Menu

Category Archives: Security

Articles about security

Where’s the macro? Malware authors are now using OLE embedding to deliver malicious files »
Cisco Won’t Patch Critical RV Wireless Router Vulnerability Until Q3
Why your password policy still sucks
Smut shaming: Anonymous fights Islamic State… with porn
Like Macros Before It, Attackers Shifting to OLE to Spread Malware
5 Ways to Defuse Data Threat from Departing Employees
Companies pay out billions to fake-CEO email scams
Hack the hackers: Eavesdrop for intel on emerging threats
Dodgy creds found in Siemens ICS gear
Microsoft planning blockchain-as-a-service for Azure apps
Password reset: 45 million creds leak from popular .com forums
SOHOpeless Cisco wireless kit needs critical patch
Microsoft releases open source bug-bomb in the rambling house of C

Risk Level: Very Low. Type: Trojan.

Several security issues have been corrected in multiple demuxers and decoders of the libav multimedia library. A full list of the changes is available at https://git.libav.org/?p=libav.git;a=blob;f=Changelog;hb=refs/tags/v11.7 For the stable distribution (jessie), this problem has been fixed in version 6:11.7-1~deb8u1. We recommend that you upgrade your libav packages.

Several vulnerabilities were found in PHP, a general-purpose scripting language commonly used for web application development. The vulnerabilities are addressed by upgrading PHP to the new upstream version 5.6.22, which includes additional bug fixes. Please refer to the upstream changelog for more information: For the stable distribution (jessie), these problems have been fixed in version […]

Spam King sent down for 30 months

Risk High Date Discovered June 14, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will […]

Risk Medium Date Discovered June 14, 2016 Description Microsoft Windows is prone to an information disclosure vulnerability. Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks. Technologies Affected Microsoft Edge Microsoft Windows 10 version 1511 for 32-bit Systems Microsoft Windows 10 version 1511 for x64-based Systems Microsoft Windows 8.1 […]

Risk High Date Discovered June 14, 2016 Description Microsoft Internet Explorer is prone to a remote privilege-escalation vulnerability. An attacker can exploit this issue to gain elevated privileges. Successful exploits may aid in further attacks. Internet Explorer 9, 10, and 11 are vulnerable. Technologies Affected Microsoft Internet Explorer 10 Microsoft Internet Explorer 11 Microsoft Internet […]

Risk High Date Discovered June 14, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will […]

Risk High Date Discovered June 14, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will […]

Risk High Date Discovered June 14, 2016 Description Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed […]

Risk High Date Discovered June 14, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will […]

Risk Medium Date Discovered June 14, 2016 Description Microsoft Internet Explorer is prone to a security-bypass vulnerability that affects the XSS Filter. An attacker can exploit this issue by tricking an unsuspecting victim into viewing a page containing malicious content. They can then execute arbitrary script code in the context of the user running the […]

Patched BadTunnel Windows Bug Has ‘Extensive’ Impact
FBI: Email Scams Take $3.1 Billion Toll on Businesses
Admins in outcry as Microsoft fix borks Group Policy
Underground Market Selling Cheap Access to Hacked Servers
Think hovering your mouse over the URL will save you? Think again!
Computer crash wipes out years of Air Force investigation records »
Critical Adobe Flash bug under active attack currently has no patch »
Say Hello to Ransomware Targeting Smart TV
Sofacy NotSoGood: Time to switch up our Trojan-slinging tactics
Cybercrooks are pimping out pwned RDP servers
Adobe warns: Cyberespionage group targeting critical Flash bug
Patch Tuesday: IE/Edge share an exploit and Windows 10 advances to build 10586.420
Cost of a data breach: $4 million. Benefits of responding quickly: Priceless
Safari 10 to turn off Flash by default
A popular cloud privacy bill stalls in the Senate
Here Is How Hackers Bypass Google’s Two-Factor Authentication
Let’s Encrypt accidentally leaks user email data
Russian hackers breach DNC computers, steal data on Trump
SAP patch batch includes fix for 3-year-old info disclosure vuln
VerticalScope experiences major data breach: 45 million records stolen

VerticalScope has experienced a major data breach, with cybercriminals making off with over 45 million records belonging to over 1,100 websites, it has been reported. LeakedSource, which provides detailed information on data breaches, said that some of the websites impacted by this include Techsupportforum.com, MobileCampsites.com, Pbnation.com and Motorcycle.com. It is believed that the security incident […]

Home invasion? 3 fears about Google Home
Block malware, ransomware, and phishing with 5 layers
Biz security deadline knocked back 3 months ‘cos Brits ignored it
East Euro crims pwning ‘high profile’ victims with Flash zero day

There’s a lot that happens in the security world, with many stories getting lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. Human Error Remains Top Security Threat In a study conducted over the course of 3 […]

Chinese loan sharks seek salacious selfies as collateral

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Russian government hackers spent a year in our servers, admits DNC
North Korea stole F-15 blueprints and 42,000 defense-related documents from South Korea
Hackers Found Their Way Inside Telegram App

Multiple security issues have been found in Icedove, Debian’s version of the Mozilla Thunderbird mail client: Multiple memory safety errors may lead to the execution of arbitrary code or denial of service. Debian follows the extended support releases (ESR) of Thunderbird. Support for the 38.x series has ended, so starting with this update we’re now […]

Microsoft June Patch Tuesday Fixes 44 Vulnerabilities
Verizon Patches Serious Email Flaw That Left Millions Exposed
It’s [insert month] of 2016, and your Windows PC can still be owned by [insert document type]
Telegram bug allows attackers to crash devices, jack up phone bills
Apple quietly launches next-gen encrypted file system
DNC Hacked, Research on Trump Stolen

Red Hat: 2016:1225-01: kernel: Important Advisory Posted by Anthony Pell    An update for kernel is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory […]

Debian: 3601-1: icedove: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3601-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 13, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : icedove CVE ID : CVE-2016-2806 Multiple security issues have been found in Icedove, Debian’s version of the Mozilla Thunderbird mail client: Multiple memory safety errors […]

Security products may seem like ‘snake oil’, but that’s OK

Risk Level: Very Low. Type: Trojan.

Buggy vote-counting software borks Australian govenment election
Someone is hacking traffic signs in US and replacing them with their own messages
Fix Coming for Flash Vulnerability Under Attack
RAA Ransomware Composed Entirely of JavaScript
Don’t run JS email attachments: ​they​ can carry potent ransomware
Clueless s’kiddies using exploit kits are behind ransomware surge
Meaningful Surveillance Reform Risks Defeat
D-Link Patches Weak Crypto in mydlink Devices
Half of Brit small biz hit by cyber crime. 10% spend zilch on infosec
Greenwich University target of revenge hack; results in huge data breach
Quantum Computation: A cryptography armageddon?

Cryptography is a cornerstone of information security. It is used to encode and decode data in order to fulfill the requirement for confidentiality, integrity, authenticity as well as non-repudiation. Together, these are frequently referred to as cryptography services. Advances in cryptanalysis, computer science and engineering are always pushing the limits of what is considered secure. […]

Yes, even smart TVs can be hit by Android ransomware
Apple looks into the benefits of differential privacy

��}��Ȳ�o��w(Ĺ�,�_�n��9�����=gv.pe�l��%�>��a:��F���7b�`�MΓlfUI֗�n�a� 8g@�����2����*�y����/o��N_�|w��4�9ġ0W��D!~���E_�&�dE��ax_�1� �*P���)���

House Poised to Advance Privacy and Defend Encryption…If Allowed to Vote
NSA Looking to Exploit Internet of Things, Including Biomedical Devices, Official Says
Hacker puts 51 million file sharing accounts for sale on dark web
Big data will fix internet security … eventually

I’ve always thought that improved computer security controls would “fix” the internet and stop persistent criminality — turns out it might be big data analytics instead. I’ve long written that only a large-scale improvement of the internet’s authentication mechanisms (that is, pervasive identity) could significantly reduce crime. If everyone on the internet had a default, […]

Man-in-the-middle biz Blue Coat bought by Symantec: Infosec bods are worried
Hack the Pentagon shutters 100 bugs
Telegram crammed: Hackers find way to send massive messages
North Korea hacks 140k computers in planned mass attacks on Seoul

Discovered: June 13, 2016 Updated: June 13, 2016 11:42:17 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP JS.Ransomcrypt.B is a Trojan horse that encrypts files on the compromised server and downloads […]

Risk High Date Discovered June 14, 2016 Description Microsoft Windows is prone to a local privilege-escalation vulnerability that occurs in the Windows kernel. A local attacker can exploit this issue to execute arbitrary code in kernel mode with elevated privileges. Technologies Affected Microsoft Windows 10 for 32-bit Systems Microsoft Windows 10 for x64-based Systems Microsoft […]

Discovered: June 14, 2016 Updated: June 14, 2016 2:51:29 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows NT, Windows Vista, Windows XP Trojan.Cryptolocker.AR is a Trojan horse that encrypts files on the compromised computer. Symantec Security Response is currently investigating this threat and will […]

Risk High Date Discovered June 14, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]

Risk High Date Discovered June 14, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote privilege-escalation vulnerability; fixes are available.