Security

Pierluigi Paganini April 02, 2016
A NIST guide tells enterprises how to secure email systems

For the first time in a decade, the US National Institute of Standards and Technology (NIST) has updated its secure email guide. The last effort of the NIST Agency in the development of email security guidelines is dated 2007 when it published the  NIST SP 800-45, Version 2 – Guidelines on Electronic Mail Security. The […]

Pierluigi Paganini April 01, 2016
SideStepper method allows to infect iOS devices via MDM Solutions

SideStepper is a method to install malicious apps on iOS devices by abusing the mobile device management (MDM) solutions. Security researchers from the Check Point firm have devised a method to install a malicious code on iOS devices by abusing the mobile device management (MDM) solutions used by many enterprises. The technique relies on a vulnerability dubbed by […]

Pierluigi Paganini March 31, 2016
The code to bypass Apple System Integrity Protection security mechanism fits in a Tweet

Apple failed in fixing the System Integrity Protection security mechanism and the exploits code released by a researcher fits in a Tweet . Last week security media reported a critical privilege escalation flaw (CVE-2016-1757) in the Apple System Integrity Protection (SIP) security mechanism, a vulnerability that was present at the time of the discovery in all the version […]

Pierluigi Paganini March 30, 2016
Following revelations on Paris attacks, US lawmakers target burner phones

Paris terrorists used burner phones and US lawmakers have proposed a bill that would force retailers to record the identity of the buyers of these devices. Law enforcement and intelligence agencies worldwide are fighting against terrorist organizations operating in their territories, but investigations are hampered by the use of encrypted communications. After the Paris attacks, intelligence agencies […]

Pierluigi Paganini March 28, 2016
1 million Gmail accounts victim of state-sponsored hacking

Google is improving its Gmail warning service to help protect the customers from state-sponsored hacking and surveillance activities. Google confirmed that one million Gmail accounts might have been targeted by nation-state hackers. The news is worrying, the company is observing a significant increase in the number of hacking attacks on user email accounts. Google announced […]

Pierluigi Paganini March 26, 2016
Bruxelles Attacks: Bombers spied a Nuclear Researcher

Terrorists behind Bruxelles attacks were spying on an eminent nuclear researcher planning a nuclear plant attack and the building of a dirty bomb. The news is disconcerting, the two brothers behind the Brussels attacks, Khalid and Ibrahim El Bakraoui, were also spying on an eminent researcher and were planning to build “dirty bomb.” The Belgium’s Federal […]

Pierluigi Paganini March 25, 2016
Google issued a new security update to fix flaws in Chrome 49

Google has issued a new security update for its Chrome 49 that patches a number of flaws, most of them discovered by external researchers. Google has updated Chrome 49 for all the available versions in order to patch several critical vulnerabilities, including the flaw discovered thanks its bounty program that were rewarded with dozen thousands of […]

Pierluigi Paganini March 24, 2016
The Apple System Integrity Protection feature bypassed

Security researchers from SentinelOne have discovered a security vulnerability affecting the Apple System Integrity Protection (SIP). Security researcher Pedro Vilaça from SentinelOne has discovered a security vulnerability ( CVE-2016-1757) affecting the Apple System Integrity Protection (SIP). The SIP is a security mechanism implemented by Apple in the OS X El Capitan operating system for the protection of certain […]

Pierluigi Paganini March 24, 2016
Patch Java immediately or attackers can hack you

The CVE-2016-0636 flaw affects Java SE running in web browsers on desktops, attackers can trigger it remotely to takeover your PC. Once again a serious security vulnerability affects the Java Oracle software, the new flaw coded as CVE-2016-0636 scored a 9.3 on the Common Vulnerability Scoring System bug severity rating. The CVE-2016-0636 vulnerability affects Java SE running in […]

Pierluigi Paganini March 23, 2016
Badlock, a severe flaw affects every version of Windows and Samba

Developers from Microsoft and Samba Team are working on a security patch to fix a severe vulnerability dubbed Badlock. Developers from Microsoft and Samba are working on a security patch to fix a severe vulnerability that affects almost every version of Windows and Samba. Samba, which is present in nearly all Linux distributions, is a free […]