Menu

Monthly Archives: July 2016

Jigsaw ransomware decrypted yet again – using a simple trick
MIT Anonymity Network Riffle Promises Efficiency, Security
Kids’ shoes seller Start-rite suspends sales following breach
Intel Patches Local EoP Vulnerability Impacting Windows 7
Hacker Selling US Medical Database of 34,000 Patients on Dark Net
Exploit kit miscreants rush to plug gap in cyber-crime marketplace
Seeking Alpha Mobile Financial App Forgoes Encryption
Killing the password: FIDO says long journey will be worth it
Feds to hire 3,500 cybersecurity pros by year’s end
Hacked 3D printers could be used to commit industrial sabotage
NSA Labels Privacy-Centric Internet Users As Extremists
HTTPS crypto’s days are numbered. Here’s how Google wants to save it
Were you planning on downloading the Pokémon GO APK? Beware fake versions!

Since 2015, thousands of aspiring Pokémon trainers have been waiting for the release of Pokémon GO, the augmented reality game that will allow players to catch hidden Pokémon’s in the real world and conquer “gyms” through the internet, traveling both physically as well as within the app itself. For the first time, we will be […]

Review: Promisec goes the extra step to secure PCs
Meet Riffle, the next-gen anonymity network that hopes to trounce Tor
It’s 2016 and Windows lets crims poison your printer drivers
50 CELEBRITY SECRETS EXPOSED scores year behind bars
US drug squads told to get a warrant before tracking mobile phones
VPN provider claims Russia seized its servers
Next month’s Firefox 48 is looking Rusty – and that’s a very good thing
This tool can tell you if you’ve been dangerously reusing your passwords
Webpages, Word files, print servers menacing Windows PCs, and disk encryption bypasses – yup, it’s Patch Tuesday
5-foot-tall security robot knocks down 16-month-old
Windows Print Spooler Flaws Lead to Code Execution
Google, Niantic to Limit Data Pokémon GO Collects
Little Snitch Bug Leaves Some Mac Systems Open to Attack

Discovered: July 11, 2016 Updated: July 11, 2016 11:52:32 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows NT, Windows Vista, Windows XP Trojan.Cryptolocker.AW is a Trojan horse that encrypts files on the compromised computer and demands payment to decrypt the files. Antivirus Protection Dates […]

Adobe Patches 52 Vulnerabilities in Flash Player
xDedic Hacked Server Market Resurfaces on Tor Domain
SCADA malware caught infecting European energy company
Ranscam Ransomware Deletes Victims’ Files Outright
Malware Dropper Built to Target European Energy Company
Nukeware: New malware deletes files and zaps system settings
Salesforce expands encryption options with ‘bring your own key’
Amazon Prime Day is Today: Over 100,000 Products Currently Discounted – Prime Day Deal Alert
Pirate swarms at risk from new patent
Hacking A Penetration Tester
Spotted! 9 signs of a malicious download

Most people’s computers get exploited in only a handful of ways. Among the most popular methods is tricking people into downloading and running Trojans. Often, unsuspecting users get socially engineered into running a malicious file or app by following a link in email or visiting a website. It can be tough to spot the fake […]

Nasty session stealing hole filled in WordPress All in One SEO plugin
Purloined password re-use checker pees in the security soup
Android Nougat may contain traces of NOT for users of custom CAs
Florida U boffins think they’ve defeated all ransomware
Aussie researcher claims ‘Antminer’ bitcoin boxen can be broken
Privacy scare over Pokémon Go app for iOS
Security analyst banned for disclosing vulnerabilities in web forums
Lawsuit filed against Snapchat for showing adult content to minors

Type: Vulnerability. Microsoft Edge and Internet Explorer are prone to a information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge and Internet Explorer are prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Edge and Internet Explorer are prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Risk Medium Date Discovered July 12, 2016 Description Microsoft Windows is prone to a local security-bypass vulnerability. Local attackers can exploit this issue to bypass certain security restrictions and perform unauthorized actions. Recommendations Permit local access for trusted individuals only. Where possible, use restricted environments and restricted shells. To exploit this vulnerability, an attacker requires […]

Risk High Date Discovered July 12, 2016 Description Microsoft Edge is prone to a security-bypass vulnerability. An attacker can leverage this issue to bypass certain security restrictions and execute arbitrary code by exploiting another vulnerability in the application. Technologies Affected Microsoft Edge Recommendations Block external access at the network boundary, unless external parties require service. […]

Risk High Date Discovered July 12, 2016 Description Microsoft Edge is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]

Risk High Date Discovered July 12, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]

Risk High Date Discovered July 12, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]

Risk High Date Discovered July 12, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]

Risk High Date Discovered July 12, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]

Discovered: July 12, 2016 Updated: July 12, 2016 3:41:32 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Infostealer.Pycerine is a Trojan horse that may steal information from the compromised computer. Antivirus Protection Dates Initial […]

Jigsaw Ransomware Decrypted, Again
‘Our Mine’ Hacks Twitter Account of Twitter CEO Jack Dorsey
Pokemon Go on, gissus your Google Gmail, Drive files, photos?
Datadog Forces Password Reset Following Breach

An update for thunderbird is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: thunderbird security update Advisory ID: RHSA-2016:1392-01 Product: Red Hat Enterprise […]

Gentoo: 201607-02 libpcre: Multiple Vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in libpcre, the worst of which could lead to arbitrary code execution, or cause a Denial of Service condition. – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201607-01 Squid: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in Squid, the worst of which could lead to arbitrary code execution, or cause a Denial of Service condition. – – – – – – – – – – – – – – – – – – – – – […]

Slackware: 2016-189-01: samba: Security Update Posted by Anthony Pell    New samba packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…] [slackware-security] samba (SSA:2016-189-01) New samba packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. Here are the details from the Slackware 14.2 […]

Debian: 3617-1: horizon: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3617-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff July 06, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : horizon CVE ID : CVE-2015-3219 CVE-2016-4428 Two cross-site scripting vulnerabilities have been found in Horizon, a web application to control an OpenStack cloud. For the […]

Serious flaw fixed in widely used WordPress plug-in
Malicious Pokémon Go App Installs Backdoor on Android Devices
Omni-shambles! Card-stealing malware checks into US hotel chain
Google Updates CA Trust Mechanisms in Android Nougat

Risk Level: Very Low. Type: Trojan, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

IoT Medical Devices: A Prescription for Disaster
Amazingly insecure industrial control systems + internet = Cupful of nope
91 Percent of Public-Facing ICS Components Are Remotely Exploitable
Drowning Dalek commands Siri in voice-rec hack attack
Lurk trojan takedown also took out Angler exploit kit
White hat banned for revealing vulns in news sites used by London councillors
Hacker bites Datadog, finds hard-to-chew bcrypt passwords
Teen thugs lure, rob Pokemon Go gamers
OpAfrica: Anonymous hacks South African arms procurement agency
Fake Pokémon Go app contains RAT; takes full control of infected device
Amazon Suffers Security Breach; 80,000 Login Credentials Leaked
Android users warned of malicious Pokémon Go app
Does Hacktivism Really Equal Terrorism?
Ukrainian Hacker Hacks Polish Telecom Giant Netia; Leaks Massive Data
Anonymous DDoS Zimbabwe Government Sites for #ShutDownZimbabwe
Android Mew-ware, I choose you: Code nasty poses as Pokemon GO
IDG Contributor Network: When your security products are insecure: Takeaways from the Symantec disclosure
Facebook offers end-to-end encrypted chat – if you find the right setting
Guccifer Hacker aka Marcel Lazăr Lehel is NOT dead
Google Testing Post-Quantum Cryptography in Chrome