Menu

Monthly Archives: February 2016

IBM to buy Resilient Systems, bringing security guru Bruce Schneier on board
Node.js 5.7 released ahead of impending OpenSSL updates
Five things you need to know about the EU-US Privacy Shield agreement
UC Berkeley makes third data breach disclosure in past 15 months
The “HawkEye” attack: how cybercrooks target small businesses for big money
Apple spells out what it would take to comply with government’s iPhone order
Google knows where your photos were taken
5 threats every company needs to pay attention to
How mobile apps leak user data that’s supposedly off-limits
Tor users being actively blocked on some websites
“Acceptable Ads”: Are there any? And who gets to monetize them?
How to avoid common travel and vacation scams
IRS: Actually, that breach last year was way worse than we thought
Disney rumored to be using anti-drone drones to protect Star Wars filming
Going to RSA? Get exclusive free swag!
UC Berkeley hit with another cyberattack

The University of California (UC), Berkeley, has revealed that it was the victim of a major cyberattack. It explained that the incident, which took place in December 2015, has affected close to 80,000 current and former members of staff and students. The victims have been notified with notice letters, which includes details about free credit […]

Monday review – the hot 24 stories of the week
Encryption still a low priority for too many cloud users
Most software already has a “golden key” backdoor: the system update
Hackers did indeed cause Ukrainian power outage, US report concludes

It was discovered that php-horde, a flexible, modular, general-purpose web application framework written in PHP, is prone to a cross-site scripting vulnerability. For the stable distribution (jessie), this problem has been fixed in version 5.2.1+debian0-2+deb8u3. For the testing distribution (stretch), this problem has been fixed in version 5.2.9+debian0-1. For the unstable distribution (sid), this problem […]

It was discovered that php-horde-core, a set of classes providing the core functionality of the Horde Application Framework, is prone to a cross-site scripting vulnerability. For the stable distribution (jessie), this problem has been fixed in version 2.15.0+debian0-1+deb8u1. For the testing distribution (stretch), this problem has been fixed in version 2.22.4+debian0-1. For the unstable distribution […]

Two SQL injection vulnerabilities were discovered in cacti, a web interface for graphing of monitoring systems. Specially crafted input can be used by an attacker in parameters of the graphs_new.php script to execute arbitrary SQL commands on the database. For the oldstable distribution (wheezy), these problems have been fixed in version 0.8.8a+dfsg-5+deb7u8. For the stable […]

Fixing the Internet’s routing security is urgent and requires collaboration

Intro from the 2016 Threat Brief: “2015 was yet another record year for cybercrime, during which more malware, malicious IPs, websites, and mobile apps were discovered than in any previous year. It comes as no surprise that the cybercrime ecosystem continues to thrive, given new innovations and little in the way of risk for those […]

Get into RSA 2016 free, meet our experts, hear great talks!
Why cybercrime isn’t fun and (video) games

For young people, the Internet can be a vital source of information, recreation, escape and more, but without the right guidance it can also be unsafe. Online games particularly make prime targets for cybercriminals, and there are also concerns that gaming networks can lead players astray, or even act as a criminal breeding ground. Whatever the reasons might […]

Apple will unbrick iPhones bricked by “1970” bug
Apple responds in iPhone unlocking case: US seeks “dangerous” powers
Facebook, Google, Microsoft to join tech industry in supporting Apple in court
Hospitals vulnerable to cyber attacks on just about everything
FBI, keep out! How to encrypt everything
Computers can tell if you’re bored

A lot happens in the security world and many stories get lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. Linux Distro Compromised This week, one of the largest Linux distro’s for Mint was targeted […]

Discovered: February 26, 2016 Updated: February 26, 2016 6:06:10 PM Type: Trojan Infection Length: Varies W97M.Downloader.F is a Word macro Trojan that downloads additional malware. For more information, please see the following resources: Antivirus Protection Dates Initial Rapid Release version February 26, 2016 revision 024 Latest Rapid Release version February 26, 2016 revision 024 Initial […]

Gustavo Grieco discovered that xerces-c, a validating XML parser library for C++, mishandles certain kinds of malformed input documents, resulting in buffer overflows during processing and error reporting. These flaws could lead to a denial of service in applications using the xerces-c library, or potentially, to the execution of arbitrary code. For the oldstable distribution […]

Daniel Gultsch discovered a vulnerability in Gajim, an XMPP/jabber client. Gajim didn’t verify the origin of roster update, allowing an attacker to spoof them and potentially allowing her to intercept messages. For the oldstable distribution (wheezy), this problem has been fixed in version 0.15.1-4.1+deb7u1. For the stable distribution (jessie), this problem has been fixed in […]

Multiple security issues have been found in Icedove, Debian’s version of the Mozilla Thunderbird mail client: Multiple memory safety errors, integer overflows, buffer overflows and other implementation errors may lead to the execution of arbitrary code or denial of service. For the oldstable distribution (wheezy), these problems have been fixed in version 38.6.0-1~deb7u1. For the […]

APPLE-SA-2016-02-25-1 Apple TV 7.2.1 Subject: APPLE-SA-2016-02-25-1 Apple TV 7.2.1 From: Apple Product Security <email@hidden> Date: Thu, 25 Feb 2016 10:58:54 -0800 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-02-25-1 Apple TV 7.2.1 Apple TV 7.2.1 is now available and addresses the following: bootp Available for: Apple TV (3rd Generation) Impact: A malicious Wi-Fi network may be […]

Apple appeals order to unlock iPhone, saying it would ‘violate the Constitution’
Microsoft strengthens security tools for Azure, Office 365
Nissan LEAF cloud security fail leaves drivers exposed
Why Facebook is using satellites to map every building in 20 countries
Tim Cook: The FBI is asking us to write the software equivalent of cancer
With few options, companies pay hush money to data thieves
Lawmakers push for encryption commission to find compromise
Breach of millions of kids’ images and messages sparks disclosure spat at uKnowKids
Exclusive: Go inside a security operations center
Celebrity nude photo hacker pleads guilty

Jakub Palaczynski discovered that websvn, a web viewer for Subversion repositories, does not correctly sanitize user-supplied input, which allows a remote user to run reflected cross-site scripting attacks. For the oldstable distribution (wheezy), this problem has been fixed in version 2.3.3-1.1+deb7u2. For the stable distribution (jessie), this problem has been fixed in version 2.3.3-1.2+deb8u1. We […]

lighttpd, a small webserver, is vulnerable to the POODLE attack via the use of SSLv3. This protocol is now disabled by default. For the oldstable distribution (wheezy), this problem has been fixed in version 1.4.31-4+deb7u4. We recommend that you upgrade your lighttpd packages.

BlackBerry eyes IoT, diversifies with new cybersecurity practice
Mousejacking: What you need to know
Porn clicker trojans keep flooding Google Play

ESET researchers have found 343 malicious porn clicker trojans, which ESET detects as Android/Clicker, on Google Play over the last seven months – and their numbers keep rising. In one of the largest malware campaigns on the Google Play Store yet, criminals continue to upload further variants of these malicious apps to the official app store […]

Porn clicker trojans at Google Play: An analysis

Malicious porn clickers are mostly fake versions of popular games with very similar names and icons to legitimate applications. For instance, there were more than 30 bogus Subway Surfers and more than 60 fake GTA applications. These apps have nothing in common with the official Subway Surfers or GTA games. The trojans were mostly devoid […]

Americans want to be safer online – but not if they have to do anything
German police given go-ahead to use home-brewed spying Trojan
Bill Gates takes issue with reports that he’s backing FBI over Apple
Attackers can turn Microsoft’s exploit defense tool EMET against itself
Tor users increasingly treated like second-class Web citizens
Here’s what tech leaders have said about the Apple-FBI dispute so far
Drupal 6 hits the end of the line
FBI backdoors force a rethink of BYOD
The Apple-FBI encryption fight: It’s not black and white
Review: 8 password managers for Windows, Mac OS X, iOS, and Android

Discovered: February 23, 2016 Updated: February 24, 2016 12:22:47 PM Type: Trojan Infection Length: 82,444 bytes Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Backdoor.Rifelku is a Trojan horse that opens a back door on the compromised computer. Antivirus […]

Aris Adamantiadis discovered that libssh, a tiny C SSH library, incorrectly generated a short ephemeral secret for the diffie-hellman-group1 and diffie-hellman-group14 key exchange methods. The resulting secret is 128 bits long, instead of the recommended sizes of 1024 and 2048 bits respectively. This flaw could allow an eavesdropper with enough resources to decrypt or intercept […]

Andreas Schneider reported that libssh2, a SSH2 client-side library, passes the number of bytes to a function that expects number of bits during the SSHv2 handshake when libssh2 is to get a suitable value for group order in the Diffie-Hellman negotiation. This weakens significantly the handshake security, potentially allowing an eavesdropper with enough resources to […]

Cyber threats come from a wide array of sources, but can be grouped into three categories: HacktivistsThese are tech-savvy individuals who are normally motivated by morality. These individuals are also classed by many (including the FBI) as terrorists. One of the main hactivist groups out there is anonymous. This group rose from one of the […]

Apple is reportedly fighting 12 more iPhone data extraction orders
The industrialization of cybercrime may be upon us

��}��8��o;����,�-R��R}Y��ew�wl����{gݾ H�$VQ$͏R�ݎ�w�?�w�qO��&�$� �$HQ*I%{���Ǔ���yN~8{����G�h�������S����=��I�G��7�)k��} ��y4a��߁’��єE����ؾ�i’�17���>��P��i�����pB��E�8�i�������ě�4�� �����,_եS�Ӯl6� RJ�l+��,ve��ԉ�ڑM=R���2Hc�;L��W,�G����E��m�{��q�y�zfQf�^�/o���___[��˲��ul�F�h� ؓ�����’�n�g���v�Ms�仓�ݧO̶�E�����% ����h�p� �K��P#Sfٴ����� tO�Cj��wU�Z,��~a�~e����7s�$d�v��Z�d��K�P� ��@�����ވ�!TG8���_�g�P��k��P �-Ck��H ���R�zC�j��F��h�h��:PIG�q��A��$�9l�C�W(��s����Q^�i�C�–����|d�A��w �q�(�~�!F�;G�ȓ�%�INe��u��Et�T͓A����_�qz�f�#�T��c���AU�h#Y�fKo����Q�y����fr�qᏕք����” i`)���tJ�������K�ށP/��|����-%�7������T�D���3F#/��8Y6�_$��U��W4 ����Tf��Oܨ��*PG�խ����[��уꯪֲ��q�8pX��v�3��jX�)��5���:�p�#�M� �aFh�^�G�b�z �ᎍQ�MO��=�,V��k�u�{��UO���z�ެՇF�=���՚�0wM�m֮�wa��$��^����F�U�[���͚’}�|W��3?�4e+h*��v����k���k����k�LlǪk��Q}��c ��!��>�4̟`0���S��x�㫟�wτ_>�P���e/e���`�%�6�E� ���Gu���]�����W�ŗv�͂���wU Z�k���2a̪�ߵ��!5΃##���*���ju�!K�j��U���7��G�KtW 5��`�>W���(�i�w������vؼ�r@���;������L���8S7�/�@G�����Ze_’�O�#b�i�_Y��k��i��_�J/�E��� �Mc�8�b�*��^�!|��ǻ��M]tT��a��V����`�1�t��Z!bIRY{zs� �!��}�qB}0�U�c`깸t�Eo%ފ�V�G+��~OPU��`�������G�ȋnדDX^E��޵���K��[��j�ST��m0��n’��7����h��7]X����Y��*}qdx^�C��;t9� �ag����V�zw�^��Y07�U���{p��>8� ��6����L/���h��`wx�`�^�n�,���8�� u��o�S3x���W�4��y3��^��0t�@�FV}KԂ��s/G a/�5’Q@”냴�Cϱ����7�]�������:/*��b��b�fZ&��E”Z��]$�3M�U�g�Oۮ>����(�@Fo�(�I�7.N<��f���9�;Prh�� m��1��@�1� ����s�!�7 Ѐ�!�b��0<�q�%+P�K�dO �eL��o�w��ſ�0T�EdM,e����O5X�%�c��v?�j���Y��SM�d�N������ ]B�(�Y�H��4��.��0?���D�[` ^�”��x�(uo���m�K����s_{3@x`������U��: 3��Q�(����8�T�V`��ƾf��R’s���T6A�#���_o�d�إ_UI�+z���zM���U�%��@�y�GRU���H=��zT�I�(t�+�[���&g��s*�&0ݟ�^H=��ۮc��E’J�rn���’�+q����q(���S’�) ƶ�G�_�������V/�������D�cC���,��E�L�C��Rk�&�`�A�x0’t�c~�.0*�3�?i��3Hܩ3�Z�0�La&b��Bq�M�M�aM^d��?����٣��g�¡�bY�(^��p7}�X�ؙf�X�L�)�?�Wk�ܝy�[�ʙ�:���F�79�����ȁ�@o�vz’F8a,��`׋��a�e!���?à�ɠ��i��G{��-‘�~�d8�z�m�������o�o�9a:�SL</頾�A�h�B�ϧ��e�̈��`0J�#�k����~�}p��XX`�&w[L����f!�L]2

Would you use an ATM that didn’t need a card…*or* a PIN?
Bill Gates backs the U.S. government in Apple’s iPhone privacy standoff
Startup touts four-factor authentication for VIP-level access
CloudFlare launches secure domain name management service
Resetting terrorist’s Apple ID password wasn’t a screwup, says FBI
Twitter password recovery bug potentially exposed data of 10,000 users
How techies are losing the Apple-FBI privacy fight
Why we must defend our last shred of privacy
Samsung comes at BlackBerry’s security crown — and will not miss
Texting-while-walking mishaps lead to relocation of giant sculpture
Digital childhoods: How different nations bring up their kids

Most parents think carefully about when to give their children their first set of house keys, or let them go out to play with no adult supervision. Yet in our digitalized world, the same caution should be exercised in the virtual world, such as on social networks or when giving children their first smart gadgets. […]

4 internet-savvy countries agree: Kids go digital too early

Nowadays, the internet and technology have become so important for business, travel and many other everyday tasks that they practically surround us all the time. This is true for the younger generation as well, including even the smallest children, but online surveys by ESET show that a majority of parents in Russia, the United Kingdom, […]

Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1622 It was discovered that a maliciously crafted extension could bypass the Same Origin Policy. CVE-2016-1623 Mariusz Mlynski discovered a way to bypass the Same Origin Policy. CVE-2016-1624 lukezli discovered a buffer overflow issue in the Brotli library. CVE-2016-1625 Jann Horn discovered a way to […]

Most Americans support the FBI over Apple, Pew study finds
Lesson from Linux Mint breach: Trust is not enough

A new form of ransomware has hit the scene, and although this one has a playful nickname it is no fun at all. The bad news is that “Locky” ransomware will encrypt virtually every commonly used file-type and targets not only local drives, but any networked drives it can find, even if they are unmapped. […]

Chinese devs abuse free Apple app-testing certs to install pirated apps
Linux Mint site hacked, users unwittingly download backdoored operating system

I hope you weren’t one of the hundreds of people who downloaded a compromised version of the Linux Mint operating system on Saturday. Because if you were, it’s possible that you’re not just running one of the more user-friendly flavours of Linux on your computer but also playing host to a Linux ELF trojan called […]

World’s biggest Linux distro infected with malware
<div>IRS reports 400% increase in phishing & malware in the past 12 months</div>
Going to Mobile World Congress? Get an exclusive freebie!
Lost at sea! Alleged Anonymous hacker found adrift near Cuba
Monday review – the hot 23 stories of the week
The security review: The state of security in companies in the EMEA region

Welcome to this week’s security review, which includes a detailed report from ESET on the state of information security in companies in the EMEA region, helpful advice on support scams and the rise of Android ransomware. The state of information security in companies in the EMEA region For this extensive report, ESET spoke to 1,700 […]

Hacker explains how he put “backdoor” in hundreds of Linux Mint downloads
Linux Mint hacked: Compromised data up for sale, ISO downloads backdoored