Vulnerabilities

I hear you. I listened to you. And I removed the comment.

I am sorry.

1 Like


Update your VLC media player.

1 Like

Update vlc because Trump started a crypto war? Did you post wrong link?

How about you just read the liked article?

Cop a load of this: 1TB of police body camera videos found lounging around public databases

1 Like

Sorry in area with extremely limited connectivity links take mins not secs to load

US Cyber Command warns that the Outlook is not so good - Iranians hitting email flaw

1 Like
5 Likes

Why does the mail program even let someone run a batch file from an email?

2 Likes

This reminds me of the Poweliks malware. A friend’s computer was infected with this and it was a huge pain to find it and neutralize it.

It was an incredibly clever way to infect the system.

1 Like

Two pentesters, one glitch: Firefox browser menaced by ancient file-snaffling bug, er, feature

1 Like

(Updated)

Anyone for unintended ChatRoulette? Zoom installs hidden Mac web server to allow auto-join video conferencing

1 Like
1 Like

Bostanov suggests a scenario where a user is persuaded to download a malicious HTML file through the usual tricks (“Click here for your free iPad!”)

No need for that. Firefox will quietly accept a file attachment and save it to your download folder, unless they’ve fixed that old old error since last October. Maybe I should point that out to them?

1 Like

So I get an email from Airbnb telling me that someone has added a new phone number to my account. Except I don’t really remember ever setting an account up.

I check the hyperlink and it appears to be pointing to the the legitimate url, so I click on it. It has my (junk) mailbox and a variation of my name on it, but it has phone numbers associated with the account that aren’t mine, and active sessions in countries that i haven’t been to. I delete those sessions. Then I close the sessions and go back to the site, this time manually typing the url. I click on the “I forgot my password” link and have it reset the password and email me a new one. I reset the password to something really long and log in.

There’s not much associated with the account. No indication that it was ever used to book a rental.

I click on the link to close the account. It makes me answer some questions but eventually dumps me into a live-chat session with an account specialist, who will be with me in a moment.

6 hours later, with no account specialist materializing, I close the browser tab.

5 Likes

Brilliant Boston boffins blow big borehole in Bluetooth’s ballyhooed barricades: MAC addy randomization broken

2 Likes

Does this happen if you’ve config’d FF to ask where to save things?

1 Like

boffin is one of those words that is english in the sense that no one outside of england seems to use it

1 Like

I never really investigated. The bug I was fixing was “Why is it saving these pages from my server silently instead of displaying them?” and I fixed that. Probably. :thinking:

It’s a perfectly cromulent word. But you need a lab-coat and a pipe to pull it off.

2 Likes