Day: November 29, 2016

CERT to Microsoft: Keep EMET alive

Microsoft wants to stop supporting its Enhanced Mitigation Experience Toolkit (EMET) because all of the security features have been baked into Windows 10. A vulnerability analyst says Windows with EMET offers additional protection not available in standalone Windows 10. “Even a Windows 7 system with EMET configured protects your application more than a stock Windows

0Shares
Read More
San Francisco's Muni says server data not accessed in ransomware hit

The San Francisco Municipal Transportation Agency said late Monday that no data had been accessed from its servers in a ransomware attack on the Muni transit system and the agency has never considered paying the ransom asked by the attacker. The statement by the SFMTA follows reports that the alleged attacker has threatened to dump

0Shares
Read More
Mirai: New wave of IoT botnet attacks hits Germany

New variant of malware used in attacks that knocked 900,000 home internet users offline. Twitter Card Style:  summary A new wave of attacks involving the Mirai botnet has crippled internet access for nearly a million home users in Germany. The latest attacks used a new version of the Mirai malware (Linux.Gafgyt.B) which is configured to

0Shares
Read More
Azure customer saves Microsoft from an RHEL disaster

Broken authentication, improperly secured configuration files, and poor certificate management: Attackers could have exploited these issues to compromise any RHEL (Red Hat Enterprise Linux) instance on Microsoft Azure. Ian Duffy, an Irish software engineer with the e-commerce company Zalando, discovered these flaws when creating a machine image of RHEL that was compliant with the Security Technical Implementation Guide

0Shares
Read More
3 clues to spotting a spam scam

I received the following “domain abuse notice” for one of my inactive registered domains last week: Those of us who have dealt with falsely blacklisted domains in the past have seen notices like this before. It’s usually from an antispam vendor or service letting you know that your domain has been used in a spam

0Shares
Read More