Menu

Monthly Archives: July 2016

Mac users who ignore the warning signs can be bitten by the Adwind RAT
Pornhub hacked: Hackers go away with $20,000 instead of exposing flaw
TechCrunch defaced by self-professed ‘white hats’
Three men charged for international cell phone fraud scheme
O2 customer DATA GRAB: Not-a-hack creds for sale on dark web
Blockchain: You’ve got questions; we’ve got answers
FBI probes DNC hack as suspicions of Russian involvement widen
Hackers create Safe Skies TSA master key from scratch, release designs
Malicious computers caught snooping on Tor-anonymized Dark Web sites
Snowden Designs a Device to Warn if Your iPhone’s Radios Are Snitching
How to report a cybercrime
3 ways websites get pwned — and threaten you

Some days when I’m wasting time on the internet, it seems like I can’t visit three websites in a row without hitting a fake “you’re infected” scam or bogus browser extension ad. Most of the time these malicious offerings launch on otherwise legitimate websites — or secretly direct your browser to illegitimate websites. For almost […]

Failing projects pray blockchain works as ‘magic middleware’
UK ‘leccy car company Ecotricity patches leaky car recharge app
European privacy body slams shut backdoors everywhere
Microsoft offers admins free Win 10 upgrade lube
Boffins snoop on snooping Tor nodes
Internet in Mumbai Goes Slow As ISPs Suffer Massive DDoS Attacks
Windows UAC Bypass Leaves Systems Open to Malicious DLLs

Several vulnerabilities have been fixed in phpMyAdmin, the web-based MySQL administration interface. CVE-2016-1927 The suggestPassword function relied on a non-secure random number generator which makes it easier for remote attackers to guess generated passwords via a brute-force approach. CVE-2016-2039 CSRF token values were generated by a non-secure random number generator, which allows remote attackers to […]

Upcoming Tor Design Battles Hidden Services Snooping

An update for mariadb55-mariadb is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: mariadb55-mariadb security update Advisory ID: RHSA-2016:1481-01 Product: Red Hat Software Collections Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1481.html Issue date: 2016-07-25 CVE Names: CVE-2015-4792 CVE-2015-4802 CVE-2015-4815 […]

An update for mysql55-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: mysql55-mysql security update Advisory ID: RHSA-2016:1480-01 Product: Red Hat Software Collections Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1480.html Issue date: 2016-07-25 CVE Names: CVE-2015-4792 CVE-2015-4802 CVE-2015-4815 […]

Debian: 3627-1: phpmyadmin: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3627-1 security@debian.org https://www.debian.org/security/ Thijs Kinkhorst July 24, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : phpmyadmin CVE ID : CVE-2016-1927 CVE-2016-2039 CVE-2016-2040 CVE-2016-2041 CVE-2016-2560 CVE-2016-2561 CVE-2016-5099 CVE-2016-5701 CVE-2016-5705 CVE-2016-5706 CVE-2016-5731 CVE-2016-5733 CVE-2016-5739 Several vulnerabilities have been fixed in phpMyAdmin, the […]

Debian: 3626-1: openssh: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3626-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 24, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : openssh CVE ID : CVE-2016-6210 Debian Bug : 831902 Eddie Harari reported that the OpenSSH SSH daemon allows user enumeration through timing differences when trying […]

Slackware: 2016-204-01: bind: Security Update Posted by Anthony Pell    New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. [More Info…] [slackware-security] bind (SSA:2016-204-01) New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. […]

Discovered: July 24, 2016 Updated: July 25, 2016 3:44:31 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows NT, Windows Vista, Windows XP Antivirus Protection Dates Initial Rapid Release version July 24, 2016 revision 025 Latest Rapid Release version July 24, 2016 revision 025 Initial […]

Trojan.Gen.5 is a generic detection for many individual but varied Trojans for which specific definitions have not been created. A generic detection is used because it protects against many Trojans that share similar characteristics. Trojan horse programs pose as legitimate programs or files that users may recognize and want to use. They rely on this […]

PornHub Hack Earns Researchers $22,000
Nascar Race Team’s Computer Hacked; Infected with Ransomware
OpenBSD 6.0 tightens security by losing Linux compatibility
Auto industry publishes first ever cybersecurity best practices

��}ے۸�����gL�-����U�

Tinder porn scam: Swipe right for NOOOOOO I paid for what?
Anonymous Hacks Turkish Energy & Gas Provider Website
Clash of Kings forum hacked, 1.6 million account details put at risk
Happy ending for Pornhub after vulnerability researchers gain access to entire user database
Tinder spam bots trick users into paying for adult content
Is digital fraud big in UK? British abacus-botherers finally have some answers
Police 3D print murder victim’s finger to unlock his phone
Wire open-sources messaging client, woos developers
Security firms team to take down rudimentary ransomware
I don’t like Mondays, Pokemon, Twitter or Facebook – Sir Bob Geldof
Verizon wants to replace your net gateways with ‘a simple mux’
Oops: Bounty-hunter found Vine’s source code in plain sight
Eurocrats to pore over Apache, KeePass code

CVE-2016-1238 John Lightsey and Todd Rinaldo reported that the opportunistic loading of optional modules can make many programs unintentionally load code from the current working directory (which might be changed to another directory without the user realising) and potentially leading to privilege escalation, as demonstrated in Debian with certain combinations of installed packages. The problem […]

Risk Level: Very Low. Type: Trojan.

Discovered: July 25, 2016 Updated: July 25, 2016 3:40:40 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Sorcurat is a Trojan horse that opens a back door on the compromised coputer. […]

Risk Level: Very Low. Type: Trojan.

PHP flaws allowed God mode access to top smut site
Cryptography vs. bigotry: the debate Australia needs to have
US standards lab says SMS is no good for authentication
Prisma App Now Available for Android; Download Now
KickassTorrents’ Mirrors Appear online with Petition for Artem Vaulin Release

Eddie Harari reported that the OpenSSH SSH daemon allows user enumeration through timing differences when trying to authenticate users. When sshd tries to authenticate a non-existing user, it will pick up a fixed fake password structure with a hash based on the Blowfish algorithm. If real users passwords are hashed using SHA256/SHA512, then a remote […]

Clash of Kings forum Breached; 1.6 Million Users’ Accounts Stolen
DNC Emails from WikiLeaks Pose Massive Privacy Threat to Donors
Munich Shooter Invited People to McDonald’s using hacked Facebook account
Researching Mr. Robot, Elliot’s world, and cybersecurity at Comic-Con

(With Comic-Con International 2016 taking place in ESET’s own backyard again this year, we are digging into all-things cybersecurity at the Con. In this article, Guest Writer Anna Keeve enters the world of Mr. Robot). ESET’s support for Comic-Con ranges from tips for staying safe while traveling, and hitting the streets to make sure people […]

5 ‘Mr. Robot’ Hacks That Could Happen in Real Life
Firefox sets kill-Flash schedule

There’s a lot that happens in the security world, with many stories getting lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. Rio Olympics: A Cyberthreat Goldmine With the 2016 Olympic games right around the corner, it’s […]

Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.50. Please see the MySQL 5.5 Release Notes and Oracle’s Critical Patch Update advisory for further details: For the stable distribution (jessie), these problems have been fixed in version 5.5.50-0+deb8u1. We recommend that […]

WikiLeaks fights The Man by, er, publishing ordinary people’s personal information

Risk High Date Discovered July 12, 2016 Description Adobe Flash Player is prone to multiple remote code-execution vulnerabilities. An attacker can exploit these issues to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely result in denial-of-service conditions. Recommendations Run all software as a nonprivileged user […]

Risk High Date Discovered July 12, 2016 Description Adobe Acrobat and Reader are prone to multiple unspecified memory-corruption vulnerabilities. Attackers can exploit these issues to execute arbitrary code in the context of the application. Failed attacks may cause a denial-of-service condition. Technologies Affected Adobe Acrobat 11.0.0 Adobe Acrobat 11.0.06 Adobe Acrobat 11.0.07 Adobe Acrobat 11.0.08 […]

Debian: 3625-1: squid3: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3625-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond July 22, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : squid3 CVE ID : CVE-2016-4051 CVE-2016-4052 CVE-2016-4053 CVE-2016-4054 CVE-2016-4554 CVE-2016-4555 CVE-2016-4556 Debian Bug : 823968 Several security issues have been discovered in the Squid caching […]

Slackware: 2016-203-01: gimp: Security Update Posted by Anthony Pell    New gimp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue. [More Info…] [slackware-security] gimp (SSA:2016-203-01) New gimp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue. Here are the details from the […]

Slackware: 2016-203-02: php: Security Update Posted by Anthony Pell    New php packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…] [slackware-security] php (SSA:2016-203-02) New php packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. Here are the details from the Slackware 14.2 […]

Debian: 3624-1: mysql-5.5: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3624-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 21, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : mysql-5.5 CVE ID : CVE-2016-3477 CVE-2016-3521 CVE-2016-3615 CVE-2016-5440 Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL […]

PowerWare Ransomware Masquerades as Locky to Intimidate Victims
PayPal Fixes CSRF Vulnerability in PayPal.me

When it comes to drive-by attacks, CryptXXX is king. In fact, out of all the exploit kits dropping payloads on victims, 80% result in CryptXXX. The creators attacked vulnerabilities in Flash Player, Java and Silver Light through using the Angler exploit kit, with malvertising helping boost their success. The malware authors were able to generate $3 Million […]

Cerber is yet another newer ransomware that has been gaining some traction over the past couple months, so we’re providing a breakdown of this new variant. First, here is how it looks: Unlike some other ransomware variants, Cerber is certainly not going for aesthetics. It also lacks any type of GUI. However, it does change your background to an […]

CrytpoMix has been gaining some traction over the past few months, so it’s a good idea that we provide a rundown of this variant in the ransomware family. This is ‘barebones ransomware’, so victims aren’t presented with a GUI or a desktop background change. All that is presented is a text file and webpage showing the same text. […]

Edward Snowden’s new case design detects if your iPhone is broadcasting its location
When the people selling you IT security solutions hack into their rival’s database…
SoakSoak using compromised websites to spread CryptXXX ransomware
Apple, Facebook and Coinbase coughed data to finger alleged pirate king
How Apple and Facebook Helped US to Arrest Kickass Torrents’ Owner

Several security issues have been discovered in the Squid caching proxy. CVE-2016-4051: CESG and Yuriy M. Kaminskiy discovered that Squid cachemgr.cgi was vulnerable to a buffer overflow when processing remotely supplied inputs relayed through Squid. CVE-2016-4052: CESG discovered that a buffer overflow made Squid vulnerable to a Denial of Service (DoS) attack when processing ESI […]

Google Fixes 48 Bugs, Sandbox Escape, in Chrome
Firefox to Block Flash in August, Disable in 2017

An update for java-1.6.0-sun is now available for Oracle Java for Red Hat Enterprise Linux 5, Oracle Java for Red Hat Enterprise Linux 6, and Oracle Java for Red Hat Enterprise Linux 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: java-1.6.0-sun security update Advisory ID: RHSA-2016:1477-01 Product: Oracle Java for Red Hat Enterprise Linux […]

An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 5, Oracle Java for Red Hat Enterprise Linux 6, and Oracle Java for Red Hat Enterprise Linux 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.7.0-oracle security update Advisory ID: RHSA-2016:1476-01 Product: Oracle Java for Red Hat Enterprise Linux […]

An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.8.0-oracle security update Advisory ID: RHSA-2016:1475-01 Product: Oracle Java […]

Red Hat: 2016:1474-01: openstack-neutron: Low Advisory Posted by Anthony Pell    An update for openstack-neutron is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Low: openstack-neutron security, bug fix, […]

Red Hat: 2016:1473-01: openstack-neutron: Low Advisory Posted by Anthony Pell    An update for openstack-neutron is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Low: openstack-neutron security and bug fix update Advisory ID: RHSA-2016:1473-01 […]

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.8.0-openjdk security update Advisory ID: RHSA-2016:1458-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2016:1458 Issue […]

Gentoo: 201607-16 arpwatch: Privilege escalation Posted by Anthony Pell    arpwatch is vulnerable to the escalation of privileges. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – Gentoo […]

Gentoo: 201607-15 NTP: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in NTP, the worst of which could lead to Denial of Service. – – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201607-14 Ansible: Privilege escalation Posted by Anthony Pell    A vulnerability in Ansible may allow local attackers to gain escalated privileges or write arbitrary files. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201607-13 libbsd: Arbitrary code execution Posted by Anthony Pell    A buffer overflow in libbsd might allow remote attackers to execute arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201607-12 Exim: Arbitrary code execution Posted by Anthony Pell    A local attacker could execute arbitrary code by providing unsanitized data to a data source or escalate privileges. – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201607-11 Bugzilla: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in Bugzilla, the worst of which could lead to the escalation of privileges. – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Bosses at UK infosec biz Quadsys confess to hacking rival reseller

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.