Menu

Monthly Archives: June 2016

LizardStresser IoT Botnet Part of 400Gbps DDoS Attacks
WA government still hopeless at infosec
Turkish Hacker Defaces Arizona State Representatives and Legislature Sites
Russia, China fight UN effort to extend human rights onto the internet
Massachusetts General Hospital Confirms Third-Party Breach

Brandon Perry discovered that xerces-c, a validating XML parser library for C++, fails to successfully parse a DTD that is deeply nested, causing a stack overflow. A remote unauthenticated attacker can take advantage of this flaw to cause a denial of service against applications using the xerces-c library. Additionally this update includes an enhancement to […]

Multiple security vulnerabilities have been discovered in the Tomcat servlet and JSP engine, which may result in information disclosure, the bypass of CSRF protections, bypass of the SecurityManager or denial of service. For the stable distribution (jessie), these problems have been fixed in version 8.0.14-1+deb8u2. For the unstable distribution (sid), these problems have been fixed […]

Aleksandar Nikolic discovered that missing input sanitising in the RTF parser in Libreoffice may result in the execution of arbitrary code if a malformed documented is opened. For the stable distribution (jessie), this problem has been fixed in version 1:4.3.3-2+deb8u5. For the testing distribution (stretch), this problem has been fixed in version 1:5.1.4~rc1-1. For the […]

Encryption, wiretaps and the Feds: THE TRUTH
Some social engineering skills and Facebook will gift your account to hackers

Debian: 3611-1: libcommons-fileupload-java: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3611-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 30, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libcommons-fileupload-java CVE ID : CVE-2016-3092 The TERASOLUNA Framework Development Team discovered a denial of service vulnerability in Apache Commons FileUpload, a package to make it […]

Ubuntu: 3022-1: LibreOffice vulnerability Posted by Anthony Pell    LibreOffice could be made to crash or run programs as your login if itopened a specially crafted file. ========================================================================== Ubuntu Security Notice USN-3022-1 June 29, 2016 libreoffice vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu […]

Debian: 3610-1: xerces-c: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3610-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 29, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : xerces-c CVE ID : CVE-2016-4463 Debian Bug : 828990 Brandon Perry discovered that xerces-c, a validating XML parser library for C++, fails to successfully parse […]

Debian: 3609-1: tomcat8: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3609-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 29, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : tomcat8 CVE ID : CVE-2015-5174 CVE-2015-5345 CVE-2015-5346 CVE-2015-5351 CVE-2016-0706 CVE-2016-0714 CVE-2016-0763 CVE-2016-3092 Multiple security vulnerabilities have been discovered in the Tomcat servlet and JSP engine, […]

Debian: 3608-1: libreoffice: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3608-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 29, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libreoffice CVE ID : CVE-2016-4324 Aleksandar Nikolic discovered that missing input sanitising in the RTF parser in Libreoffice may result in the execution of arbitrary […]

Foxit Patches 12 Vulnerabilities in PDF Reader

Risk Level: Very Low. Type: Trojan.

Conficker Used in New Wave of Hospital IoT Device Attacks
LizardStresser recruits an army of zombie webcams to launch DDoS attacks
Hackers: Ditch the malware, we’re in… Just act like a normal network admin. *Whistles*
Security Sessions: Is hospital security on life support?
Muslim Match dating site hacked. Private messages and profiles posted online
Fight back! Learn to hunt threats with free tools
Mingis on Tech: The ethics of self-driving cars — and killer robots
The Android ransomware threat has quadrupled in just one year
Hackers abused SWIFT to steal $10 million from Ukrainian bank
Big Blue finds big green in derailing transport
SSH Keys
General tips for working with iptables
Install DenyHosts on a CentOS box
Hopeless Vic agencies have two years to hit infosec best practice

The TERASOLUNA Framework Development Team discovered a denial of service vulnerability in Apache Commons FileUpload, a package to make it easy to add robust, high-performance, file upload capability to servlets and web applications. A remote attacker can take advantage of this flaw by sending file upload requests that cause the HTTP server using the Apache […]

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Discovered: June 29, 2016 Updated: June 30, 2016 12:54:57 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows NT, Windows Vista, Windows XP Trojan.Cryptolocker.AU is a Trojan horse that encrypts files on the compromised computer and demands payment to decrypt the files. Antivirus Protection Dates […]

Honey, why are porno apps on your Android?! Er, um, malware did it!
While you filled your face at Noodles and Co, malware was slurping your bank cards
FTC Closes 70 Percent of Data Breach Investigations, Weighing PCI-DSS Standard
Alleged Brit hacker Lauri Love bailed amid US extradition battle lull
How RASP protects applications from attacks
IDG Contributor Network: Israeli cybersecurity prowess on display in DC and Tel Aviv
Hard Rock Las Vegas, Noodle and Co. Confirm Hacks
Kremlin hackers and the Democratic National Committee: How deep is the rabbit-hole?

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Flaws in Symantec products expose millions of computers to hacking
InfiniBand-on-die MIA in Oracle’s new ‘Sonoma’ Sparc S7 processor
The iPhone is nine years old – and still no significant malware outbreaks
Fancy hacking Man City? Happy days: Footy club to host hackathon
Hard Rock Cafe experiences data breach

The Hard Rock Cafe and Casino Las Vegas has released a statement alerting customers that their data may have been compromised if they visited the resort between October 27th, 2015 and March 21st, 2016. After receiving several reports of unauthorized activity associated with payment cards, the resort started an investigation into their card payment methods. […]

Planes, Trains and Automobiles Increasingly in Cybercriminal’s Bullseye
Stay cyber safe on the road: 10 tips for this summer season

��}�۶��o�*���R,��/�X��Ήϵco�I6��NQ$$q�”~�Fq������[�O��Or�d��?��hd’ٲωM�@��_h4��{��������ׯ_�}��`��h`�p��0�#ﲯ��!�$IxhYl�Sj�} ��y

Hacker puts 9.3M U.S. patient records up for sale
Digital patch kit: How to protect yourself from data leaks

��}�۶��o�*���ZR,��/�X��N�s�؛qN��;E��DE0�Yq����٭ڭ�Wت}��or�d� ER�F��N�e��”�F��_h4��w��:}�����wo^��u��8�x̳�QO���Ƃ��=M���8��c���pӏ�jP���1���-x��NxlQQ�����=�T�1�c��,��寞��� ��c+�x�K�~�1�_ �?�?>�O�$�bw��A=��Έ��ք�K�Oƹ�S׉�=�_�6��G������G���^� �H����ȍ�~�Cw�ڀ��s����ߧ���D�x/;O����g���׭�Z?}aw>t/�Z�D���:V̍V;�����Q������ig������j�~s�����vW�b��������iQL�?K����pb�=����*���B��K0o

New CryptXXX ransomware variant made authors $50K in two weeks
Please stop spreading the Facebook privacy notice hoax
Body of evidence: Biometrics and YOU
Zero-interaction remote wormable hijack hole blasts Symantec kit
Global terror database World-Check leaked
Play Store malware roots phones, installs an app every two minutes
US Senator Wyden: Why I had to halt FBI’s latest internet spying push
Thousands of CCTV Devices Found DDoSing Small-Business Websites
Microsoft rethinks Windows 10 upgrade push following complaints
Unwanted Windows 10 update wins woman $10,000 from Microsoft
Meet the grin reaper: Password manager now snaps login SELFIES
Botnet Powered by 25,000 CCTV Devices Uncovered
SWIFT hackers nick $10m from Ukraine bank

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3607-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 28, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : linux CVE ID : CVE-2015-7515 CVE-2016-0821 CVE-2016-1237 CVE-2016-1583 CVE-2016-2117 CVE-2016-2143 CVE-2016-2184 CVE-2016-2185 CVE-2016-2186 CVE-2016-2187 CVE-2016-3070 CVE-2016-3134 CVE-2016-3136 CVE-2016-3137 CVE-2016-3138 CVE-2016-3140 CVE-2016-3156 CVE-2016-3157 CVE-2016-3672 CVE-2016-3951 CVE-2016-3955 CVE-2016-3961 CVE-2016-4470 CVE-2016-4482 CVE-2016-4485 CVE-2016-4486 CVE-2016-4565 CVE-2016-4569 CVE-2016-4578 CVE-2016-4580 […]

Ubuntu: 3021-1: Linux kernel vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-3021-1 June 27, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: […]

Ubuntu: 3021-2: Linux kernel (OMAP4) vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-3021-2 June 27, 2016 linux-ti-omap4 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: Several security issues were fixed in the kernel. Software […]

Gentoo: 201606-19 kwalletd: Information disclosure Posted by Anthony Pell    Kwalletd password stores are vulnerable to codebook attacks. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – Gentoo […]

Multiple vulnerabilities have been found in IcedTea allowing remote attackers to affect confidentiality, integrity, and availability through various vectors. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Ubuntu: 3018-1: Linux kernel vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-3018-1 June 27, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: […]

Ubuntu: 3020-1: Linux kernel (Vivid HWE) vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-3020-1 June 27, 2016 linux-lts-vivid vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. […]

Ubuntu: 3019-1: Linux kernel (Utopic HWE) vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-3019-1 June 27, 2016 linux-lts-utopic vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. […]

Ubuntu: 3018-2: Linux kernel (Trusty HWE) vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-3018-2 June 27, 2016 linux-lts-trusty vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: Several security issues were fixed in the kernel. […]

Ubuntu: 3016-4: Linux kernel (Xenial HWE) vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-3016-4 June 27, 2016 linux-lts-xenial vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. […]

Ubuntu: 3017-1: Linux kernel vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-3017-1 June 27, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 Summary: Several security issues were fixed in the kernel. Software Description: – […]

Ubuntu: 3017-3: Linux kernel (Wily HWE) vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-3017-3 June 27, 2016 linux-lts-wily vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. […]

Multiple US Healthcare Insurance Database (655,000 Patients) for sale

Risk Level: Very Low. Type: Trojan.

Cerber ransomware targets enterprises via Office 365
Google Play Hit with Rash of Auto-Rooting Malware
You know how that data breach happened? Three words: eBay, hard drives
Pandora tells some users to reset their passwords
Malware on Google Play steals Viber photos and videos
655,000 Healthcare Records Being Sold on Dark Web
Bart ransomware takes files hostage by hiding them in password-protected ZIP files
VASCO explains how to secure data access within the Healthcare industry
Study: Encryption use increase largest in 11 years
FBI expansion of surveillance powers meets obstacle