Menu

Monthly Archives: August 2016

Samsung Pay Vulnerability allows Hackers to make Fraudulent Transactions
Anonymous DDoS Brazilian Government Websites Because Rio Olympics
Symantec appoints first cybersecurity czar to woo hacking talent
Apple rushes out iOS update, shuts out jailbreakers
Resistance is futile: DARPA’s competition to automate security
What Facebook plans to do next will SHOCK you!!!
How hacking brainwaves could reveal our deeply guarded secrets
Bitcoin robber offers $600K “giveaway”
Classic Shell hackers: We infected FossHub so ransomware couldn’t (and yeah, also for fun)
Game over, security researchers – DARPA’s AI bug hunters are coming for your jobs
Mr. Robot eps2.3logic-b0mb.hc – the security review
Kazakhstan accused of hacking journos, activists by EFF
Phisherfolk phlock to Rio for the Olympics
World’s largest bitcoin-dollar exchange robbed
Hackers unleash smart Twitter phishing tool that snags two in three users
Fortinet axes two per cent of workforce, chops 100 sales, ad staff, execs

Ubuntu: 3046-1: LibreOffice vulnerability Posted by Anthony Pell    LibreOffice could be made to crash or run programs as your login if itopened a specially crafted file. ========================================================================== Ubuntu Security Notice USN-3046-1 August 04, 2016 libreoffice vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: LibreOffice […]

Never Trust a Found USB Drive, Black Hat Demo Shows Why
Telegram app’s SMS activation used to expose activists and journalists

Debian: 3641-1: openjdk-7: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3641-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff August 04, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : openjdk-7 CVE ID : CVE-2016-3458 CVE-2016-3500 CVE-2016-3508 CVE-2016-3550 CVE-2016-3606 Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in […]

Apple Launches Bug Bounty with Maximum $200,000 Reward
How the HTTPS-snooping, email addy and SSN-raiding HEIST JavaScript code works
In DARPA challenge, smart machines compete to fend off cyberattacks
Lack of Encryption Leads to Large Scale Cookie Exposure
Risk management: Picking the right tool for the job
Black Hat 2016 wrap-up: Same stuff, different year?

Red Hat: 2016:1573-01: squid: Moderate Advisory Posted by Anthony Pell    An update for squid is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: […]

How Bugs Lead to a Better Android
Supercomputers give a glimpse of cybersecurity’s automated future
Miller, Valasek Deliver Final Car Hacking Talk
Apple’s bug bounty program favors quality over quantity

Debian: 3640-1: firefox-esr: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3640-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff August 03, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : firefox-esr CVE ID : CVE-2016-2830 CVE-2016-2836 CVE-2016-2837 CVE-2016-2838 CVE-2016-5252 CVE-2016-5254 CVE-2016-5258 CVE-2016-5259 CVE-2016-5262 CVE-2016-5263 CVE-2016-5264 CVE-2016-5265 Multiple security issues have been found in the Mozilla […]

Hacking Hotel Keys and Point of Sale Systems at DEFCON
The advanced security techniques of criminal hackers
Never Trust a Found USB Drive, Black Hat Demo Shows Why
Why some risk assessments fail

Discovered: August 4, 2016 Updated: August 5, 2016 3:38:31 PM Type: Trojan, Virus Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP SONAR.BC.CryptDrop!g4 is a heuristic detection to detect suspicious programs that might drop known […]

Social engineering tricks and why CEO fraud emails work
Joshua Drake on Android Security Post-Stagefright

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Debian: 3639-1: wordpress: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3639-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso August 03, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : wordpress CVE ID : CVE-2015-8834 CVE-2016-5832 CVE-2016-5834 CVE-2016-5835 CVE-2016-5837 CVE-2016-5838 CVE-2016-5839 Several vulnerabilities were discovered in wordpress, a web blogging tool, which could allow remote […]

How to wade through the flood of security buzzwords and hype

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Beware of ransomware hiding in shortcuts
Researchers Go Inside a Business Email Compromise Scam

Risk Level: Very Low. Type: Trojan.

The changing economics of cybercrime
Researchers Bypass Chip-and-Pin Protections at Black Hat

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Researchers Bypass Chip-and-Pin Protections at Black Hat

Debian: 3638-1: curl: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3638-1 security@debian.org https://www.debian.org/security/ Alessandro Ghedini August 03, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : curl CVE ID : CVE-2016-5419 CVE-2016-5420 CVE-2016-5421 Several vulnerabilities were discovered in cURL, an URL transfer library: CVE-2016-5419 Bru Rom discovered that libcurl would attempt […]

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Afraid someone is misusing your webcam?

Imagine a situation where you are working on your laptop and all of the sudden the green light next to your built-in webcam blinks for a second and immediately goes dark again. Would you just ignore it? Or would you start digging around to find out if it was something more serious? If you want […]

Risk Level: Very Low. Type: Trojan, Virus, Worm.

iOS 9.3.4 released, fixing critical security hole. Update now
Frequent password changes are the enemy of security, FTC technologist says

Risk Level: Very Low. Type: Trojan.

Big spike in card fraud in Europe

There was a notable spike in card fraud in Europe last year, with the UK the worst hit, according to new data from FICO. The tech company revealed that the UK experienced an 18% rise in card fraud over a 12-month period, resulting in losses worth approximately $118 million. The UK is clearly a big […]

Earn up to $200,000 as Apple *finally* launches a bug bounty
Massive new study lifts the lid on top websites’ tracking secrets

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Israeli security firm hacks ISIS forum, discloses future targets
Fake Prisma apps found on Google Play

Before the release of the Android version of Prisma, a popular photo transformation app, fake Prisma apps flooded the Google Play Store. ESET researchers discovered fake Prisma apps of different types, including several dangerous trojan downloaders. The Google Play security team removed them from the official Android store at ESET’s notice. Prior to that point, […]

An update for firefox is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: firefox security update Advisory ID: RHSA-2016:1551-01 Product: Red Hat Enterprise […]

Multiple security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors, buffer overflows and other implementation errors may lead to the execution of arbitrary code, cross-site scriping, information disclosure and bypass of the same-origin policy. For the stable distribution (jessie), these problems have been fixed in version 45.3.0esr-1~deb8u1. For the […]

Multiple security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors, buffer overflows and other implementation errors may lead to the execution of arbitrary code, cross-site scriping, information disclosure and bypass of the same-origin policy. For the stable distribution (jessie), these problems have been fixed in version 45.3.0esr-1~deb8u1. For the […]

Does dropping malicious USB sticks really work? Yes, worryingly well…
Password changes for the sake of it don’t improve security, says FTC technologist

Several vulnerabilities were discovered in wordpress, a web blogging tool, which could allow remote attackers to compromise a site via cross-site scripting, bypass restrictions, obtain sensitive revision-history information, or mount a denial of service. For the stable distribution (jessie), these problems have been fixed in version 4.1+dfsg-1+deb8u9. We recommend that you upgrade your wordpress packages.

Several vulnerabilities were discovered in wordpress, a web blogging tool, which could allow remote attackers to compromise a site via cross-site scripting, bypass restrictions, obtain sensitive revision-history information, or mount a denial of service. For the stable distribution (jessie), these problems have been fixed in version 4.1+dfsg-1+deb8u9. We recommend that you upgrade your wordpress packages.

Hackers Hijack a Big Rig Truck’s Accelerator and Brakes
Yahoo looks into major data breach claims

Yahoo is looking into claims that it has become the latest high-profile victim of a major data breach. It is thought up to 200 million accounts are affected. If found to be true, it is thought to be connected to an unknown individual who refers to himself as Peace. He has already claimed responsibility for […]

$61 million stolen from accounts at Bitcoin exchange Bitfinex
Apple’s lack of 2SV for Find My Phone nearly costs student his digital life

An update for ntp is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: ntp security update Advisory ID: RHSA-2016:1552-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1552.html Issue date: 2016-08-03 CVE […]

200 million Yahoo passwords being sold on the dark web?
Meet the men who spy on women through their webcams

Several vulnerabilities were discovered in cURL, an URL transfer library: CVE-2016-5419 Bru Rom discovered that libcurl would attempt to resume a TLS session even if the client certificate had changed. CVE-2016-5420 It was discovered that libcurl did not consider client certificates when reusing TLS connections. CVE-2016-5421 Marcelo Echeverria and Fernando Muñoz discovered that libcurl was […]

Several vulnerabilities were discovered in cURL, an URL transfer library: CVE-2016-5419 Bru Rom discovered that libcurl would attempt to resume a TLS session even if the client certificate had changed. CVE-2016-5420 It was discovered that libcurl did not consider client certificates when reusing TLS connections. CVE-2016-5421 Marcelo Echeverria and Fernando Muñoz discovered that libcurl was […]

Car hacking at speed – where vulnerabilities turn from critical to fatal

There’s a fundamental difference between criminal hackers and white hat vulnerability researchers. When a white hat finds a vulnerability they may explore it, and write an interesting presentation about what can be achieved through the flaw, but once they’ve described the security weakness to the appropriate party and the hole is closed – that’s it. […]

Car hacking at speed – where vulnerabilities turn from critical to fatal
Lost your iPhone? Be on guard for a perfectly-timed Apple ID phishing attack

Red Hat: 2016:1541-03: kernel-rt: Important Advisory Posted by Anthony Pell    An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: […]

2016 Rio Olympic Games: The safe way to obtain tickets online

This year is the year of sporting fans. Over the past few months especially, they have had the opportunity to move from one big sporting event to the next with few gaps in-between. First, just before the summer break, sports fans enjoyed a full month of football with the European Championship in France, followed by […]

Profiles in cryptographic courage

I recently finished reading “Hedy’s Folly” by the scholar Richard Rhodes. In it he discusses the “most beautiful woman in the world,” 1930s and ‘40s superstar Hedy Lamarr. With her composer friend George Antheil, she invented frequency hopping. Frequency hopping (or spread spectrum) is a technology that underlies the communication transport and security of almost […]

Advertisers could be tracking you via your battery status
Android users to receive notifications when new devices added to account

Android users will receive push notifications on their smartphone, alerting them to a new device being added to their account, Google has announced. It said that this feature is a key component of security, complementing other features like two-step verification and single sign-on. In particular, all of these features ensure that Android users are safe […]

Barclays launches voice recognition technology for telephone banking

When it comes to telephone banking, Barclays is looking to lead the way by enabling voice recognition technology for all of its customers. This means that when it comes to the usual security process for this particular service, instead of typing in a password, customers will instead be verified by their voice. While the bank […]

Red Hat: 2016:1538-01: golang: Moderate Advisory Posted by Anthony Pell    An update for golang is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: […]

Torrentz.eu, largest Torrent Search Engine Shuts Down; Quits Operation

Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1704 The chrome development team found and fixed various issues during internal auditing. CVE-2016-1705 The chrome development team found and fixed various issues during internal auditing. CVE-2016-1706 Pinkie Pie discovered a way to escape the Pepper Plugin API sandbox. CVE-2016-1707 xisigr discovered a URL spoofing […]

Beware of Fake Android Prisma Apps Running Phishing, Malware Scam

Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1704 The chrome development team found and fixed various issues during internal auditing. CVE-2016-1705 The chrome development team found and fixed various issues during internal auditing. CVE-2016-1706 Pinkie Pie discovered a way to escape the Pepper Plugin API sandbox. CVE-2016-1707 xisigr discovered a URL spoofing […]

Get rid of these undesirable ‘friends’ on this popular social network

Whether because they share too much, because they send links and applications that you are not interested in, because you don’t know for real who they are, or because they are too passionate about their opinions, there are some online ‘friends’ that you should keep away from. Tomorrow we will celebrate the International Day of […]

PoodleCorp Says it DDoSed GTA and PlayStation Servers

An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2016:1539-01 Product: Red […]

Emilien Gaspar discovered that collectd, a statistics collection and monitoring daemon, incorrectly processed incoming network packets. This resulted in a heap overflow, allowing a remote attacker to either cause a DoS via application crash, or potentially execute arbitrary code. Additionally, security researchers at Columbia University and the University of Virginia discovered that collectd failed to […]

Emilien Gaspar discovered that collectd, a statistics collection and monitoring daemon, incorrectly processed incoming network packets. This resulted in a heap overflow, allowing a remote attacker to either cause a DoS via application crash, or potentially execute arbitrary code. Additionally, security researchers at Columbia University and the University of Virginia discovered that collectd failed to […]

Bitfinex Exchange Hacked; $70 Million Worth of Bitcoin Stolen