Â
Â
In our final segment, Doug, Jeff, Patrick, and Lee give you the latest security news to talk about a Zero Day for Windows, the battle over Huawei with the US and Google, & unpatched hardware and companies tripping themselves up!
Dougâs Stories
- https://nakedsecurity.sophos.com/2019/05/23/the-city-of-baltimore-is-being-held-hostage-by-ransomware/
- https://www.bleepingcomputer.com/news/security/new-zero-day-exploit-for-bug-in-windows-10-task-scheduler/
- https://vulmon.com/vendoradvisory?qidtp=huawei_security_advisories&qid=00906a438725b28e1fe0958213b604e9
//discussion about Google and Huawei//
- https://theweek.com/articles/842837/googles-huawei-ban-exposes-alarming-app-store-duopoly
- https://theweek.com/speedreads/841493/report-trump-expected-sign-executive-order-that-block-huawei-from
- https://www.xda-developers.com/google-revoke-huawei-android-ban-blacklist/
Leeâs Stories
- Sensitive Data for 2.25 Million Russians exposed online
- Unsecured Survey Databases exposes infor from 8 Million Marketing data gathered from surveys, free sample requests, etc.
- Slack for Windows Vulnerability Slack for Windows 3.3.7 weakness can allow attackers to manipulate where userâs files are stored to a hacker file share. Low risk, fixed in version 3.4.0.
- Salesforce still hasnât recovered Flaw in Salesforce script resulted in all permissions being granted to every profile, primarily EU and North America customers, service degraded until issue resolved.
- 20,000+ Linksys routers leaking information Bug is from 2014. Fix: apply latest firmware and enable firewall. These devices are marketed to home users, perhaps better to replace that 5 year old router?
- DHS warns of âStrong Concernsâ that Chinese-made drones are stealing data In short the drone manufacturers are obligated to turn over data to the Chinese government on demand. One of the biggest Chinese drone manufacturers is DJI.
- Instagram Influencer Account information captured/leaked Information on 49 million users was captured and stored in an open access database.
- MuddyWater BlackWater campaign using Anti-Detecion Techniques This is a new PowerShell-based downloader leveraging POWERHELLO which replaces POWERSTATS. While highly targeted it is interesting to see new techniques to avoid detection.
- Future Windows 10 updates will block some Wi-Fi Future Windows 10 updates will discontinue support for WEP or TKIP. Move to WAP2 or 3.
- New Bill Requires Propbable Cause to Search Electronic Devices at The Border Currently, CBP can search someoneâs phone and send the information to DHS without a warrant. CNET reports 30,000 devices searched at The Border last year.
- ARM Reportedly tells employees to suspend all business with Huawei The ban is due to ARM being US origin technology, and therefore covered by the US Restrictions.
- Several chip companies stop supplying Huawei Qualcomm, Intel, Xilinx and Broadcom are reportedly no longer supplying Huawei after Trump adminstration blacklist. Expect delays in 5G rollout, and carriers impacted replacing Huawei equipment already purchased.
- Google cuts of Huawei phones from future Android Updates Google says that it will restrict Huaweiâs access to futureAndroid OS updates, Google Play store, tick-tock..
- All the companies that have cut ties with Huawei Intel, Panasonic, Qualcomm, Xilinix, Broadcom no longer supplying Huawei after blacklist. See also Several Chip companies reportedly stopped supplying Huawei after ban
- Laptop full of malware for sale high bit $1.1MÂ A laptop deliberately infected with six notorious strains of malware, including WannaCry and ILoveYou, is being auctioned in the US as an art project. Currently air-gapped, will be shipped with Internet disabled.
Jeffâs Stories
- Assange Indicted Under Espionage Act, Raising First Amendment Issues latebreaking news
- 12 Dark Secrets of Encryption ooohhhâŚI wonder what they are
- Ransomware Cyberattacks Knock Baltimoreâs City Services Offline this hits close to home. literally.
Patrickâs Stories
- Someone Hacked Trumpâs Golf Scores
- UK Prepares to Hack Back
- Sim Swap Attack Costs Him $100,000 overnight
Full Show Notes
Follow us on Twitter: https://www.twitter.com/securityweekly
Gloss