Yikes! Vim is included in nearly all GNU/Linux and BSD distributions, so this is quite a significant vulnerability, even though comparatively few end-users actually directly use it. https://arstechnica.com/information-technology/2019/06/if-you-havent-patched-vim-or-neovim-text-editors-you-really-really-should/
ETHICAL HACKING NET-185-001N Week 13
HP's new security controller ( https://www.anandtech.com/show/14225/hps-security-push-sure-sense-endpoint-security-controller ) sounds interesting, but it definitely needs to be sufficiently hardened to make it worthwhile. The idea is to use AI to detect malware based on behavior, to protect against zero-day exploits and such. A disturbing development that I just read about is the 'Land Lordz' scam using other domains to get people to make cash deposits for listings on AirBNB that are not legitimate. ( ‘Land Lordz’ Service Powers Airbnb Scams ) One of the stranger recent security occurrences was that a poorly documented security feature in Microsoft Edge breaks another security feature (marking a file as from the web) that causes a certain type of file, the MHT file, to be opened without a sandbox using Internet Explorer, since it is the default to open that type of file. ( https://arstechnica.com/information-technology/2019/04/unexpected-security-feature-in-micros...
Comments
Post a Comment