Security and DRM
-
Security updates for Monday
Security updates have been issued by Debian (docker-registry, gpac, libraw, libreoffice, rainloop, and sysstat), Fedora (bottles, c-ares, edk2, libssh, microcode_ctl, python-vkbasalt-cli, rust-buffered-reader, rust-nettle, rust-nettle-sys, rust-rpm-sequoia, rust-sequoia-keyring-linter, rust-sequoia-octopus-librnp, rust-sequoia-openpgp, rust-sequoia-policy-config, rust-sequoia-sop, rust-sequoia-sq, rust-sequoia-sqv, rust-sequoia-wot, and xen), SUSE (opera), and Ubuntu (Jhead, linuxptp, and sudo).
-
Email Phishing Using Kali Linux
No matter how often you go online and how or why you primarily use the Internet, you’ve probably seen phishing attack attempts. They’re now so common and problematic that cybersecurity professionals regularly provide information to help people spot and avoid phishing attacks.
Phishing can be extremely damaging and have widespread consequences for victim organizations including financial losses, data theft, and severe, lasting reputational harm. For this reason, many cybersecurity teams have in-house training that tests how employees respond to phishing attacks. Cybersecurity teams use phishing training tools to send spoofed emails, create fake login pages and otherwise behave as genuine scammers would.
Kali Linux is an open-source, Debian-based Linux platform for digital forensics and penetration tests. Using open-source tools with it allows people to run phishing simulations. The results of those efforts can illuminate vulnerabilities and indicate what leaders should do to make phishing attacks less likely. This article will demonstrate how you can conduct your own email phishing training using open-source tools on Kali Linux to improve your organization’s security posture and protect against cyberattacks and data breaches.
-
New York county still dealing with ransomware eight months after attack
The fallout from an eight-month-old cyber attack on a county in Long Island, New York has devolved into mud-slinging as leaders try to figure out just what is going on.
Suffolk County was hit with a ransomware attack in early September 2022, which led county executive Steve Bellone to issue nine separate emergency declarations, Long Island publication Newsday said – the most recent of which was enacted earlier this month.
-
New York county still dealing with ransomware eight months after attack
The fallout from an eight-month-old cyber attack on a county in Long Island, New York has devolved into mud-slinging as leaders try to figure out just what is going on.
-
Insurance regulators examining Point32Health data breach
The Division of Insurance is monitoring the Point32Health data breach, which may have compromised personal data including addresses, medical history and Social Security numbers of current and former Harvard Pilgrim Health Care policyholders, according to Executive Office of Housing and Economic Development spokesperson Margaret Quackenbush.
-
HP has found an exciting new way to DRM your printer!
I’m not talking about how printers quietly waste their own ink, or pretend cartridges are empty when they’re not, or lock out official cartridges from other regions. Heck, I’m not even talking about “Dynamic Security,” the delightful feature where new HP firmware updates secretly contain malware that blocks batches of third-party cartridges while pretending to harden your printhead against hacks.
[...]
“In fact, the only way a customer can get rid of HP+ once activated is to buy a new printer,” the IITC writes. HP didn’t answer our questions about the firmware update, including why it isn’t prominently disclosed that there’s no way to uninstall it.