In-brief: RESTful application program interfaces (APIs) are a key ingredient to building powerful, scalable web-based applications. But they can also open the door to web-based attacks, while also baffling traditional penetration testing tools and processes. In this article, Barracuda’s Neeraj Khandelwal explains why.
Software
Hard Coded Password Sinks Fleet of DSL Routers
In-brief: A hard coded firmware password could provide remote hackers with access to a wide range of home broadband routers, underscoring the risk posed by shared hardware and software, according to an alert from Carnegie Mellon University’s CERT this week.
The Internet of Things has an Infrastructure Problem
In-brief: will the development of the Internet of Things stall because of a lack of investment in supporting wireless infrastructure? A panel at a recent conference warned that it is possible.
Plug and Pray? Virta Labs Using Power Analysis to Spot IoT Compromises
In-brief: A start-up, Virta Laboratories, says that its new PowerGuard technology can spot malicious software infections on any device by studying changes in how it consumes electricity. The technology has big implications for managing risk on the Internet of Things.
Facebook Awards $100k for Fix to Common C++ Flaw
In-brief: Facebook said on Wednesday that it was doubling the amount of its Internet Defense Prize, awarding $100,000 to a group of researchers from Georgia Tech for work on static type casting vulnerabilities.