Menu

Monthly Archives: August 2016

Mozilla launches free website security scanning service
After iOS, Opera’s Free VPN App is Available for Android Devices
Threatpost News Wrap, August 26, 2016
How to opt out of WhatsApp sharing your phone number with Facebook
21st century cybercriminals: The threat landscape has evolved

��}ے�F���(AsD�”^�n�u��d�n��;+k;�@��`�M�1��/;���_0�OΗlfV@�M�i�ޕf,�@UVV�*++��ᝧoN����3��W/����p�]�ro�ӄ��� 粧��C6����4�a`���Ew5�s��Hp�� ���#���d6�N���p�=�FI�fZ1H���>��B��Q�u�w�޵�����n�~�u�j-7�m��ˡ���;K�!O4�7���P��ݜ%M��v�1

Real-life examples test whether you are prepared for a cyberattack
Apple patches iOS security flaws found in spyware targeting activist
Hackers insert malware onto Thai ATMs, steal 12 million baht
Cisco starts patching firewall devices against NSA-linked exploit
Don’t bring your bad security habits to the cloud
Muddying the waters of infosec: Cyber upstart, investors short medical biz – then reveal bugs
HP Laptops Block Unwelcome Snoopers
Apple iOS users, update now – zero-day attack seen in the wild

Two vulnerabilities were discovered in quagga, a BGP/OSPF/RIP routing daemon. CVE-2016-4036 Tamás Németh discovered that sensitive configuration files in /etc/quagga were world-readable despite containing sensitive information. CVE-2016-4049 Evgeny Uskov discovered that a bgpd instance handling many peers could be crashed by a malicious user when requesting a route dump. For the stable distribution (jessie), these […]

Risk Level: Very Low. Type: Trojan.

Discovered: August 26, 2016 Updated: August 26, 2016 2:51:12 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Ransom.Fantom is a Trojan horse that may perform malicious activities on the compromised computer. Symantec Security Response […]

Discovered: August 25, 2016 Updated: August 26, 2016 11:37:57 AM Type: Trojan Infection Length: 98,816 bytes Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Ransom.Tearhide is a Trojan horse that encrypts files on the compromised computer. Antivirus […]

Anatomy of a cryptographic collision – the “Sweet32” attack
IoT manufacturer caught fixing security holes
Emergency iOS Update Patches Zero Days Used by Government Spyware
WhatsApp to share user data including phone numbers with Facebook
France, Germany Call for European Decryption Law
Update your iPhones, iPads right now – govt spy tools exploit vulns
Keystroke Recognition Uses Wi-Fi Signals To Snoop

Red Hat: 2016:1763-01: qemu-kvm-rhev: Moderate Advisory Posted by Anthony Pell    An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 9.0 (Mitaka). Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: qemu-kvm-rhev security update Advisory ID: RHSA-2016:1763-01 Product: Red Hat […]

Russia’s Mail.ru Hacked Again; 27 million Accounts Stolen
Ghostbusters star’s website defaced with racist and explicit images
VMware Patches Flaws in Identity and Cloud Products
Tor Update Fixes ReachableAddresses Problem
A quarter of banks’ data breaches are down to lost phones and laptops
Mr. Robot eps2.6succ3ss0r.p12 – the security review
7 Database Security Best Practices
Wildfire ransomware code cracked: Victims can now unlock encrypted files for free
Google to rate down sites with aggravating pop-up ads
New collision attacks against triple-DES, Blowfish break HTTPS sessions
The catch-22 with Apple security
Practical steps for strengthening your company’s password rules
Doing business with Asia? Then worry more about security

Risk Level: Very Low. Type: Trojan.

Discovered: August 24, 2016 Updated: August 25, 2016 10:16:22 AM Type: Trojan Infection Length: 266,240 bytes Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Ransom.Purugef is a Trojan horse that encrypts files on the compromised computer. Antivirus […]

Cisco Begins Patching Equation Group ASA Zero Day
DCNS submarine document leak exposes Indian naval secrets
Security Sessions: The pitfalls of security awareness training
French, German ministers demand new encryption backdoor law
GTAGaming Hack Blamed on Old vBulletin Software

Red Hat: 2016:1756-01: qemu-kvm-rhev: Moderate Advisory Posted by Anthony Pell    An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: qemu-kvm-rhev security and bug fix update Advisory ID: RHSA-2016:1756-01 […]

Slackware: 2016-236-03: Linux kernel: Security Update Posted by Anthony Pell    New Linux kernel packages are available for Slackware 14.2 and -current to fix a security issue. [More Info…] [slackware-security] Linux kernel (SSA:2016-236-03) New Linux kernel packages are available for Slackware 14.2 and -current to fix a security issue. Here are the details from the […]

Slackware: 2016-236-02: libgcrypt: Security Update Posted by Anthony Pell    New libgcrypt packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. [More Info…] [slackware-security] libgcrypt (SSA:2016-236-02) New libgcrypt packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. […]

Slackware: 2016-236-01: gnupg: Security Update Posted by Anthony Pell    New gnupg packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. [More Info…] [slackware-security] gnupg (SSA:2016-236-01) New gnupg packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. […]

An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2016:1664-01 Product: Red […]

Red Hat: 2016:1657-01: kernel: Important Advisory Posted by Anthony Pell    An update for kernel is now available for Red Hat Enterprise Linux 7.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security update Advisory ID: RHSA-2016:1657-01 Product: […]

Risk Level: Very Low.

98 things Facebook knows about you
Leaked ShadowBrokers Attack Upgraded to Target Current Versions of Cisco ASA
Wildfire Ransomware Campaign Disrupted
ATM Malware: Hackers Steal 12.29 million Baht ($350,000) from Thai Banks
Shock horror! Ashley Madison security was woeful, finds investigation
Blizzard Suffers Yet Another DDoS Attack
“Highly invasive” plan to collect traveler social media details criticized by group
French submarine builder DCNS springs leak: India investigates
New Collision Attacks Against 3DES, Blowfish Allow for Cookie Decryption
A deeper look at business impact of a cyberattack
Lax ALM security ‘contributed’ to Ashley Madison data breach

Avid Life Media (ALM), recently rebranded as Ruby Corp, has been heavily criticized for its lax cybersecurity measures, which contributed to the Ashley Madison data breach. According to a joint investigation by the Office of the Privacy Commissioner of Canada and the Office of the Australian Information Commissioner, ALM had “inadequate security safeguards and policies” […]

Snowden speculates leak of NSA spying tools is tied to Russian DNC hack
Hackers Trick Facial-Recognition Logins With Photos From Facebook (What Else?)
Alleged NSA hackers probably gave away a small fortune by leaking exploits
Attacker’s Playbook Top 5 Is High On Passwords, Low On Malware
Major update drops for popular Pwntools penetration showbag
Intel douses Wildfire ransomware as-a-service Euro menace
Equation Group exploit hits newer Cisco ASA, Juniper Netscreen
Boffins design security chip to spot hidden hardware trojans in processors
Hacked hookup site Ashley Madison’s security was laughable

Risk Level: Very Low. Type: Trojan.

Grand Theft Auto (GTA) Fan Forum Hacked; Thousands of Accounts Stolen
Some ISPs in India are blocking access to ThePirateBay.org

Red Hat: 2016:1654-01: qemu-kvm-rhev: Moderate Advisory Posted by Anthony Pell    An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: qemu-kvm-rhev security update Advisory […]

Red Hat: 2016:1655-01: qemu-kvm-rhev: Moderate Advisory Posted by Anthony Pell    An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: qemu-kvm-rhev security update Advisory […]

Red Hat: 2016:1652-01: qemu-kvm-rhev: Moderate Advisory Posted by Anthony Pell    An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: qemu-kvm-rhev security update Advisory […]

Red Hat: 2016:1653-01: qemu-kvm-rhev: Moderate Advisory Posted by Anthony Pell    An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: qemu-kvm-rhev security update Advisory […]

A Cellphone That Can Self-assemble Itself

Discovered: August 22, 2016 Updated: August 23, 2016 4:45:21 PM Infection Length: Varies Systems Affected: Linux Hacktool.Equation is a detection for hacking tools allegedly used by the Equation group and released to the public by an attack group calling itself the Shadow Brokers. For more information, see our blogs: Antivirus Protection Dates Initial Rapid Release […]

Blizzard blighted by another DDoS storm
Epic data breach revealed, but was your password stolen?
Epic Games Forums Hacked, SQL Injection Vulnerability Blamed
GozNym Banking Trojan Targeting German Banks
Facial recognition can be tricked with Facebook photos
Timing of Browser-Based Security Alerts Could Be Better
EU ministers look to tighten up privacy – JUST KIDDING – surveillance laws
Epic Games Forums Suffer Data Breach; 800k Accounts Stolen
Side channel power, the new security front
Do your kids know good password hygiene? Here are some rules

Growing up before the age of the internet and social networks has left many older users unprepared for risks looming in the virtual world. From that perspective, today’s kids are lucky, as the best cybersecurity practices, such as good password hygiene, are at hand. So, if you are not exactly the most security savvy of […]

How the NSA snooped on encrypted Internet traffic for a decade
Paranoia rules! 5 types of imaginary malware

When you’ve been writing about security for as long as I have, you develop a following. I’m grateful to my readers — without them, my editor would need to find another security writer. But I can’t help but notice that among those who consume my content is a small but tenacious group of people who […]

Who needs software vulnerabilities when you can find lame passwords?
Wikipedia co-founder Jimmy Wales’ Twitter account hijacked
‘NSA’ hack okshun woz writ by Inglish speeker trieing to hyde
Crims share vulns but vendors don’t. This needs fixing
Epic Games forums breached, salted passwords nabbed
Software-defined networking is dangerously sniffable
Epic Games forums hacked again – over 800,000 gamers put at risk