Vulnerable web applications allow hackers to bypass corporate firewalls netsparker.com
A detailed technical article which explains how malicious attackers can target vulnerable web applications running on developers' workstations.
A detailed technical article which explains how malicious attackers can target vulnerable web applications running on developers' workstations.
I use 1Password to securely share passwords and notes with my colleagues. Can't recommend them enough and I'm super honoured to have them as a sponsor.
Similar to Linux a few months back (link), a number of Windows versions can be rendered unresponsive by it. A fix was included in this month's Patch Tuesday.
We all know that once an attacker gets physical access to your device it's much harder to defend yourself. This bypasses disk encryption though, and even firmware passwords if the device is in sleep mode. It's a bit hard to make out if anything can be done, but how I understand it is that one can only make it as hard as possible by using disk encryption, a firmware password and always shut down or hibernate your device.
There's a vulnerability in apk, the default package manager. It can be exploited through a malicious package or a man-in-the-middle (MiTM) attack. Lot's of Docker images are based in Alpine, so check your own.
Automatic updates, USB restricted mode and password management improvements.
This seems to have missed the window of their regular patch cycle last week. It fixes seven vulnerabilities, one of which can trigger remote code execution.
Article on the internal process after the Equifax hack. Not exactly heartwarming. Hackernews discussion here.
Nice project from Templarbit, gathering all information on high-level breaches.
Very cool project. It provides an environment to learn about how the OWASP Top 10 security risks apply to Node.js applications and teaches how to mitigate them.
It's a sad fact that many companies only seem to change their insecure practices when they are publicly shamed about them. Troy Hunt makes his position on this very clear with a bunch of examples.
Another one of Troy's. I must admit that I don't know how CA's are going to stay alive with Let's Encrypt being a pretty awesome thing.