Menu

Monthly Archives: August 2016

Instagram accounts hacked, altered to promote adult dating spam
Scammers are hacking Instagram accounts and altering profiles with sexually suggestive imagery to lure users to adult dating and porn spam. Read More
Old Facebook scam gets ready for new boost

ESET researchers are warning about Facebook hoax scams that spread fake terror news to trick victims into disclosing their Facebook credentials. For example, Facebook users in the Czech Republic were targeted with a fake news report on a “deadly attack in Prague”. Soon after the Facebook scam was publicly disclosed in Czech mainstream media, the […]

Smart sex toy is oh so dumb when it comes to security
DEF CON 24: US government retains dozens, not thousands, of zero-days
Vulnerability Exposes 900M Android Devices-and Fixing Them Won’t Be Easy
Black Hat and DEF CON: The song remains the same
Speaking in Tech: Nope, sorry waiter. I won’t pay with that card reader
Microsoft’s cloud-based operations manager tackles security
Microsoft says patch your Windows PCs now against critical security vulnerabilities
Bungling Microsoft singlehandedly proves that golden backdoor keys are a terrible idea
Funny story, this. UK.gov’s ‘open banking app revolution’. Security experts not a fan of it
Apple says banks can’t touch iPhone NFC without harming security
Samsung: Hackers can’t pwn our NFC payment kit. No way, nuh-uh, not true (Well, OK, maybe)
Torrentz.eu Clone Emerges online as Torrentz2.eu
Web pages, Word docs, PDF files, fonts – behold your latest keys to infecting Windows PCs

Tobias Stoeckmann discovered that cache files are insufficiently validated in fontconfig, a generic font configuration library. An attacker can trigger arbitrary free() calls, which in turn allows double free attacks and therefore arbitrary code execution. In combination with setuid binaries using crafted cache files, this could allow privilege escalation. For the stable distribution (jessie), this […]

Oracle’s Point-of-service Division MICROS Suffers Massive Data Breach
Good news: Teen hacker gets 1-million-air-miles bug bounty reward. Bad news: It’s United
Your Monitor is not safe; Hackers could use it to spy on you
Windows PDF Library Flaw Puts Edge Users at Risk for RCE
Google Chrome will beat Flash to death with a shovel: Why… won’t… you… just… die!
Cat-themed mobile ransomware steals SMS messages, encrypts files
Project Sauron stands on the shoulders of past state-sponsored malware

Red Hat: 2016:1582-01: nodejs010-nodejs-minimatch: Moderate Advisory Posted by Anthony Pell    An update for nodejs010-nodejs-minimatch is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: nodejs010-nodejs-minimatch security update Advisory ID: RHSA-2016:1582-01 Product: Red Hat Software Collections […]

Red Hat: 2016:1583-01: rh-nodejs4-nodejs-minimatch: Moderate Advisory Posted by Anthony Pell    An update for rh-nodejs4-nodejs-minimatch is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: rh-nodejs4-nodejs-minimatch security update Advisory ID: RHSA-2016:1583-01 Product: Red Hat Software Collections […]

Red Hat: 2016:1581-01: kernel: Important Advisory Posted by Anthony Pell    An update for kernel is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security update Advisory ID: RHSA-2016:1581-01 Product: […]

Red Hat: 2016:1580-01: chromium-browser: Important Advisory Posted by Anthony Pell    An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:1580-01 Product: Red Hat […]

Debian: 3645-1: chromium-browser: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3645-1 security@debian.org https://www.debian.org/security/ Michael Gilbert August 09, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : chromium-browser CVE ID : CVE-2016-5139 CVE-2016-5140 CVE-2016-5141 CVE-2016-5142 CVE-2016-5143 CVE-2016-5144 Several vulnerabilites have been discovered in the chromium web browser. CVE-2016-5139 GiWan Go discovered a […]

Debian: 3644-1: fontconfig: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3644-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso August 08, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : fontconfig CVE ID : CVE-2016-5384 Debian Bug : 833570 Tobias Stoeckmann discovered that cache files are insufficiently validated in fontconfig, a generic font configuration library. […]

Slackware: 2016-219-03: openssh: Security Update Posted by Anthony Pell    New openssh packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…] [slackware-security] openssh (SSA:2016-219-03) New openssh packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. Here are […]

Slackware: 2016-219-01: curl: Security Update Posted by Anthony Pell    New curl packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…] [slackware-security] curl (SSA:2016-219-01) New curl packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. Here are […]

Slackware: 2016-219-02: mozilla-firefox: Security Update Posted by Anthony Pell    New mozilla-firefox packages are available for Slackware 14.1 and 14.2 to fix security issues. [More Info…] [slackware-security] mozilla-firefox (SSA:2016-219-02) New mozilla-firefox packages are available for Slackware 14.1 and 14.2 to fix security issues. Here are the details from the Slackware 14.2 ChangeLog: +————————–+ patches/packages/mozilla-firefox-45.3.0esr-i586-1_slack14.2.txz: Upgraded. […]

Slackware: 2016-219-04: stunnel: Security Update Posted by Anthony Pell    New stunnel packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…] [slackware-security] stunnel (SSA:2016-219-04) New stunnel packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. Here are […]

Debian: 3643-1: kde4libs: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3643-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso August 06, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : kde4libs CVE ID : CVE-2016-6232 Debian Bug : 832620 Andreas Cord-Landwehr discovered that kde4libs, the core libraries for all KDE 4 applications, do not properly […]

Debian: 3642-1: lighttpd: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3642-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond August 05, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : lighttpd CVE ID : CVE-2016-1000212 Debian Bug : 832571 Dominic Scheirlinck and Scott Geary of Vend reported insecure behavior in the lighttpd web server. Lighttpd […]

“900 million Androids vulnerable to Quadrooter bugs” – what you need to know
Fake QR code app gets hacker into luxury airport lounges for free
A Month Without Adobe Flash Player Patches
What your hacked account is worth on the Dark Web
Email: how secure is yours? [Survey]
Internet Minefield: Beware of fake WiFi spots in Rio stealing user data
Misuse of Language: ‘Cyber’; When War is Not a War, and a Weapon is Not a Weapon
Internet of Car…rikey what the hell just happened to my car?
Nigerian scammer infects himself with malware
Nemucod is back and serving an ad-clicking backdoor instead of ransomware

The trojan downloader Nemucod is back with a new campaign. This time however, it has changed the payload served to its victims – ransomware is not its go-to malware. Currently the “weapon of choice” is a backdoor detected by ESET as Win32/Kovter, in this instance mainly focusing on ad-clicking. As a backdoor, this trojan allows […]

Car hacking: Defcon style

This year at Defcon, the car hacking village is bigger than ever, with more cars, car hacking adapters and giant snarls of tiny exposed wires tied to demo stations with car parts screwed to plywood stands than ever before. It’s car hacking 101 here, and class is in full force. The first thing you notice […]

NIST: It’s time move on from SMS 2FA

SMS-based two-factor authentication (2FA) should be phased out, according to the National Institute of Standards and Technology (NIST) at the US Department of Commerce. In its most recent Digital Authentication Guideline – draft version – the federal technology agency explained that this is because there are risks with this approach. NIST stated that as SMS messages […]

Torrentz Has Died, But It Won’t Take Torrenting With It
Hackers Fool Tesla S’s Autopilot to Hide and Spoof Obstacles
Google Domain Enables HSTS Protection
Blabbing on social media foils terrorists’ rocket attack plan
SHA-2 shortcut: Easy certificate management for Linux

I spend a lot of time working on enterprise Public Key Infrastructure (PKI), especially in light of the coming SHA-1 deprecation deadlines. It’s nearly all I do these days. One question my customers ask all the time is how to provision certificates on non-Windows devices and computers. Microsoft does an excellent job of automating the […]

Black Hat 2016: When middleware takes over the world

In years past at Black Hat here in Las Vegas, there was row after row of hardware, then, in later years, row after row of software for your workstation. Now there’s row after row of middleware designed to interpret all that data in real time and try to make sense of it all, to find […]

UK tops European charts … for carder fraud
Windows 10 Anniversary Update crashing under Avast antivirus update
Google password fill effort could kill Android malware’s best tricks

Risk High Date Discovered August 9, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will […]

Risk High Date Discovered August 9, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will […]

Risk Medium Date Discovered August 9, 2016 Description Microsoft Internet Explorer is prone to a local information-disclosure vulnerability. An authenticated attacker can leverage this issue to obtain sensitive information that may aid in further attacks. Internet Explorer 10 and 11 are vulnerable. Recommendations Permit local access for trusted individuals only. Where possible, use restricted environments […]

Risk Medium Date Discovered August 9, 2016 Description Microsoft Internet Explorer and Edge are prone to an information-disclosure vulnerability. Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks. Edge and Internet explorer 9, 10 and 11 are vulnerable. Technologies Affected Microsoft Edge Microsoft Internet Explorer 10 Microsoft Internet Explorer […]

Risk Medium Date Discovered August 9, 2016 Description Microsoft Internet Explorer and Edge are prone to an information-disclosure vulnerability. Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks. Edge and Internet explorer 9, 10 and 11 are vulnerable. Technologies Affected Microsoft Edge Microsoft Internet Explorer 10 Microsoft Internet Explorer […]

Risk Medium Date Discovered August 9, 2016 Description Microsoft Internet Explorer and Edge are prone to an information-disclosure vulnerability. Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks. Edge and Internet explorer 9, 10 and 11 are vulnerable. Technologies Affected Microsoft Edge Microsoft Internet Explorer 10 Microsoft Internet Explorer […]

Risk High Date Discovered August 9, 2016 Description Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed […]

Risk High Date Discovered August 9, 2016 Description Microsoft Windows is prone to a local privilege-escalation vulnerability that occurs in the Windows kernel. A local attacker can exploit this issue to execute arbitrary code in kernel mode with elevated privileges. Technologies Affected Microsoft Windows 10 Version 1607 for 32-bit Systems Microsoft Windows 10 Version 1607 […]

Risk High Date Discovered August 9, 2016 Description Microsoft Windows is prone to a local privilege-escalation vulnerability that occurs in the Windows kernel. A local attacker can exploit this issue to execute arbitrary code in kernel mode with elevated privileges. Technologies Affected Microsoft Windows 10 Version 1607 for 32-bit Systems Microsoft Windows 10 Version 1607 […]

Risk High Date Discovered August 9, 2016 Description Microsoft Windows is prone to a local privilege-escalation vulnerability that occurs in the Windows kernel. A local attacker can exploit this issue to execute arbitrary code in kernel mode with elevated privileges. Technologies Affected Microsoft Windows 10 Version 1607 for 32-bit Systems Microsoft Windows 10 Version 1607 […]

Even Solar Panels Can Be Hacked
Big Red alert: Oracle’s MICROS payment terminal biz hacked
19-year-old wins one million airmiles after finding United Airlines bugs
Breach Forces Password Change on Oracle MICROS PoS Customers

We all know that Internet of Things (IoT) is the future and that everything from your refrigerator to your toaster may eventually connect to the internet. With that being the case, it’s important to remember that these connected devices need to be designed with security in mind. On Saturday at the Def Con hacking conference in […]

Malware Infected PokémonGo Apps Found on GooglePlay Store
90% off Become an Ethical Hacker With This Complete eLearning Bundle – Deal Alert
ProjectSauron APT On Par With Equation, Flame, Duqu

Risk Level: Very Low. Type: Trojan.

How to pick a lock
Tor can be cracked “like eggshells”, warns US judge
Almost a billion devices may be at risk from QuadRooter Android flaw
Critical Security Flaws in Android Devices Affecting Millions of Users
Quadrooter Flaw in Qualcomm Chips Puts 900M Android Devices At Risk
Bitfinex asks users to share losses of bitcoin theft
PCs’ PCs pwned: Irish cops probe mystery malware attack
iOS 9.3.4 Patches Critical Code Execution Flaw
Tesla Model S’s autopilot can be blinded with off-the-shelf hardware
Android trojan loads ads, installs paid apps on victims’ devices
Brit network O2 hands out free Windows virus with USB pens
Eye of Sauron-themed trojan targets Russia, Sweden
Monday review – the hot 19 stories of the week
How to spear-phish Twitter users with greater success
Stealthy malware infects digitally-signed files without altering hashes
If you use ‘smart’ Bluetooth locks, you’re asking to be burgled
World’s lamest ransomware authors won’t answer fake tech support line
Broken BitBank Bitfinex shaves 36% from all accounts
‘Nigerian scammer’ busted after he infected himself with malware
Latest Androids have ‘god mode’ hack hole, thanks to Qualcomm
Video surveillance recorders riddled with zero-days

Andreas Cord-Landwehr discovered that kde4libs, the core libraries for all KDE 4 applications, do not properly handle the extraction of archives with “../” in the file paths. A remote attacker can take advantage of this flaw to overwrite files outside of the extraction folder, if a user is tricked into extracting a specially crafted archive. […]

24 Funny, Upsetting and Shocking Hacked Traffic Signs
US Politicians tell DEF CON it’ll take Congress ages to sort out how to regulate crypto
Twitter Accounts of Vimeo Founder Zach Klein, YouTuber Alexa Losey Hacked