Menu

Monthly Archives: July 2016

Risk Level: Very Low. Type: Trojan, Virus, Worm.

EFF Files Lawsuit Challenging DMCA’s Restrictions on Security Researchers
15 Vulnerabilities in SAP HANA Outlined
Tinder safe dating spam uses safety to scam users out of money
Scammers drive users to fake verification site that signs them up to adult webcam and erotic video websites. Read More
Playstation chief Shuhei Yoshida has his Twitter hacked by OurMine
GOP delegates suckered into connecting to insecure Wi-Fi hotspots
How to secure your cyber infrastructure from threats like ransomware?
Ransomware gang: How can I extort you today?
Turns out that you can’t trust ‘Trump free Wifi’ at the Republican National Congress
Cisco patches critical exposure in management software
Petition urges Apple not to release technology for jamming phone cameras
IoT Insecurity: Pinpointing the Problems
Hackers are targeting the Rio Olympics, so watch out for these cyberthreats
Drupalgeddon hits Warframe – nearly 800,000 gamers’ account details being sold on the net
Analyzing Mr. Robot: S02E01

��}ے�F���(QsD�”�[߻�:RKkF����h����$� ƥٴ���p�m^�e#6b����OΗlfV���l�c�J3�@�*+++3+3+�����oO�~x�}}�����&��a��5�jߟ֘��}5������w�n���Oy� ֠ν� 7��{�D�MyhPQ��ٗ�ډpC�����5f�_�Zȯ�66xhN?�� G�^������g��ډ�zFh�,��/��|Uט�A���3O�a��̶���◶�5��b�k���h�i8|Э�4b�p-�C�]r��& “���aϸ�/����}�G;���s����7�����M����o.��U����ipi8�e��t3`O^�����n����vv:����W’�v�=��%,��L�v/�ϝA-�&�B��”�56�mj�o��u=��!��f�;�%��v8�M1m�����$�”봻z�MOO”�`��?��W��j�#��Og�������V��74dWS�w���GŸ��-�*�~|��آ2�K�8���� �ӹLJ7>0]jPa!oO��܈B;�r%y�5p(�n��&*”ܸ,��?��5b߻)#�$^�&x���*{Ԛz�����T�%̼J����ta��E��?�%�6L�n��Z��1�)-�Wm�w����w�W�$r#x���0�]�0uR�CGкu���Z0wC�jN9J����v�DT������c;= b~��/��F��{�в���Kh+1B��ۏ-�p��)Z#b�f)���E�V=�z�;^��bQfNN�����t����������v:{�>�v��C(ߦc�6s�Ks��/����wJ>0�{�k�4��O��/f5�-�)�S��”�hSKۧ�` �������,�J%���`+0�PD��İx�o��C�t�6�����tf�|G���”x��)[��C˅�H�Y�PP�~����q��M ���`��� plm�3iiZw���j|d8?�B��䌘��}Z���Fԁ�d�M�/�+{E=‰OQ`�,a��B��’�e�s�€�p�l�|c���!��ۓ�h��R)1�@����a2ԡ����R�@�1� �hyAhK%5�� ����u�J�>5C�Y��}uʸ�^����K8�㥟�#V���Q�����M ��]�`3nN���J`�)���n�m�����M �0�n�V���l����A��1� y����@�WF5U=.�uo��a�t%�k�u@�I������ ��.��^��%����&>/�roE5*K�,Pd�3�2��@�%o?�*]v�a�A��R�X;���E�A?Wi��yN���O �������OJ’oY�)��Q��[1����,�G��~��O��Y�-� ��8��`�e�� ��u�ܡ���nw#]�}���Fk���l)ӡWFȃ�}�cy[�[��JykO��5L8�-{mt�r@o���fF���f�B�wrc�5L�gU}U�Be?�%蛬��K������$j�TPMq� �la�=`�s|*w���l2��?.mn ӿM+��+`�,_x���Y��N*ĴyX�V�Zq���,l�� � /�@U�H} 8?����d�A��G!-�8i’����)�}g���w3’�B�� +6�!��`$Ŋ���߾��E�j�E����b����i���d�X�7�*��b� f�gp�gh���F>���0/�ͮ��P�f{_-s�Q��bVWղ�U s/]�J˜�V�Ug��f��d{m�7�G����彁R�z5����YW_��)1�9m7: ��>��8�E��`�����=���8�D�F�D�9�^�lu��b~K�z�ա��i��9Pd�1�z�@oR�d�pl�=4���L~�|ò���i�ţm(ߣգfY�i�e �֓�;��2�`�N~ti!IWg0.VX�?~�ﰼLӸBF3��`�}M�V⽘6����@.yB=��šIB�7&��] [ph�v��Mj�`_̡����Eǒ�.�~�ygt� ���A1��2x/���;�铱�9Q@)�R�a 6g�*,Iõ��4�W�Gn�f[��t�%M���gՑz)1�V�R��29�>�`�,�cp/V@��=�])}lQX9;n9�’ ��r�sv^��-���c�%uOlTB� 7��v��&o���}*E�Ȁ���k��qՅ��2�oGߺ�On2͖7 ��e���$�Fhw�b��1xt��f���ի��T}���MUW8*���ٌ`� �}a�Di=�zŴ��x��-��§�휏|&YF?nd#YcFVӔF�.Q�#�4:��”�5LF+� ���+��M���tL�?M0i /��*�e#_fb oQuzr�)Ώ�~C��3��e`Tb����~�}##]��7�����ӥ���㧴��w�ɽ��xL�+}Q�����նU/��L�x�T��:s|���;?�����[�?o���5����U������[���5{ �|ޚ�yk�j��fޚ}b}ޚ�yk��ٹ&>o���5������P��7����?�� “6�t(1p�et�rw��Q -�!�ۉ�-�5�D�g�F�ϻID��I=�DӡKr�⁘��_�6f-�J��~F4O�p����B��9�F�H�J�kof�{�!������o��o����U

Microsoft and pals re-write arms control pact to save infosec industry
Asian nations mull regional ‘Europol’ in fight against cybercrime
Kickass Torrents Goes Down; Owner Arrested
Massive DDoS Attack Shut Down Several Pro-ISIS Websites

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Users of iPhones and Macs must update to avoid Stagefright-like bug
Everyone’s favorite infosec biz – Blue Coat – must cough up $40m to rival in patent rip-off row
Salesforce will only support Nexus and Samsung Galaxy phones to avoid Android fragmentation
Firefox to banish hidden Flash files – and kill off sneaky ad snoopers
Oracle’s monster security update fixes Java, database bugs
SoakSoak Botnet Pushing Neutrino Exploit Kit and CryptXXX Ransomware

Anti-virus software is a program or set of programs that are designed to prevent, search for, detect, and remove viruses, and other forms of malware such as worms, trojans, adware, and more. As our world continues to become ever more connected, anti-virus remains critical for users seeking to keep their devices protected. However, it’s vital that the […]

US Congress websites recovering after three-day DDoS attack
Oracle issues largest patch bundle ever, fixing 276 security flaws
Oracle Patches Record 276 Vulnerabilities with July Critical Patch Update
How Bad is the North Korean Cyber Threat?
Feds shut down tech support scammers, freeze assets
Jackware: When connected cars meet ransomware

2016 is already being dubbed “The Year of Ransomware” and ransomware features prominently in my upcoming “Mid-Year Threat Review” webinar. In that webinar I will also be talking about the IoT (Internet of Things) and more specifically the IoIT (the Internet of Insecure Things); mainly because risks arising from the latter are on the rise. […]

New HIPAA guidance addresses ransomware
Google says government requests for user data at all-time high
Russian security firm linked to cybercrime gang
Hacker shows Reg how one leaked home address can lead to ruin
What’s big and red and squashes 276 bugs, 19 of them critical?
Flaws found in security products from AVG, Symantec and McAfee
WordPress admin? Thinking of spending time with the family? Think again
WhatsApp gets another Brazilian whack as magistrate blocks it again

Scott Geary of VendHQ discovered that the Apache HTTPD server used the value of the Proxy header from HTTP requests to initialize the HTTP_PROXY environment variable for CGI scripts, which in turn was incorrectly used by certain HTTP client implementations to configure the proxy for outgoing HTTP requests. A remote attacker could possibly use this […]

Anonymous DDoS Rio Court Website for Blocking WhatsApp in Brazil
Apple kills eavesdrop bug in FaceTime
What keeps former New York Mayor Rudy Giuliani awake at night?

It was discovered that Django, a high-level Python web development framework, is prone to a cross-site scripting vulnerability in the admin’s add/change related popup. For the stable distribution (jessie), this problem has been fixed in version 1.7.7-1+deb8u5. We recommend that you upgrade your python-django packages.

A vulnerability was discovered in mysql-connector-java, a Java database (JDBC) driver for MySQL, which may result in unauthorized update, insert or delete access to some MySQL Connectors accessible data as well as read access to a subset of MySQL Connectors accessible data. The vulnerability was addressed by upgrading mysql-connector-java to the new upstream version 5.1.39, […]

The Troubling State of Security Cameras; Thousands of Devices Vulnerable
BlackBerry chief: We don’t have to make phones to make phones

Debian: 3622-1: python-django: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3622-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 18, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : python-django CVE ID : CVE-2016-6186 It was discovered that Django, a high-level Python web development framework, is prone to a cross-site scripting vulnerability in the […]

An update for httpd is now available for Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: httpd security update Advisory ID: RHSA-2016:1421-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2016:1421 Issue […]

An update for httpd is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: httpd security and bug fix update Advisory ID: RHSA-2016:1422-01 Product: Red […]

Debian: 3621-1: mysql-connector-java: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3621-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 18, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : mysql-connector-java CVE ID : CVE-2015-2575 A vulnerability was discovered in mysql-connector-java, a Java database (JDBC) driver for MySQL, which may result in unauthorized update, insert […]

Red Hat: 2016:1420-01: httpd24-httpd: Important Advisory Posted by Anthony Pell    An update for httpd24-httpd is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: httpd24-httpd security update Advisory ID: RHSA-2016:1420-01 Product: Red Hat Software Collections […]

DDoS trends: Bigger, badder but not longer

How are they a security threat? People, not computers, create computer threats. Computer predators victimize others for their own gain. Give them access to the internet — and to your PC — and the threat they pose to your security increases exponentially. Computer hackers are unauthorized users who break into computer systems in order to steal, […]

Google Chrome Malware Leads to Sketchy Facebook Likes
Carbon Black snaps up cloud-dwelling threat-sniffing ‘next-gen AV’
Ex-Cardinals Exec Sentenced Four Years for Astros Hack
Steemit experienced hack, theft of user funds, and DDoS attack
Baton Rouge City Website Hacked Against Alton Sterling’s Death
IoT baby monitor style hacks still a threat

APPLE-SA-2016-07-18-6 iTunes 12.4.2 Subject: APPLE-SA-2016-07-18-6 iTunes 12.4.2 From: Apple Product Security Date: Mon, 18 Jul 2016 17:26:55 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-07-18-6 iTunes 12.4.2 iTunes 12.4.2 for Windows is now available and addresses the following: libxml2 Impact: Multiple vulnerabilities in libxml2 Description: Multiple memory corruption issues were addressed through improved memory handling. […]

APPLE-SA-2016-07-18-5 Safari 9.1.2 Subject: APPLE-SA-2016-07-18-5 Safari 9.1.2 From: Apple Product Security Date: Mon, 18 Jul 2016 17:22:29 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-07-18-5 Safari 9.1.2 Safari 9.1.2 is now available and addresses the following: WebKit Available for: OS X El Capitan v10.11.6 Impact: Visiting a malicious website may disclose image data from another […]

APPLE-SA-2016-07-18-4 tvOS 9.2.2 Subject: APPLE-SA-2016-07-18-4 tvOS 9.2.2 From: Apple Product Security Date: Mon, 18 Jul 2016 17:21:14 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-07-18-4 tvOS 9.2.2 tvOS 9.2.2 is now available and addresses the following: CoreGraphics Available for: Apple TV (4th generation) Impact: A remote attacker may be able to execute arbitrary code Description: […]

APPLE-SA-2016-07-18-3 watchOS 2.2.2 Subject: APPLE-SA-2016-07-18-3 watchOS 2.2.2 From: Apple Product Security Date: Mon, 18 Jul 2016 17:20:02 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-07-18-3 watchOS 2.2.2 watchOS 2.2.2 is now available and addresses the following: CoreGraphics Available for: Apple Watch Sport, Apple Watch, Apple Watch Edition, and Apple Watch Hermes Impact: A remote attacker […]

APPLE-SA-2016-07-18-2 iOS 9.3.3 Subject: APPLE-SA-2016-07-18-2 iOS 9.3.3 From: Apple Product Security Date: Mon, 18 Jul 2016 17:17:26 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-07-18-2 iOS 9.3.3 iOS 9.3.3 is now available and addresses the following: Calendar Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later Impact: A […]

APPLE-SA-2016-07-18-1 OS X El Capitan v10.11.6 and Security Update 2016-004 Subject: APPLE-SA-2016-07-18-1 OS X El Capitan v10.11.6 and Security Update 2016-004 From: Apple Product Security Date: Mon, 18 Jul 2016 17:14:08 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-07-18-1 OS X El Capitan v10.11.6 and Security Update 2016-004 OS X El Capitan v10.11.6 and Security […]

If you find the FBI’s cybercrime webpage can you let them know?
Security software that uses ‘code hooking’ opens the door to hackers
Hacker Steals Amazon Marketplace Credentials from 3rd Party Server
Apple fixes FaceTime eavesdropping bug, other other flaws may remain
Your antivirus doesn’t like Ammyy. And fraudsters will use that to RAT you out (again)
Malicious scripts gaining prevalence in Brazil

Had we looked at a map of malware detections in Brazil a year ago, we would have seen that the two main computer threats were the downloaders that installed banking trojans, and the banking trojans themselves. Today the situation remains the same, but with an extra special ingredient – while threats used to be Windows .exe […]

Apple Fixes Vulnerabilities Across OS X, iOS, Safari
Neutrino exploit kit adds former IE zero-day flaw to its arsenal
IBM grows in cloud and data analytics but overall revenue slides
Sandia Labs Researchers Build DNA-Based Encrypted Storage
Flaw in vBulletin add-on leads to Ubuntu Forums database breach
Ubuntu Forums hack exposes 2 million users
Passwords not compromised by Ubuntu Forums data breach

A major data breach on the Ubuntu Forums has not compromised the passwords of its affected users. In an update to its announcement that an incident had taken place, its developer Canonical Ltd was keen to highlight that this information was not accessed. However, as Jane Silber, CEO of Canonical Ltd, revealed, usernames, emails addresses […]

4 basic security facts everyone should know

Today, almost all hacking is done by professional criminals. In many countries, illegal hacking accounts for more crime, dollar-wise, than noncomputer crime. The United Kingdom recently joined that club. Why is this important? First, if you find malware on your system, there’s a good chance it’s trying to steal your money. Second, no one is […]

MacKeeper threatens to sue 14-year-old YouTuber
Governments Googling Google about you more than ever says Google
Maxthon web browser blabs about your PC all the way back to Beijing
Guilt by ASN: Compiler’s bad memory bug could sting mobes, cell towers
World-Check terror suspect DB hits the web at just US$6750
Hardball hacker thrown in the cooler for 46 months for guessing rival team’s password
Alpine County Superior Court, CA Website Hacked Against Trump and Racism
For $800 you can buy internet engineers’ answer to US government spying
CGI Script Vulnerability ‘Httpoxy’ Allows Man-in-the-Middle Attacks

Gentoo: 201607-07 Chromium: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in the Chromium web browser, the worst of which allows remote attackers to execute arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201607-06 CUPS: Buffer overflow Posted by Anthony Pell    A buffer overflow in CUPS might allow remote attackers to execute arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201607-05 Cacti: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in Cacti, the worst of which could lead to the remote execution of arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201607-04 GD: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in GD, the worst of which allows remote attackers to execute arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Debian: 3620-1: pidgin: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3620-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 15, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : pidgin CVE ID : CVE-2016-2365 CVE-2016-2366 CVE-2016-2367 CVE-2016-2368 CVE-2016-2369 CVE-2016-2370 CVE-2016-2371 CVE-2016-2372 CVE-2016-2373 CVE-2016-2374 CVE-2016-2375 CVE-2016-2376 CVE-2016-2377 CVE-2016-2378 CVE-2016-2380 CVE-2016-4323 Yves Younan of Cisco Talos […]