Menu

Category Archives: Security

Articles about security

How Bugs Lead to a Better Android
Supercomputers give a glimpse of cybersecurity’s automated future
Miller, Valasek Deliver Final Car Hacking Talk
Hacking Hotel Keys and Point of Sale Systems at DEFCON

Debian: 3640-1: firefox-esr: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3640-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff August 03, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : firefox-esr CVE ID : CVE-2016-2830 CVE-2016-2836 CVE-2016-2837 CVE-2016-2838 CVE-2016-5252 CVE-2016-5254 CVE-2016-5258 CVE-2016-5259 CVE-2016-5262 CVE-2016-5263 CVE-2016-5264 CVE-2016-5265 Multiple security issues have been found in the Mozilla […]

Apple’s bug bounty program favors quality over quantity
The advanced security techniques of criminal hackers
Never Trust a Found USB Drive, Black Hat Demo Shows Why
Why some risk assessments fail

Discovered: August 4, 2016 Updated: August 5, 2016 3:38:31 PM Type: Trojan, Virus Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP SONAR.BC.CryptDrop!g4 is a heuristic detection to detect suspicious programs that might drop known […]

Social engineering tricks and why CEO fraud emails work

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Joshua Drake on Android Security Post-Stagefright

Debian: 3639-1: wordpress: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3639-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso August 03, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : wordpress CVE ID : CVE-2015-8834 CVE-2016-5832 CVE-2016-5834 CVE-2016-5835 CVE-2016-5837 CVE-2016-5838 CVE-2016-5839 Several vulnerabilities were discovered in wordpress, a web blogging tool, which could allow remote […]

How to wade through the flood of security buzzwords and hype

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Researchers Go Inside a Business Email Compromise Scam
Researchers Bypass Chip-and-Pin Protections at Black Hat
The changing economics of cybercrime

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Researchers Bypass Chip-and-Pin Protections at Black Hat

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Debian: 3638-1: curl: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3638-1 security@debian.org https://www.debian.org/security/ Alessandro Ghedini August 03, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : curl CVE ID : CVE-2016-5419 CVE-2016-5420 CVE-2016-5421 Several vulnerabilities were discovered in cURL, an URL transfer library: CVE-2016-5419 Bru Rom discovered that libcurl would attempt […]

Afraid someone is misusing your webcam?

Imagine a situation where you are working on your laptop and all of the sudden the green light next to your built-in webcam blinks for a second and immediately goes dark again. Would you just ignore it? Or would you start digging around to find out if it was something more serious? If you want […]

Risk Level: Very Low. Type: Trojan, Virus, Worm.

iOS 9.3.4 released, fixing critical security hole. Update now
Frequent password changes are the enemy of security, FTC technologist says

Risk Level: Very Low. Type: Trojan.

Big spike in card fraud in Europe

There was a notable spike in card fraud in Europe last year, with the UK the worst hit, according to new data from FICO. The tech company revealed that the UK experienced an 18% rise in card fraud over a 12-month period, resulting in losses worth approximately $118 million. The UK is clearly a big […]

Earn up to $200,000 as Apple *finally* launches a bug bounty

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Israeli security firm hacks ISIS forum, discloses future targets
Fake Prisma apps found on Google Play

Before the release of the Android version of Prisma, a popular photo transformation app, fake Prisma apps flooded the Google Play Store. ESET researchers discovered fake Prisma apps of different types, including several dangerous trojan downloaders. The Google Play security team removed them from the official Android store at ESET’s notice. Prior to that point, […]

Multiple security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors, buffer overflows and other implementation errors may lead to the execution of arbitrary code, cross-site scriping, information disclosure and bypass of the same-origin policy. For the stable distribution (jessie), these problems have been fixed in version 45.3.0esr-1~deb8u1. For the […]

An update for firefox is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: firefox security update Advisory ID: RHSA-2016:1551-01 Product: Red Hat Enterprise […]

Does dropping malicious USB sticks really work? Yes, worryingly well…

Multiple security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors, buffer overflows and other implementation errors may lead to the execution of arbitrary code, cross-site scriping, information disclosure and bypass of the same-origin policy. For the stable distribution (jessie), these problems have been fixed in version 45.3.0esr-1~deb8u1. For the […]

Password changes for the sake of it don’t improve security, says FTC technologist

Several vulnerabilities were discovered in wordpress, a web blogging tool, which could allow remote attackers to compromise a site via cross-site scripting, bypass restrictions, obtain sensitive revision-history information, or mount a denial of service. For the stable distribution (jessie), these problems have been fixed in version 4.1+dfsg-1+deb8u9. We recommend that you upgrade your wordpress packages.

Yahoo looks into major data breach claims

Yahoo is looking into claims that it has become the latest high-profile victim of a major data breach. It is thought up to 200 million accounts are affected. If found to be true, it is thought to be connected to an unknown individual who refers to himself as Peace. He has already claimed responsibility for […]

Hackers Hijack a Big Rig Truck’s Accelerator and Brakes

Several vulnerabilities were discovered in wordpress, a web blogging tool, which could allow remote attackers to compromise a site via cross-site scripting, bypass restrictions, obtain sensitive revision-history information, or mount a denial of service. For the stable distribution (jessie), these problems have been fixed in version 4.1+dfsg-1+deb8u9. We recommend that you upgrade your wordpress packages.

$61 million stolen from accounts at Bitcoin exchange Bitfinex
Apple’s lack of 2SV for Find My Phone nearly costs student his digital life

An update for ntp is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: ntp security update Advisory ID: RHSA-2016:1552-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1552.html Issue date: 2016-08-03 CVE […]

200 million Yahoo passwords being sold on the dark web?
Meet the men who spy on women through their webcams
Car hacking at speed – where vulnerabilities turn from critical to fatal

There’s a fundamental difference between criminal hackers and white hat vulnerability researchers. When a white hat finds a vulnerability they may explore it, and write an interesting presentation about what can be achieved through the flaw, but once they’ve described the security weakness to the appropriate party and the hole is closed – that’s it. […]

Several vulnerabilities were discovered in cURL, an URL transfer library: CVE-2016-5419 Bru Rom discovered that libcurl would attempt to resume a TLS session even if the client certificate had changed. CVE-2016-5420 It was discovered that libcurl did not consider client certificates when reusing TLS connections. CVE-2016-5421 Marcelo Echeverria and Fernando Muñoz discovered that libcurl was […]

Several vulnerabilities were discovered in cURL, an URL transfer library: CVE-2016-5419 Bru Rom discovered that libcurl would attempt to resume a TLS session even if the client certificate had changed. CVE-2016-5420 It was discovered that libcurl did not consider client certificates when reusing TLS connections. CVE-2016-5421 Marcelo Echeverria and Fernando Muñoz discovered that libcurl was […]

Car hacking at speed – where vulnerabilities turn from critical to fatal
Lost your iPhone? Be on guard for a perfectly-timed Apple ID phishing attack
2016 Rio Olympic Games: The safe way to obtain tickets online

This year is the year of sporting fans. Over the past few months especially, they have had the opportunity to move from one big sporting event to the next with few gaps in-between. First, just before the summer break, sports fans enjoyed a full month of football with the European Championship in France, followed by […]

Red Hat: 2016:1541-03: kernel-rt: Important Advisory Posted by Anthony Pell    An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: […]

Profiles in cryptographic courage

I recently finished reading “Hedy’s Folly” by the scholar Richard Rhodes. In it he discusses the “most beautiful woman in the world,” 1930s and ‘40s superstar Hedy Lamarr. With her composer friend George Antheil, she invented frequency hopping. Frequency hopping (or spread spectrum) is a technology that underlies the communication transport and security of almost […]

Android users to receive notifications when new devices added to account

Android users will receive push notifications on their smartphone, alerting them to a new device being added to their account, Google has announced. It said that this feature is a key component of security, complementing other features like two-step verification and single sign-on. In particular, all of these features ensure that Android users are safe […]

Advertisers could be tracking you via your battery status

Red Hat: 2016:1538-01: golang: Moderate Advisory Posted by Anthony Pell    An update for golang is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: […]

Barclays launches voice recognition technology for telephone banking

When it comes to telephone banking, Barclays is looking to lead the way by enabling voice recognition technology for all of its customers. This means that when it comes to the usual security process for this particular service, instead of typing in a password, customers will instead be verified by their voice. While the bank […]

Torrentz.eu, largest Torrent Search Engine Shuts Down; Quits Operation

Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1704 The chrome development team found and fixed various issues during internal auditing. CVE-2016-1705 The chrome development team found and fixed various issues during internal auditing. CVE-2016-1706 Pinkie Pie discovered a way to escape the Pepper Plugin API sandbox. CVE-2016-1707 xisigr discovered a URL spoofing […]

Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1704 The chrome development team found and fixed various issues during internal auditing. CVE-2016-1705 The chrome development team found and fixed various issues during internal auditing. CVE-2016-1706 Pinkie Pie discovered a way to escape the Pepper Plugin API sandbox. CVE-2016-1707 xisigr discovered a URL spoofing […]

Beware of Fake Android Prisma Apps Running Phishing, Malware Scam
Get rid of these undesirable ‘friends’ on this popular social network

Whether because they share too much, because they send links and applications that you are not interested in, because you don’t know for real who they are, or because they are too passionate about their opinions, there are some online ‘friends’ that you should keep away from. Tomorrow we will celebrate the International Day of […]

An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2016:1539-01 Product: Red […]

PoodleCorp Says it DDoSed GTA and PlayStation Servers

Emilien Gaspar discovered that collectd, a statistics collection and monitoring daemon, incorrectly processed incoming network packets. This resulted in a heap overflow, allowing a remote attacker to either cause a DoS via application crash, or potentially execute arbitrary code. Additionally, security researchers at Columbia University and the University of Virginia discovered that collectd failed to […]

Bitfinex Exchange Hacked; $70 Million Worth of Bitcoin Stolen

Emilien Gaspar discovered that collectd, a statistics collection and monitoring daemon, incorrectly processed incoming network packets. This resulted in a heap overflow, allowing a remote attacker to either cause a DoS via application crash, or potentially execute arbitrary code. Additionally, security researchers at Columbia University and the University of Virginia discovered that collectd failed to […]

The 10 Security Commandments for every SysAdmin

System administrators are responsible for the reliable operation of corporate IT resources, working around the clock to manage deployments and upgrades, as well as finding the fastest way to solve problems. Celebrating the 17th annual SysAdmin Day, we recognize their dedication and workplace contributions and want to show appreciation for their talent. However, we wondered […]

It was discovered that redis, a persistent key-value database, did not properly protect redis-cli history files: they were created by default with world-readable permissions. Users and systems administrators may want to proactively change permissions on existing ~/rediscli_history files, instead of waiting for the updated redis-cli to do so the next time it is run. For […]

PoodleCorp Shut Down Blizzard and League of Legends (NA) Servers

It was discovered that redis, a persistent key-value database, did not properly protect redis-cli history files: they were created by default with world-readable permissions. Users and systems administrators may want to proactively change permissions on existing ~/rediscli_history files, instead of waiting for the updated redis-cli to do so the next time it is run. For […]

Telegram App Hacked Again; Millions of Contacts Revealed

Two use-after-free vulnerabilities were discovered in DBD::mysql, a Perl DBI driver for the MySQL database server. A remote attacker can take advantage of these flaws to cause a denial-of-service against an application using DBD::mysql (application crash), or potentially to execute arbitrary code with the privileges of the user running the application. For the stable distribution […]

Red Hat: 2016:1532-02: kernel-rt: Important Advisory Posted by Anthony Pell    An update for kernel-rt is now available for Red Hat Enterprise MRG 2.5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: […]

Central Ohio Urology Group Hacked; 223GB of Crucial Data Leaked (Updated)
The US Submarines with Cyber Offensive Features
How many zero-day vulns is Uncle Sam sitting on? Not as many as you think, apparently
Phoenix-based Banner Health Suffers Data Breach Affecting 3.7M
Three times as bad as malware: Google shines light on pay-per-install
PLC-Blaster Worm Targets Industrial Control Systems
AdBlock Plus blocked in China: 159m forbidden from stripping adverts
How over 30 Jeeps were Hacked into and Driven Away
Researcher hides stealthy malware inside legitimate digitally signed files

There’s a lot that happens in the security world, with many stories getting lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. Banner Health Warns Patients Over Cyber Attack Recently, Banner Health has begun notifying nearly 4 […]

Gunter Ollmann on the Future of Ransomware, Exploit Kits, and IoT

Encrypting ransomware is so popular now that competitors will sabotage one another to get the upper hand. This is refreshing for victims, however, as they reap the benefit of these potential clashes between cybercriminals. ‘Chimera Ransomware’ has just had its keys leaked to the public, which is fantastic news for anyone who has been a victim […]

New Android Trojan SpyNote leaks on underground forums
ISF publishes major update to its information security guide

The Information Security Forum (ISF) has published a major update to its Standard of Good Practice for Information Security  for IT security professionals. The Standard, as it is known, is a comprehensive guide to internet security best practise, providing organizations with a ready-made framework for responding to and managing major incidents. The latest edition shows a […]

There’s a lot that happens in the security world, with many stories getting lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. Wireless Keyboards Found To Be Vulnerable To Radio Hack In a recent study, it was […]

SentinelOne’s $1m ransomware guarantee dismissed as PR stunt
WhatsApp doesn’t properly erase your deleted messages, researcher reveals
Get rid of these undesirable ‘friends’ on major social network

Either because they share too much, because they send links and applications that you are not interested in, because you don’t know for real who they are, or because they are too passionate about their opinions, there are some online ‘friends’ that you should keep away from. Tomorrow we will celebrate the International Day of […]

Android app found in Google Play store stole users’ photos, videos
Would you risk running a VPN in the United Arab Emirates?
Black Hat: 9 free security tools for defense and attacking
FBI said to investigate possible hack of another Democratic Party organization