Menu

Monthly Archives: August 2016

DetoxCrypto ransomware-as-a-service rears its ugly head
Californian gets 50 months in prison for Chinese ‘technology spy’ work
Indians could face jail time for torrenting and file sharing

Discovered: August 23, 2016 Updated: August 23, 2016 1:46:38 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Ransom.AlmaLocker is a Trojan horse that encrypts files on the compromised computer. Antivirus Protection Dates Initial Rapid […]

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Worm.

Discovered: August 23, 2016 Updated: August 23, 2016 3:18:27 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Shakstiler is a Trojan horse that steals information from the compromised computer. Antivirus Protection Dates Initial Rapid […]

Discovered: August 22, 2016 Updated: August 23, 2016 8:29:24 AM Infection Length: Varies Systems Affected: Linux Backdoor.Equation is a detection for back door Trojans allegedly used by the Equation group and released to the public by an attack group calling itself the Shadow Brokers. For more information, read the following resources: Antivirus Protection Dates Initial […]

Australia Post says use blockchain for voting. Expert: you’re kidding
Obihai Patches Memory Corruption, DoS, CSRF Vulnerabilities in IP Phones
Medical Detection Goes High Tech
Hancitor Downloader Shifts Attack Strategy

Red Hat: 2016:1640-01: kernel: Important Advisory Posted by Anthony Pell    An update for kernel is now available for Red Hat Enterprise Linux 6.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory […]

Software exploits overrated – it’s the humans you need to be watching
Juniper Acknowledges Equation Group Targeted ScreenOS
Facebook Photos Lead to Hacking of Facial Recognition System
Has Microsoft “broken” millions of webcams? (And how to fix yours.)
Eddie Bauer Confirms Payment Card Breach of US, Canadian Stores
Internet Connected Plugs can be Easily Exploited by Hackers
Wikipedia’s Jimmy Wales didn’t die this weekend, despite what his hacked Twitter account said
Four in five Android devices inherit Linux snooping flaw
Smart IoT socket suffers from dumb security vulnerabilities
Now WikiLeaks is distributing malware
5 back-to-school tips to help kids stay safe online
Ransomware: To pay or not to pay?

Towards the end of July 2016, Kevin Townsend brought it to my attention that Europol, the European Union’s law enforcement agency, had announced an initiative to address the ransomware problem. No More Ransom is intended to provide information and help victims recover their data without paying a ransom to the criminals. As well as being […]

Snooped-on man free to sue spyware maker
Monday review – the hot 21 stories of the week
Automate, integrate, collaborate: Devops lessons for security
Is security keeping pace with continuous delivery?
German minister seeks facial recognition at airports, train stations
Beauty site lets anyone read customers’ personal information
I got the power – over your IoT power-point
IOActive turns up the most SOHOpeless router so far
Mechanical Phish auto-exploit auto-patch kit lands on GitHub
7 Cases When Victims Paid Ransom to stop cyber attacks
Twitter account of WikiPedia Founder Jimmy Wales Hacked by OurMine
Kid who DDoSed Aussie bank, cyber crime unit walks free
Windows 10 anniversary update causes webcam malfunction worldwide
Confirmed: hacking tool leak came from “omnipotent” NSA-tied group
Wikileaks hosts hundreds of malware files in email dumps

Risk Level: Very Low. Type: Trojan.

Snowden files confirm Shadow Brokers spilled NSA’s Equation Group spy tools over the web
Cyber Criminals using Locky Ransomware against Healthcare Industry
Shopped in an Eddie Bauer store recently? Your card’s probably gone. It’s just gone
Poorly configured DNSSEC servers at root of DDoS attacks

Red Hat: 2016:1637-01: rh-mariadb101-mariadb: Important Advisory Posted by Anthony Pell    An update for rh-mariadb101-mariadb is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: rh-mariadb101-mariadb security update Advisory ID: RHSA-2016:1637-01 Product: Red Hat Software Collections […]

Red Hat: 2016:1630-01: rh-python34-python: Moderate Advisory Posted by Anthony Pell    An update for rh-python34-python is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: rh-python34-python security update Advisory ID: RHSA-2016:1630-01 Product: Red Hat Software Collections […]

Red Hat: 2016:1628-01: python27-python: Moderate Advisory Posted by Anthony Pell    An update for python27-python is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: python27-python security update Advisory ID: RHSA-2016:1628-01 Product: Red Hat Software Collections […]

Red Hat: 2016:1629-01: python33-python: Moderate Advisory Posted by Anthony Pell    An update for python33-python is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: python33-python security update Advisory ID: RHSA-2016:1629-01 Product: Red Hat Software Collections […]

Red Hat: 2016:1627-01: rh-python35-python: Moderate Advisory Posted by Anthony Pell    An update for rh-python35-python is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: rh-python35-python security update Advisory ID: RHSA-2016:1627-01 Product: Red Hat Software Collections […]

Red Hat: 2016:1632-01: kernel-rt: Important Advisory Posted by Anthony Pell    An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: […]

Red Hat: 2016:1631-01: realtime-kernel: Important Advisory Posted by Anthony Pell    An update for kernel-rt is now available for Red Hat Enterprise MRG 2.5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: […]

An update for python is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: python security update Advisory ID: RHSA-2016:1626-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1626.html Issue […]

Red Hat: 2016:1633-01: kernel: Important Advisory Posted by Anthony Pell    An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: […]

New Brazilian Banking Trojan Uses Windows PowerShell Utility
Multiple Vulnerabilities Identified in ‘Utterly Broken’ BHU Routers
Twitter takes down 235K extremist accounts
Man hacks Android app to get free beer

This week’s Threat Recap is filled with everything from the latest retailer succumbing to malware infection to a possible hack on the NSA. Read up on five of the latest threat happenings to stay informed and up-to-date. Eddie Bauer Stores Compromised It is reported that point of sale systems at several Eddie Bauer stores across North America […]

Donald Trump Campaign Hacked; Targeted with Malware: Report
Two-speed Android update risk: Mobes face months-long wait
New firmware update? No, it’s the devious Marcher Android trojan up to no good
Threatpost News Wrap, August 19, 2016
Why you should hire good, skilled cybersecurity professionals

��}ے�F���(Q3″i/}�f�Z����QK���ڎ”P$��f�rG�ا�؍8���s��|�ff@�$��� i�Tee孲�����=yy�����޼x~��ݣa4r���A�”��Y����W݊78`�(����Hnx�u� �����w4����%�/��Sύ�io&��0S��V”q��9�A(�n� 3������v�|�=’��Ӯ�”_��#ѭ�b�{A�)=��hصĥm �~4��ڑ�-4�#��2H�8B�Hh�”�� �xn�y��/����`w���E��E�����j��|��پ���0 /�c[�y|��HXL����^�@8�JM�D@Ev3+l$,�w+~`��u��V���>�})BaƁMt�c_SH�P�Dh�w�fPC�� ���w�螦�7C;dH

Twitter suspends 360,000 accounts for terrorist ties
The NSA’s hoard of cyber weapons makes some experts nervous
Police chiefs: we need the right to decrypt your stuff
Why people ignore security alerts up to 87% of the time
Keep using password managers — bugs and all
WikiLeaks uploads 300+ pieces of malware among email dumps
Uber’s specially modified self-driving cars to hit the road this month
Banking system SWIFT was anything but on security, ex-boss claims
EFF Blasts Microsoft Over ‘Malicious’ Windows 10 Rollout Tactics

Felix Doerre and Vladimir Klebanov from the Karlsruhe Institute of Technology discovered a flaw in the mixing functions of Libgcrypt’s random number generator. An attacker who obtains 4640 bits from the RNG can trivially predict the next 160 bits of output. A first analysis on the impact of this bug for GnuPG shows that existing […]

Felix Doerre and Vladimir Klebanov from the Karlsruhe Institute of Technology discovered a flaw in the mixing functions of GnuPG’s random number generator. An attacker who obtains 4640 bits from the RNG can trivially predict the next 160 bits of output. A first analysis on the impact of this bug for GnuPG shows that existing […]

Beware; Hackers targeting Pokemon Go Users with Smishing Scam
50% off Vimtag VT-361 Pan&Tilt HD WiFi Video Security Camera with Night Vision – Deal Alert

Debian: 3650-1: libgcrypt20: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3650-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso August 17, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libgcrypt20 CVE ID : CVE-2016-6313 Felix Doerre and Vladimir Klebanov from the Karlsruhe Institute of Technology discovered a flaw in the mixing functions of Libgcrypt’s […]

Debian: 3649-1: gnupg: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3649-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso August 17, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : gnupg CVE ID : CVE-2016-6313 Felix Doerre and Vladimir Klebanov from the Karlsruhe Institute of Technology discovered a flaw in the mixing functions of GnuPG’s […]

Cisco zero-day shows up in “Shadow Brokers” leaked attack tools
OIG Report Finds Vulnerabilities in Medicaid Services Agency
GPG Patches 18-Year-Old Libgcrypt RNG Bug
Scammers Used Google AdSense to Drop Malware on Android Devices
Mr. Robot eps2.5_h4ndshake.sme – the security review
Following data breach, Sage employee arrested at Heathrow airport
Locky Targets Hospitals In Massive Wave Of Ransomware Attacks
Why do we ignore up to 90% of computer security alerts? Because we’re terrible at multi-tasking…
NIST’s new password rules – what you need to know
Snowden says Russia ‘probably responsible’ for NSA hack
Bitcoin website suspects it will be targeted by state-sponsored hackers, warns users
Unsecured DNSSEC Easily Weaponized, Researchers Warn
The Future Of ATM Hacking
US: We’re now ready to give up our role governing the internet
Nemucod serves nasty package: Ransomware and ad-clickers

Just last week ESET reported on Nemucod shifting away from ransomware and downloading the ad-clicking malware Kovter instead. Now, it seems that the operators of the notorious downloader went a step further and are serving their victims the whole package – ransomware as well as ad-clickers. As before, the targeted user receives an email with […]

Vulnerable smart home IoT sockets let hackers access your email account
Poorly Configured DNSSEC = Potential DDoS Weapon
6 Things To Know For Securing Amazon Web Services
Pen-testing made easy with Datasploit social engineering toolset
No One Wants to Buy Those Stolen NSA-Linked ‘Cyberweapons’
A new low! SMS scammers prey on parents’ fears to make a few bucks