Menu

Monthly Archives: June 2016

Quantum Computation: A cryptography armageddon?

Cryptography is a cornerstone of information security. It is used to encode and decode data in order to fulfill the requirement for confidentiality, integrity, authenticity as well as non-repudiation. Together, these are frequently referred to as cryptography services. Advances in cryptanalysis, computer science and engineering are always pushing the limits of what is considered secure. […]

Yes, even smart TVs can be hit by Android ransomware
Apple looks into the benefits of differential privacy

��}��Ȳ�o��w(Ĺ�,�_�n��9�����=gv.pe�l��%�>��a:��F���7b�`�MΓlfUI֗�n�a� 8g@�����2����*�y����/o��N_�|w��4�9ġ0W��D!~���E_�&�dE��ax_�1� �*P���)���

House Poised to Advance Privacy and Defend Encryption…If Allowed to Vote
NSA Looking to Exploit Internet of Things, Including Biomedical Devices, Official Says
Hacker puts 51 million file sharing accounts for sale on dark web
Big data will fix internet security … eventually

I’ve always thought that improved computer security controls would “fix” the internet and stop persistent criminality — turns out it might be big data analytics instead. I’ve long written that only a large-scale improvement of the internet’s authentication mechanisms (that is, pervasive identity) could significantly reduce crime. If everyone on the internet had a default, […]

Man-in-the-middle biz Blue Coat bought by Symantec: Infosec bods are worried
Hack the Pentagon shutters 100 bugs
Telegram crammed: Hackers find way to send massive messages
North Korea hacks 140k computers in planned mass attacks on Seoul

Type: Vulnerability. Microsoft Windows is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Risk High Date Discovered June 14, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]

Risk High Date Discovered June 14, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]

Risk High Date Discovered June 14, 2016 Description Microsoft Windows is prone to a local privilege-escalation vulnerability that occurs in the Windows kernel. A local attacker can exploit this issue to execute arbitrary code in kernel mode with elevated privileges. Technologies Affected Microsoft Windows 10 for 32-bit Systems Microsoft Windows 10 for x64-based Systems Microsoft […]

Discovered: June 14, 2016 Updated: June 14, 2016 2:51:29 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows NT, Windows Vista, Windows XP Trojan.Cryptolocker.AR is a Trojan horse that encrypts files on the compromised computer. Symantec Security Response is currently investigating this threat and will […]

Discovered: June 13, 2016 Updated: June 13, 2016 11:42:17 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP JS.Ransomcrypt.B is a Trojan horse that encrypts files on the compromised server and downloads […]

Update your buggy Samsung PC bloatware to plug privilege bug
Forget Game of Thrones as Android ransomware infects TVs
Dell France, Ireland, Netherlands and UK Subdomains Hacked
Let’s Encrypt Accidentally Spills 7,600 User Emails
Orlando shootings bring Facebook’s safety check to US soil
Siemens Firmware Updates Patch SIMATIC Vulnerabilities

Risk Level: Very Low. Type: Trojan.

Tech Giant Microsoft Acquires Social Media Giant LinkedIn
51 Million iMesh Accounts Available on Black Market
One Year After Hack, IRS Debuts Updated Get Transcript Service
Study: Most companies can’t protect confidential documents
From Hacking into NASA to having his own TV Show, the Journey of Walter O’Brien
Tell us, evil phisherfolk: What’s wrong with Angler Exploit Kit?
Let’s Encrypt lets 7,600 users… see each other’s email addresses
Jigsaw ransomware uses live chat to relay payment instructions
Fresh hell for TalkTalk customers: TeamView trap unleashed
How to protect your Office 365 users with multi-factor authentication
Facebook activates ‘Safety Check’ after Orlando massacre
Symantec to acquire Blue Coat for $4.65 billion

Discovered: June 13, 2016 Updated: June 13, 2016 2:09:30 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP PHP.Ransomcrypt.C is a Trojan horse that encrypts files on the compromised server. Antivirus Protection […]

Anonymous Deface ISIS Twitter Accounts with Pornographic Content
Cyber Criminals Running Sophisticated Malware Campaign Via Skype
Netgear Router Update Removes Hardcoded Crypto Keys
10 security TED Talks you can’t miss
Crafty plan to give FBI warrantless access to browser histories axed

Discovered: June 10, 2016 Updated: June 10, 2016 11:27:56 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Munidub is a Trojan horse that may download potentially malicious files on the compromised computer. Antivirus Protection […]

Multiple security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors, buffer overflows and other implementation errors may lead to the execution of arbitrary code or spoofing. Wait, Firefox? No more references to Iceweasel? That’s right, Debian no longer applies a custom branding. Please see these links for further information: […]

Marcin Icewall Noga of Cisco Talos discovered an out-of-bound read vulnerability in the CInArchive::ReadFileItem method in p7zip, a 7zr file archiver with high compression ratio. A remote attacker can take advantage of this flaw to cause a denial-of-service or, potentially the execution of arbitrary code with the privileges of the user running p7zip, if a […]

Debian: 3600-1: firefox-esr: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3600-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 09, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : firefox-esr CVE ID : CVE-2016-2818 CVE-2016-2819 CVE-2016-2821 CVE-2016-2822 CVE-2016-2828 CVE-2016-2831 Multiple security issues have been found in the Mozilla Firefox web browser: Multiple memory safety […]

Debian: 3599-1: p7zip: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3599-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 09, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : p7zip CVE ID : CVE-2016-2335 Debian Bug : 824160 Marcin ‘Icewall’ Noga of Cisco Talos discovered an out-of-bound read vulnerability in the CInArchive::ReadFileItem method in […]

Discovered: June 9, 2016 Updated: June 10, 2016 1:42:34 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows NT, Windows Vista, Windows XP Trojan.Ransomcrypt.AY is a Trojan horse that encrypts files on the compromised computer and asks the user to pay in order to decrypt […]

Risk Level: Very Low. Type: Trojan.

Government regulation will clip coders’ wings, says Bruce Schneier
Decryption Utilities Unlock Files Encrypted by All TeslaCrypt Versions
Mozilla’s new fund will prevent the next Heartbleed, Shellshock
Threatpost News Wrap, June 10, 2016
32 million Twitter account credentials up for grabs – but site says it wasn’t hacked
Twitter Forces Password Reset on Some Exposed Accounts
How a boobytrapped PDF file could exploit your Chrome browser – and it’s not Adobe’s fault!
Did you know there’s a mega cybercrime backlog in Ireland? Now you do
$90K Windows Zero Day Gets a Price Cut
Securing the server programs hiding in your Docker containers
Why you don’t have to fix every vulnerability
Firefox 47 fixes 13 vulnerabilities, boosts YouTube playback, HTML5 support
Crysis creeps: Our ransomware locks network drives and PCs. Bargain
Android malware embeds into browsers, intercepts and changes URLs
EMC and VMware both suffer malicious user access messes
China pledges tighter privacy as it centralises personal health data
RIP ROP: Intel’s cunning plot to kill stack-hopping exploits at CPU level
Anonymous Boosts Up OpIcarus, Shuts Down Bilderberg Group Website
Twitter: Don’t know where hackers got those logins but it wasn’t from us

Risk High Date Discovered March 8, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]

uTorrent Forum Suffers Data Breach, 385,000 Credentials Database Stolen
uTorrent Forums User List Stolen
Google patches high-severity flaw in Chrome’s PDF reader

An update for firefox is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: firefox security update Advisory ID: RHSA-2016:1217-01 Product: Red Hat Enterprise […]

Google Patches High Severity Browser PDF Vulnerability
Change Your Passwords! Hacker Selling 33 million Twitter Logins on Dark Web
Stolen Twitter Credentials Latest Dataset For Sale
Uber awards researcher $10,000 for reporting serious security hole
VIDEO: The best video security blog? Thank you!
Latest Intelligence for May 2016
Our latest intelligence reveals Angler responsible for over 51 percent of exploit kit attacks, and one email in every 134 is now malicious. Read More
CryptXXX Ransomware Jumps From Angler to Neutrino Exploit Kit
VIDEO: George Harrison finds death is no escape from hackers
Hitting emails and Facebook: Ray-Ban scam is back

A while ago, we informed you about a Ray-Ban scam campaign flooding Facebook via hacked profiles. Using fake ads that offered massive discounts, attackers tried to lure users into “buying” branded sunglasses, thus giving up their payment card details via an unsecured channel. Spread mostly via posts disguised as ads for Ray-Bans, the scam also […]

French B&Q equivalent ‘hacked’ to offer visitors vulgar DIY tools
Most organizations unconfident in ability to protect data after breach

��}��6��oOU���3�b��e�c��;���m=�dslEBg(��e4�3U�;쯭ڭ�Wت}��o�=�v ^��hd’ٵs1E�F���G�99���s��٫��o���K�u�i?�*$�й�*�舌�882�jx���{4��ݻO�G���FM�ˮr�{1�b�lP�X�WW��Ul`����#w�x�(��U��/ڏO���3peP/�w�=��9�]�ҡ��c��Ա�qצ��E5�Aω��”�ti�Ui��#�j�S풆�бߓ �m��ߦ���~�칯��l�����������͟__X��EU���tی��lI`O�������흴w[��������w’O�>iu8,”�L��.HHݮ�3�FcJ�1�_�݊”�L��]%����]E�x:��S�:�4�V:�L��1 4����F|g�֐�`�:����辦���$��� v&�o�&S’F4�i��G����ʏb�#�s~cD�H�A�CdžƁ[�8.�EbDԏ� �����d��4�B'(0����>��C��! iA9Ӎ��b���.j�}��7″&�Դ�ČE�3 ��=��.��Ğ��A�iju����L��@����n��&�{h䨧I����]C�5���|��� ��}�GŐ�G�>����q^��0v,�.,������E ��I�J��AR���G��P�9T�ph��N��U�d�:`��>��a�ք�Z;G�ã���f�� n��`�o��j��@C�h��Ǚ�#�2k%��o�Q��#%N���Hj����nL�#�m��(�L�p�,(�R�}؜�Y�*��_�\HZb:�2�ZP����”���~xCwq�7�/� �>}��n2r)3�?�u=��:y ����4��|� ���ȓ�M�~~ ]|�D��4|+��)в�ݽ[Bm�1j�o�fEY�6�;pJ�1vV����Ƕ�_vQ삉�Ʈ!!ʊ��:�=9Ų��b��@f������1�%eLk���.,���P��ⱆ�įz�R�z��mU��e���v��

How Bad Is Burr-Feinstein Anti-Encryption Legislation?
New Intelligence Bill Gives FBI More Secret Surveillance Power
This company uses AI to stop cyberattacks before they start
Do it now! From SHA-1 to SHA-2 in 8 steps
Sophos U-turns on lack of .bat file blocking after El Reg intervenes
Google IMAP losing old security protocols this month
Boffins shake up smartphone with motion-sensor as microphone
Chrome’s PDF reader has arbitrary code execution flaw
Robot lung probe wins licence from US authorities
Melbourne motorway to lose its $1k-per-call emergency phones