Menu

Monthly Archives: June 2016

(Update) 800-pound Comodo tries to trademark upstart rival’s “Let’s Encrypt” name
Not so fast: Some security defaults shouldn’t change
3 ways to screw up data security in the cloud
<div>Not so fast: Some security defaults shouldn't change</div>

There’s an old security mantra that says “always change the defaults!” Although this seems like a good general rule, in fact it’s true only for certain kinds of settings. Changing the defaults in other cases will just end up biting you in the end with little increased security to show for it. A few months […]

Nuclear goes boom
US hospitals hacked with ancient exploits
Eat my reports! Bart ransomware slips into PCs via .zip’d JavaScript
Ransomware scum target corporate Office 365 users in 0-day campaign
Riverbed’s NetProfiler, NetExpress virty appliances patched
Google’s Widevine DRM doesn’t quite manage
25,000 malware-riddled CCTV cameras form network-crashing botnet

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. CVE-2015-7515, CVE-2016-2184, CVE-2016-2185, CVE-2016-2186, CVE-2016-2187, CVE-2016-3136, CVE-2016-3137, CVE-2016-3138, CVE-2016-3140 Ralf Spenneberg of OpenSource Security reported that various USB drivers do not sufficiently validate USB descriptors. This allowed a physically present user with a […]

Risk Level: Very Low. Type: Trojan.

With the sheer amount of available pornographic images of child abuse – often called child porn – available online, it may seem that there is little you can do to protect your children, or yourself, from this type of content. This isn’t true. Here are eight key tools and tactics to eliminate – or significantly reduce […]

It was only a matter of time before phone hacking rose to the top of the media-driven hysteria list Thanks to the rapid growth of mobile device adoption and the subsequent rapid growth in mobile threats, phone hacking prevention is a hot topic. A headache reserved for celebrities in the past, smartphone-infiltration concerns have crossed the VIP vs. […]

Apple Leaves iOS 10 Beta Kernel Unencrypted: Pros and Cons
Visiting America? US border agents want your Twitter, Facebook URLs
Woman Sues Microsoft for Automatic Windows 10 Upgrades and Wins

Discovered: June 25, 2016 Updated: June 27, 2016 8:35:56 AM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows NT, Windows Vista, Windows XP Trojan.Ranscrypt.BA!gm is a heuristic detection used to detect threats associated with the Trojan.Ransomcrypt.BA family. Antivirus Protection Dates Initial Rapid Release version June […]

Discovered: June 25, 2016 Updated: June 27, 2016 11:46:39 AM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows NT, Windows Vista, Windows XP Trojan.Ransomcrypt.BA is a Trojan horse that encrypts files on the compromised computer and asks the user to pay in order to decrypt […]

Google CEO Sundar Pichai’s Quora and Twitter Accounts Hacked
Google’s CEO Sundar Pichai hit by hackers
Crooks abusing Facebook to offer credit card samples
New CryptXXX Can Evade Detection, Outsmart Decryption Tools
Intel mulls sale of Intel Security – reports
Automated bots bombard EU referendum petition with fake signatures
Comodo stands down from trademark tussle with Let’s Encrypt
Botnet-powered ballot stuffing suspected in 2nd referendum petition
Anime site redirects to Neutrino exploit kit, CryptXXX ransomware
Swagger stumbles: Flaw enables remote code execution
Inside the World of the Dark DDoS
Scam victim sues TalkTalk
Hackers peer into Uber passenger privates, find and plot trips on maps
Lenovo Solution Center portal patched to shutter hacker god mode hole
Medicos could be world’s best security bypassers, study finds
Facebook ‘Comment Tagging Malware’ Spreading via Google Chrome
IRS kills off PINs citing increasing suspicious activity
Intel to quit the security business (again), and jettison McAfee?
South Yorkshire (UK) Police Websites Hacked
Hacker Selling 1.1 million Lookbook.nu Emails and Plain Text Passwords
Chrome Bug Allows Netflix or Amazon Prime Video Download for Free

It was discovered that pdfbox, a PDF library for Java, was susceptible to XML External Entity attacks. For the stable distribution (jessie), this problem has been fixed in version 1:1.8.7+dfsg-1+deb8u1. For the testing distribution (stretch), this problem has been fixed in version 1:1.8.12-1. For the unstable distribution (sid), this problem has been fixed in version […]

YouTube’s Popular Channels WatchMojo and Redmercy Hacked
A Bug in Chrome Makes It Easy to Pirate Movies
Let’s Encrypt accuses Comodo of trying to swipe its brand
Malware Museum’s top 10 blasts from the past
NASCAR team red-flagged by ransomware attack

There’s a lot that happens in the security world, with many stories getting lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. First ‘Hack the Pentagon’ Event a Major Success Several months ago, the Department of Defense […]

Medical Study Blasts Hospitals’ Security Practices

An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel-rt security, bug fix, and enhancement update Advisory ID: RHSA-2016:1301-01 Product: […]

An update for ocaml is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: ocaml security update Advisory ID: RHSA-2016:1296-01 Product: Red Hat Enterprise Linux Advisory […]

An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2016:1277-01 Product: Red […]

Selfrando Technique Mitigates Attacks Unmasking Tor Users
How malware could steal data from an air-gapped PC – via its fan
Voter Database Leak Exposes 154 Million Sensitive Records
Cyberattacks should be included in international humanitarian law

��}�۶��o�*��gM)I]��K�챓�|�mfr��l�DBg(��e4g��c�V�>�V���y��@ �H���N�e��”�F���h4���=�$S�x��5�?i$��Ƚ�k�x�L�$ܷ�`�Sf��} ��ysƬXէS���]6�(QJ�’��v����?Z���ĥ���c�N�q�=f�nŒs�#�D_�|2�������> �t�{�}�P�� �^��w��?�9�������9��&�lw��/vw�{O�vv�۝�w;;�vg���g;Ϟvz����g$b^_��K��ƀ �_�ݎc�L��ҾF�_’0�}M�l63g�s�Y��4r�K���,4$RV2aS[�C�xC�er�{������Oܘ ����;uc��Ʉ0b��}������C�$��T���!��m/u������|�G&���ȥ>0��%�U��؎ܰ4h��x����b�mDl�yD;�I�7Y���y�L(�L`�S���x��|`,o��;;V{��nY*�F��Q@�P�2-�I�(���E�%u/@9P�����`�(qm�-,��r�m�zQC��^�ky �̠�p���(����+h�Ij���,K�~�f��*a:��O� (�a���1�[ǝ���^�a���n/7 ���A�n�ou�@��Q ��;�c���*�5 ��:q>د�Y�N��Cz��i8V��-] �o��Q����F�ڂ�J)Y���Uǂ�P�v��8VIL��/��?’�,b���$���$N��%�qB�^�%���]��S5/�uT�┞S�V@�;3�w��y2�48u�X���8&}�IҘ��o�w8��`}�bsf���i�� b,^�۽��~���mA=3���#��f��’ zV/-�r����-����l�l�=s �=������2�ͮvuu��7J}���5l��O�o�4h��9���rZ�5�MNl����O8���fk��c�p�”y�@��к��0���( ��`(;pG�{����]�;��͈%i����0��16�3�X8:A���|�c �#�u��$��Z�� %��G�ھE�����vo{����׆����N��n������iB��U�iz�’�A��8T���S�@�v� �/�l������:M�2m9}�}��C���N���z[�ZȐ��m�Vm�]ۚs��g�� !(��=�E��e�m���uhYN�.���[N���@_els��/��ʹR���Gv��l�^�[ClY֋�]���? �ZZ6i2�9���Ӱ�W��5nMZ��(�n�i��FFЖ`�֜-��`�8 q”����L& 6��ڭ�6�����jL��_&6�P޻�’?����7���o��~���hKe�z�����)’K���|l`9����T�ټj�i��v��Z0�6q�zl !���e���;|#���l��t��ơG/��©���Ѧ~ЇA�yA`[�ra� h�}�0w�uծϽ,:q������3f��Yu”�����0�b+ltN�������P�[���4��37Yt1�z6������:�V� �_�;���:3����T�ňE��I���U��9�}�

Threatpost News Wrap, June 24, 2016
Privacy, risk and trolls: Dealing with the security challenges of YouTube fame
Look into our network, not around our network… you’re under
US court rules that FBI can hack into a computer without a warrant
Let’s Encrypt and Comodo in trademark tussle
Over half of world’s top domains weak against email spoofing
Updating code can mean fewer security headaches
Popular Anime Site Infected, Redirecting to Exploit Kit, Ransomware
Godless mobile malware can root 90% of Android devices
It’s time to lock the door on backdoors
Sorry, but there’s no universal cloud security solution
Swagger staggered as hacker drops dapper code execution cracker
Australia’s Defence Department tips AU$12M to seat spies with students
Israeli researcher fans fears: here’s another way to cross the airgap
Necurs Botnet is Back, Updated With Smarter Locky Variant
Acer Online Store Hacked; 34,000 Customers Data Stolen

An update for libxml2 is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: libxml2 security update Advisory ID: RHSA-2016:1292-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2016:1292 Issue […]

Hackers Just Leaked Personal Data of US Military Officials and it’s Legit
Mobile Advertising Firm Found Tracking Users To Pay $950K
The number of corporate users hit by crypto ransomware is skyrocketing
Carbonite Triggers Password Reset for 1.5M Customers After Reuse Attack
Unpatched Remote Code Execution Flaw Exists in Swagger
Redefining how we share our security data.
Security holes found in widely-used file compression library, leaving other products dangerously exposed
154 million voter records exposed, revealing gun ownership, Facebook profiles, and more
WordPress Security Update Patches Two Dozen Flaws
Let’s Encrypt Celebrates Big HTTPS Milestone
More code deploys means fewer security headaches
Why APIs beat proxies for cloud security
Fraudsters impersonate victims’ ISPs in new tech support scam
Revive revived: Oculus DRM push shattered as DIY devs strike back
Tor onion hardening will be tear-inducing for feds
Libarchive needs patching again

Risk Level: Very Low. Type: Trojan.

Zuck covers up mic and cam pickup because sharing isn’t always good
FTC dings InMobi ad network for tracking world+dog
Patched libarchive Vulnerabilities Have Big Reach
Nuclear, Angler Exploit Kit Activity Has Disappeared

Risk High Date Discovered June 14, 2016 Description Microsoft Windows is prone to a remote code-execution vulnerability. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. Technologies Affected Microsoft Edge Microsoft Windows 10 for 32-bit […]

Risk Medium Date Discovered June 14, 2016 Description Microsoft Windows is prone to a local privilege-escalation vulnerability. Local attackers can exploit this issue to execute arbitrary code with elevated privileges. Technologies Affected Microsoft Windows 10 for 32-bit Systems Microsoft Windows 10 for x64-based Systems Microsoft Windows 10 version 1511 for 32-bit Systems Microsoft Windows 10 […]

Risk High Date Discovered June 14, 2016 Description Microsoft Edge is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can take advantage of this vulnerability to execute arbitrary code in the context of the currently logged-in user. Failed attacks […]

Email Servers For More Than Half of World’s Top Sites Can Be Spoofed
New Android Malware Makes Anonymous Calls and Sends Texts

Red Hat: 2016:1272-01: python-django-horizon: Important Advisory Posted by Anthony Pell    An update for python-django-horizon is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: python-django-horizon security, bug fix, and […]