Showing posts with label Security Tips. Show all posts
Showing posts with label Security Tips. Show all posts
Sunday
Disabling Flash in browser may not be enough to secure your machines
Disabling Flash in your PC browser may help stave off online attacks, but it may still not be enough, a security vendor warns.
Fortinet said Flash files can also be embedded in various document formats including Microsoft Office documents and even PDF files.
"Even if you have disabled Flash in your browsers, Flash exploits can still leverage Flash player vulnerabilities through software like Microsoft Office and Adobe Reader," Fortinet's Bing Liu said in a blog post.
As proof of concept, Liu crafted a PowerPoint file that would cause the caculator program to pop up when loaded in apps with a vulnerable Flash plugin.
The Flash exploit "works well inside a PPT and PDF document until I uninstall the Flash player on my computer," Liu said.
Such a situation "is just one simple example of ways in which Flash can be exploited outside of a web browser," Liu added.
"What all this means, unfortunately, is that disabling the Flash plugin in your browsers isn't a complete solution to Flash security. Flash is a technology that can be embedded in many places and requires vigilance on the part of users as well as smart edge and endpoint protection and rigorously patched software to ensure that Flash exploits don't end up on your network," Liu said. — Joel Locsin/LBG, GMA News
source: gmanetwork.com
Friday
After hacking, Yahoo Mail users advised to reset passwords, heed security tips
Following an attack on January 30, Yahoo Mail prompted affected users to reset the passwords of their email accounts.
The attack was billed as “coordinated effort to gain unauthorized access to Yahoo Mail accounts.” Yahoo Senior Vice President of Platforms and Personalization Products Jay Rossiter has since stated in the company's official blog that a list of usernames and passwords were likely collected from a compromised third-party database, and that they have “no evidence that they were obtained directly from Yahoo’s systems."
“Our ongoing investigation shows that malicious computer software used the list of usernames and passwords to access Yahoo Mail accounts. The information sought in the attack seems to be names and email addresses from the affected accounts’ most recent sent emails,” he said.
Aside from resetting passwords of hacked accounts, Yahoo Mail has also prompted second sign-in verification to “allow users to re-secure their accounts.”
Users may also receive an email notification or a text message asking them to chage their passwords if they have not yet been already prompted.
Rossiter also said that Yahoo has implemented additional measures to block attacks against its systems. Yahoo also sought assistance from federal law enforcement to find and prosecute the perpetrators of the attack.
Rossiter advised users to adopt better password practices like changing passwords regularly and using different variations of symbols and characters to help keep their accounts secure. He also advised them never to use the same password on multiple sites or services since these make users vulnerable to attacks of this kind.
“We regret this has happened and want to assure our users that we take the security of their data very seriously,” he said. — Kim Luces / KDM, GMA News
source: gmanetwork.com
Subscribe to:
Posts (Atom)


