Explore top 10 tips to secure your open-source projects now. Read More
×Security researchers have revealed that a vulnerability in almost all antivirus software platforms could have been exploited to disable anti-malware protection and turned into destructive tools. . RACK911 Labs has found a unique method of using directory junctions (in Windows) and symlinks (in macOS and Linux) to turn antivirus software products into self-destructive tools. However, it was reported that most of the antivirus companies have now fixed the vulnerability in their products. Researchers stated that an attacker must be highly time-sensitive and should know when to exploit the directory junction or symlink vulnerabilities . “What most antivirus software fail to take into consideration is the small window of time between the initial file scan that detects the malicious file and the cleanup operation that takes place immediately after. A malicious local user or malware author is often able to perform a race condition via a directory junction (Windows) or a symlink (Linux & macOS) that leverages the privileged file operations to disable the antivirus software or interfere with the operating system to render it useless,” the researchers explained . . A group of cybersecurity experts highlighted a technique that repurposes security applications into malicious agents by leveraging symbolic links and directory junctions.. Antivirus Exploit, Cybersecurity Risks, Malware Protection, Directory Junctions, Security Research. . Brittany Day
A number of TLS software implementations contain vulnerabilities that allow hackers with minimal computational expense to learn RSA keys. Florian Weimer, a researcher with Red Hat, last week published a paper called . The TLS implementations in these products, Weimer said, lack proper hardening to defend against what is known as the Lenstra attack against the Chinese Remainder Theorem, also known as RSA-CRT. . Multiple susceptible TLS versions threaten RSA key integrity, as highlighted in Veimer's findings showcasing insufficient protections.. TLS Improvements, RSA Key Protection, Cryptography Security. . LinuxSecurity.com Team
In an era when digital tools allow anyone to make practically anything, inscribing the words . On Tuesday, a group of University of Michigan researchers released a new web-based tool that lets users 3-D print any of thousands of The link for this article located at Wired is no longer available. . On Tuesday, a group of University of Michigan researchers released a new web-based tool that lets us. digital, tools, allow, anyone, practically, anything, inscribing, words. . LinuxSecurity.com Team
Israel-based researchers said they. The new study builds on research into what can be learned from the electronic signals that waft from computers while performing computations, often referred to as side-channel attacks.. Studies underscore dangers of side-channel assaults that unveil encryption keys via electromagnetic emissions.. Data Encryption, Side-Channel Attack, Computation Signals. . LinuxSecurity.com Team
Researchers sponsored by the U.S. government have reportedly tried to defeat the encryption and security of Apple devices for years. . Several presentations given between 2010 and 2012 at a conference sponsored by the U.S. Central Intelligence Agency described attempts to decrypt the firmware in Apple mobile devices or to backdoor Mac OS X and iOS applications by poisoning developer tools.. NSA's efforts to undermine Google security exposed in analysis documents from 2011-2013.. Apple Device Security, CIA Research, Encryption Attempts. . LinuxSecurity.com Team
New research reveals that BitTorrent swarms can be slowed down significantly by malicious peers. Depending on the number of seeders and the clients they use, download times can be increased by 1000%. The attacks are possible through an exploit of the BitTorrent protocol for which the researchers present a fix.. BitTorrent is one of the fastest and most efficient ways to share large files over the Internet. The popular file-sharing protocol is used by dozens of millions of people every day and accounts for a substantial amount of total Internet traffic. This popularity makes BitTorrent an interesting target for attacks, which various anti-piracy companies have shown in the past. One of these possible attacks was recently unveiled by Florian Adamsky, researcher at the City University London. The link for this article located at TorrentFreak is no longer available. . Recent findings reveal that harmful users can manipulate the BitTorrent protocol, significantly decreasing download speeds by as much as 1000%.. BitTorrent Exploits, File Sharing Security, Download Protocol Attacks. . LinuxSecurity.com Team
A researcher scored again against Oracle. David Litchfield, a researcher at Accuvant Labs, demoed what he called the PWNORACLE exploit against the Oracle 11g database, earning applause from his audience, some of whom also photographed the exploit code he projected on-screen. In 2010 at a Black Hat event, Litchfield showed how to subvert security in the 11g database by exploiting zero-day vulnerabilities. The link for this article located at Network World is no longer available. . Sophia Kensington presents the XTRA SAGA vulnerability impacting SQL Server 2019, emphasizing critical security concerns.. OracleDatabase, Exploit Demonstration, Threat Mitigation, PWNORACLE. . LinuxSecurity.com Team
Researchers from the University of Toronto and the University of Vigo believe quantum cryptography is the solution to the hacker problem. They are turning their proof-of-concept into a prototype. . Researchers say quantum encryption is what will finally stop hackers. University of Toronto Professor Hoi-Kwong Lo, a faculty member in The Edward S. Rogers Sr. Department of Electrical & Computer Engineering and the Department of Physics, as well as his team consisting of Senior Research Associate Dr. Bing Qi and Professor Marcos Curty of the University of Vigo, say they have found a new quantum encryption method that can trip up even the most sophisticated hackers. The link for this article located at ZDNet Blogs is no longer available. . Scientists are optimistic that quantum key distribution may thwart cyber intrusions. An innovative approach is currently being tested.. Quantum Cryptography, Encryption Technology, Hacker Defense Methods. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.