Menu

Category Archives: Security

Articles about security

Risk Level: Very Low. Type: Trojan.

Discovered: August 30, 2016 Updated: August 30, 2016 10:15:13 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Atmoripper is a Trojan horse for Automatic Teller Machines (ATMs) that allows an attacker to issue commands […]

Top 5 threats for online gamers and how to avoid them

We all know how much you enjoy playing – socially, professionally or casually – video games, which is why we want to take this opportunity to share more information about safe online gaming. Previously we have discussed how to protect yourself while playing, with professional online gamers offering advice based on their knowledge and experience as […]

Researchers: MedSec, Muddy Waters Set Bad Precedent With St. Jude Medical Short
68 Million Credentials Spilled in 2012 Dropbox Hack
Fairware Attacks Targeting Linux Servers
Adobe patches critical vulnerability in ColdFusion application server
Hackers Stole 68M Dropbox Passwords (Change yours now)
Millions of Dropbox users are being advised to change their passwords
How to keep viral memes from spreading malware in your enterprise
BitTorrent client is found distributing Mac-based malware
Review: SentinelOne blocks and dissects threats
I went on holiday. Hackers didn’t.
Angler’s obituary: Super exploit kit was the work of Russia’s Lurk group
HPE yawns, stretches, and patches January OpenSSH bug in virtual access products
More banks plundered through SWIFT attacks
Dropbox: Leaked DB of 68 million account passwords is real
USBee stings air-gapped PCs: Wirelessly leak secrets with a file write
OneLogin breached, hacker finds cleartext credential notepads

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Alex Jones’ Infowars Hacked; Thousands of Accounts Sold Online
BASHLITE Family Of Malware Infects 1 Million IoT Devices
How to Leak Data From Air-Gapped Computers With a USB Device
Inside the Demise of the Angler Exploit Kit

Slackware: 2016-242-01: kernel: Security Update Posted by Anthony Pell    New kernel packages are available for Slackware 14.1 to fix a security issue. [More Info…] [slackware-security] kernel (SSA:2016-242-01) New kernel packages are available for Slackware 14.1 to fix a security issue. Here are the details from the Slackware 14.1 ChangeLog: +————————–+ patches/packages/linux-3.10.103/*: Upgraded. A flaw […]

Ubuntu: 3070-1: Linux kernel vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-3070-1 August 29, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: […]

Ubuntu: 3072-2: Linux kernel (OMAP4) vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-3072-2 August 29, 2016 linux-ti-omap4 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: Several security issues were fixed in the kernel. Software […]

Ubuntu: 3071-1: Linux kernel vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-3071-1 August 29, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: […]

FBI: Arizona, Illinois Voter Registration Systems May Have Been Pwned

Risk Level: Very Low. Type: Trojan, Worm.

Risk Level: Very Low. Type: Trojan, Worm.

Privacy Groups File FTC Complaint over WhatsApp Data Sharing with Facebook
Kuwait Automotive Imports Company Hacked; 10k Accounts Leaked
New ransomware threat deletes files from Linux web servers
VMWorld: Do you know where your data is?

VMWorld this year feels like a confessional – operators coming clean about their lack of data visibility, heads hung in shame. The reasons are many, but foremost is workload – once you provision a data volume you never have time to get back to it and ask why, or update it really to mesh with […]

71,000 Minecraft World Map accounts leaked online after ‘hack’
OSX/Keydnap spreads via signed Transmission application

Last month ESET researchers wrote an article about a new OS X malware called OSX/Keydnap, built to steal the content of OS X’s keychain and maintain a permanent backdoor. At that time of the analysis, it was unclear how victims were exposed to OSX/Keydnap. To quote the original article: “It could be through attachments in […]

<div>Hollywood's 5 biggest hacking myths</div>

If you’ve ever hacked for a living — wearing a white hat, I hope — you probably can’t stand the unrealistic light most shows and movies shine on hacking and hackers. On the big and small screens, supergenius hackers enjoy instantaneous success and always manage to stay one step ahead of the law. Typically they’re […]

Hollywood’s 5 biggest hacking myths
Ripper! Boffins find malware thought behind $347k Thai ATM raids
Victoria Gov tips $6.5M into uni security seeder, city-country farm tech

Discovered: August 29, 2016 Updated: August 30, 2016 12:01:53 PM Type: Trojan Infection Length: 39,936 bytes Systems Affected: Windows 2000, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP Trojan.Odinaff is a Trojan horse that opens a back door on the compromised computer. Antivirus Protection Dates Initial […]

FBI Warned State Election Board Systems of Hacks
1.7 Million Opera Browser Users Told To Reset Passwords
Viner Amanda Cerny’ Vine Account Hacked; Verification Badge Removed
45% off Dictionary Hidden Book Safe With Lock – Deal Alert
FBI: Look out – hackers are breaking into US election board systems

Windows 10 has been notorious about automatically installing updates on users’ machines and now there is a ransomware that aims to capitalize on it. The new ransomware, Fantom, is based on the EDA2 open-source ransomware project on GitHub called hidden tear that’s recently been abandoned. Fantom behind the scenes In an attempt to conceal malicious intention, […]

Debian: 3655-1: mupdf: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3655-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso August 26, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : mupdf CVE ID : CVE-2016-6265 CVE-2016-6525 Debian Bug : 832031 833417 Two vulnerabilities were discovered in MuPDF, a lightweight PDF viewer. The Common Vulnerabilities and […]

An update for java-1.6.0-openjdk is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: java-1.6.0-openjdk security update Advisory ID: RHSA-2016:1776-01 Product: Red Hat Enterprise […]

RIPPER ATM Malware Uses Malicious EVM Chip
Iran’s Key Petrochemical Complexes Attacked by Malicious Malware
Dropbox Forces Password Reset for Older Users
Ghost Squad Shuts Down Israeli Prime Minister, Bank of Israel websites
Review: Top tools for preventing data leaks
Dream on if you think spies will reveal their exploits
Chinese CA hands guy base certificates for GitHub, Florida uni
Big data busts crypto: ‘Sweet32’ captures collisions in old ciphers
Russia MP’s son found guilty after stealing 2.9 million US credit cards
NewSat network breach ‘most corrupted’ Oz spooks had seen: report
Our pacemakers are totally secure, says short-sold St Jude
GoDaddy customers targeted by clever phishing scam
Human Cells’ DNA can Store Complex Data- MIT Bio-Engineers
Anonymous Hacks Deutsche Bank Group’ Subsidiary Against Aachen Repression
Opera Syncing Web Browser Service Suffers Breach, Passwords Stolen

Two vulnerabilities were discovered in MuPDF, a lightweight PDF viewer. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-6265 Marco Grassi discovered a use-after-free vulnerability in MuPDF. An attacker can take advantage of this flaw to cause an application crash (denial-of-service), or potentially to execute arbitrary code with the privileges of the user […]

Hacker Wins Bug Bounty After Exposing Critical Facebook Security Flaw
Windows10 Anniversary Update Causing Devices to Crash – Yet Again!
SpyNote Trojan (RAT); Yet Another Bad News for Android Users

Alexander Sulfrian discovered a buffer overflow in the yy_get_next_buffer() function generated by Flex, which may result in denial of service and potentially the execution of code if operating on data from untrusted sources. Affected applications need to be rebuild. bogofilter will be rebuild against the updated flex in a followup update. Further affected applications should […]

This updates fixes many vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service or the execution of arbitrary code if malformed TIFF, WPG, RLE, RAW, PSD, Sun, PICT, VIFF, HDR, Meta, Quantum, PDB, DDS, DCM, EXIF, RGF or BMP files are processed. For […]

Andrew Carpenter of Critical Juncture discovered a cross-site scripting vulnerability affecting Action View in rails, a web application framework written in Ruby. Text declared as HTML safe will not have quotes escaped when used as attribute values in tag helpers. For the stable distribution (jessie), this problem has been fixed in version 2:4.1.8-1+deb8u4. For the […]

This week’s Threat Recap covers everything from, ‘Fantom’, the new ransomware that disguises itself as a Windows update, to hackers using Facebook photos to trick facial-recognition logins. Decryption Keys Released for Wildfire Ransomware Recently, researchers have announced the public availability of decryption keys for users affected by the Wildfire ransomware variant. This particular variant did focused […]

Pacemaker Hacking Fears Rise With Critical Research Report

Debian: 3654-1: quagga: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3654-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond August 26, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : quagga CVE ID : CVE-2016-4036 CVE-2016-4049 Debian Bug : 822787 835223 Two vulnerabilities were discovered in quagga, a BGP/OSPF/RIP routing daemon. CVE-2016-4036 Tamás Németh discovered […]

Debian: 3653-1: flex: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3653-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff August 25, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : flex CVE ID : CVE-2016-6354 Debian Bug : 832768 Alexander Sulfrian discovered a buffer overflow in the yy_get_next_buffer() function generated by Flex, which may result […]

Debian: 3652-1: imagemagick: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3652-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff August 25, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : imagemagick CVE ID : CVE-2016-4562 CVE-2016-4563 CVE-2016-4564 CVE-2016-5010 CVE-2016-5687 CVE-2016-5688 CVE-2016-5689 CVE-2016-5690 CVE-2016-5691 CVE-2016-5841 CVE-2016-5842 CVE-2016-6491 Debian Bugs : 832885 832887 832888 832968 833003 832474 […]

Debian: 3651-1: rails: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3651-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso August 25, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : rails CVE ID : CVE-2016-6316 Debian Bug : 834155 Andrew Carpenter of Critical Juncture discovered a cross-site scripting vulnerability affecting Action View in rails, a […]

Update iPhone to iOS 9.3.5; Prevent this Highly Sophisticated Spyware
Mozilla launches free website security scanning service
After iOS, Opera’s Free VPN App is Available for Android Devices
Threatpost News Wrap, August 26, 2016
21st century cybercriminals: The threat landscape has evolved

��}ے�F���(AsD�”^�n�u��d�n��;+k;�@��`�M�1��/;���_0�OΗlfV@�M�i�ޕf,�@UVV�*++��ᝧoN����3��W/����p�]�ro�ӄ��� 粧��C6����4�a`���Ew5�s��Hp�� ���#���d6�N���p�=�FI�fZ1H���>��B��Q�u�w�޵�����n�~�u�j-7�m��ˡ���;K�!O4�7���P��ݜ%M��v�1

Real-life examples test whether you are prepared for a cyberattack
Apple patches iOS security flaws found in spyware targeting activist
Cisco starts patching firewall devices against NSA-linked exploit
Don’t bring your bad security habits to the cloud
Muddying the waters of infosec: Cyber upstart, investors short medical biz – then reveal bugs
HP Laptops Block Unwelcome Snoopers

Discovered: August 25, 2016 Updated: August 26, 2016 11:37:57 AM Type: Trojan Infection Length: 98,816 bytes Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Ransom.Tearhide is a Trojan horse that encrypts files on the compromised computer. Antivirus […]

Discovered: August 26, 2016 Updated: August 26, 2016 2:51:12 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Ransom.Fantom is a Trojan horse that may perform malicious activities on the compromised computer. Symantec Security Response […]

Risk Level: Very Low. Type: Trojan.

Two vulnerabilities were discovered in quagga, a BGP/OSPF/RIP routing daemon. CVE-2016-4036 Tamás Németh discovered that sensitive configuration files in /etc/quagga were world-readable despite containing sensitive information. CVE-2016-4049 Evgeny Uskov discovered that a bgpd instance handling many peers could be crashed by a malicious user when requesting a route dump. For the stable distribution (jessie), these […]

IoT manufacturer caught fixing security holes
Emergency iOS Update Patches Zero Days Used by Government Spyware
WhatsApp to share user data including phone numbers with Facebook
France, Germany Call for European Decryption Law
Update your iPhones, iPads right now – govt spy tools exploit vulns
Keystroke Recognition Uses Wi-Fi Signals To Snoop