Wenatchee Valley College - CTS Discussion Board

You are not logged in. Would you like to login or register?



10/22/2019 10:31 am  #1


Security Class Article #4 - Due October 28th

Reminder - Quiz this Friday...

Post a new article here by Monday.  Try to find a good one that is actually interesting and READ it.  Write a good summary and a link to the original article too.  Make sure to put your name in it.

 

10/23/2019 10:12 am  #2


Re: Security Class Article #4 - Due October 28th

NordVPN confirms it was hacked
An expired internal private key was exposed, resulting in a security breach, allowing an attacker to gain access to one of NordVPN's servers.  Since NordVPN uses a "zero logs" policy claiming they dont track, collect, or share private data, the attacker wasn't able to gain any personal or private data.  However, NordVPN claims that there is a possibility that the attacker was able to perform a complex "man-in-the-middle" attack and intercept a VPN user's connection.  NordVPN chose not to name the data center provider in which the vulnerable server's private key was exposed.

https://techcrunch.com/2019/10/21/nordvpn-confirms-it-was-hacked/


Jesse Kilthau

Last edited by jkilthau2856 (10/23/2019 10:13 am)

 

10/26/2019 8:55 pm  #3


Re: Security Class Article #4 - Due October 28th

Here's a good example of something we've been doing in class recently.  AWS (Amazon) was attacked by  a DDOS attack Thursday, from 10 am- 6 pm.  Make one question their security, especially with the holiday shopping season just beginning.
April
https://www.infosecurity-magazine.com/news/aws-customers-hit-by-eighthour-ddos/#.XbUeSNlw1eg.

 

10/27/2019 7:28 pm  #4


Re: Security Class Article #4 - Due October 28th

Apple takes "Trojan Clicker's" off the app store.
This is surprising because of how well known Apple is of having safe/locked down app store.

They found 17 apps that were opening the web in the background and clicking on ad's endlessly.
Some categories  of the apps included:

FM Radio
Restaurant finder
BMI calculator
Video editor
File manager



https://cyware.com/news/apple-removes-malicious-ios-apps-infected-with-clicker-trojan-0aad89a8

 

10/27/2019 9:46 pm  #5


Re: Security Class Article #4 - Due October 28th

Cybercriminals are doing big business in the gaming chat app Discord

So any one who has discord may want to know about this. So it seems hackers are getting use discord for their own personal use of selling hack accounts,social security,and any other credit cards, not only that they offer their service for any sort off tool to get the job done 

https://www.cbsnews.com/news/cybercriminals-are-doing-big-business-in-the-gaming-chat-app-discord/
by JuanCarlosMendezJr

 

10/27/2019 10:52 pm  #6


Re: Security Class Article #4 - Due October 28th

A recent Samsung security flaw involving fingerprint accessibility affects the Galaxy S10, S10+, Note 10, and Note 10+. (Pretty much all of Samsung's 2019 phones with ultrasonic fingerprint scanners.) Some third-party screen protectors have an underside texture which might look like a fingerprint to the scanner. When scanned fingerprints are registered with the protector installed, the phones are learning the protector as part of your fingerprint. Anyone with the protector could then unlock the phone regardless of fingerprint.
-Zach Howard

https://www.androidpolice.com/2019/10/25/samsung-will-begin-patching-fingerprint-scanner-security-flaw-within-24-hours/

 

10/27/2019 11:36 pm  #7


Re: Security Class Article #4 - Due October 28th

​Avast Vulnerability Potentially Allows DLL Hijacking
What’s the issue?
Tracked as CVE-2019-17093, the vulnerability allows an attacker to load a malicious DLL file to bypass defenses and escalate privileges.


  • The attacker requires administrative privileges to exploit this bug. Once exploited, the vulnerability allows the loading of malicious DLL in multiple processes.
  • Owing to self-defense mechanisms, even administrators are not allowed to write DLL to the AM-PPL (Anti-Malware Protected Process Light).
  • However, this restriction can be bypassed by writing the DLL file to an unprotected folder from which components are loaded by the application.

Why did this happen?
Researchers present two root causes behind the vulnerability.

Last edited by bpedersen3277 (10/27/2019 11:48 pm)

 

10/28/2019 7:22 am  #8


Re: Security Class Article #4 - Due October 28th

https://interestingengineering.com/an-ethical-hacker-discovered-japanese-hotel-robots-could-be-used-to-spy-on-guests
Hackers a robot in Japan
A hacker by the name Lance R. Vick who is a ethical hacker has stated that he has found a flaw in the systems of the robots at a hotel in japan, With the exploit it allowed for the hackers to be able to spy on the people at the hotel. Which caused a big problem for the hotel and then their actions was to get them out out of the hotel for.

 

10/28/2019 7:59 am  #9


Re: Security Class Article #4 - Due October 28th

Phishing and spam mail has seen a rise through 2019, where spam mail now accounts for a staggering 57.6% of email traffic. China was the largest culprit of sending spam, responsible for about 24% total, followed by US (14%) and Russia (5%). Many of these spam emails are designed for phishing attacks, have viruses attached to their files, or include trojans. Hackers constantly adapt to real world events to make their spam mail more enticing, such as targeting Game of Thrones fans before its final season release and even major sporting events. Spammers have also used fake tax services and urged the recipient by telling them they only have 24 hours to file their tax return or they won't get it, for instance.

Derek D
https://www.techrepublic.com/article/phishing-attacks-jump-by-21-in-latest-quarter-says-kaspersky/

 

10/28/2019 9:24 am  #10


Re: Security Class Article #4 - Due October 28th

https://threatpost.com/adobe-creative-cloud-users-exposed-hackers/149563/
Nearly 7.5 million adobe creative cloud users were left open to phishing campaigns after their records were left exposed. Which it seemed that the data base was open for about a week. Which isn't the first time they have been breached. -Jose Gamino

 

Board footera

 

Powered by Boardhost. Create a Free Forum