Pular para o conteúdo principal

Compartilhe

Verdade Inconfortável

Qualquer pessoa pode rastrear você online em menos de 10 minutos — e é completamente legal. Visual: tela preta + cursor piscando. Subtítulo: "O que é OSINT e por que isso muda tudo para sua empresa." 02 Slide OSINT não é espionagem. É investigação com dados que você mesmo deixou para trás. Open Source Intelligence = inteligência gerada a partir de fontes públicas: redes sociais, registros, domínios, metadados. Tudo legal. Tudo disponível. E tudo sobre você. 03 Slide Empresas perdem processos por não saber o que está publicado sobre elas. Documentos vazados, e-mails esquecidos, fotos com metadados, contratos em cache. A prova que condena sua empresa pode estar indexada no Google agora. 04 Slide Provas digitais têm validade legal — mas só se coletadas corretamente. Print de tela não serve em juízo. Hash criptográfico, timestamp certificado e cadeia de custódia são o que diferenciam evidência de suposição. 05 Slide O erro mais comum: descobrir a prova e destruí-la sem querer ao ...

NOVA ATUALIZAÇÃO DO IOS SOLUCIONA GRANDES BURACOS DE SEGURANÇA, ENTÃO FAÇA ISSO AGORA

APPLE UPDATES IOS with enough regularity that it begins to feel routine. And most time, it is, especially the farther you get from the company’s yearly, feature-packed version overhauls. iOS 10.2.1, released today, is not routine. In fact, it’s very important that you download it as soon as you reasonably can.
Most iOS updates involve security fixes of varying severity. iOS 10.2.1, though, protects against a wide range of potentially devastating attacks.
Apple details over a dozen vulnerabilities in all in the iOS 10.2.1 release, including 11 focused around WebKit, the browser engine behind Safari, the App Store, and lots of iOS apps. They also include two instances in which a malicious application could execute arbitrary code with kernel privileges, which is to say, it could take complete control of your device.
“It can add files, delete files, or execute any actions,” says JP Taggart, senior security researcher at Malwarebytes. “Want to record conversations and forward them to someone else? It can do that. Want to install additional malicious software? It can do that. Want to uninstall programs on the affected phone? It can do that. Want to hide these actions, programs and files from the user? It can do that too.”
Several of the WebKit vulnerabilities can also lead to arbitrary code execution, and may be even more alarming. That’s because while Apple can limit the number of malicious apps in its ecosystem through App Store vetting, WebKit presents a less filtered opportunity for malice.

If there’s a bright side to the update announcement, it’s that it took some of the best researchers to find them. Google’s Project Zero, in particular, reported nine of the vulnerabilities. It’s impossible to know for sure, but that makes it unlikely that either awareness or use of these opportunities were widely known among bad actors.
“These were some top notch hackers who found them, so the bar was quite high,” says iOS forensics expert Jonathan Zdziarski.
If they were used, says Taggart, it would most likely have been by nation-states against high-profile targets. And there’s likely not enough information in Apple’s disclosure to start a broader rash of attacks in the near future.
Still, all it takes to be sure in your security is a quick firmware update. When you have a good Wi-Fi connection, go to Settings > General > Software Update. Tap Download and Install. Go get a coffee or something, and by the time you’re back, you should be all patched up. (You can also update through iTunes, if you insist.)
Do it today, if you can. While the bad guys may not know exactly how to compromise your iPhone, they know that it’s possible. “They now know where to concentrate their efforts,” says Taggart,” and what will yield the best results.
Additional reporting by Andy Greenberg.
https://www.wired.com/2017/01/new-ios-update-fixes-big-security-holes-get-now

Comentários

Manual de Fontes Abertas

CLICA

Pericia Digital

Como usar um Agente OSINT IA

Postagens mais visitadas