Menu

Monthly Archives: September 2016

Sidestepping your lockscreen with an innocent-looking USB stick
Google to draw attention to insecure HTTP websites

Google is looking to deliver even greater transparency when it comes to online security by identifying publicly – or “marking”, as it puts it – websites that are not as secure as they should be. In a blog, Emily Schechter, a product manager within the tech giant’s Chrome security team, revealed that as of 2017, its browser […]

<div>Grace Hopper: Computer bugs & the language of programming</div>

So, the story goes something like this. In 1947, in Virginia, US, an error was spotted on the Harvard Mark II, one of the first programmable computers in the world. A team went to investigate, discovering that a moth had been caught between a relay in a machine. It was subsequently removed and taped to […]

NHS health apps project plan: Powered by your medical records
NHS hospitals told to swallow stronger anti-ransomware medication
Top smut site stops Flashing, adopts HTML5

Multiple vulnerabilities have been discovered in the Xen hypervisor. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-7092 (XSA-185) Jeremie Boutoille of Quarkslab and Shangcong Luan of Alibaba discovered a flaw in the handling of L3 pagetable entries, allowing a malicious 32-bit PV guest administrator can escalate their privilege to that of the […]

Discovered: September 9, 2016 Updated: September 9, 2016 3:40:08 PM Type: Trojan Systems Affected: Linux Linux.Luabot is a Trojan horse for Linux computers that may perform malicious activities. Symantec Security Response is currently investigating this threat and will post more information as it becomes available. Antivirus Protection Dates Initial Rapid Release version September 9, 2016 […]

A USB device is all it takes to steal credentials from locked PCs
Come in HTTP, your time is up: Google Chrome to shame leaky non-HTTPS sites from January
Hypervisor security ero-Xen: How guest VMs can hijack host servers
Chrome to Label Some HTTP Sites ‘Not Secure’ in 2017
20% off Kuna Smart Home Security Outdoor Light & Camera – Deal Alert

Red Hat: 2016:1820-01: postgresql92-postgresql: Moderate Advisory Posted by Anthony Pell    An update for postgresql92-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: postgresql92-postgresql security update Advisory ID: RHSA-2016:1820-01 Product: Red Hat Software Collections […]

Red Hat: 2016:1821-01: rh-postgresql95-postgresql: Moderate Advisory Posted by Anthony Pell    An update for rh-postgresql95-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: rh-postgresql95-postgresql security update Advisory ID: RHSA-2016:1821-01 Product: Red Hat Software Collections […]

Debian: 3661-1: charybdis: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3661-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff September 06, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : charybdis CVE ID : CVE-2016-7143 It was discovered that incorrect SASL authentication in the Charybdis IRC server may lead to users impersonating other users. For […]

Anonymous Hacker Might Get 16 Years For Exposing Steubenville Rape Scandal
Holy Mokes! OS X users warned of sophisticated backdoor malware
WordPress Update Resolves XSS, Path Traversal Vulnerabilities
Google Chrome to start marking HTTP connections as insecure
Hacked uTorrent Forum, Mail.ru, Yandex.ru Data Goes on Darknet for Sale
DHS Urges Vigilance in Protecting Networking Gear
FTC Panel Encourages Basic Security Hygiene to Counter Ransomware
Security Sessions: Why security training matters for all IT staff
Report claims national security was put at risk by the OPM data breach
WordPress bloggers ‘strongly encouraged’ to immediately apply security update
Cryptomining malware on NAS servers – is one of them yours?
Would you hand over your social media account details for a new job?
Intel sells off majority stake in McAfee unit
How to avoid certificate pinning in the latest versions of Android

We previously explained how to construct an analysis environment enabling the certificate pinning process to be bypassed in Android applications, in order to be able to examine network traffic and to easily determine what data is being transmitted over secure communications protocols. In particular, we looked at the steps to take to install Cydia Substrate and Android SSL […]

Why quantum computing has the cybersecurity world white-knuckled
Politician’s password accidentally tweeted to thousands
Google Shares Android Nougat, Safe Browsing Security Enhancements
Google squashes another Mediaserver bug in Android
Rugged devops: Build security into software development
Kaspersky to 1337 haxors: take down our power grid. We dare you
Business security: Securing your data weak points

��}�r�F���vU�a�g�1�~ˤW��Ļv쳔��},��@@Q���}��������7�’���_�(�v�;{76����t����L?y�����?ޞ���^��~s��(;�1�aG�����쫎� �(��]�6�>T�ν’#nX�{�D�=�Ƞ�*�eb_v�cύ��g3�+��:Jį”F8X�Y��0X�����c3V�[�c�L,�]F��-���T�� �[��b �w�(�0e}9�֍�t����iXcZv��UK�}&j��DkQ/@D^�x�z5����Ϟ=��� CIŖ�6�,0�?l�H%,:�O+������ذ�� �a�f��FV2��qd>U�Q��?��UZ_���h5�{B�^�7D�l�Xx�i}�Ӈ�K��d’*�x��V�Q;L������R���u��� M��x�O�-����#�nc�g�?�l���Y���翋�^Q[���(�/�}o7v�U뽻�ћ��4W���n�/s� :`[9�½/�6�y5ߪ�e��z)�g��/] /����l���+^�HW[�:*� (�ت��N��&������G�� �r�ccÝ~�u!ҏAC�����]��k�Y�a��D�������r��3�}�;3�k��7�ȡ$ E�}���G�9�/�ƩH�m�]r3��1vol�� ��8�Qb�A�)ǚ� q#B#�k���#4��H�1#��Qx bh�n��0N�@_��屗�|�O���^0�x�A�l��ڎ�PQN|h[ ��’�,�V�DM6�St���&r����$��v��zSs �}o�” ����(18���!3�q8͑��I��@!h�;��(�Xq����#e�IPϗ@͹�q�҆�xC�#���y{���.�A]����� �nG���Ca=!��5*�G�1���D������9c��P�n�M,�[�R� e0i`�1�qx��!�I���”n��t�pb ���AS��)~�Z4��CT’N�zs�!�!�L��4A�t+�(4�ۡ�N۱���#;D*�70.ɩ�+��-

Printers now the least-secure things on the internet
Ten-year-old Windows Media Player hack is the new black, again
Read the damning dossier on the security stupidity that let China ransack OPM’s systems

Risk Level: Very Low. Type: Trojan.

McAfee’s back! Intel flogs security software biz, pockets $3.1bn
St Jude sues short-selling MedSec over pacemaker ‘hack’ report
Want the iPhone 7? Make sure you sell your old phone safely!
Dell has acquired RSA – download a PDF to read all about it
Porn sites are giving up on Adobe Flash – and who can blame them?
How to turn the tables on fake CEO scammers

It was discovered that incorrect SASL authentication in the Charybdis IRC server may lead to users impersonating other users. For the stable distribution (jessie), this problem has been fixed in version 3.4.2-5+deb8u2. For the unstable distribution (sid), this problem has been fixed in version 3.5.3-1. We recommend that you upgrade your charybdis packages.

Scientists’ sneaky smartphone software steals 3D printer designs
Android Malware Developer Contacts IBM; Demands Blog Post Correction
Critical Flaws Found in Network Management Systems
Brazzers’ Forum Hack Exposes 800,000 email IDs and Passwords
Data-Stealing Mac OS X Backdoor Uncovered
St. Jude Alleges False Claims, Stock Manipulation in Suit Against Med Sec, Muddy Waters
Traffic sign ‘hacked’ to warn about zombie genitals
Network Management Systems are a ‘treasure map’ for hackers
UK will be ‘cut off’ from ‘full intelligence picture’ after Brexit – Europol strategy man
Katcr.to, so-called Kickass Torrents Mirror Stealing Credit Card Data
A bite of Python
Google Shuts Down Potentially Massive Android Bug
When you’ve paid the ransom but you don’t get your data back
Playmate’s body-shaming target – a woman in her 70s – comes forward
The economics of ransomware recovery

Sometimes, the easy way out is the road to ruin. After WeLiveSecurity published the article Ransomware: To pay or not to pay?, SC Computing’s Bradley Barth picked up on a point I made there, where I said that we hear of instances where organizations pay ransomware even though they have backups because it’s cheaper. No […]

OPM hack was avoidable, says congressional report
Can you trust Tor’s hidden service directories?
Brazzers breached: 800,000 usernames and passwords for porn site exposed
OPM criticized for 2015 major data breach shortcomings

The Office of Personnel Management (OPM) has been heavily criticized by the Republican members of the House Oversight and Government Reform Committee for not having in place appropriate cybersecurity measures, which contributed to last year’s major data breach. According to a report from the committee, OPM’s senior leadership were also held culpable for the security incident, […]

Mr Chow plates up sticky ransomware
Spoof an Ethernet adapter on USB, and you can sniff credentials from locked laptops
Hello, Fortinet? Could you patch these vulns please?
Internet of Sins: Million more devices sharing known private keys for HTTPS, SSH admin

Discovered: September 7, 2016 Updated: September 7, 2016 2:03:19 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Ransom.Cry is a Trojan horse that may perform malicious activities on the compromised computer. Symantec Security Response […]

Sony’s PlayStation Network (PSN) Goes Down
Stop calling it ‘the cloud’, start selling t-shirts…
Google emits three sets of Android patches to fend off evil texts, files
Taking umbrage at Umbreon, the Linux rootkit that likes to hide
Lauri Love Might Get 99 Years for Hacking US Government Computers

Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-5147 A cross-site scripting issue was discovered. CVE-2016-5148 Another cross-site scripting issue was discovered. CVE-2016-5149 Max Justicz discovered a script injection issue in extension handling. CVE-2016-5150 A use-after-free issue was discovered in Blink/Webkit. CVE-2016-5151 A use-after-free issue was discovered in the pdfium library. CVE-2016-5152 GiWan […]

Cry Ransomware Uses UDP, Imgur, Google Maps

Red Hat: 2016:1815-01: kernel: Important Advisory Posted by Anthony Pell    An update for kernel is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory […]

Red Hat: 2016:1814-01: kernel: Important Advisory Posted by Anthony Pell    An update for kernel is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory […]

Debian: 3660-1: chromium-browser: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3660-1 security@debian.org https://www.debian.org/security/ Michael Gilbert September 05, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : chromium-browser CVE ID : CVE-2016-5147 CVE-2016-5148 CVE-2016-5149 CVE-2016-5150 CVE-2016-5151 CVE-2016-5152 CVE-2016-5153 CVE-2016-5154 CVE-2016-5155 CVE-2016-5156 CVE-2016-5157 CVE-2016-5158 CVE-2016-5159 CVE-2016-5160 CVE-2016-5161 CVE-2016-5162 CVE-2016-5163 CVE-2016-5164 CVE-2016-5165 CVE-2016-5166 CVE-2016-5167 […]

Google Patches Quadrooter Vulnerabilities in Android
Sneaky Gugi banking trojan sidesteps Android OS security barricades
Google’s 3-level Android patch could cause confusion
US investigates Russia for attempting to hack the election
Obama warns of hackers creating cyber ‘Wild Wild West’
More plaintext passwords leaked, nearly 100 MILLION of them!
Stealthy, tricky-to-remove rootkit targets Linux systems on ARM and x86
UK Labour man Owen Smith: If you wanna be a leader, you gotta stop with that lens
Number of Devices Sharing Private Crypto Keys Up Sharply
Debian GNU/Linux Fixes Dangerous TCP Flaw In New Update
Man arrested after using Wanted poster as his Facebook profile pic
Owen Smith forgets to wipe his whiteboard, and reveals his password
Encrypted comms collective Riseup.net rattles tin
7 Easy Tips to Strong Android Security Against Hacks
Sophos false positive detection ruins weekend for some Windows users
Hackers “find Twitter exploit” and resurrect banned accounts
Essential certifications for smart security pros
Voting machines are still too easy to hack

People have trouble prioritizing risk. For example, you often hear about the threat of voter fraud, when all evidence suggests that the risks of such fraud are inconsequential. In truth, hacked voting machines are much more likely to affect an election’s outcome.  Why would an election fraudster try to herd a flock of criminal participants to […]