<img src="https://secure.ruth8badb.com/159098.png" alt="" style="display:none;">

IT Security Newsletter - 8/10/2020

SHARE

Top News

Chinese hackers have pillaged Taiwan's semiconductor industry

Taiwan has faced existential conflict with China for its entire existence and has been targeted by China's state-sponsored hackers for years. But an investigation by one Taiwanese security firm has revealed just how deeply a single group of Chinese hackers was able to penetrate an industry at the core of the Taiwanese economy, pillaging practically its entire semiconductor industry. READ MORE...

Breaches

Hackers Dump 20GB of Intel's Confidential Data Online

More than 20 gigabytes of proprietary data and source code from chipmaker Intel Corp. was dumped online by a third party, likely the result of a data breach from earlier this year. The announcement of the "first 20gb release in a series of large Intel leaks" was made by user and IT consultant Tillie 1312 Kottmann #BLM on Twitter, who called the information "Intel exconfidential Lake Platform Release." READ MORE...

Hacking

Chinese Researchers Show How They Remotely Hacked a Mercedes-Benz

A team of Chinese researchers has described the analysis process that resulted in the discovery of 19 vulnerabilities in a Mercedes-Benz E-Class, including flaws that can be exploited to remotely hack a car. The research was conducted starting in 2018 by Sky-Go, the vehicle cybersecurity unit of Chinese security solutions provider Qihoo 360. The findings were disclosed to Daimler, which owns the Mercedes-Benz brand, in August last year. READ MORE...

Software Updates

Samsung rolls out Android updates fixing critical vulnerabilities

Samsung has started rolling out Android's August security updates to mobile devices to fix critical security vulnerabilities in the operating system. This week Android published their August 2020 security updates, which includes numerous security patches for critical vulnerabilities impacting the latest devices. As observed by BleepingComputer, Samsung Galaxy devices are automatically pulling updates today, August 8, 2020. READ MORE...

Information Security

Ohio becomes first state to release vulnerability policy for election-related websites

Ohio's secretary of state has established guidelines for security experts to find and help fix software flaws in the state's election-related websites, the first such move by a state as the 2020 election approaches. The vulnerability disclosure policy (VDP) covers registration websites for Ohio residents and overseas and military voters, among other sites, and provides legal liability protections for researchers. READ MORE...

Exploits/Vulnerabilities

Bugs in HDL Automation expose IoT devices to remote hijacking

A security researcher discovered vulnerabilities in an automation system for smart homes and buildings that allowed taking over accounts belonging to other users and control associated devices. In a presentation on Saturday at the IoT Village during the DEF CON hacker conference, Barak Sternberg shows how some weak spots in the HDL automation system could have been leveraged by attackers to fully compromise it. READ MORE...


Over 30 Vulnerabilities Discovered Across 20 CMS Products

Researchers have identified more than 30 vulnerabilities across 20 popular content management systems (CMS), including Microsoft SharePoint and Atlassian Confluence. The research was conducted by Alvaro Muñoz of GitHub and Oleksandr Mirosh of Micro Focus Fortify, and it focused on the security controls implemented by various CMS frameworks and products and methods for bypassing them. READ MORE...

Encryption

The quest to liberate $300,000 of bitcoin from an old ZIP file

In October, Michael Stay got a weird message on LinkedIn. A total stranger had lost access to his bitcoin private keys-and wanted Stay's help getting his $300,000 back. It wasn't a total surprise that The Guy, as Stay calls him, had found the former Google security engineer. Nineteen years ago, Stay published a paper detailing a technique for breaking into encrypted zip files. The Guy had bought around $10,000 worth of bitcoin in January 2016, well before the boom. READ MORE...

On This Date

  • ...in 1821, Missouri is admitted as the 24th state.
  • ...in 1831, William Driver of Salem, Massachusetts, is the first to use the term "Old Glory" in connection with the American flag.
  • ...in 1960, NASA launches Discoverer 13 satellite; it would become the first object ever recovered from orbit.
  • ...in 1977, US and Panama sign Panama Canal Zone accord, guaranteeing Panama would have control of the canal after 1999.