Maximum Lifespan of SSL/TLS Certificates is 398 Days Starting Today

The Hacker News-- Starting today, the lifespan of new TLS certificates will be limited to 398 days, a little over a year, from the previous maximum certificate lifetime of 27 months (825 days). In a move that's meant to boost security, Apple, Google, and Mozilla are set to reject publicly rooted digital certificates in their … Continue reading Maximum Lifespan of SSL/TLS Certificates is 398 Days Starting Today

Cisco Issues Warning Over IOS XR Zero-Day Flaw Being Targeted in the Wild

The Hacker News-- Cisco has warned of an active zero-day vulnerability in its router software that's being exploited in the wild and could allow a remote, authenticated attacker to carry out memory exhaustion attacks on an affected device. "An attacker could exploit these vulnerabilities by sending crafted IGMP traffic to an affected device," Cisco said … Continue reading Cisco Issues Warning Over IOS XR Zero-Day Flaw Being Targeted in the Wild

Apple’s notarization process fails to protect

Malwarebytes Labs-- In macOS Mojave, Apple introduced the concept of notarization, a process that developers can go through to ensure that their software is malware-free (and must go through for their software to run on macOS Catalina). This is meant to be another layer in Apple’s protection against malware. Unfortunately, it’s starting to look like … Continue reading Apple’s notarization process fails to protect

Lock and Code S1Ep14: Uncovering security hubris with Adam Kujawa

Malwarebytes Labs-- This week on Lock and Code, we discuss the top security headlines generated right here on Labs and around the Internet. In addition, we talk to Adam Kujawa, security evangelist and director of Malwarebytes Labs, about “security hubris,” the simple phenomenon in which businesses are less secure than they actually believe. Ask yourself, … Continue reading Lock and Code S1Ep14: Uncovering security hubris with Adam Kujawa