Menu

Category Archives: Security

Articles about security

Security software that uses ‘code hooking’ opens the door to hackers
Hacker Steals Amazon Marketplace Credentials from 3rd Party Server
Apple fixes FaceTime eavesdropping bug, other other flaws may remain
Your antivirus doesn’t like Ammyy. And fraudsters will use that to RAT you out (again)
Malicious scripts gaining prevalence in Brazil

Had we looked at a map of malware detections in Brazil a year ago, we would have seen that the two main computer threats were the downloaders that installed banking trojans, and the banking trojans themselves. Today the situation remains the same, but with an extra special ingredient – while threats used to be Windows .exe […]

Apple Fixes Vulnerabilities Across OS X, iOS, Safari
Neutrino exploit kit adds former IE zero-day flaw to its arsenal
IBM grows in cloud and data analytics but overall revenue slides
Sandia Labs Researchers Build DNA-Based Encrypted Storage
Flaw in vBulletin add-on leads to Ubuntu Forums database breach
Ubuntu Forums hack exposes 2 million users
Passwords not compromised by Ubuntu Forums data breach

A major data breach on the Ubuntu Forums has not compromised the passwords of its affected users. In an update to its announcement that an incident had taken place, its developer Canonical Ltd was keen to highlight that this information was not accessed. However, as Jane Silber, CEO of Canonical Ltd, revealed, usernames, emails addresses […]

4 basic security facts everyone should know

Today, almost all hacking is done by professional criminals. In many countries, illegal hacking accounts for more crime, dollar-wise, than noncomputer crime. The United Kingdom recently joined that club. Why is this important? First, if you find malware on your system, there’s a good chance it’s trying to steal your money. Second, no one is […]

MacKeeper threatens to sue 14-year-old YouTuber
Governments Googling Google about you more than ever says Google
Maxthon web browser blabs about your PC all the way back to Beijing
Guilt by ASN: Compiler’s bad memory bug could sting mobes, cell towers
World-Check terror suspect DB hits the web at just US$6750
Hardball hacker thrown in the cooler for 46 months for guessing rival team’s password
Alpine County Superior Court, CA Website Hacked Against Trump and Racism
For $800 you can buy internet engineers’ answer to US government spying
CGI Script Vulnerability ‘Httpoxy’ Allows Man-in-the-Middle Attacks

Gentoo: 201607-07 Chromium: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in the Chromium web browser, the worst of which allows remote attackers to execute arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201607-06 CUPS: Buffer overflow Posted by Anthony Pell    A buffer overflow in CUPS might allow remote attackers to execute arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201607-05 Cacti: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in Cacti, the worst of which could lead to the remote execution of arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201607-04 GD: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in GD, the worst of which allows remote attackers to execute arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Debian: 3620-1: pidgin: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3620-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 15, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : pidgin CVE ID : CVE-2016-2365 CVE-2016-2366 CVE-2016-2367 CVE-2016-2368 CVE-2016-2369 CVE-2016-2370 CVE-2016-2371 CVE-2016-2372 CVE-2016-2373 CVE-2016-2374 CVE-2016-2375 CVE-2016-2376 CVE-2016-2377 CVE-2016-2378 CVE-2016-2380 CVE-2016-4323 Yves Younan of Cisco Talos […]

Debian: 3619-1: libgd2: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3619-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 15, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libgd2 CVE ID : CVE-2016-5116 CVE-2016-5766 CVE-2016-6128 CVE-2016-6132 CVE-2016-6161 CVE-2016-6214 Debian Bug : 829014 829062 829694 Several vulnerabilities were discovered in libgd2, a library for […]

Researchers Crack Furtim, SFG Malware Connection
Two Million Passwords Breached in Ubuntu Hack
Pokémon GO goes down. Hackers claim responsibility
Adobe cockup means you may have two different versions of Flash installed on your PC
A smarter approach to password security ‘needed’

��}�r�Ʋ�o�*�0��5Ș�K&}d�>�9�㍜�͵��!0$!��Q��������j�j��ϭ�’��M�$�=3�E��h�ٲ�H$0��������3��Γ�����)�����on?�DS�8���j?�(��Ⱦ�)��L��?0o��Sf��]��z8a��߂O���SQ^Tcb�{n��H{3�BL�D�”2��CsB��E�8i� 1��p����v�M}�C’�����,_եS�S�m6� ʔ��V4�Y��6�ƿ4��ڑM-4��z�*Hc�;L�i�,�G� �xn�`ئ��:�%�{����Ģ�5z���q�^��o��1��©�y����۷,;�:?��rF��@�����k�ͅN(�U�v���$: -6Ϳ�ޙ��`�)r@�Do�_�E�n��C!�����0?�*||�%�?����C��Ȯ�Յ�E%��S=�v�S�}�Ln �J�*^]ۮ�Vh����)�s�Pε,|#�����-LU���*�>*�J��{���������̠90��y1���z��h�)i�o{�>�4�%i�h�*���pۘK/��F4v������|`E���7D}��BLQm�{͛`���L@�]f{d4���n���Eu��,�>�J_���Q@��`�n�$_�n �u�9H��=��5�’�� 5-}���fg�p;� v�����[2���= �Ƃ��iځ ���n�Y4�=�#:t��jRQo����j帷s5�YוZX��W�W���ӄ;&�.���j���0�?m����y�q[����: ULt���c�;�z�|6`y�Y���aP��?C]�#NC� l�P’b�K�y+V6���Wk`���a��’oE�1Zz��Ł�ê��9��3�W

Firefighting, security and compliance

��}�v9��}N�L�d����fɔǖ�.��%W��:`&H��Ld�E˥s�q�w_v��u��?�/و��$E�tu�Ue���@D “�y����_�>c߾{����’��e.�ƃ���Ok��ȹ���M��?l���7���wkP��É���-�D�NEĩ�!~���A�Dz��”���5f�o�Z$.�66xdMx�hG#�����p����c�DN}9C7�ų��ǢX��S1�]8b�� ʕ�9v4��±�A_Z����Z��n���cW� �B�ȱ�� � {��g��d﹯zOm.������[���m����V�^��4��c�H��n�ɳ����㝽���n��|o����O”��X�� T���=K ��{Q� ㈅�6u”�/�� fK�D���Zp�����y����t�ڝ�v�G�H �m$�&�H_ќDו��9�����tTTD�劥�qr���e�~�÷�8ps8~�AD�9C.ϵ�`/�-�P����CG�p5�#n�����S~������Ǫr�2tcɐ����C��d��:�w�et�����a�s�ݹ��v:+�M� Z�Zh��^o4Y����q�|,�摜v�}Wr;L�f2���͏�8ז�x��H��ȵ��)�%������4�`(E9X�X���S�x�oI�/��8 ���֎�ĭ���rf��|1��S�H�l�>Ն

Tech leaders challenged daily to sort through a crush of new security apps
UKFast owner slurps app security biz Pentest
Euro IP study finds 25 Tor-and-Bitcoin-loving pirate business models
World’s worst exploit kit weaponises white hats’ proof of concept code
Tor veteran Lucky Green exits, torpedos critical ‘Tonga’ node and relays
Security firm clarifies power-station ‘SCADA’ malware claim
Intel’s SGX tiptoes towards Linux
Extortion trojan watches until crims find you doing something dodgy
Hacker Selling Entire US Voters’ Registration Records on Dark Net
OpenSSH has user enumeration bug
Matrimonial Matching Site Shadi.com Hacked; Data Dumped Online
Hackers Selling Terrorist Database on Dark Web, Claiming its ‘Proven Legit’
Android banking malware stops you calling customer service to cancel your cards
How you could steal money from Instagram, Microsoft and Google with help from a premium rate phone number

Yves Younan of Cisco Talos discovered several vulnerabilities in the MXit protocol support in pidgin, a multi-protocol instant messaging client. A remote attacker can take advantage of these flaws to cause a denial of service (application crash), overwrite files, information disclosure, or potentially to execute arbitrary code. For the stable distribution (jessie), these problems have […]

Several vulnerabilities were discovered in libgd2, a library for programmatic graphics creation and manipulation. A remote attacker can take advantage of these flaws to cause a denial-of-service against an application using the libgd2 library (application crash), or potentially to execute arbitrary code with the privileges of the user running the application. For the stable distribution […]

Ubuntu Forums hacked (again)
Ubuntu Forums Suffer Data breach; Credit Goes to SQL Flaw
Samsung spills beans on mystery username, password emails to devs

HSBC Sites Downed Briefly After Cyber Attack Earlier this week, it was reported that HSBC had been the victim of a cyber attack and both it’s US and UK sites had been taken offline. The messages remaining on both sites announced that an organization called OurMine had found a vulnerability and would only stop the […]

HSBC Website Suffers DDoS Attack

Several vulnerabilities were found in PHP, a general-purpose scripting language commonly used for web application development. The vulnerabilities are addressed by upgrading PHP to the new upstream version 5.6.23, which includes additional bug fixes. Please refer to the upstream changelog for more information: https://php.net/ChangeLog-5.php#5.6.23 For the stable distribution (jessie), these problems have been fixed in […]

Juniper Crypto Bug Let Attackers Eavesdrop on Router, Switch Traffic
Patched IE Zero Day Incorporated into Neutrino EK
McCain: Come to my encryption hearing. Tim Cook: No, I’m good. McCain: I hate you, I hate you, I hate you
Since you love Flash so much, Adobe now has TWO versions for you
Hackers steal millions from ATMs using ‘just their smartphones’
$29.99 for the IT Security & Ethical Hacking Certification Training ($1,895 value) – Deal Alert

Ubuntu: 3037-1: Linux kernel (Vivid HWE) vulnerability Posted by Anthony Pell    The system could be made to crash under certain conditions. ========================================================================== Ubuntu Security Notice USN-3037-1 July 14, 2016 linux-lts-vivid vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: The system could be made to […]

Ubuntu: 3035-3: Linux kernel (Wily HWE) vulnerability Posted by Anthony Pell    The system could be made to crash under certain conditions. ========================================================================== Ubuntu Security Notice USN-3035-3 July 14, 2016 linux-lts-wily vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: The system could be made to […]

Ubuntu: 3035-2: Linux kernel (Raspberry Pi 2) vulnerability Posted by Anthony Pell    The system could be made to crash under certain conditions. ========================================================================== Ubuntu Security Notice USN-3035-2 July 14, 2016 linux-raspi2 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 Summary: The system could be made to […]

Ubuntu: 3034-1: Linux kernel vulnerability Posted by Anthony Pell    The system could be made to crash under certain conditions. ========================================================================== Ubuntu Security Notice USN-3034-1 July 14, 2016 linux vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: The system could be made to crash under […]

Debian: 3618-1: php5: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3618-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff July 14, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : php5 CVE ID : CVE-2016-5768 CVE-2016-5769 CVE-2016-5770 CVE-2016-5771 CVE-2016-5772 CVE-2016-5773 Several vulnerabilities were found in PHP, a general-purpose scripting language commonly used for web application […]

Red Hat: 2016:1427-01: atomic-openshift: Important Advisory Posted by Anthony Pell    An update for atomic-openshift is now available for Red Hat OpenShift Enterprise 3.2. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: atomic-openshift security and bug fix update Advisory ID: RHSA-2016:1427-01 Product: […]

Ubuntu: 3032-1: eCryptfs vulnerability Posted by Anthony Pell    eCryptfs could be made to expose sensitive information. ========================================================================== Ubuntu Security Notice USN-3032-1 July 14, 2016 ecryptfs-utils vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 Summary: eCryptfs could be made to expose sensitive information. […]

Scan Reveals Hydropower Plants, Other Critical Infrastructure Exposed Online

Discovered: July 14, 2016 Updated: July 14, 2016 7:02:14 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Infostealer.Spyolog is a Trojan horse that opens a back door, steals information, and downloads […]

Threatpost News Wrap, July 15, 2016
Cisco patches serious flaws in router and conferencing server software
Silently clicking on porn ads you can’t even see – this could be you…
This Android Trojan blocks the victim from alerting banks
BAE Systems partners with SWIFT to bolster hacker intel
Tor shakes up exec board following Appelbaum withdrawal
The makings of a man-in-the-middle attack
Persistent XSS flaws patched in multiple WordPress plugins
MIT researchers unveil new anonymity scheme that could rival Tor
Cisco gives you two nasty bugs to fix before the weekend
Bank boffins drop slick incident response tool for Mandiant mobs
Google’s Nexii stand tall among Android’s insecure swill
Chinese hacker jailed for shipping aerospace secrets home
Microsoft silently kills dev backdoor that boots Linux on locked-down Windows RT slabs

Risk Level: Very Low. Type: Trojan.

Discovered: July 15, 2016 Updated: July 15, 2016 2:10:36 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows NT, Windows Vista, Windows XP Trojan.Ransomcrypt.BB is a Trojan horse that encrypts files on the compromised computer and asks for payment to decrypt the files. Antivirus Protection […]

Hackers Selling FUD Stampado Ransomware for Just $39
Thermostat biz Nest warms to home security, touts cam with cloud storage subscription
New Locky ransomware version can operate in offline mode
Digital Rights Advocates Call for Investigation Around W3C’s DRM Extension

Red Hat: 2016:1425-01: rh-nginx18-nginx: Moderate Advisory Posted by Anthony Pell    An update for rh-nginx18-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: rh-nginx18-nginx security update Advisory ID: RHSA-2016:1425-01 Product: Red Hat Software Collections […]

An update for flash-plugin is now available for Red Hat Enterprise Linux 5 Supplementary and Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2016:1423-01 Product: Red Hat Enterprise Linux Supplementary Advisory […]

Gentoo: 201607-03 Adobe Flash Player: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – […]

Updated kernel packages that fix one security issue and several bugs are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Important security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2016:1406-01 Product: Red Hat Enterprise Linux Advisory […]

Updated kernel packages that fix one security issue and several bugs are now available for Red Hat Enterprise Linux 7 Extended Update Support. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: kernel security and bug fix update Advisory ID: RHSA-2016:1395-01 Product: Red Hat […]

Cisco Patches DoS Flaw in NCS 6000 Routers
What’s hot at Cisco Live
Academics Build Early-Warning Ransomware Detection System
Dirt Cheap Stampado Ransomware Sells on Dark Web for $39