Menu

Monthly Archives: July 2016

The truth about bug finders: They’re essentially useless
BMW web portal vulns pose car hack risk – researchers
Watch Out for Keydnap Malware Stealing Mac Login Credentials
Facebook Messenger End-to-End Encryption Not On By Default
Facebook Messenger gets opt-in end-to-end encryption with Secret Conversations
Dropping Elephant APT Targets Old Windows Flaws
Threatpost News Wrap, July 8, 2016
Apple devices held for ransom, massive iCloud account hack rumours
Google Chrome tests future of encryption with post-quantum crypto
Malaysia-based credit card fraud ring broken, 105 arrested
CryptXXX, Cryptobit Ransomware Spreading Through Campaign
Copy paste slacker hackers pop corp locks in ode to stolen code
CloudFlare pros pen paranoid phone plan for pwn-free peregrination
Facebook ‘glitch’ that deleted the Philando Castile shooting vid: It was the police – sources
414,949 D-Link cameras, IoT devices can be hijacked over the net
1 in 20 Wendy’s burger joints hacked? No, make that 1 in 3 – 1,025 in total
Over 1000 Wendy’s restaurants hacked – customers’ credit card details stolen

Two cross-site scripting vulnerabilities have been found in Horizon, a web application to control an OpenStack cloud. For the stable distribution (jessie), these problems have been fixed in version 2014.1.3-7+deb8u2. For the testing distribution (stretch), these problems have been fixed in version 3:9.0.1-2. For the unstable distribution (sid), these problems have been fixed in version […]

CryptXXX Ransomware Updates Ransom Note, Payment Site

Discovered: July 6, 2016 Updated: July 6, 2016 11:32:15 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Asruex is a Trojan horse that steals information from the compromised computer. It may also download potentially […]

Risk Level: Very Low. Type: Trojan.

D-Link Wi-Fi Camera Flaw Extends to 120 Products
How Android Nougat will help protect your password from ransomware
How to remove your Windows 10 password
Android KeyStore Encryption Scheme Broken, Researchers Say
US government tells Symantec and Norton Antivirus users to apply security patches immediately
Cafe killer remote code execution affects 140 million MIUI Androids
Latest Intelligence for June 2016
Our latest intelligence reveals nearly a 30 percentage point drop in web attacks using Angler and a 20 percentage point increase in Manual Sharing social [...]
How your smartwatch or fitness tracker could reveal your ATM PIN
Antivirus merger: Avast offers $1.3 billion for AVG
Security Sessions: The state of cloud security
Ransomware: First files … now complete devices

A major threats to computer security is malicious code. In fact, over the years, it has become one of the main causes of security incidents, from the first viruses in 1986 to the most sophisticated malware of today. And this particular type of malware, although it is not new, has become increasingly troublesome for both businesses […]

Android’s full-disk encryption just got much weaker-here’s why
8 Reasons You Need a Security Penetration Test
5 Ways To Think Like A Hacker
APT Group ‘Patchwork’ Cuts-and-Pastes a Potent Attack
What I learned playing prey to Windows scammers
Big news in the anti-virus industry. Avast to acquire AVG for $1.3 billion
Android users warned of HummingBad malware, as millions of devices infected
WikiLeaks knocked offline in ongoing feud between OurMine hacking gang and Anonymous
Loose wrists shake chips: Your wrist-job could be a PIN-snitch
Palo Alto offers $16,000 in looming CTF hack off
Unmasking malware in TLS connections? It can be done, say Cisco researchers
Sysadmins: Use these scripts to fully check out of your conference calls
⌘+c malware smacks Macs, drains keychains, pours over Tor

Discovered: July 6, 2016 Updated: July 7, 2016 10:12:01 AM Type: Trojan Infection Length: 28,672 bytes Systems Affected: Mac OS X OSX.Keydnap is a Trojan horse for Mac OS X computers that opens a back door on the compromised computer. It may also steal information and download potentially malicious files. Antivirus Protection Dates Initial Rapid […]

The truth about Silent Circle’s super-secure, hyper-privacy phones: No one’s buying them
Study: More than 50% of small businesses were breached in the past year
Attention, small biz using Symantec AV: Smash up your PCs, it’s the safest thing to do
Researchers Tie Pirrit Adware to Israeli Marketing Company
Huge double boxset of Android patches lands after Qualcomm disk encryption blown open

Slackware: 2016-187-01: mozilla-thunderbird: Security Update Posted by Anthony Pell    New mozilla-thunderbird packages are available for Slackware 14.1, 14.2, and – -current to fix security issues. [More Info…] [slackware-security] mozilla-thunderbird (SSA:2016-187-01) New mozilla-thunderbird packages are available for Slackware 14.1, 14.2, and – -current to fix security issues. Here are the details from the Slackware 14.2 […]

Debian: 3616-1: linux: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3616-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 04, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : linux CVE ID : CVE-2014-9904 CVE-2016-5728 CVE-2016-5828 CVE-2016-5829 CVE-2016-6130 Debian Bug : 828914 Several vulnerabilities have been discovered in the Linux kernel that may lead […]

Red Hat: 2016:1378-01: openstack-ironic: Moderate Advisory Posted by Anthony Pell    An update for openstack-ironic is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: openstack-ironic security update Advisory ID: RHSA-2016:1378-01 Product: Red Hat […]

Red Hat: 2016:1377-01: openstack-ironic: Moderate Advisory Posted by Anthony Pell    An update for openstack-ironic is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: openstack-ironic security update Advisory ID: […]

Debian: 3614-1: tomcat7: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3614-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 02, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : tomcat7 CVE ID : CVE-2016-3092 The TERASOLUNA Framework Development Team discovered a denial of service vulnerability in Apache Commons FileUpload, a package to make it […]

Debian: 3615-1: wireshark: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3615-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff July 02, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : wireshark CVE ID : CVE-2016-5350 CVE-2016-5351 CVE-2016-5353 CVE-2016-5354 CVE-2016-5355 CVE-2016-5356 CVE-2016-5357 CVE-2016-5359 Multiple vulnerabilities were discovered in the dissectors/parsers for PKTC, IAX2, GSM CBCH and […]

Debian: 3613-1: libvirt: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3613-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 02, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libvirt CVE ID : CVE-2016-5008 Vivian Zhang and Christoph Anton Mitterer discovered that setting an empty VNC password does not work as documented in Libvirt, […]

Debian: 3612-1: gimp: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3612-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 01, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : gimp CVE ID : CVE-2016-4994 Debian Bug : 828179 Shmuel H discovered that GIMP, the GNU Image Manipulation Program, is prone to a use-after-free vulnerability […]

Android Security Bulletin Features Two Patch Levels
Top Router Maker TP-Link Loses Control Over Configuration Domain
NASA spacecraft has its Twitter hacked by someone’s butt
Meet Eleanor, the Mac malware that uses Tor to obtain full access to systems
Adwind RAT Resurfaces, Targeting Danish Companies
Bitcoin child abuse image pervs will be hunted down by the IWF
New Tor-powered backdoor program targets Macs
21% off SentrySafe Fire-Safe Waterproof File Storage Box – Deal Alert
Java Deserialization attacks on JBoss Middleware
Most Post-Intrusion Cyber Attacks Involve Everyday Admin Tools
‘Double speak’ squawk users as Silent Circle kills warrant canary
Outed China ad firm infects 10m Androids, makes $300k a month
TP-Link abandons ‘forgotten’ router config domains
HPE rushes out patch for more than a year of OpenSSL vulns
Nasty BIOS bug slugs Gigabyte, hackers say
Chap fails to quash ‘shared password’ ‘hacking’ conviction
Could your selfies be held to ransom? Alleged Instagram account hacker arrested
Huawei learns photo meta-data can bite you in the bum
PlayStation, Facebook block users due to ‘offensive’ first names
EasyDoc malware adds Tor backdoor to Macs for botnet control
Get FREE threat intelligence on hackers and exploits with the Recorded Future Cyber Daily
Symantec bugfest highlights the dangers of security software
Encryption Bypass Vulnerability Impacts Half of Android Devices
The Changing Face of Pseudo-Darkleech
FBI faults Clinton’s personal email system, but doesn’t recommend prosecution
Mozilla’s Servo is an early step to making Firefox more secure
Chinese Ad Firm Raking in $300K a Month Through Adfraud, Android Malware

Risk Level: Very Low. Type: Trojan.

What is a computer virus? Think of a biological virus – the kind that makes you sick. It’s persistently nasty, keeps you from functioning normally and often requires something powerful to get rid of it. A computer virus is very similar. Designed to relentlessly replicate, these threats infect your programs and files, alter the way your […]

Scope of ThinkPwn UEFI Zero Day Expands
Chicago man pleads guilty in celebrity iCloud data breach

��}�r۸���j�a� ��H��_�#�:Nr&g�gf�&YDBm���ò&���g�j���V��}��$� ��$˲���MΙ�”�F���h4�Gw��9>���3��髗�����Cꎺ s�O�lh_vot@�Q��7�� 3��u�

Lenovo ThinkPwn UEFI exploit also affects products from other vendors
EU uncorks €1.8bn in cybersecurity investment. Thirsty, UK?
Data leak dangers: Know your weak spots

From customer credit card details that ease the flow at online checkouts to employee records that are vital to HR departments, today’s businesses are built on sensitive data. In many ways, it’s the lifeblood that makes the modern company tick. If experience is anything to go by, though, it can also feel like the next […]

10 cutting-edge tools that take endpoint security to a new level
7 trends in advanced endpoint protection
11 signs your kid is hacking — and what to do about it
5 years, 2,300 data breaches. What’ll police do with our Internet Connection Records?
Fembots land Ashley Madison in hot water with the FTC
Theft of twenty-somethings’ IDs surges
Second celebgate hacker pleads guilty to phishing