720-891-1663

Oh, You Wanted That App to be Secure?

As an experiment, researchers at the University of Bonn posed as a client trying to develop software.  They hired 43 freelance software developers from Freelancer.com  for either 100 Euros or 200 Euros. They asked the freelancers to develop a small part of a fictitious web site, the site’s registration system. Since this was a university […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Security News bites for the Week Ending March 8, 2019

Commerce Department Wants Companies to Publish Ingredients of their Software The Commerce Department is trolling around the RSA conference trying to get companies to publish the ingredients in their software – the so called bill of materials that I have written about before – so that users can understand what libraries are being loaded.  The […]

Continue reading → [DISPLAY_ACURAX_ICONS]

One in Three Companies Suffered Data Breaches Due To Mobile Malware

As people use their mobile devices as what one friend used to call a “pocket super computer” as opposed to something where you dial 7 digits (remember that) and talk to someone, hackers have figured out that the new attack vector is your phone. In part, this is due to the fact that finally, after […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Adobe Releases Emergency Patch For Cold Fusion

Adobe seems to have trouble catching a break sometimes, Today they released an emergency patch for a vulnerability in the Cold Fusion application that Adobe bought in 2005. The bug allows an attacker to bypass the file upload restrictions, allowing an attacker to upload a malicious executable and then get the target system to execute […]

Continue reading → [DISPLAY_ACURAX_ICONS]

This is Why I am So Adamant About the Importance of Patching

Just ONE day after the announcement of the NINETEEN YEAR OLD bug in the very popular WinRAR utility, Checkpoint Software found examples of it being exploited in the wild.  Given that the vast majority of the 500 million copies  will likely NEVER be patched and the fact that the bug allows the hacker to take […]

Continue reading → [DISPLAY_ACURAX_ICONS]