loc

SunOS 5.10 Generic_147148-26 Local Privilege Escalation

SunOS version 5.10 Generic_147148-26 local privilege escalation exploit. A buffer overflow in the CheckMonitor() function in the Common Desktop Environment versions 2.3.1 and earlier and 1.6 and earlier, as distributed with Oracle Solaris 10 1/13 (Update 11) and earlier, allows local users to gain root privileges via a long palette name passed to dtsession in a malicious .Xdefaults file.




loc

Solaris xlock Information Disclosure

A low impact information disclosure vulnerability in the setuid root xlock binary distributed with Solaris may allow local users to read partial contents of sensitive files. Due to the fact that target files must be in a very specific format, exploitation of this flaw to escalate privileges in a realistic scenario is unlikely.




loc

Common Desktop Environment 1.6 Local Privilege Escalation

A buffer overflow in the _SanityCheck() function in the Common Desktop Environment version distributed with Oracle Solaris 10 1/13 (Update 11) and earlier allows local users to gain root privileges via a long calendar name or calendar owner passed to sdtcm_convert in a malicious calendar file. The open source version of CDE (based on the CDE 2.x codebase) is not affected, because it does not ship the vulnerable program. Versions 1.6 and below are affected.




loc

NTCrackPipe 1.0 Local Windows Account Cracker

NTCrackPipe is a basic local Windows account cracking tool.





loc

FreeBSD Bug Grants Local Root Access








loc

Avast Anti-Virus Local Credential Disclosure

Avast Anti-Virus versions prior to 19.1.2360 suffer from a local credential disclosure vulnerability.




loc

OpenSMTPD 6.6.1 Local Privilege Escalation

smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell meta-characters in a MAIL FROM field. This affects the "uncommented" default configuration. The issue exists because of an incorrect return value upon failure of input validation.




loc

Fintech Locations of the Future 2019/20: London tops first ranking

London has been named fDi’s inaugural Fintech Location of the Future for 2019/20, followed by Singapore and Belfast. 




loc

Tourism Locations of the Future 2019/20 – FDI Strategy

Australia tops the FDI Strategy category of fDi's Tourism Locations of the Future 2019/20 rankings, followed by Costa Rica and Azerbaijan.




loc

Thousands Of Servers Infected With Lilocked Ransomware




loc

man-cgi Local File Inclusion

man-cgi versions prior to 1.16 suffer from a local file inclusion vulnerability.




loc

Keep Your Data Safe: The Joy of Locking Your Computer

Here's a simple way to keep your data safe from potential bad actors in one easy step. Are you ready? Here it is: Log out and lock your computer whenever you're not in front of it.

That's right, it's so simple it can almost be seen as an analog approach to cybersecurity. But make no mistake, all those in-depth disk encryption efforts can be rendered pointless. If you step away from your computer while it's on and unlocked, anyone passing by can access it.

Working Remotely Promotes Data Vulnerability

What's perhaps most insidious about someone gaining physical access to your computer is the fact that the attacker doesn't need any advanced technical know-how to steal sensitive information. A momentary lapse in vigilance at work or a coffee shop can result in a data breach of epic proportions.

Let's say you're working remotely at your favorite café down the street from your apartment and you get up to put in an order for a late breakfast, forgetting to lock your laptop. During that brief moment, a low-key cybervillian could easily stick a USB drive into your computer and copy any sensitive files about you — or your organization — and leave undetected.

Furthermore, if you were logged in to Gmail, your medical records, or your bank account, that malefactor could wreak havoc on your personal and professional life in a matter of minutes.

Tips for Protecting Yourself

The good news about all of this is that warding off these types of would-be data plunderers is really, really easy — it's simply a matter of using your operating system's screen locking functionality. If you don't want to do this, then at the very least you should log out of any sensitive online accounts whenever you step away from your machine.

For each of the following options, be sure you are aware of the password connected to your user login before locking yourself (or anyone else) out.

Screen Locking in Microsoft Windows

  • Press Ctrl+Alt+Delete and select Lock this computer
  • Press Windows+L

Either of these will lock your computer and require a password to log back in. You can choose Control Panel > Personalization > Screen Saver Settings and set up a screen saver that provides a login screen to get back in once it's been initiated.

Screen Locking in macOS

  • On an external keyboard or older laptops, press Ctrl+Shift+Eject
  • On a MacBook Air or Pro Retina, press Ctrl+Shift+Power

You can also go to System Preferences > Security & Privacy > General and select Require password immediately after sleep or screen saver begins (provided you have already set up a screen saver by clicking System Preferences > Desktop & Screen Saver).

Additional Cybersecurity Resources

Get more security tips from the National Cyber Security Alliance. National Cyber Security Awareness Month — observed every October — was created as a collaborative effort between government and industry to ensure that all Americans have the resources they need to stay safer and more secure online. Find out how you can get involved.

Image: National Cyber Security Alliance





loc

View from Europe: will European investment go local?

Long-dominant global supply chains look less tenable in the light of pressures ranging from pandemics to disasters, trade tensions and protectionism.




loc

Dublin tops European HQ location rankings

The UK is the top country, but Dublin is leading city, for foreign companies setting up headquarters in Europe, according to fDi’s ranking.




loc

Reforms could unlock African development, reports McKinsey

Continued African development could hinge on public finance reforms.




loc

Group effort helps The Fresh Market stay local

Financial incentives from two different cities persuaded US grocery chain The Fresh Market to stay headquartered in its home state of North Carolina.




loc

Balochistan representative hails new dawn

Sardar Popalzai, president of the Balochistan Economic Forum, talks about the blue economy and the Pakistani province’s tourism potential.




loc

EWF launches world’s first open source blockchain for the energy industry

The Energy Web Foundation (EWF) this week announced that it has launched the world’s first public, open-source, enterprise-grade blockchain tailored to the energy sector: the Energy Web Chain (EW Chain). As a refresher, blockchain allows for peer-to-peer energy market transactions.




loc

Clearway Energy sets up blockchain test to trade renewable energy credits

Clearway Energy Group, one of the U.S.’s largest clean power developers, is launching a pilot electronic marketplace for renewable energy credits as more states push for solar and wind projects.




loc

Lincoln Clean Energy: Texas' Lockett Wind project commercially operational

The Lockett Wind farm in Wilbarger has the potential to generate more than 700,000 MWh of renewable energy per year, enough to power the equivalent of 70,000 homes. 




loc

New study shows benefits of local renewable energy marketplaces

The financial benefits of buying and selling locally produced energy from rooftop solar, wind turbines and batteries within communities have been revealed in a test case run by energy tech firm LO3 Energy.




loc

Japanese businesses test blockchain to trade renewable energy

This week independent power producer Marubeni and LO3 Energy said they have started a pilot project in Japan where LO3 will administer an energy marketplace using blockchain to connect a number of Marubeni’s power production facilities, including renewables, with offices and factories around Japan in a virtual marketplace. The project will simulate energy transactions to test the viability of the concept with the ultimate goal of creating a full-scale commercially operational network in the future.




loc

UK local authority to produce all electricity from solar

Two large-scale solar farms are set to make Warrington Borough Council the first local authority in the UK to produce all its own electricity from clean energy.




loc

World’s largest utility joins EWF’s energy blockchain ecosystem

Last week, the Energy Web Foundation (EWF) announced it had officially signed more than 100 affiliates in an effort to become the world’s largest blockchain ecosystem.




loc

Ameren tests software that could unlock future ‘transactive energy marketplace’

Ameren is preparing to test a Canadian company’s software that could someday help usher in a radically different business model for the utility.




loc

Clearway Energy sets up blockchain test to trade renewable energy credits

Clearway Energy Group, one of the U.S.’s largest clean power developers, is launching a pilot electronic marketplace for renewable energy credits as more states push for solar and wind projects.




loc

Singapore-based Blockchain Company Sparks Interest from TEPCO

According to Martin Lim, COO of Electrify.Asia, a company facilitating peer-to-peer energy trading across the distribution grid, blockchain technology doesn’t take utilities out of the equation, but rather it adds another layer of potential revenue for them and helps reduce the cost of delivering energy to homes and businesses.





loc

Scientists Say Blockchain ‘Delivering on Energy Promises’

One of the first unbiased, major comprehensive reviews of blockchain has concluded that the technology is “actually delivering on its promises in a number of areas directly related to energy”.




loc

Japanese businesses test blockchain to trade renewable energy

This week independent power producer Marubeni and LO3 Energy said they have started a pilot project in Japan where LO3 will administer an energy marketplace using blockchain to connect a number of Marubeni’s power production facilities, including renewables, with offices and factories around Japan in a virtual marketplace. The project will simulate energy transactions to test the viability of the concept with the ultimate goal of creating a full-scale commercially operational network in the future.




loc

World’s largest utility joins EWF’s energy blockchain ecosystem

Last week, the Energy Web Foundation (EWF) announced it had officially signed more than 100 affiliates in an effort to become the world’s largest blockchain ecosystem.




loc

Ameren tests software that could unlock future ‘transactive energy marketplace’

Ameren is preparing to test a Canadian company’s software that could someday help usher in a radically different business model for the utility.




loc

Boeing to launch Australia’s first locally built combat aircraft since 1942

The Boeing Company is set to design and build a large, military unmanned air vehicle (UAV) in Australia, with the first flight set for 2020. The Australian government will invest A$40 million in the project.




loc

Australian Clean Energy Deadlock Spurs Companies to Focus Abroad

Political deadlock over Australia’s clean energy future is prompting companies such as Vestas Wind Systems A/S and Acciona SA to increasingly turn to rival markets for growth.




loc

NHA launches UnlockHydro initiative

An educational campaign announced this week by the National Hydropower Association aims to increase awareness about the hydroelectric sector amongst the public and policymakers.




loc

NHA launches UnlockHydro initiative

An educational campaign announced this week by the National Hydropower Association aims to increase awareness about the hydroelectric sector amongst the public and policymakers.




loc

Indian Cabinet approves US$854.4 million investment for 900-MW Arun 3 hydropower project located in Nepal

India’s Cabinet Committee on Economic Affairs announced today it has approved investment for the generation component of the 900-MW Arun 3 hydropower project on Arun River in Sankhuwasabha district of eastern Nepal, for an estimated Rs. 5723.72 crore (US$854.4 million).