back to article Palo Alto gateway security alert, FSB hack, scourge of data-stealing web plugins, and more

Let's catch up with all the recent infosec news beyond what we've already covered. Palo Alto Networks gateway apps vulnerable to hijacking If you're using Palo Alto Network's GlobalProtect Portal or Gateway, ensure you're using the latest version of the software. The biz quietly issued a maintenance update to close a security …

  1. Ken Moorhouse Silver badge

    servicing a cracked windshield.

    A windows vulnerability that had absolutely nothing to do with Microsoft.

  2. Blazde Silver badge
    WTF?

    Bluetooth hair straighteners

    "Whilst reverse engineering the BLE communications was an interesting challenge, it’s not actually necessary. As there is no pairing or bonding established over BLE when connecting a phone, anyone in range with the app can take control of the straighteners."

    Good. This product doesn't deserve any security.

  3. Ken Moorhouse Silver badge

    Bluetooth haircare is hot, hot, hot

    Neat: Hair straighteners that style sideburns too.

  4. Ken Moorhouse Silver badge

    BLE

    You can now have a fry-up on your head.

    (Think bacon rather than beacon)

  5. Charles 9

    What I'd like to see is some Turing-luke proof that ANYTHING "smart" CAN and WILL be hacked to cause physical harm, then present the proof to mainstream news as a means to convince legislators to regulate such products to save lives.

    1. hmv

      Indeed. It's all to easy to forget in our rush to condemn those who fail to update (which I've just done myself) that each and every patch is in essence a product recall for a serious fault. Perhaps when we update we should be billing the vendor for the time required.

    2. GrapeBunch
      Mushroom

      What I'd like to see is some Turing-like proof that ANYTHING "smart" CAN and WILL be hacked to cause physical harm, then present the proof to mainstream news as a means to convince legislators to regulate such products to save lives.

      Including electrical or gas board smart meters. The challenge to attackers, whether state-sponsored or mischievous kiddies, is substantial. But the scale of damage possible is staggering. </rant>

  6. hmv

    Palo Alto: Why Keeping Up To Date Is Good ...

    To those who aren't aware, it's worth pointing out that the latest version of 8.1.x is 8.1.9 and 8.1.3 was released in August 2018; if you're that far out of date, you haven't been paying enough attention.

    1. Anonymous Coward
      Anonymous Coward

      Re: Palo Alto: Why Keeping Up To Date Is Good ...

      While keeping up-to-date is a good thing, let's discuss why Palo Alto decided it's vulnerabilities don't warrant CVE's?

      I mean I could speculate what those reasons may be...

  7. Pascal Monett Silver badge

    Death Wish, the new version

    I sure hope those guys at 0v1ru$ are not based in Russia or thereabouts. That contractor will never be heard of again, and if those hackers are not on another continent, I think they are going to have to learn to live while looking over their shoulders for the rest of their lives.

    The CIA, the DoD, the FBI, they can impress you, but the FSB is going to send a team to kill you. After interrogation. Painful interrogation.

    1. Anonymous Coward
      Anonymous Coward

      Re: Death Wish, the new version

      You make it sound like that's a bad thing. I disagree.

    2. Anonymous Coward
      Anonymous Coward

      Re: Death Wish, the new version

      How do they deal with orphaned masochists?

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like