Wenatchee Valley College - CTS Discussion Board

You are not logged in. Would you like to login or register?

Security Class » Security Class Article #6 - Due Monday December 3rd » 11/27/2018 10:49 am

rperez3648
Replies: 12

Go to post

Rosa:

The United States Postal Service has patched a critical security vulnerability that exposed the data of more than 60 million customers to anyone who has an account at the USPS.com website. The attacker could have pulled off email addresses, usernames, user IDs, account numbers, street addresses, phone numbers, authorized users and mailing campaign data from as many as 60 million USPS customer accounts. The Postal Service ignored the report for a year until recently. The Postal Service is further investigating.

https://thehackernews.com/2018/11/usps-data-breach.html

Security Class » Security Class Article #5 - Due 11/19/18 » 11/16/2018 9:58 am

rperez3648
Replies: 12

Go to post

Rosa Perez    https://thehackernews.com/2018/11/mobile-hacking-exploits.html

White hat hackers competition held Nov 13-14 in Tokyo found that Iphone X with IOS 12.1, Samsung Galaxy 9, Xiaomi Mi6 running the latest version of software from popular smartphone manufacturers can be hacked. A team of two researchers, Richard Zhu and Amat Cama, who named themselves Fluoroacetate, discovered and managed to exploit a pair of vulnerabilities in a fully patched Apple Iphone X over WiFi. For their target they chose to retrieve a photo that had recently been deleted from the Iphone. They also hacked in the Samsung Galaxy S9 by exploiting a memory heap overflow vulnerability in the phone's baseband component and obtaining code execution. Xiaomi Mi6 handset via NFC(near-field communications) which is using the touch-to-connect feature, they forced the phone to open the web browser and navigate to their specially crafted webpage. With the highest of 45 points and a total of $215,000 prize money, Fluoroacetate researchers Cama and Zhu earned the title "Master of Pwn, logging five out of six successful demonstrations of exploits against Iphone X, Galaxy S9, & Xiaomi Mi6. The vulnerabilities will be available in 90 days and they will remain open until the affected vendors issue security patches to address them.

 

Security Class » Security Discussion Topic #2 Due Monday the 15th » 10/12/2018 10:17 am

rperez3648
Replies: 15

Go to post

Google says a bug in an API for its Google+ social networking service exposed personal details for about 500,000 accounts, but it believes the data wasn't misused. Google patched the bug in March but chose to not publicly disclose the problem, based on a recommendation made by its privacy and data protection office. Google's decision to not disclose the data leak is likely to raise eyebrows because technology companies have faced increasing pressure and regulatory scrutiny over their data handling and privacy practices.
https://www.bankinfosecurity.com/google-forced-to-reveal-exposure-private-data-a-11587

Security Class » Security Discussion Article #1 - Post reply to this article » 10/03/2018 10:29 am

rperez3648
Replies: 17

Go to post

New Android App called Intra to give older versions of android a safety update. Intra can offer that additional layer of web protection to billions of mobile browsers around the world to which Private DNS is not available for older versions of Android. 

https://www.wired.com/story/jigsaw-intra-app-dns-encryption/

Board footera

 

Powered by Boardhost. Create a Free Forum