|
Dell announced today that they detected attackers in their systems on November 9th, 2018 who were attempting to extract customer information from the Dell.com, Premier, Global Portal, and support.dell.com sites. According to Dell's breach notification, they detected unauthorized users in their systems on November 9th, 2018. These attackers were trying to retrieve customers information from Dell.com accounts that included names, email addresses, and hashed passwords. "On November 9, 2018, Dell detected and disrupted unauthorized activity on our network that attempted to extract Dell.com customer information, limited to names, email addresses and hashed passwords," stated Dell's security disclosure. "Upon detection, we immediately implemented countermeasures and began an investigation. We also retained a digital forensics firm to conduct an independent investigation and engaged law enforcement." While their investigation did not reveal that any information was stolen, Dell decided to perform a mandatory reset on all Dell.com accounts. This password resets will occur when the user next logs in. You can find the security disclosure on OUR FORUM. When users have been installing Sennheiser's HeadSetup software, little did they know that the software was also installing a root certificate into the Trusted Root CA Certificate store. To make matters worse, the software was also installing an encrypted version of the certificate's private key that was not as secure as the developers may have thought. Similar to the Lenovo SuperFish fiasco, this certificate and its associated private key, was the same for everyone who installed the particular software. Due to this, it could allow an attacker who was able to decrypt the private key to issue fraudulent certificates under other domain that they have no control over. This would allow them to perform man-in-the-middle attacks to sniff the traffic when a user visits these sites. While these certificate files are deleted when a user uninstalls the HeadSetup software, the trusted root certificate was not removed. This would allow an attacker who had the right private key to continue to perform attacks even when the software was no longer installed on the computer. According to a vulnerability disclosure issued today by security consulting firm Secorvo these certificates were discovered when doing a random check of a computer's Trusted Root Certificate CA store. Learn more from OUR FORUM. A new patent application suggests that Microsoft could be working on a device that will come with the multi-part camera system. According to the patent, the camera system will have a body and a flexible mount, and it would be able to reduce the tilt error. First noticed by us, the patent titled “Self-aligning multi-part camera system” was published by USPTO earlier today and filed by Microsoft in 2016. “In some multi-part electronic devices, at least two of the multiple parts can be positioned to overlap each other to provide a specific operation for the camera. As just one example, the overlapped mode may provide for additional focusing options based on using optical elements in a second part of the device with a main camera part in a first part of the device when the first and second parts of the device are overlapped,” Microsoft explains in the background section of the patent application. The device feature multiple displays or body parts with one part comprising a camera and there is another camera module which is mounted on the second part of the device. Want to know more visit OUR FORUM. |
Latest Articles
|


