Menu

Category Archives: Security

Articles about security

Cerber ransomware earns $2.3M with 0.3% response rate
Galaxy Note 7 catches the eye and more
New Point-of-Sale Malware Campaign hits 20 Hotels in US
VeraCrypt security audit: Four PGP-encoded emails VANISH
Credit-card stealing malware hits Hyatt, Marriott, Sheraton hotel chains
Why security is a transversal issue for video games development

How many times in the field of software development have we heard that safety must be considered from the outset to the release – and subsequent maintenance – of the app or program in question? Hundreds, right? Fortunately, developers have understood this fundamental concept for programming, especially those who write code for operating systems or […]

The World Series of Hacking-without humans
A New Wireless Hack Can Unlock 100 Million Volkswagens
How 3 fintech startups are shaking up security
6 security advances worth celebrating

In the spirit of the Olympics, it’s time to celebrate our hard-won computer security defense advancements. Given the endless stream of news about embarrassing hacks and data breaches, I can see why you might be skeptical. The fact is tens of millions of computers are currently exploited, nearly every company is owned, and those that […]

A simple way to kill off Twitter trolls
China launches quantum satellite to test spooky action at a distance
White hat pops Windows User Account Control with log viewer data
Brisbane council loses $500k to scammers
Researchers crack homomorphic encryption

Discovered: August 16, 2016 Updated: August 16, 2016 3:24:49 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Antivirus Protection Dates Initial Rapid Release version August 16, 2016 revision 007 Latest Rapid […]

Shadow Broker hacking group auctions off claimed NSA online spy tools
TCP Flaw in Linux Extends to 80 Percent of Android Devices
Hackers Claim Stealing NSA Hacking Tools; Selling Them Online
Latest Windows UAC Bypass Permits Code Execution
Google AdSense abused to distribute Android spyware

Debian: 3648-1: wireshark: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3648-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff August 12, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : wireshark CVE ID : CVE-2016-6504 CVE-2016-6505 CVE-2016-6506 CVE-2016-6507 CVE-2016-6508 CVE-2016-6509 CVE-2016-6510 CVE-2016-6511 Multiple vulnerabilities were discovered in the dissectors for NDS, PacketBB, WSP, MMSE, RLC, […]

Red Hat: 2016:1613-01: php: Moderate Advisory Posted by Anthony Pell    An update for php is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: […]

Red Hat: 2016:1610-01: php54-php: Moderate Advisory Posted by Anthony Pell    An update for php54-php is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: […]

Red Hat: 2016:1612-01: rh-php56-php: Moderate Advisory Posted by Anthony Pell    An update for rh-php56-php is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: rh-php56-php security update Advisory ID: RHSA-2016:1612-01 Product: Red Hat Software Collections […]

Red Hat: 2016:1606-01: qemu-kvm: Moderate Advisory Posted by Anthony Pell    An update for qemu-kvm is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: […]

Red Hat: 2016:1611-01: php55-php: Moderate Advisory Posted by Anthony Pell    An update for php55-php is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: […]

Red Hat: 2016:1609-01: php: Moderate Advisory Posted by Anthony Pell    An update for php is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: […]

Debian: 3647-1: icedove: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3647-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff August 11, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : icedove CVE ID : CVE-2016-2818 Multiple security issues have been found in Icedove, Debian’s version of the Mozilla Thunderbird mail client: Multiple memory safety errors […]

Red Hat: 2016:1605-01: Red Hat OpenShift Enterprise: Moderate Advisory Posted by Anthony Pell    An update is now available for Red Hat OpenShift Enterprise 3.1 and Red Hat OpenShift Enterprise 3.2. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat OpenShift […]

Red Hat: 2016:1603-01: mariadb55-mariadb: Important Advisory Posted by Anthony Pell    An update for mariadb55-mariadb is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: mariadb55-mariadb security update Advisory ID: RHSA-2016:1603-01 Product: Red Hat Software Collections […]

An update for mariadb is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: mariadb security update Advisory ID: RHSA-2016:1602-01 Product: Red Hat Enterprise Linux […]

Red Hat: 2016:1604-01: rh-mariadb100-mariadb: Important Advisory Posted by Anthony Pell    An update for rh-mariadb100-mariadb is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: rh-mariadb100-mariadb security update Advisory ID: RHSA-2016:1604-01 Product: Red Hat Software Collections […]

Trojan.Ransomcrypt.BG is a Trojan horse that encrypts files on the compromised computer and asks for payment to decrypt the files. Symantec Security Response is currently investigating this threat and will post more information as it becomes available.

Westin, Marriott, Sheraton Hotels Hit By Payment Card Malware
Pokémon Go Exploitation Saga Continues; Beware of New Ransomware
Christians Against Poverty pleads for forgiveness over data breach
Cisco security crew uncovers bug in industrial control kit
Tor users in the States were hacked by Australian authorities
Blogger turns tables on cyber-scammer by infecting them with ransomware
Facebook VP Adam Mosseri’s Twitter Account Hacked by OurMine
Organizations can learn from Apple’s bug bounty approach
Machine learning offers new hope against cyber attacks
U.S. intelligence to share supply chain threat reports with industry
Someone seems to be trying to spy on VeraCrypt’s security audit
Respect: Windows 10 security impresses hackers
IT snafu takes down Action Fraud’s web crime reporting form
QuadRooter: Unfortunately, you can’t have it patched for now

Soon after the discovery of the QuadRooter vulnerability, a remedy appeared on the Google Play app store. Unfortunately, neither of the two apps named “Fix Patch QuadRooter” by Kiwiapps Ltd. would patch the Android system. Already pulled from Google Play on ESET’s notice, these apps were malicious, serving their victims with unwanted ads. On top […]

Pen-test trio crafts ‘Datasploit’ tool for easy social engineering
Russian sports doping whistleblower fears for safety after hack
POS malware stings 20 US hotels
Air gap breached by disk drive noise
Forensics tool nabs data from Signal, Telegram, WhatsApp
Accountancy software firm Sage breached in apparent insider attack

Discovered: August 15, 2016 Updated: August 15, 2016 1:41:02 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows NT, Windows Vista, Windows XP Antivirus Protection Dates Initial Rapid Release version August 15, 2016 revision 007 Latest Rapid Release version August 15, 2016 revision 007 Initial […]

Discovered: August 15, 2016 Updated: August 15, 2016 1:31:54 PM Type: Trojan Infection Length: 274,432 bytes Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Zombrari is a Trojan horse that modifies the primary DNS server settings on […]

Russian Olympics whistleblower Yuliya Stepanova hacked after Wada Breach

Multiple vulnerabilities were discovered in the dissectors for NDS, PacketBB, WSP, MMSE, RLC, LDSS, RLC and OpenFlow, which could result in denial of service or the execution of arbitrary code. For the stable distribution (jessie), these problems have been fixed in version 1.12.1+g01b65bf-4+deb8u8. For the testing distribution (stretch), these problems have been fixed in version […]

Multiple security issues have been found in Icedove, Debian’s version of the Mozilla Thunderbird mail client: Multiple memory safety errors may lead to the execution of arbitrary code or denial of service. For the stable distribution (jessie), this problem has been fixed in version 1:45.2.0-1~deb8u1. For the testing distribution (stretch), this problem has been fixed […]

Hackers take over security camera; live stream girls’ bedroom on Internet
KickassTorrents’ ‘mirror’ Kat.am; stealing users’ credit card data
Guccifer 2.0 drops private data of more than 200 Democratic Party Members
A Russian cyber-gang, the Oracle MICROS hack, and five more POS makers in crims’ sights
EU Struggles to Determine Growing Cost of Cyberattacks
New Linux Malware Installs Bitcoin Mining Software on Infected Device
DIY bank account raiding trojan kit touted in dark web dive bars
Undocumented SNMP String Exposes Rockwell PLCs to Remote Attacks
Academics Devise New Way to Steal Data from Air-Gapped Computers
World Anti-Doping Agency Site Hacked; Thousands of Accounts Leaked
How to protect yourself from mobile ID theft
How do you securely exchange encrypted-decrypted-recrypted data? Ask Microsoft
Key Fob Hack Allows Attackers To Unlock Millions Of Cars
Millions of Volkswagens can be broken into with a wireless hack
EU-US Privacy Shield launches: Key points to this agreement

There has been a lot riding on this divisive and complicated agreement, which is why it has taken over two and a half years for all the involved parties to iron out all the details. As of July 12th, the new framework was officially adopted and put into effect. The EU-US Privacy Shield, as it […]

AWS to enterprises: Bring your own encryption
Video jacking – hopefully not coming to a phone charging point near you
Hacked Instagram accounts seducing users with adult dating spam
Meet DDoSCoin, the cryptocurrency that pays when you p0wn
Boffins’ blur-busting face recognition can ID you with one bad photo
SMS Privacy Given Final Nail in the Coffin by Canadian Court Ruling
Instagram Accounts Getting Hacked; Spreading Adult Content

Risk High Date Discovered August 9, 2016 Description Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability due to a use-after-free error. Specifically, this issue occur within the ‘CAnchor’ object. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue […]

Risk High Date Discovered August 9, 2016 Description Microsoft Windows is prone to a local privilege-escalation vulnerability that occurs in the Windows kernel. A local attacker can exploit this issue to execute arbitrary code in kernel mode with elevated privileges. Technologies Affected Microsoft Windows 10 Version 1607 for 32-bit Systems Microsoft Windows 10 Version 1607 […]

New Gmail Alerts Warn of Unauthenticated Senders
Why Anonymous Should Spy on ISIS Forums Rather than DDoSing Them
Thieves can wirelessly unlock up to 100 million Volkswagens, each at the press of a button
Microsoft Mistakenly Leaks Secure Boot Key
Bluetooth Hack Leaves Many Smart Locks, IoT Devices Vulnerable
Google Says ‘a bug’ removed West Bank and Gaza from the map
Imperva under pressure to find buyer after disappointing results
A new $500,000 iOS bug bounty beats Apple’s offer
Found an iOS zero-day? This firm will pay you $300,000 more than Apple
Developers need secure coding environments
Secure Boot proves insecurity of backdoors
Want secure code? Give devs the right tools
QuadRooter vulnerabilities leaves 900 million Android devices at risk of attack

Over 900 million Android smartphones and tablets are vulnerable to cyberattacks, as they contain a set of four vulnerabilities dubbed QuadRooter. These flaws were found in devices that use Qualcomm chipsets, Check Point revealed at this year’s DEF CON 24 Hacking Conference in Las Vegas. It stated that if any of the four vulnerabilities are […]

Hilton hotels’ email so much like phishing it fooled its own techies
Almost all cars sold by VW Group since 1995 at risk from unlock hack
Linux malware? That’ll never happen. Ok, just this once then
McAfee outs malware dev firm with scores of Download.com installs