This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.
The teenage author of the Mikeyy and StalkDaily worms that hit Twitter users hard one weekend ago appears to have struck lucky. As a result of his infamy, he has a brand new job.
The teenage author of the Mikeyy and StalkDaily worms that hit Twitter users hard one weekend ago appears to have struck lucky. As a result of his infamy, he has a brand new job.In a move that is likely to disgust many who are involved in protecting computers against security threats, a Web applications development company called ExqSoft Solutions has hired 17-year-old Mikeyy Mooney.
Interestingly, Travis Rowland, CEO of ExqSoft Solution, was quick to publicize Mooney's signing:
In my opinion, ExqSoft Solutions was utterly irresponsible in offering Mooney the job and publicizing his acceptance -- less than a week after the first wave of attacks.
The last thing we want is a legion of other kids exploiting software and Websites in the hope they, too, might be rewarded with a job offer.
Graham Cluley is senior technology consultant at Sophos, and has been working in the computer security field since the early 1990s. When he's not updating his other blog on the Sophos website you can find him on Twitter at @gcluley. Special to Dark Reading.
Enterprise Vulnerabilities From DHS/US-CERT's National Vulnerability DatabaseCVE-2019-4031 PUBLISHED: 2019-10-16
IBM Workload Scheduler Distributed 9.2, 9.3, 9.4, and 9.5 contains a vulnerability that could allow a local user to write files as root in the file system, which could allow the attacker to gain root privileges. IBM X-Force ID: 155997.
ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document with '<span color="' followed by arbitrary Python code.
The Yale Bluetooth Key application for mobile devices allows unauthorized unlock actions by sniffing Bluetooth Low Energy (BLE) traffic during one authorized unlock action, and then calculating the authentication key via simple computations on the hex digits of a valid authentication request. This a...
There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occurs due to incorrect sanitization of the name field when being processed and stored. This allows a user to craft a payload for Node.js and Electron, such...
In X.Org X Server 1.20.4, there is a stack-based buffer overflow in the function XQueryKeymap. For example, by sending ct.c_char 1000 times, an attacker can cause a denial of service (application crash) or possibly have unspecified other impact.