Smartphone manufacturer Xiaomi downloads all personal data

International Business Times  story The Xiaomi phones are sold in China and the head of global expansion was a Google executive. F-Secure a Finnish co.   and their blog: Finances of F-secure and more I know them as an Anti-Virus company among other things.  

JimmyJohn’s investigating breach with customer credit cards

KrebsonSecurity has the story.  There was unauthorized card activity known due to cards that were created by the stolen card data. (this credit card fraud is called “card-present”) The speculation is that JimmyJohn’s has been breached and at this point we are waiting for JimmyJohn’s investigation.   In the meantime if you want a delicious … Read more

Symantec end point protection got Owned

Offensive Security has the information. As Offensive  Security was performing a pentest, they noticed that Symantec Endpoint protection had a flaw -one that allows the hacker to escalate security privileges.   This is very bad as it is not a direct execution flaw, but it is a stealth method.   So one never notices as … Read more

2Q report by IBM X-Force, 23% of websites vulnerable.

CSRF or Cross Site Request forgery is the highest likely method of attack Broken Authentication is second And cross-site scripting(XSS) is third SQL Injection as well as security misconfigurations are also higher than 10% of he vulnerability types.   The IBM report at X-Force blog  recounts the challenges a web application scanner has as to … Read more