Hundreds of Lenovo models are vulnerable to three major flaws. . Cybersecurity experts from ESET have found three security flaws in hundreds of different Lenovo laptop models which could put millions of users at risk. ESET said exploiting these vulnerabilities would allow attackers to deploy and successfully execute UEFI malware either in the form of SPI flash implants like LoJax or ESP implants like ESPecter. In total, three vulnerabilities have been discovered, which are now tracked as CVE-2021-3970, CVE-2021-3971 (also known as SecureBackDoor and SecureBackDoorPreim), and CVE-3972 (SMM memory corruption inside the SW SMI handler function). . Kaspersky discovers multiple severe vulnerabilities in HP computers, endangering countless users by enabling possible UEFI malware intrusions.. Lenovo Laptop Flaws, UEFI Malware Risks, Cybersecurity Vulnerabilities. . Brittany Day
Do you need to get a security clearance for your new job? Don't hold your breath. The U.S. Office of Personnel Management (OPM) announced it is temporarily suspending its Electronic Questionnaires for Investigations Processing (E-QIP) system. This is the web-based program used to complete and submit security background investigation forms.. In a statement OPM Director Katherine Archuleta claimed that the E-QIP fix was "not the direct result of malicious activity on this network, and there is no evidence that the vulnerability in question has been exploited." The link for this article located at ZDNet Security is no longer available. . The U.S. Office of Personnel Management has paused the E-QIP system due to a new issue, with no malicious intent found, causing delays in background checks. U.S. OPM Security, E-QIP System Issue, Background Check Delay, Cybersecurity Risk. . Dave Wreski
A former Goldman Sachs software developer has been sentenced to eight years in prison for stealing proprietary code used in the firm's high-speed trading platform.. Sergey Aleynikov worked at Goldman from 2007 to 2009 and was a programmer responsible for the firm's high-frequency trading software, which has generated more than $500 million in profit for the firm since 1999, prosecutors said. In June of 2009, he transferred The link for this article located at The Register UK is no longer available. . Ex-Goldman engineer Sergey Aleynikov faces punishment for pilfering confidential trading algorithms, heightening alarm over cybersecurity risks.. Goldman Sachs Software Theft, High-Frequency Trading, Cybersecurity Breach. . LinuxSecurity.com Team
About 6 percent of the Interior Department's computer systems remain disconnected from the Internet, 11 months after a federal judge ordered a departmentwide shutdown citing security concerns, according to a Nov. 1 Interior report. . .. About 6 percent of the Interior Department's computer systems remain disconnected from the Internet, 11 months after a federal judge ordered a departmentwide shutdown citing security concerns, according to a Nov. 1 Interior report . Most of the systems support the Bureau of Indian Affairs and the Office of the Special Trustee, agencies that rely on information technology to fulfill the department's trust fund duties. "The relative security and integrity of DOI's computer systems is gradually improving," Interior officials said in their 11th status report to the court, one in a series of updates required by U.S. District Judge Royce Lamberth. The link for this article located at FCW is no longer available. . About 6 percent of the Interior Department's computer systems remain disconnected from the Internet,. about, percent, interior, department's, computer, systems, remain, disconnected, internet. . Anthony Pell
Network Associates has been snared in a web of accusations over whether it will place backdoors for the U.S. government in its security software. Since Network Associates (NETA) makes popular security products, including McAfee anti-virus software and Pretty Good Privacy . . . . Network Associates has been snared in a web of accusations over whether it will place backdoors for the U.S. government in its security software. Since Network Associates (NETA) makes popular security products, including McAfee anti-virus software and Pretty Good Privacy encryption software, reports of a special arrangement with the U.S. government have drawn protests and threats of a boycott. The flap started last week, when news reports began to appear about an FBI project code-named "Magic Lantern." Details are sketchy, but Magic Lantern reportedly works by masquerading as an innocent e-mail attachment that will insert FBI spyware inside your computer. The link for this article located at Wired is no longer available. . Network Associates has been snared in a web of accusations over whether it will place backdoors for . network, associates, snared, accusations, whether, place, backdoors. . LinuxSecurity.com Team
Maybe John Palafoutas said it best. "People are not concerned about privacy, they're hysterical about privacy," the head of the American Electronics Association said during a spirited debate at the Aspen Summit Monday night. The debate will rage on in . . . . Maybe John Palafoutas said it best. "People are not concerned about privacy, they're hysterical about privacy," the head of the American Electronics Association said during a spirited debate at the Aspen Summit Monday night. The debate will rage on in the private sector, among consumers and in government circles before the issue is concisely defined, let alone settled. Even the language in the largely-uncharted waters of online privacy is vague. Not just consumers, but business and government are still pretty much in the dark about Internet privacy, including what it really is, summiteers say. The link for this article located at ComputerUser is no longer available. . The discussion of digital privacy at the Mountain Forum underscores user apprehensions and the ambiguity related to web confidentiality.. Internet Privacy, Cybersecurity Issues, Consumer Concerns, Data Protection. . LinuxSecurity.com Team
The CIO Council is asking every federal chief information officer to find and fix the lapses that made a top 10 list of critical Internet security threats. The list, released Thursday, includes problems that have solutions, but the solutions have . . .. The CIO Council is asking every federal chief information officer to find and fix the lapses that made a top 10 list of critical Internet security threats. The list, released Thursday, includes problems that have solutions, but the solutions have not been put in place by federal systems administrators. So agency World Web Web sites keep getting hacked, and agencies keep ending up in the news after being hit by attacks that should not have happened, said Allan Paller, director of research at the SANS Institute, a group of federal, industry and academic experts that coordinated the list. The link for this article located at Federal Computer Week is no longer available. . The CIO Council is asking every federal chief information officer to find and fix the lapses that ma. council, asking, every, federal, chief, information, officer, lapses. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.