Menu

Monthly Archives: August 2016

U.S. intelligence to share supply chain threat reports with industry
Someone seems to be trying to spy on VeraCrypt’s security audit
How to tell the “real” @realDonaldTrump, and why it’s a security lesson for us all
Safer Gmail: more warnings against fakes, phishers, and spoofers
Respect: Windows 10 security impresses hackers
IT snafu takes down Action Fraud’s web crime reporting form
QuadRooter: Unfortunately, you can’t have it patched for now

Soon after the discovery of the QuadRooter vulnerability, a remedy appeared on the Google Play app store. Unfortunately, neither of the two apps named “Fix Patch QuadRooter” by Kiwiapps Ltd. would patch the Android system. Already pulled from Google Play on ESET’s notice, these apps were malicious, serving their victims with unwanted ads. On top […]

Pen-test trio crafts ‘Datasploit’ tool for easy social engineering
Russian sports doping whistleblower fears for safety after hack
POS malware stings 20 US hotels
Air gap breached by disk drive noise
Forensics tool nabs data from Signal, Telegram, WhatsApp
Accountancy software firm Sage breached in apparent insider attack

Discovered: August 15, 2016 Updated: August 15, 2016 1:31:54 PM Type: Trojan Infection Length: 274,432 bytes Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Zombrari is a Trojan horse that modifies the primary DNS server settings on […]

Discovered: August 15, 2016 Updated: August 15, 2016 1:41:02 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows NT, Windows Vista, Windows XP Antivirus Protection Dates Initial Rapid Release version August 15, 2016 revision 007 Latest Rapid Release version August 15, 2016 revision 007 Initial […]

Russian Olympics whistleblower Yuliya Stepanova hacked after Wada Breach

Multiple vulnerabilities were discovered in the dissectors for NDS, PacketBB, WSP, MMSE, RLC, LDSS, RLC and OpenFlow, which could result in denial of service or the execution of arbitrary code. For the stable distribution (jessie), these problems have been fixed in version 1.12.1+g01b65bf-4+deb8u8. For the testing distribution (stretch), these problems have been fixed in version […]

Multiple security issues have been found in Icedove, Debian’s version of the Mozilla Thunderbird mail client: Multiple memory safety errors may lead to the execution of arbitrary code or denial of service. For the stable distribution (jessie), this problem has been fixed in version 1:45.2.0-1~deb8u1. For the testing distribution (stretch), this problem has been fixed […]

Hackers take over security camera; live stream girls’ bedroom on Internet
KickassTorrents’ ‘mirror’ Kat.am; stealing users’ credit card data
Guccifer 2.0 drops private data of more than 200 Democratic Party Members
A Russian cyber-gang, the Oracle MICROS hack, and five more POS makers in crims’ sights
EU Struggles to Determine Growing Cost of Cyberattacks
New Linux Malware Installs Bitcoin Mining Software on Infected Device
DIY bank account raiding trojan kit touted in dark web dive bars
IBM PC is 35 – let’s all go back to the 80s!
Undocumented SNMP String Exposes Rockwell PLCs to Remote Attacks
Facebook rolls out code to kick the shins off Adblock Plus reblocking
Text messages aren’t private, judge rules
Academics Devise New Way to Steal Data from Air-Gapped Computers
World Anti-Doping Agency Site Hacked; Thousands of Accounts Leaked
How to protect yourself from mobile ID theft
SMS or authenticator app – which is better for two-factor authentication?
How do you securely exchange encrypted-decrypted-recrypted data? Ask Microsoft
Key Fob Hack Allows Attackers To Unlock Millions Of Cars
Millions of Volkswagens can be broken into with a wireless hack
EU-US Privacy Shield launches: Key points to this agreement

There has been a lot riding on this divisive and complicated agreement, which is why it has taken over two and a half years for all the involved parties to iron out all the details. As of July 12th, the new framework was officially adopted and put into effect. The EU-US Privacy Shield, as it […]

Exploit broker offers 2.5 times what Apple offers for serious iOS bugs
Facebook shutters Bloke’s Advice group after posts encouraged assault
AWS to enterprises: Bring your own encryption
Video jacking – hopefully not coming to a phone charging point near you
Researchers announce Linux kernel “network snooping” bug
Hacked Instagram accounts seducing users with adult dating spam
Meet DDoSCoin, the cryptocurrency that pays when you p0wn
Boffins’ blur-busting face recognition can ID you with one bad photo
SMS Privacy Given Final Nail in the Coffin by Canadian Court Ruling
Instagram Accounts Getting Hacked; Spreading Adult Content

Risk High Date Discovered August 9, 2016 Description Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability due to a use-after-free error. Specifically, this issue occur within the ‘CAnchor’ object. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue […]

Risk High Date Discovered August 9, 2016 Description Microsoft Windows is prone to a local privilege-escalation vulnerability that occurs in the Windows kernel. A local attacker can exploit this issue to execute arbitrary code in kernel mode with elevated privileges. Technologies Affected Microsoft Windows 10 Version 1607 for 32-bit Systems Microsoft Windows 10 Version 1607 […]

New Gmail Alerts Warn of Unauthenticated Senders
Why Anonymous Should Spy on ISIS Forums Rather than DDoSing Them
Mr. Robot eps2.4m4ster-s1ave.aes – the security review
Couple sue over IP glitch that repeatedly sent Feds to their house
Thieves can wirelessly unlock up to 100 million Volkswagens, each at the press of a button
Microsoft Mistakenly Leaks Secure Boot Key
Bluetooth Hack Leaves Many Smart Locks, IoT Devices Vulnerable
Feds move to stop social media mockery of nursing home residents
Google Says ‘a bug’ removed West Bank and Gaza from the map
Imperva under pressure to find buyer after disappointing results
A new $500,000 iOS bug bounty beats Apple’s offer
Found an iOS zero-day? This firm will pay you $300,000 more than Apple
Want secure code? Give devs the right tools
Secure Boot proves insecurity of backdoors
Developers need secure coding environments
Facebook starts bypassing adblockers
QuadRooter vulnerabilities leaves 900 million Android devices at risk of attack

Over 900 million Android smartphones and tablets are vulnerable to cyberattacks, as they contain a set of four vulnerabilities dubbed QuadRooter. These flaws were found in devices that use Qualcomm chipsets, Check Point revealed at this year’s DEF CON 24 Hacking Conference in Las Vegas. It stated that if any of the four vulnerabilities are […]

Hilton hotels’ email so much like phishing it fooled its own techies
Almost all cars sold by VW Group since 1995 at risk from unlock hack
Linux malware? That’ll never happen. Ok, just this once then
McAfee outs malware dev firm with scores of Download.com installs
Indian hacking gang goes on three-year Chinese phishing trip
Patch vBulletin, or get popped
$200,000 for a serious iOS bug? Pfft, we’ll give you $500,000, says exploit broker Exodus

Several vulnerabilities have been found in PostgreSQL-9.4, a SQL database system. CVE-2016-5423 Karthikeyan Jambu Rajaraman discovered that nested CASE-WHEN expressions are not properly evaluated, potentially leading to a crash or allowing to disclose portions of server memory. CVE-2016-5424 Nathan Bossart discovered that special characters in database and role names are not properly handled, potentially leading […]

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Linux security backfires: Flaw lets hackers inject malware into downloads, disrupt Tor users, etc
Raucous Ruckus router ruckus roundly rumbles: Infosec bod says Wi-Fi kit is weak, biz says no

Risk High Date Discovered August 9, 2016 Description Microsoft Windows is prone to a security vulnerability that may allow attackers to conduct spoofing attacks. Attackers can exploit this issue to spoof and impersonate a legitimate user. Other attacks are also possible. Recommendations Deploy network intrusion detection systems to monitor network traffic for malicious activity. Deploy […]

Risk High Date Discovered August 9, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]

vBulletin Patches Serious Flaw in Forum Software
Get Ready for More Ads on Facebook and Ad Blockers Won’t Matter
Juniper Hotfixes Shut Down IPv6 DDoS Vulnerability

Risk Level: Very Low. Type: Trojan.

Discovered: August 8, 2016 Updated: August 8, 2016 1:14:14 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Antivirus Protection Dates Initial Rapid Release version August 8, 2016 revision 007 Latest Rapid Release version […]

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Serious TCP Bug in Linux Systems Allows Traffic Hijacking
Facebook’s favorite hacker is back – with an ironic security hole
Teen hacker flies to Black Hat on his one million free airmiles
Flip Feng Shui attack on cloud VMs exploits hardware weaknesses
Instagram hackers add porn links and snaps to pwned accounts
Microsoft rushes to fix issue that unlocks devices protected by Secure Boot
5 critical holes fixed in Microsoft’s August 2016 updates – patch now!
Dota2 Forum Hacked; 1,923,972 Million User Data Stolen
Putting Apple Bug Bounty Rewards in Perspective
Faceless recognition can identify you, even when your face is hidden
Hitler ‘ransomware’ offers to sell you back access to your files – but just deletes them
Windows 10 Attack Surface Grows with Linux Support in Anniversary Update