Menu

Monthly Archives: July 2016

Encrypting ransomware is so popular now that competitors will sabotage one another to get the upper hand. This is refreshing for victims, however, as they reap the benefit of these potential clashes between cybercriminals. ‘Chimera Ransomware’ has just had its keys leaked to the public, which is fantastic news for anyone who has been a victim […]

New Android Trojan SpyNote leaks on underground forums
ISF publishes major update to its information security guide

The Information Security Forum (ISF) has published a major update to its Standard of Good Practice for Information Security  for IT security professionals. The Standard, as it is known, is a comprehensive guide to internet security best practise, providing organizations with a ready-made framework for responding to and managing major incidents. The latest edition shows a […]

There’s a lot that happens in the security world, with many stories getting lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. Wireless Keyboards Found To Be Vulnerable To Radio Hack In a recent study, it was […]

SentinelOne’s $1m ransomware guarantee dismissed as PR stunt
WhatsApp doesn’t properly erase your deleted messages, researcher reveals
Get rid of these undesirable ‘friends’ on major social network

Either because they share too much, because they send links and applications that you are not interested in, because you don’t know for real who they are, or because they are too passionate about their opinions, there are some online ‘friends’ that you should keep away from. Tomorrow we will celebrate the International Day of […]

Android app found in Google Play store stole users’ photos, videos
Would you risk running a VPN in the United Arab Emirates?
Black Hat: 9 free security tools for defense and attacking
FBI said to investigate possible hack of another Democratic Party organization
New attack bypasses HTTPS protection on Macs, Windows, and Linux
Security professionals ‘extremely concerned’ by cybercrime threat

Security professionals are more concerned than ever by the threat of cybercrime, according to new poll. The Black Hat Attendee Survey 2016 – the second of its kind – found that 72% of cyber experts anticipate having to deal with a major data breach over the next year. This view is in response to the growing […]

It’s time for a discussion about malvertising
Argos changes 150 easily guessed drop-off system passwords
Download Microsoft Pix App for Stunning Photo Results on Apple Devices

Discovered: July 29, 2016 Updated: July 29, 2016 2:57:54 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Infostealer.Rultazo is a Trojan horse that steals information from the compromised computer. Antivirus Protection […]

Don’t use a VPN in United Arab Emirates – unless you wanna risk jail and a $545,000 fine

Multiple vulnerabilities have been discovered in the Xen hypervisor. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2015-8338 Julien Grall discovered that Xen on ARM was susceptible to denial of service via long running memory operations. CVE-2016-4480 Jan Beulich discovered that incorrect page table handling could result in privilege escalation inside a Xen […]

Debian: 3633-1: xen: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3633-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff July 27, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : xen CVE ID : CVE-2015-8338 CVE-2016-4480 CVE-2016-4962 CVE-2016-5242 CVE-2016-6258 Multiple vulnerabilities have been discovered in the Xen hypervisor. The Common Vulnerabilities and Exposures project identifies […]

Debian: 3632-1: mariadb-10.0: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3632-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 27, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : mariadb-10.0 CVE ID : CVE-2016-3477 CVE-2016-3521 CVE-2016-3615 CVE-2016-5440 Several issues have been discovered in the MariaDB database server. The vulnerabilities are addressed by upgrading MariaDB […]

Google Details Linux Kernel Defenses, New and Old
Get Transcript IRS fraud lands married couple in prison
Cyberattacks affect ‘nearly every single company’

��}�r۸���j�a΄�D$�aˎm)7q�����’g�l�uA”$ѦH��=W�w�?���U��or�d��?$˲���JΙ�”�F���h4�;O^��כ�䗷/_��}0��.q�7�i�3�i$��9�i�x�L�8س,�Sfy�] ��:�0j�o���`�bʋ�S��Cߋ�o/������bv[���pBÈŽ$����p����q�O;W��i��c����)�ig�~+�g�Oz6;s���?��ء� ��z�*Hc��̈��g,tF��=��M�����p�&]�e�MYk�*8z>xC�4i���t�>�V�0�Ψ��4ff���=|�����}�����[�g�n���9|v���Q�#`�`��wJB��(�pY4a�%هQ��)��ӂ�������!��f挹���0 ����Sk)+��)�,�ΡY�!��29t�=����� o’ND�x��ؙ:�3�̜xB1�a�o�N���ŀ�4���4″t4bØܻ��

Petya Sabotages Rival Ransomware Chimera, Leaks Decryption Keys
LastPass Patches Ormandy Remote Compromise Flaw
How Illegal Streaming is Putting Your Security at Risk
5 highlights from the ‘information security Olympic Games’

There is nothing quite like the Summer Olympic Games. Often described as one of the greatest sports events in the world, the spectacle of this historic sporting extravaganza, in terms of the pomp of the ceremony to the amazing feats achieved by the athletes, makes for captivating viewing. In the spirit of this year’s event, […]

Security FUD and malware outbreaks boost Sophos’ coffers
Security Sessions: Generational differences in security, privacy attitudes
Citibank IT guy deliberately wiped routers, shut down 90% of firm’s networks across America
Petya, Mischa ransomware-as-a-service affiliate system goes live
How should businesses respond to the TechCrunch hack?
Flight sim records show MH370 captain practiced ‘flight’ near search area
Exclusive transcript: WikiLeaks reveals ass call from a zoo
WikiLeaks Releases Voicemails from Hacked DNC Emails
Apps record your heartbeat but now you worry the Census will remember your name?
LastPass hacked; security compromised for good
Airbus doesn’t just make aircraft – now it designs drone killers
Donald Trump asks for help from Russian hackers. Cher isn’t happy
Couple in the cooler for sucking $1m out of Uncle Sam via IRS ‘Get Transcript’ scam
Flaw with password manager LastPass could hand over control to hackers
White House Beefs Up Cyber Threat Response Action Plan

Several vulnerabilities were found in PHP, a general-purpose scripting language commonly used for web application development. The vulnerabilities are addressed by upgrading PHP to the new upstream version 5.6.24, which includes additional bug fixes. Please refer to the upstream changelog for more information: https://php.net/ChangeLog-5.php#5.6.24 For the stable distribution (jessie), these problems have been fixed in […]

Secunia Research at Flexera Software discovered an integer overflow vulnerability within the _gdContributionsAlloc() function in libgd2, a library for programmatic graphics creation and manipulation. A remote attacker can take advantage of this flaw to cause a denial-of-service against an application using the libgd2 library. For the stable distribution (jessie), this problem has been fixed in […]

Did Donald Trump really just ask Russia to hack the US govt? Yes, he did
Trump Comments Straddle Line of Soliciting Computer Crime
Ex-Citibank IT bloke wiped bank’s core routers, will now spend 21 months in the clink
Hackers to show how to hack wireless keyboard from 250 feet away
Jacob Appelbaum is a bullying sex pest, says ex-employer Tor Project

An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: java-1.7.0-openjdk security update Advisory ID: RHSA-2016:1504-01 Product: Red Hat Enterprise […]

Ubuntu: 3043-1: OpenJDK 8 vulnerabilities Posted by Anthony Pell    Several security issues were fixed in OpenJDK 8. ========================================================================== Ubuntu Security Notice USN-3043-1 July 27, 2016 openjdk-8 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS Summary: Several security issues were fixed in OpenJDK 8. Software Description: […]

Debian: 3631-1: php5: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3631-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff July 26, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : php5 CVE ID : CVE-2016-5385 CVE-2016-5399 CVE-2016-6289 CVE-2016-6290 CVE-2016-6291 CVE-2016-6292 CVE-2016-6294 CVE-2016-6295 CVE-2016-6296 CVE-2016-6297 Several vulnerabilities were found in PHP, a general-purpose scripting language commonly […]

Debian: 3630-1: libgd2: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3630-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 26, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libgd2 CVE ID : CVE-2016-6207 Secunia Research at Flexera Software discovered an integer overflow vulnerability within the _gdContributionsAlloc() function in libgd2, a library for programmatic […]

An update for kernel is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security, bug fix, and enhancement update Advisory ID: RHSA-2016:1489-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1489.html […]

NIST Recommends SMS Two-Factor Authentication Deprecation
Attributing Advanced Attacks Remains Challenge For Researchers
Oh deer.io: Cyberpunks using one-stop DIY web biz shops
Sorry, your Motorola Android isn’t going to get monthly security updates
LastPass security hole could have seen hackers steal your passwords
The KickassTorrents Case Could Be Huge
Over 100 suspicious, snooping Tor nodes discovered
Schneier: Next president may face IoT cyberattack that causes people to die
Linux 4.7 now out with enhanced security and advanced graphics support
NIST is no longer hot for SMS-based two-factor authentication
Saved from ransomware thugs… by rival ransomware thug
StackPath offers security as a service to enterprise clouds
Explo-Xen! Bunker buster bug breaks out guests from hypervisor
Zero-day hole can pwn millions of LastPass users, all that’s needed is a malicious site
Osram’s Lightify smart bulbs blow a security fuse – isn’t anything code audited anymore?
Cisco busts ransomware rodent targeting bitcoin, cryptocoin subreddits
Cisco warns responders: Drop ego, assimilate with the IR playbook
Did the Russians really hack the DNC or is this another Sony Pictures moment? You decide

Several issues have been discovered in the MariaDB database server. The vulnerabilities are addressed by upgrading MariaDB to the new upstream version 10.0.26. Please see the MariaDB 10.0 Release Notes for further details: https://mariadb.com/kb/en/mariadb/mariadb-10026-release-notes/ For the stable distribution (jessie), these problems have been fixed in version 10.0.26-0+deb8u1. For the unstable distribution (sid), these problems have […]

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

3D print biz Shapeways hacked, home and email addresses swiped
Facebook Phishing Scam Using Pornographic Images to Steal Login Data
Yahoo Ordered to Explain Data Gathering Procedures in Deleted Email Case
Anti-theft kill switches in smartphones just got a little less creepy

Several vulnerabilities were discovered in the Network Time Protocol daemon and utility programs: CVE-2015-7974 Matt Street discovered that insufficient key validation allows impersonation attacks between authenticated peers. CVE-2015-7977 CVE-2015-7978 Stephen Gray discovered that a NULL pointer dereference and a buffer overflow in the handling of ntpdc reslist commands may result in denial of service. CVE-2015-7979 […]

SentinelOne says if you get hit by ransomware, it will pay the ransom
Kimpton Hotels Investigating Payment Card Fraud

Red Hat: 2016:1487-01: samba4: Moderate Advisory Posted by Anthony Pell    An update for samba4 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: […]

An update for samba is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: samba security and bug fix update Advisory ID: RHSA-2016:1486-01 Product: […]

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:1485-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1485.html Issue date: 2016-07-26 CVE Names: […]

Debian: 3629-1: ntp: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3629-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff July 25, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : ntp CVE ID : CVE-2015-7974 CVE-2015-7977 CVE-2015-7978 CVE-2015-7979 CVE-2015-8138 CVE-2015-8158 CVE-2016-1547 CVE-2016-1548 CVE-2016-1550 CVE-2016-2516 CVE-2016-2518 Several vulnerabilities were discovered in the Network Time Protocol daemon […]

Debian: 3628-1: perl: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3628-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 25, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : perl CVE ID : CVE-2016-1238 CVE-2016-6185 Debian Bug : 829578 Multiple vulnerabilities were discovered in the implementation of the Perl programming language. The Common Vulnerabilities […]

Odds are your office is ill-prepared for network-ransacking ransomware
BlackBerry hopes you’ll gobble up its $299 midrange biz ‘Droid
It’s 2016 and your passwords can still be sniffed from wireless keyboards
Public, Private Sector Team to Fight Ransomware
‘No More Ransom’ Anti-Ransomware Portal; Recovers Encrypted Data for Free
Reworked OpenSSL on track for government validation
Yes, there has been a data breach at O2. But it’s not really their fault
KeySniffer Vulnerability Opens Wireless Keyboards to Snooping
Unpatched Smart Lighting Flaws Pose IoT Risk to Businesses