Don’t Let the Vulnera-Bullies Win. Use our free tool to see if you are patched against Vulnerability CVE-2020-0601

Credit to Author: Trend Micro| Date: Fri, 17 Jan 2020 17:40:24 +0000

So much for a quiet January! By now you must have heard about the new Microsoft® vulnerability CVE-2020-0601, first disclosed by the NSA (making it the first Windows bug publicly attributed to the National Security Agency). This vulnerability is found in a cryptographic component that has a range of functions—an important one being the ability…

The post Don’t Let the Vulnera-Bullies Win. Use our free tool to see if you are patched against Vulnerability CVE-2020-0601 appeared first on .

Read more

Don’t Let the Vulnera-Bullies Win. Patch Against Vulnerability CVE-2020-0601 with our Free Tool!

Credit to Author: Trend Micro| Date: Fri, 17 Jan 2020 17:40:24 +0000

So much for a quiet January! By now you must have heard about the new Microsoft® vulnerability CVE-2020-0601, first disclosed by the NSA (making it the first Windows bug publicly attributed to the National Security Agency). This vulnerability is found in a cryptographic component that has a range of functions—an important one being the ability…

The post Don’t Let the Vulnera-Bullies Win. Patch Against Vulnerability CVE-2020-0601 with our Free Tool! appeared first on .

Read more

Kadena launches a hybrid platform to connect public, private blockchains

Credit to Author: Lucas Mearian| Date: Thu, 16 Jan 2020 12:10:00 -0800

Brooklyn-based spinoff Kadena has launched a hybrid blockchain that can scale horizontally, enabling multiple electronic ledgers to talk to each other via smart contracts – and letting users transfer cryptocurrency between the chains.

Hybrid blockchains combine permissioned chains for businesses to transact in the background while connecting to a public blockchain (via an API) for consumers and others to make money transfers or access information about products moving across supply chains.

“Their hybrid blockchain model looks interesting, mainly because it enables interoperability via smart contracts that run on public chains and talk to/with private chains,” said Avivah Litan, a vice president of research at Gartner. “That way, enterprises can keep their private data and transactions limited to the private chain but benefit from the liquidity and cross-chain access available by leveraging smart contracts running on the public chain.”

To read this article in full, please click here

Read more

Worried about an NSA ChainOfFools/CurveBall attack? There are lots of moving parts. Test your system.

Credit to Author: Woody Leonhard| Date: Fri, 17 Jan 2020 06:42:00 -0800

If you want to install the January Patch Tuesday patches, by all means, go right ahead. That said, I continue to recommend that you hold off installing the January Microsoft patches until we get a clearer reading on potential bugs.

The pro-patch-now argument generally goes something like this: Everybody is recommending that you install the patches to protect against the Crypto bug — almost all of the major security folks, the researchers, the big online sites, your local news station, your congresscritter, your neighbor’s nine-year-old, even the bleeping NSA. It’s a little patch. Why not just install it and be done with it?

To read this article in full, please click here

Read more

This Week in Security News: The First Patch Tuesday Update of 2020 and Pwn2Own Vancouver Announced

Credit to Author: Jon Clay (Global Threat Communications)| Date: Fri, 17 Jan 2020 13:35:11 +0000

Welcome to our weekly roundup, where we share what you need to know about the cybersecurity news and events that happened over the past few days. This week, learn about a major crypto-spoofing bug impacting Windows 10 that has been fixed as part of Microsoft’s January Patch Tuesday update. Also, read about the launch of…

The post This Week in Security News: The First Patch Tuesday Update of 2020 and Pwn2Own Vancouver Announced appeared first on .

Read more

Oracle’s January 2020 update patches 334 security flaws

Credit to Author: John E Dunn| Date: Fri, 17 Jan 2020 11:31:27 +0000

The January 2020 update featured a joint record of 334 patches, matching an identical number released in July 2018.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/uQefUNviL2Q” height=”1″ width=”1″ alt=””/>

Read more

Google will now accept your iPhone as an authentication key

Credit to Author: Lisa Vaas| Date: Fri, 17 Jan 2020 11:13:19 +0000

Google has updated its Smart Lock to let iOS users security-dongle-ize their iPhones.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/E-1ND1RZhgg” height=”1″ width=”1″ alt=””/>

Read more