Menu

Monthly Archives: September 2016

Russian Search Engine Rambler.ru Hacked; 100M Plaintext Passwords Stolen
Hacker takes down CEO wire transfer scammers, sends their Win 10 creds to the cops
Obama says USA has world’s biggest and best cyber arsenal
Pokémon-loving VXer targets Linux with ‘Umbreon’ rootkit
98.1 million CLEARTEXT passwords pasted as Rambler.ru rumbled

CVE-2016-5696 Yue Cao, Zhiyun Qian, Zhongjie Wang, Tuan Dao, and Srikanth V. Krishnamurthy of the University of California, Riverside; and Lisa M. Marvel of the United States Army Research Laboratory discovered that Linux’s implementation of the TCP Challenge ACK feature results in a side channel that can be used to find TCP connections between specific […]

Apple issues critical updates for Mac – Users MUST update OS X, Safari

An update for thunderbird is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: thunderbird security update Advisory ID: RHSA-2016:1809-01 Product: Red Hat Enterprise […]

Debian: 3659-1: linux: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3659-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso September 04, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : linux CVE ID : CVE-2016-5696 CVE-2016-6136 CVE-2016-6480 CVE-2016-6828 Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial […]

Debian: 3653-2: flex: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3653-2 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso September 04, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : flex CVE ID : CVE-2016-6354 Debian Bug : 832768 835542 It was reported that the update for flex as released in DSA-3653-1 did not completely […]

7 Million LifeBoat Accounts from Jan 2016 Breach Leaked Online
Riseup, providing encrypted comms for over 15 years, is running out of money
Exposed! Almost 800,000 Brazzers usernames and passwords revealed after forum hack
More IoT insecurity: the routers that take instructions from anyone
Variety confirms CMS hijack by hacking collective OurMine

Variety has confirmed that its content management system (CMS) was hijacked on the weekend by the hacking collective OurMine. Once in, the group was able to send subscribers to the online and print publisher multiple newsletters via email. The subject line stated “Hacked By #OurMine”, while the body text read: “Hello Variety, it’s #OurMine, don’t […]

Suspect arrested in 5-year-old kernel.org breach
Podcast with Ahmed Mansoor, the world’s most spied-on man
11 easy tips to secure your Mac against hackers
Google Chrome fixes serious vulnerabilities, thanks to bug fighters
Sophos Windows users face black screens after false positive snafu
5 security practices hackers say make their lives harder
Monday review – the hot 18 stories of the week
Sundown exploit kit authors champions of copy-paste hacking
Microsoft thought of the children and decided to ban some browsers
Pixellation popped: AI can ID you, even after PhotoShop phuzzing
Extra Bacon? Yes please, even though the Cisco bug of this name is bad for you

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Google swats Nexus 5X vulnerable fastboot memory dump flaw
Hacked BitcoinTalk.org Forum Database Goes for Sale on Dark Web
It’s 2016, and anti-virus products still goof up like this…
Phishing and data theft await users due to target=”_blank” vulnerability
Hacker Selling 68 Million Stolen Dropbox User Accounts on Dark Web
OurMine Hacks Variety Website; Sends Fake Emails to Readers
Firm loses $44m due to an online email scam

Risk Level: Very Low.

Man who hacked Kernel.org, Linux Foundation in 2011 Arrested
Azerbaijani hackers leak secret data from Armenian Intel server
BBC mistakenly sent news alert in Bengali; Readers took it as a hack
Linux Foundation Restructuring CII Security Effort for Scale

Discovered: September 2, 2016 Updated: September 3, 2016 12:00:55 AM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Ransom.Fsociety is a Trojan horse that encrypts files on the compromised computer and asks the user to […]

BASHLITE malware turning millions of Linux Based IoT Devices into DDoS botnet

European Company Loses Millions in Targeted Phishing Scam In the last couple weeks, Leoni AG, one of the largest electrical wiring companies in Europe fell victim to a Business Email Compromise (BEC) scam involving the CFO transferring a significant sum of money to a non-verified bank account. This location was likely the main target due […]

Hanno Boeck discovered multiple vulnerabilities in libidn, the GNU library for Internationalized Domain Names (IDNs), allowing a remote attacker to cause a denial of service against an application using the libidn library (application crash). For the stable distribution (jessie), these problems have been fixed in version 1.29-1+deb8u2. For the testing distribution (stretch), these problems have […]

Microsoft Adds .NET Core, ASP.NET to Bug Bounty Program
Google patches critical bug on Android Nexus 5X devices
Bloke accused of Linux kernel.org hack nabbed during traffic stop
NBA’s Golden State Warriors sued for ‘mic snooping’ mobile app
Online Music Database Last.fm Hacked; 43M accounts Leaked

Debian: 3658-1: libidn: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3658-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso September 01, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libidn CVE ID : CVE-2015-8948 CVE-2016-6261 CVE-2016-6263 Hanno Boeck discovered multiple vulnerabilities in libidn, the GNU library for Internationalized Domain Names (IDNs), allowing a remote […]

Red Hat: 2016:1797-01: ipa: Moderate Advisory Posted by Anthony Pell    An update for ipa is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: ipa security update Advisory […]

Hacking mobile login tokens tricky but doable, says reverse-engineer
And the worst passwords from the Last.fm hack are…
Android Patch Fixes Nexus 5X Critical Vulnerability
“Hillary Clinton hacker” Guccifer sentenced to 52 months for other crimes
Fantom ransomware pretends to be a Windows critical update
Two Crypto-currency Websites Suffered Huge Data Breaches
Microsoft bug bounty program adds .Net Core and ASP.Net Core
Apple quashes 3 zero-days with emergency Mac update
Apple Patches Trident Vulnerabilities in OS X, Safari
Azerbaijani hacktivists leak Armenian security service docs
CEO fraud: How to stay protected against this modern day deception

So, you’re minding your own business working through your day-to-day battle of never-ending emails and sorting through all the stuff you should have finished yesterday. Suddenly, an urgent email drops into your inbox from the boss, asking for an urgent transfer of £8,000 to a designated bank account. It’s not overly unusual: it’s from the […]

Threatpost News Wrap, September 2, 2016
Kaspersky ‘terminates’ deal with security reseller Quadsys
Regular password changes make things worse
18 years of Googling: Malware can still be just one click away

How do you navigate through virtual reality? What is the first webpage you open when you are looking for something online? Where do you go to answer a ‘how to’ question most often? For the majority of users, the answer would be Google. It’s been 18 years since Stanford PhD students Larry Page and Sergey […]

Patch now! Recent iOS vulnerability affects Macs too
Mac users vulnerable to state-sponsored Trident attack, fixed in iOS last week. Patch now
Adobe ices ColdFusion server admin password, file hack hole
Lightspeed PoS vendor breached, sensitive database tapped
Google crushes 33 Chrome bugs, pays boffins more than $56k
Patch now: Apple emits fix for Pegasus spyware bugs in OS X, Safari

Discovered: September 1, 2016 Updated: September 2, 2016 12:02:36 PM Type: Trojan Infection Length: 3,921,408 bytes Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Ransom.Serpico is a Trojan horse that encrypts files on the compromised computer and […]

How much does your kid hate exams? This lad hacked his government to skip them
Did you stay at any of these 60 Kimpton hotels? Whelp, hackers have your card details
Romanian hacker Guccifer sentenced to 52 months in U.S. prison
George W Bush hacker Guccifer to spend 52 months in the big house
Malvertising Campaign Pushing Neutrino Exploit Kit Shut Down

Slackware: 2016-244-01: mozilla-thunderbird: Security Update Posted by Anthony Pell    New mozilla-thunderbird packages are available for Slackware 14.1, 14.2, and -current to fix security issues. [More Info…] [slackware-security] mozilla-thunderbird (SSA:2016-244-01) New mozilla-thunderbird packages are available for Slackware 14.1, 14.2, and -current to fix security issues. Here are the details from the Slackware 14.2 ChangeLog: +————————–+ […]

Guccifer hacker jailed for four years by Virginia court
Insecure Redis Instances at Core of Attacks Against Linux Servers
DressCode? More like code for an Android botnet…
Transmission hijacked to broadcast Mac malware
Financial cybersecurity ‘needs to be a key agenda item at G20’

Improving financial cybersecurity at an international level must be a key agenda item at the G20 Summit in China this month (September 4th-5th). This is according to a group of prominent US senators, who have urged president Barack Obama to raise this critical issue at the event. In a letter to the White House, Gary […]

40% of Facebook users click on phishy links. Do you?
Chrome 53 Fixes Address Spoofing Vulnerability, 32 Other Bugs
Mac password-stealing malware haunts Transmission app… again
‘Identity and access management solution without compromise’ is compromised
Patched ColdFusion Flaw Exposes Applications to Attack
Yahoo email privacy lawsuit settled
How one company lost $44 million through an email scam
Mr. Robot season 2 episode 2.7init5.fve – the security review
The Dropbox data breach is a warning to update other passwords
SWIFT Warns Banks Of More Cyberattacks
How to turn on HTTPS company-wide in one swoop
Healthcare and local gov are most likely UK bodies to suffer infosec breaches
VMworld: Can you trust your API?

The VMware ecosystem has become huge and now encompasses a daunting number of platforms that you don’t even think about, including many in the IoT world. But now, all of these devices have to talk to each other in order to get along, and they do that with Application Program Interfaces (API). Are APIs all […]

OS X malware spread via signed Transmission app… again
Cisco SOHO switches patched for SOHOpeless vuln
Blackhat wannabes proffer probably bogus Linux scamsomware