Menu

Category Archives: Security

Articles about security

Chap fails to quash ‘shared password’ ‘hacking’ conviction
Could your selfies be held to ransom? Alleged Instagram account hacker arrested
Huawei learns photo meta-data can bite you in the bum
PlayStation, Facebook block users due to ‘offensive’ first names
EasyDoc malware adds Tor backdoor to Macs for botnet control
Get FREE threat intelligence on hackers and exploits with the Recorded Future Cyber Daily
Symantec bugfest highlights the dangers of security software
Encryption Bypass Vulnerability Impacts Half of Android Devices
The Changing Face of Pseudo-Darkleech
FBI faults Clinton’s personal email system, but doesn’t recommend prosecution
Mozilla’s Servo is an early step to making Firefox more secure
Chinese Ad Firm Raking in $300K a Month Through Adfraud, Android Malware

Risk Level: Very Low. Type: Trojan.

What is a computer virus? Think of a biological virus – the kind that makes you sick. It’s persistently nasty, keeps you from functioning normally and often requires something powerful to get rid of it. A computer virus is very similar. Designed to relentlessly replicate, these threats infect your programs and files, alter the way your […]

Scope of ThinkPwn UEFI Zero Day Expands
Chicago man pleads guilty in celebrity iCloud data breach

��}�r۸���j�a� ��H��_�#�:Nr&g�gf�&YDBm���ò&���g�j���V��}��$� ��$˲���MΙ�”�F���h4�Gw��9>���3��髗�����Cꎺ s�O�lh_vot@�Q��7�� 3��u�

Lenovo ThinkPwn UEFI exploit also affects products from other vendors
EU uncorks €1.8bn in cybersecurity investment. Thirsty, UK?
Data leak dangers: Know your weak spots

From customer credit card details that ease the flow at online checkouts to employee records that are vital to HR departments, today’s businesses are built on sensitive data. In many ways, it’s the lifeblood that makes the modern company tick. If experience is anything to go by, though, it can also feel like the next […]

10 cutting-edge tools that take endpoint security to a new level
7 trends in advanced endpoint protection
11 signs your kid is hacking — and what to do about it
5 years, 2,300 data breaches. What’ll police do with our Internet Connection Records?
Fembots land Ashley Madison in hot water with the FTC
Theft of twenty-somethings’ IDs surges
Second celebgate hacker pleads guilty to phishing
Word hole patched in 2012 is ‘unchallenged’ king of Office exploits
Researcher pops locks on keylogger, finds admin’s email inbox
Israel’s security minister suckers Zucker for Facebook’ed killings
Vuln drains energy sector control kit

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Another Popular YouTube Channel ‘LeafyIsHere’ Hacked; Defaced
Lizard Squad Taking Over CCTV Devices to Conduct DDoS Attacks
Hackers should beware bogus UPS couriers bearing handcuffs…
The security review: How secure are our cash machines?

Welcome to this week’s security review, including a closer look at cash machine security on the 49-year anniversary of the ATM. Also this week, we looked at how to stay safe from malicious scripts and how to avoid data leaks by plugging the holes in your organization’s defenses. ATMs turn 49: How secure are our cash machines? […]

Mozilla emits nightly builds of heir-to-Firefox browser engine Servo
Why CIOs should care about click fraud
The tech support scam king. 135 tech scam domains registered to one person
How to rid your new PC of pre-installed junk, once and for all
Klepto Zepto could steal millions in looming ransomware wave
One in 200 enterprise handsets is infected
SQLite developers need to push the patch
Here’s how to SMS spam Liberal voters and get away with it
Lenovo scrambling to get a fix for BIOS vuln

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. CVE-2014-9904 It was discovered that the snd_compress_check_input function used in the ALSA subsystem does not properly check for an integer overflow, allowing a local user to cause a denial of service. CVE-2016-5728 Pengfei […]

Shmuel H discovered that GIMP, the GNU Image Manipulation Program, is prone to a use-after-free vulnerability in the channel and layer properties parsing process when loading a XCF file. An attacker can take advantage of this flaw to potentially execute arbitrary code with the privileges of the user running GIMP if a specially crafted XCF […]

Watch 2 Chinese Installing ATM Skimmer in a Pakistani Bank
Internet Bot Exposes 20 Million MTN Irancell Users’ Data
11 ways to fight off ransomware

Vivian Zhang and Christoph Anton Mitterer discovered that setting an empty VNC password does not work as documented in Libvirt, a virtualisation abstraction library. When the password on a VNC server is set to the empty string, authentication on the VNC server will be disabled, allowing any user to connect, despite the documentation declaring that […]

The TERASOLUNA Framework Development Team discovered a denial of service vulnerability in Apache Commons FileUpload, a package to make it easy to add robust, high-performance, file upload capability to servlets and web applications. A remote attacker can take advantage of this flaw by sending file upload requests that cause the HTTP server using the Apache […]

Multiple vulnerabilities were discovered in the dissectors/parsers for PKTC, IAX2, GSM CBCH and NCP, SPOOLS, IEEE 802.11, UMTS FP, USB, Toshiba, CoSine, NetScreen, WBXML which could result in denial of service or potentially the execution of arbitrary code. For the stable distribution (jessie), these problems have been fixed in version 1.12.1+g01b65bf-4+deb8u7. For the testing distribution […]

There’s a lot that happens in the security world, with many stories getting lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. Hard Rock Las Vegas Confirms Credit Card Breach Recently, the Hard Rock Cafe in Las […]

Locky Variant Zepto Debuts with Big Spam Push
Dating Website “Muslim Match” Hacked; Everything Leaked Online
Firmware exploit can defeat new Windows security features on Lenovo ThinkPads
Oculus chief latest social media hack victim
Siemens Patches Password Reconstruction Vulnerability in SICAM PAS
How to secure your social media accounts

Courtesy of Facebook, Twitter, Instagram and Snapchat – to name but a few – we are increasingly living digital lives, where we interact and engage with our friends and family online. Social media has, without a shadow of a doubt, become central to our way of life. And yet, while millions use these platforms on a […]

<div>Hard Rock Hotel & Casino Las Vegas experiences data breach</div>

��}�r۸���j�a� ��H��_�#�$Nr&��kǞ���d] It(��˞���kl��Cl�>���’�n��ɲ�d2w�s&�H��ht7�F�ᝧo�}��p�����’��#��}���OG #6r��Z0�’�$ �-+��Y~|W�:�Nu����p�ʋ��=�k���0?1�/B�[��k ;O,l���(fI?MFƞF�A=��j���8�!Mܡ��z�Ϝ1+V���3��� J��3�I&}���63�q}7q�g�6�X�Sic���0�E�ȵ��W �����f�G��(��^u�:�uF�ã÷�m��/�?����Ǻ����&�lw���vw�{��vv�۝��v��{����Γǝ��E����G1���Ʌ�� c@��/�nDZF��qi_#ׇ��&�x6��3�g,fv�ɅiSk)+��)�-�ΡY�!��29t�=����;�A�’nL�x� �ĝ��3���dB1�an?L��c�h��#�!H�G��ix@i��yIc�3���M�I��RP�I���b X`��>�05p��M��n�V�n��c�w���1″�a�3z��!��p�$��(�2��x/@qP���T �|�(qm�-,�C��ِ/j�/5��F���{���_y -�#�dm]9��W���,^Z%L����9�6��2�;F��qgk��~�w���o����h�E�v�v��lm�w�A�Q)��;�c��X*�6 ��:q>�I$���p��%]*5a�>��V�N�4����K ʂ>lX�,hCi��ő[H�`J]�,-��Yxf�@Ǔ ��w8�[�׀� 9z�^:v}���h�FR͍SzF�[m%n�� f��,d���=bI�����’mHc�h�}��x���ފ͙D��’F�޲����x���n�|����Z����Ï8H#�i�4� �j��ˡ֓�=���m/u��Ә�� ���gN����#��[���./�_wF�ϕ^���-��)�M�m~:��[N��F�ɉ͞yy����}�]'{�f��E-d���z��Ʈl͹��3��؝����t �ۖm����֡e8��~o9;�}���eο,��*�J�n�f�}ڲ�z�o �eY/~rqLǯA�44AjMh٤a�|�p�zN�n^b��ָ5i�� j���QD/A[�9[s:�ƂQ4�4��_�����E2�ٿ�n�=;�Y�

Not using Adobe’s PDF reader doesn’t mean you’re avoiding PDF malware
Study reveals security gap in big data projects
How a hacker stole a Facebook user’s account with just a fake passport
UEFA’s Euro 2016 app is airing football fans’ privates in public
700,000 Muslim Match dating site private messages leaked online
11 essential data security tips for travelers

I travel all over the world for my job, and for my hobbies. Although there are still plenty of places I haven’t been, I’ve visited enough foreign countries that I don’t deny it when someone calls me a world traveler. Over the years, I’ve experienced my fair share of foreign spying. I know what it’s […]

Attackers rely on legit IT tools to carry out their plans
Chinese gambling site served near record-breaking complex DDoS
Cracking Android’s full-disk encryption is easy on millions of phones – with a little patience
Hydra hacker bot spawns internet of things DDoS clones
400 million Foxit users need to catch up with patched-up reader

Risk Level: Very Low. Type: Trojan.

LizardStresser IoT Botnet Part of 400Gbps DDoS Attacks
WA government still hopeless at infosec
Turkish Hacker Defaces Arizona State Representatives and Legislature Sites
Russia, China fight UN effort to extend human rights onto the internet
Massachusetts General Hospital Confirms Third-Party Breach

Brandon Perry discovered that xerces-c, a validating XML parser library for C++, fails to successfully parse a DTD that is deeply nested, causing a stack overflow. A remote unauthenticated attacker can take advantage of this flaw to cause a denial of service against applications using the xerces-c library. Additionally this update includes an enhancement to […]

Multiple security vulnerabilities have been discovered in the Tomcat servlet and JSP engine, which may result in information disclosure, the bypass of CSRF protections, bypass of the SecurityManager or denial of service. For the stable distribution (jessie), these problems have been fixed in version 8.0.14-1+deb8u2. For the unstable distribution (sid), these problems have been fixed […]

Aleksandar Nikolic discovered that missing input sanitising in the RTF parser in Libreoffice may result in the execution of arbitrary code if a malformed documented is opened. For the stable distribution (jessie), this problem has been fixed in version 1:4.3.3-2+deb8u5. For the testing distribution (stretch), this problem has been fixed in version 1:5.1.4~rc1-1. For the […]

Encryption, wiretaps and the Feds: THE TRUTH
Some social engineering skills and Facebook will gift your account to hackers

Debian: 3611-1: libcommons-fileupload-java: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3611-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 30, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libcommons-fileupload-java CVE ID : CVE-2016-3092 The TERASOLUNA Framework Development Team discovered a denial of service vulnerability in Apache Commons FileUpload, a package to make it […]

Ubuntu: 3022-1: LibreOffice vulnerability Posted by Anthony Pell    LibreOffice could be made to crash or run programs as your login if itopened a specially crafted file. ========================================================================== Ubuntu Security Notice USN-3022-1 June 29, 2016 libreoffice vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu […]

Debian: 3610-1: xerces-c: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3610-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 29, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : xerces-c CVE ID : CVE-2016-4463 Debian Bug : 828990 Brandon Perry discovered that xerces-c, a validating XML parser library for C++, fails to successfully parse […]

Debian: 3609-1: tomcat8: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3609-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 29, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : tomcat8 CVE ID : CVE-2015-5174 CVE-2015-5345 CVE-2015-5346 CVE-2015-5351 CVE-2016-0706 CVE-2016-0714 CVE-2016-0763 CVE-2016-3092 Multiple security vulnerabilities have been discovered in the Tomcat servlet and JSP engine, […]

Debian: 3608-1: libreoffice: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3608-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 29, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libreoffice CVE ID : CVE-2016-4324 Aleksandar Nikolic discovered that missing input sanitising in the RTF parser in Libreoffice may result in the execution of arbitrary […]

Foxit Patches 12 Vulnerabilities in PDF Reader

Risk Level: Very Low. Type: Trojan.

Conficker Used in New Wave of Hospital IoT Device Attacks
LizardStresser recruits an army of zombie webcams to launch DDoS attacks
Hackers: Ditch the malware, we’re in… Just act like a normal network admin. *Whistles*
Security Sessions: Is hospital security on life support?
Muslim Match dating site hacked. Private messages and profiles posted online
Fight back! Learn to hunt threats with free tools