Menu

Monthly Archives: March 2016

Trolls who use fake profiles to torment others to be prosecuted
RSA: Will your next phone have quantum cryptographic 2FA?

��}��F��o)��P�&�”��R�H�Ԓǚ�,�[�W�v�”�n���l����k#�”�.�`�M�I.3� �f�)پ�f,�@UVVVfVVVV��{��������ׯ���}&�EO;�Xx��n�Y�WO��e����1#�xhh�ٯ��_�����$�3p�^�� {$�U=>=������c��-.K��ω���]�kWA���F��¸�3t,@��r�O~�/����0�s_w����?’/o����8�:���&�w���l�s`�_��t����wv�����Z����w���=mw%,��L���Y(ܞ�3WDc!�1�_�݊”�M�����_�0�=M �t:5��u.D$�$t�i��40R�x,&”j�w�֤��et�=����{��ލ��!����3q�!l6u�1`�`�ѿ�8vbW���l�_[/Źy�r-Iu�”<�xh�Z��Ʉ�3mI�?�-���4ΒPJr���8zK��O���%?�,c�P����N�M�ϣ���x�79�I�<�=���6����ևw�0��=��&y��I�4��|A�’Y���!X�@���GZ���X1R;����П��~�ۢ�����k���;�칵_o��z�2c�9��O?���MWx�x��n�p�����`���z6v�%�0B�����F�n����[���{�bM�Տ,3 �Gd+ٱ1�VU�����”Q�p�աU�����5�~�-#����z�”g�cC����T�D�� �����w� �B|ױ���.�a�`q�fk�a�N�~Ȟ�`Y�v�_u 3Ȍ���~�t��9a”j���á�4΃C3����S�� �J����U ۷���UG �)٪Oj�M�Y��3|#�8��5�’b��ޱ�(p��֬(���8�3�O}�6�h���јZU_����C���ZW�S��!k1��_�J/ƕ���2Z��Q�’�]�O�C���Ww˕f~e���:s�����=`���ia dՙ7�kO�r΂��o�o �]723#�YhL|�sů��������[�Ys������י)4��4��Cޮ’�M���e����s.|�E)AI�2��gr�ls��Ő’n���E� �X���-Q�j�!f����`��N@�>5�=2Zh�l 7CE���:�F�~�B�?�G1����:N3��b��C�Y3���!z�1��LKTAj��.����è`���p�=��+�ۣ0a”���Z�ѹ�ϲ���+��P��v:u�z�*�

This state wants to ban gun-toting, flame-shooting, gas-spraying drones
8 fears keeping security professionals up at night
Teacher resigns after student shares nude photos found on her unlocked phone
DROWN Flaw Illustrates Dangers of Intentionally Weak Crypto
Hacker Says He Can Hijack a $35K Police Drone a Mile Away
US to renegotiate rules on exporting “intrusion software”
New attack steals secret crypto keys from Android and iOS phones

Discovered: March 4, 2016 Updated: March 4, 2016 2:54:01 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows Me, Windows NT, Windows Vista, Windows XP Trojan.Snifula.F!gm is a heuristic detection used to detect threats associated with the Trojan.Snifula.F family. Antivirus Protection Dates Initial Rapid Release version March 4, 2016 revision 019 […]

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service, information leak or data loss. CVE-2013-4312 Tetsuo Handa discovered that users can use pipes queued on local (Unix) sockets to allocate an unfair share of kernel memory, leading to denial-of-service (resource exhaustion). This issue was previously […]

Ralf Schlatterbeck discovered an information leak in roundup, a web-based issue tracking system. An authenticated attacker could use it to see sensitive details about other users, including their hashed password. After applying the update, which will fix the shipped templates, the site administrator should ensure the instanced versions (in /var/lib/roundup usually) are also updated, either […]

The update for linux issued as DSA-3426-1 and DSA-3434-1 to address CVE-2015-8543 uncovered a bug in ctdb, a clustered database to store temporary data, leading to broken clusters. Updated packages are now available to address this problem. For the oldstable distribution (wheezy), this problem has been fixed in version 1.12+git20120201-5. For the stable distribution (jessie), […]

PHP.Cryptolocker.G is a Trojan horse that encrypts files on the compromised computer and then prompts the user to purchase a password in order to decrypt them. For more information on ransomware, see our blog: The dawn of ransomwear: How ransomware could move to wearable devices

Risk High Date Discovered February 12, 2008 Description Microsoft Publisher is prone to a remote code-execution vulnerability. An attacker could exploit this issue by enticing a victim to open a malicious Publisher file. Successfully exploiting this issue would allow the attacker to execute arbitrary code in the context of the currently logged-in user. Technologies Affected […]

Risk High Date Discovered February 12, 2008 Description Microsoft Publisher is prone to a remote code-execution vulnerability. An attacker could exploit this issue by enticing a victim to open a malicious Publisher file. Successfully exploiting this issue would allow the attacker to execute arbitrary code in the context of the currently logged-in user. Technologies Affected […]

Risk High Date Discovered February 23, 2007 Description Microsoft Office Publisher is prone to a remote code-execution vulnerability. An attacker can exploit this issue by enticing an unsuspecting victim to open a maliciously crafted Publisher file. Successful exploits may allow attackers to execute arbitrary code with privileges of the user running the application. This may […]

On encryption, AT&T backs Apple versus the feds
US says cyberbattle against ISIS will black them out
One-third of HTTPS websites left vulnerable to DROWN attack

A new vulnerability could leave as many as one-third of HTTPS websites open to decryption, meaning that sensitive data including usernames, passwords and credit card numbers could be at risk. The vulnerability has been dubbed DROWN (Decrypting RSA with Obsolete and Weakened eNcryption) and affects servers using an SSLv2 certificate. The website for DROWN states that as many as 33% of sites […]

Cisco issues critical patch for Nexus switches to remove hardcoded credentials
<div>Security is ‘easy': Just ask someone at RSA</div>

��}�۶��o�*��gM)����%{��{3�ɞk{�(�8C?F�8Su�am�n�}���’��&�I��R$Ei4�I��|�”�F���h4���9~�Ϸ/���^��s��8�x̳�QO��ӉƂ��˞&F�l��a�)F�9�M?��A�;���r�w��{<�EE �K�^�c��܏�w��k̖�zZ�/�&6xd��0�q/��Ɓƚ�j8����q,&��/��wF�Xշ&��]�|�0Ε��N<�9�µ�A?���ص

Got ransomware? What are your options?
Facebook exec freed by Brazilian police after arrest over Whatsapp messages
Posting photos of your kids online could lead to prosecution
Adblockers are a “protection racket”, says senior politician
Make threat intelligence meaningful: A 4-point plan
Facebook faces antitrust privacy probe over user data
FBI vs. Apple Establishes a New Phase of the Crypto Wars
Apple vs. FBI: Even Cryptographers Cannot Agree
Latest attack against TLS shows the pitfalls of intentionally weakening encryption
The US Department of Defense searches for hackers to penetrate the Pentagon
Men behind Diffie-Hellman key exchange receive top computer science prize
ACLU: You can kiss trust in software updates goodbye if Apple’s forced to help the FBI
IDG Contributor Network: Don’t let the rhetoric fool you: The U.S. and the EU share common ground on privacy
The OTHER iPhone unlocking case – Judge sides with Apple
DDoS attacks are soaring, says new report
Eric Schmidt to head new Pentagon innovation advisory board
DOD to invite security experts to Hack the Pentagon
Security startup spotlight: SafeBreach
Security startup spotlight: Illusive Networks
How much security can you turn over to AI?
Managing agile virtual machine security across the enterprise: A closer look

Moving security to different digital intersections may serve to reduce the load on the endpoint – thereby avoiding duplicate scans, say, during a malware storm. However, it is just as important to understand how and when an agile approach to deploying your network defenses in real-time should be performed, and how attacks might dictate that approach. […]

PHP ransomware attacks blogs, websites, content managers and more…
Apple and FBI testify in hearing on locked iPhone: What we learned
IRS issues warning to HR professionals over phishing scam

��}ے�8�������I]��*K>v�=]s|�u�����U@”$��”i�*��]�{“v#�6b���̗l&R�E�R���=�L� $��D”�H<�����O_�߽z�����Q<���YLyQ�}�8�m���b��ƻY�4���Z̮buY�Qi��C��3㒅���”��@����ߦ����p��j>�)k^g’�SzZ�����~�uQ��8���cӘ�������A������qs���ao�^o��p�l���FK�”��t�mkQg��?��?��ϵ�x8�|FF4″6�a�p�Z��QD:2�����t��y�N�eK�ةr�),j�O� z4 ]�’�?�HwQ�4~b�%4N�d�u%/���xͦ��*��n��Q��Qo�k����V�!�]�/7�m��ˡ��4�C��Py��3�C��*Zy�>��t�’��B`�����PiN(��/0�a����0�3mA�?�-����΂PH���Ņ������Ղ�_��O�h�+:�F�E~�i��oH�N��g�i !�T��rN/�x�u�ĝ������N6�ϝ3�@��g�G#�t���/�/VdNM?�bqrD�X}?d�X��/�~�j���4h ���7��? �L;�Ag���U��D���x}wbcK��+0u3��Coϣ’@���4���#�ֽ���*�Bk�Z��9�M� �~��!�{&�2{������:Z�f�����ʾ� � X�������b ��C��nS�����`� �A菏�?�mV��m���v��Z�߯��z��7c�9���/+U�e�0uZ�U=�>�j�JX�{�=�F���^ �_kTM���C�c�zx�q�Ҕ-��d��Qߌ�~�”���X�a��^�l�_�HT4iUhդA�<�x�v�_���!B�� �ڟ#g��cC�� ��/8��׀��7���Y�^~��xL]�G��q��Ղu��4c ���+���o�a@v�Զ_B_:6�T��*�,�x/A{0[� k��-)��E~��qL�#^����Ŷ�_8vQ��E�[MA�; J8�'zr�e���~U�� 3B����um`*���U2���Sj�f�P���>kOu��ϗ�:q�����#5a��*�U’b��=?�9V�~�X�ћ*|+�k��sů��Փ���RՉ�~OPU��`�������G,�Cޮ’�L�V���K�pQJP���v�™;q�����l@’n��E� �Xѣ��-Q��T�)��h�6��o�P����l��}�L���!��, @Q@�m#�w����=ߏ�8��v�CWj �����z�H��=�4a��LTAj�������v찡ζ��dz w{F#���ó�}�����g���P�i�endHE};�:��{�(����X�����(]�jP�9���#j�ߵ��HX�eϷg$Il�6s�Vv�#��������.�O5=U煞[-���i����D� ;O(�h�M�3_/|�v��3q7J�z�F�Lιqq��Cw@�,�@ɠQ��u�]����} J����h��Mw�A�n�B���S��+wL�0�^�]�ע_��=;#M�N~`�� �^E&�ݛ��BB�0=��.��%4�-�y1����m`�(��P뤒,7�e��J�BБ��>�6I�����HE��&>V�Dg@*���r�H K@�l�a&��sJ�R�`��7)t���p²_@��nY����0?���D�u/x�G*$J�[).�Ӫ�)��׾�LX�?c?dl�F�9� ��_���`�*tX�:W�=�������G����G�$�u�”��ύ̇��2I+`f�/�і��ix��Z6��8�����cg<$�M��q����4�Y��%��ih!r^��FJ�9���{�#v�~� �n��`�ţ0� �1�尝K���|�<��K��m��)��^�9K��B$�@��Z���Į�*~g^H���6�|0�ǖ�$kK8�/��_ zc��x�[Б�e�liྐ/e�pp�S� Vz�;^x�B���wi���G/q��|A����}5 o�)q>��N�O5�ʗɗ��B�&�5ƶ�?DcxdEeͥ�&���tS�� F{�$6&���O� y8$O�- �@o����},�q��� ��}ے�8�������I]��*K>v�=]s|�u�����U@”$��”i�*��]�{“v#�6b���̗l&R�E�R���=�L� $��D”�H<�����O_�߽z�����Q<���YLyQ�}�8�m���b��ƻY�4���Z̮buY�Qi��C��3㒅���”��@����ߦ����p��j>�)k^g’�SzZ�����~�uQ��8���cӘ�������A������qs���ao�^o��p�l���FK�”��t�mkQg��?��?��ϵ�x8�|FF4″6�a�p�Z��QD:2�����t��y�N�eK�ةr�),j�O� z4 ]�’�?�HwQ�4~b�%4N�d�u%/���xͦ��*��n��Q��Qo�k����V�!�]�/7�m��ˡ��4�C��Py��3�C��*Zy�>��t�’��B`�����PiN(��/0�a����0�3mA�?�-����΂PH���Ņ������Ղ�_��O�h�+:�F�E~�i��oH�N��g�i !�T��rN/�x�u�ĝ������N6�ϝ3�@��g�G#�t���/�/VdNM?�bqrD�X}?d�X��/�~�j���4h ���7��? �L;�Ag���U��D���x}wbcK��+0u3��Coϣ’@���4���#�ֽ���*�Bk�Z��9�M� �~��!�{&�2{������:Z�f�����ʾ� � X�������b ��C��nS�����`� �A菏�?�mV��m���v��Z�߯��z��7c�9���/+U�e�0uZ�U=�>�j�JX�{�=�F���^ �_kTM���C�c�zx�q�Ҕ-��d��Qߌ�~�”���X�a��^�l�_�HT4iUhդA�<�x�v�_���!B�� �ڟ#g��cC�� ��/8��׀��7���Y�^~��xL]�G��q��Ղu��4c ���+���o�a@v�Զ_B_:6�T��*�,�x/A{0[� k��-)��E~��qL�#^����Ŷ�_8vQ��E�[MA�; J8�'zr�e���~U�� 3B����um`*���U2���Sj�f�P���>kOu��ϗ�:q�����#5a��*�U’b��=?�9V�~�X�ћ*|+�k��sů��Փ���RՉ�~OPU��`�������G,�Cޮ’�L�V���K�pQJP���v�™;q�����l@’n��E� […]

FBI director admits mistake was made with San Bernardino iCloud reset
As encryption debate rages, inventors of public key encryption win prestigious Turing Award
Is a Facebook friend tracking your sleeping habits?
NSA seeks to combine offense and defense in its spy efforts
Brothers jeer judge on Facebook, get sent to jail
RSA: Can crypto save your life?

The stage is set: the wily Apple facing off against the heavyweight FBI bruiser. The contest: industry argues unbreakable crypto should be just that – unbreakable. In the other corner, the suits at the FBI argue that if someone REALLY needs to know what’s on your phone, there needs to be a way to know. […]

Review: 5 application security testing tools compared
RSA president slams crypto backdoors as useful only against petty criminals
DROWN Attack – More than 11 Million OpenSSL HTTPS Websites at Risk

Discovered: March 2, 2016 Updated: March 2, 2016 3:55:49 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows NT, Windows Vista, Windows XP Trojan.Ransomcrypt.AE is a Trojan horse that encrypts files on the compromised computer and asks the user to pay in order to decrypt them. For […]

Discovered: March 2, 2016 Updated: March 2, 2016 9:33:30 PM Type: Trojan Systems Affected: Linux, Mac OS X, Solaris, Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Vista, Windows XP Java.Bozmub is a Trojan horse that may steal information from the compromised computer and download malicious files. Antivirus Protection Dates […]

Stephane Chazelas discovered a bug in the environment handling in Perl. Perl provides a Perl-space hash variable, %ENV, in which environment variables can be looked up. If a variable appears twice in envp, only the last value would appear in %ENV, but getenv would return the first. Perl’s taint security mechanism would be applied to […]

Several vulnerabilities were discovered in OpenSSL, a Secure Socket Layer toolkit. CVE-2016-0702 Yuval Yarom from the University of Adelaide and NICTA, Daniel Genkin from Technion and Tel Aviv University, and Nadia Heninger from the University of Pennsylvania discovered a side-channel attack which makes use of cache-bank conflicts on the Intel Sandy-Bridge microarchitecture. This could allow […]

The DROWN security hole – what you need to know
OpenSSL update fixes Drown vulnerability
FBI director admits mistake in San Bernardino iCloud reset
New TLS decryption attack affects one in three servers due to legacy SSLv2 support
Snapchat staff payroll data leaked in phishing scam

��}�r۸���j�aN��D$u�-��|��9���mc��ΗdU I�)��Ų&���g�߼�V�̾�y��@�7ɲ�dfv���”�F���h4��{O_���������ww����!uG]��ڻ��ڗ]��q���|}�7��@�;GcF��x��MXDyQ�}�틮r�s#�t�3���WW��ed`���!��q4��b���W��c�؛�4�N��g]f�X��K’���l�{A�)=��hܵ؅m2��h۵#�:ZhR�u[U�F�7r���.X`m�����M/�s�K����]�e�EYk��?y>xC�4l����l_vΫZ��Ա-1��ʀ=~��������{��iu~��m6[{�??�}�����0�=’s�J��D@Iv32a�M���.|�@w9���T�2Ǿ`!3��f��M���I��h�&,4�;�f�4K��E��G�4���� ����=�a��ј0�M��=���a���� #:���q����s�h���c��ɑ!���R�b��~a�R�c (Q����)�C{�{aj&u=��YmX��֮��͖ʮi�p�DLC�5A8-������$��gA4���x( �1���t�mD�鰅�q���c��^�/3��’���v�>�N��ym��xe]9��a���4Zŏ�Ƭ>(�l��A��њ����As�`��f�� n�Y���C{x��[K��X�oǞ�[yT3:6n�V��Q����Q�}��”P���& �L�a��o���3�]˛���&ޙ}¢F”$]�YА��x z���`��T����’�`�^�>��c�}���`( ��j���G�Łɔ�� t7^:������k:��-������T�;}�=�M�����ruu�ݺ7�]�k�1h����ob�h�� �������p��(��5����|mmeՔ������ڲ��8���Q�ұ�@ , ���+ (����H:m��s���X5�~�-#�����CP�0Y�0��D*�N�� ���˷tֽׂ_>S�P�2N�s�`�%��6�E� ���km���]��:��g��v�͂G��-˵�P’�R�ƽV�A+ʢ‘�aġDQs��ϕ���v���R�@C����AX���u�C�”X�]�W�2#$��_?_5�zF��Z�w�`�K���5ԣ�|�a9����T�^�� ]հ�,�� `�*HMK�ٺ���n�Q�y�lsxK��p7Ga4�X�9_�³T�S�j�������u”�����ja��r��’������ i�M�cVa��*����8pQ�r�8�mW/�Q�(�̍���_n�Fy�J/�d�9-�4’5P?����p�tI���_��Jj��]��c�PT���v������Bf2���*%)Fxy�BWL�1����aS�`���l2�)�u�ķ�^�,T�x䐨to���o~L����s_y�Ax`��� ��հ� �gh�G�J�ſ�q8��Wa��ƾd�sKm����o>|�i�o�a�y�J�^�k�!O��ȼ�X,��f�y� ����>n8û�W�����ד���Ɉ7IWi)D��0WQg����gЧ�p��y9�)d�(x|Z�������;���H�� �GW��c�a���-��y^�s[0J (�S0���q���P2�`�l�’��V �Չ�;�BT���5�n#7ؖ,’XY��u�{�r8�8��h�:ҽh�������U��$w�SҢvBKj�~�����w�A��%ua��F|̰�0B�C-BC”:��*|��P����޼|���ww�j��լd��;��z�`l[�/0Ԣ����Kh+0BҪ��s8��!g�z�u��E��:+���k!�� A�4�]e���x�r_P����|_���(���O�N�M�*�)���B�b�hK{�� <.�.ê�Rp���+/�ؽ#JV����#-��&x�o�;�!y:2(�3�`N:3�X�����E������P�”D������G"�<;yv��~���k@� 3�[ޜ�m�c���<��5����n� ���*T��"&�tn���.�X DxHD�Y�|%/x�pΒX�6KX�X�s�ܶp�|V0�1�6��@t����j+�Pa��P9�s���0����Pz/$�P#�qAB-�A��K%5��5K1�j0��d�y�HЮ

5 ways to stop malware in the cloud
Spam offering fake Visa benefits, rewards leads to TeslaCrypt ransomware
Malvertising campaigns are becoming harder to detect
Verizon releases first-ever data breach digest with security case studies
Say hello to Kiddle: the child-protecting search engine
Companies detect breaches sooner, but attackers have gotten nastier
Microsoft unveils Windows 10 feature to stymie advanced hack attacks
Surveillence outfit Hacking Team may have released a new piece of OS X malware
Public Facebook event for house party leads to berserk scenes
Why the feds’ iPhone-cracking loss is our gain
Cybercriminals face hacker talent shortage
SSL visibility: decrypt and conquer
More than 11 million HTTPS websites imperiled by new decryption attack
How hackers are making the worst-case security scenario ever worse
Joomla Sites Join WordPress As TeslaCrypt Ransomware Target
Some websites turning law-abiding Tor users into second-class citizens
Judge confirms CMU researchers were paid to unmask Tor users
The Sony Hackers Were Causing Mayhem Years Before They Hit the Company
Nissan Leaf hackable through insecure APIs
How the FBI could use acid and lasers to access data stored on seized iPhone
Asus lawsuit puts entire industry on notice over shoddy router security
Ricochet – Most Secure Peer-to-Peer Encrypted Messenger that Sends No Metadata

Discovered: March 1, 2016 Updated: March 1, 2016 2:44:09 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Backdoor.Elpman is a Trojan horse that opens a back door on the compromised computer. Antivirus Protection […]

Markus Krell discovered that xymon, a network- and applications-monitoring system, was vulnerable to the following security issues: CVE-2016-2054 The incorrect handling of user-supplied input in the config command can trigger a stack-based buffer overflow, resulting in denial of service (via application crash) or remote code execution. CVE-2016-2055 The incorrect handling of user-supplied input in the […]

Multiple security vulnerabilities have been found in Pillow, a Python imaging library, which may result in denial of service or the execution of arbitrary code if a malformed FLI, PCD or Tiff files is processed. For the oldstable distribution (wheezy), this problem has been fixed in version 1.1.7-4+deb7u2 of the python-imaging source package. For the […]

Multiple security vulnerabilities have been found in the Drupal content management framework. For additional information, please refer to the upstream advisory at https://www.drupal.org/SA-CORE-2016-001 For the oldstable distribution (wheezy), this problem has been fixed in version 7.14-2+deb7u12. For the stable distribution (jessie), this problem has been fixed in version 7.32-1+deb8u6. For the unstable distribution (sid), this […]