chinese could have found the same bug within the OS. ....

United States , Richi Jennings , Itay Cohen , Kieren Mccarthy , Andy Greenberg , Equation Group , Equation Group Epme , Epme Equation Group , Security Blogwatch , China Hijacked , Check Point , Shadow Broker , Shadow Brokers , Lockheed Martin , ஒன்றுபட்டது மாநிலங்களில் , பணக்காரர் ஜென்னிங்ஸ் , அது கோஹன் , ஆண்டி க்ரீன்பெர்க் , சமன்பாடு குழு , காசோலை பாயஂட் , நிழல் தரகர் , நிழல் தரகர்கள் , லாக்ஹீட் மார்டின் ,

APT team attacks white hats: Google fingers North Korea



A vulnerability broker he had known for a while and trusted had introduced him to a new researcher called James Willy from New York, Caceres [said]. We hopped in a group chat, the three of us, and he sent me a Visual Studio project to take a look at a driver bug that caused a blue screen of death.

James [said] it was linked to Google Chrome – an instant attention-grabber for bug hunters. Vulns affecting software used by tens of millions worldwide are rare and command hefty rewards. … The code was all legit, it was a real crash with potential security implications, but I wasn t careful when I opened the Visual Studio project. [But] opening some Visual Studio projects can cause code to execute, which was the North Koreans attack vector. ....

New York , United States , Hong Kong , North Korea , North Korean , Alejandro Caceres , Jon Porter , Gareth Corfield , Adam Weidemann , James Willy , Richi Jennings , Catalin Cimpanu , Brian Bixby , Lazarus Group , Google Threat Analysis Group , Threat Analysis Group , Security Blogwatch , Visual Studio , Visual Studio Project , Visual Studio Build , Google Chrome , Anonymous Coward , Seongsu Park , Great Firewall , North Korean Super Hackers , புதியது யார்க் ,

FireEye hacked 'by Russia.' Who's next?


Richi Jennings
Industry analyst and editor, RJAssociates
 
FireEye the huge security company, with revenues of $900 million and countless US federal agencies on its customer roll confessed this week that it had been hacked. Its proprietary red-teaming tool set was stolen.
Officially, the firm’s not saying who perpetrated the intrusion. But secret-squirrel sources say it was Russia APT29 to be precise.
It’s being seen as revenge for outing Russia as the culprit for other high-profile shenanigans. In this week’s
Your humble blogwatcher curated these bloggy bits for your entertainment. Not to mention: 
RC in PH.
What’s the craic? Dustin Volz and Robert McMillan report ....

Jake Williams , Dan Goodin , Kevin Mandia , Richi Jennings , Hal Pomeranz , Robert Mcmillan , Soray Morris , Andy Greenberg , Dustin Volz , Red Team , Fireeye Red Team , Security Blogwatch , Fireeye Says It Was Breached , Nation State Hackers , Cozy Bear , Lily Hay Newman , Recent Cyber Attack , Grease Monkey , Ray Morris , ஜேக் வில்லியம்ஸ் , டான் குடின் , கெவின் மண்டியா , பணக்காரர் ஜென்னிங்ஸ் , ராபர்ட் மக்மிலந் , ஆண்டி க்ரீன்பெர்க் , டஸ்டின் வொல்ஜ் ,