Menu

Latest articles

Happy ending for Pornhub after vulnerability researchers gain access to entire user database
Tinder spam bots trick users into paying for adult content
Is digital fraud big in UK? British abacus-botherers finally have some answers
Police 3D print murder victim’s finger to unlock his phone
Wire open-sources messaging client, woos developers
Security firms team to take down rudimentary ransomware
I don’t like Mondays, Pokemon, Twitter or Facebook – Sir Bob Geldof
Verizon wants to replace your net gateways with ‘a simple mux’
Oops: Bounty-hunter found Vine’s source code in plain sight
Eurocrats to pore over Apache, KeePass code

CVE-2016-1238 John Lightsey and Todd Rinaldo reported that the opportunistic loading of optional modules can make many programs unintentionally load code from the current working directory (which might be changed to another directory without the user realising) and potentially leading to privilege escalation, as demonstrated in Debian with certain combinations of installed packages. The problem […]

Risk Level: Very Low. Type: Trojan.

Discovered: July 25, 2016 Updated: July 25, 2016 3:40:40 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Sorcurat is a Trojan horse that opens a back door on the compromised coputer. […]

Risk Level: Very Low. Type: Trojan.

PHP flaws allowed God mode access to top smut site
Cryptography vs. bigotry: the debate Australia needs to have
US standards lab says SMS is no good for authentication
Prisma App Now Available for Android; Download Now
KickassTorrents’ Mirrors Appear online with Petition for Artem Vaulin Release

Eddie Harari reported that the OpenSSH SSH daemon allows user enumeration through timing differences when trying to authenticate users. When sshd tries to authenticate a non-existing user, it will pick up a fixed fake password structure with a hash based on the Blowfish algorithm. If real users passwords are hashed using SHA256/SHA512, then a remote […]

Clash of Kings forum Breached; 1.6 Million Users’ Accounts Stolen
DNC Emails from WikiLeaks Pose Massive Privacy Threat to Donors
Munich Shooter Invited People to McDonald’s using hacked Facebook account
Researching Mr. Robot, Elliot’s world, and cybersecurity at Comic-Con

(With Comic-Con International 2016 taking place in ESET’s own backyard again this year, we are digging into all-things cybersecurity at the Con. In this article, Guest Writer Anna Keeve enters the world of Mr. Robot). ESET’s support for Comic-Con ranges from tips for staying safe while traveling, and hitting the streets to make sure people […]

5 ‘Mr. Robot’ Hacks That Could Happen in Real Life
Firefox sets kill-Flash schedule

There’s a lot that happens in the security world, with many stories getting lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. Rio Olympics: A Cyberthreat Goldmine With the 2016 Olympic games right around the corner, it’s […]

Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.50. Please see the MySQL 5.5 Release Notes and Oracle’s Critical Patch Update advisory for further details: For the stable distribution (jessie), these problems have been fixed in version 5.5.50-0+deb8u1. We recommend that […]

WikiLeaks fights The Man by, er, publishing ordinary people’s personal information

Risk High Date Discovered July 12, 2016 Description Adobe Flash Player is prone to multiple remote code-execution vulnerabilities. An attacker can exploit these issues to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely result in denial-of-service conditions. Recommendations Run all software as a nonprivileged user […]

Risk High Date Discovered July 12, 2016 Description Adobe Acrobat and Reader are prone to multiple unspecified memory-corruption vulnerabilities. Attackers can exploit these issues to execute arbitrary code in the context of the application. Failed attacks may cause a denial-of-service condition. Technologies Affected Adobe Acrobat 11.0.0 Adobe Acrobat 11.0.06 Adobe Acrobat 11.0.07 Adobe Acrobat 11.0.08 […]

Debian: 3625-1: squid3: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3625-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond July 22, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : squid3 CVE ID : CVE-2016-4051 CVE-2016-4052 CVE-2016-4053 CVE-2016-4054 CVE-2016-4554 CVE-2016-4555 CVE-2016-4556 Debian Bug : 823968 Several security issues have been discovered in the Squid caching […]

Slackware: 2016-203-01: gimp: Security Update Posted by Anthony Pell    New gimp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue. [More Info…] [slackware-security] gimp (SSA:2016-203-01) New gimp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue. Here are the details from the […]

Slackware: 2016-203-02: php: Security Update Posted by Anthony Pell    New php packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…] [slackware-security] php (SSA:2016-203-02) New php packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. Here are the details from the Slackware 14.2 […]

Debian: 3624-1: mysql-5.5: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3624-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 21, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : mysql-5.5 CVE ID : CVE-2016-3477 CVE-2016-3521 CVE-2016-3615 CVE-2016-5440 Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL […]

PowerWare Ransomware Masquerades as Locky to Intimidate Victims
PayPal Fixes CSRF Vulnerability in PayPal.me

When it comes to drive-by attacks, CryptXXX is king. In fact, out of all the exploit kits dropping payloads on victims, 80% result in CryptXXX. The creators attacked vulnerabilities in Flash Player, Java and Silver Light through using the Angler exploit kit, with malvertising helping boost their success. The malware authors were able to generate $3 Million […]

Cerber is yet another newer ransomware that has been gaining some traction over the past couple months, so we’re providing a breakdown of this new variant. First, here is how it looks: Unlike some other ransomware variants, Cerber is certainly not going for aesthetics. It also lacks any type of GUI. However, it does change your background to an […]

CrytpoMix has been gaining some traction over the past few months, so it’s a good idea that we provide a rundown of this variant in the ransomware family. This is ‘barebones ransomware’, so victims aren’t presented with a GUI or a desktop background change. All that is presented is a text file and webpage showing the same text. […]

Edward Snowden’s new case design detects if your iPhone is broadcasting its location
When the people selling you IT security solutions hack into their rival’s database…
SoakSoak using compromised websites to spread CryptXXX ransomware
Apple, Facebook and Coinbase coughed data to finger alleged pirate king
How Apple and Facebook Helped US to Arrest Kickass Torrents’ Owner

Several security issues have been discovered in the Squid caching proxy. CVE-2016-4051: CESG and Yuriy M. Kaminskiy discovered that Squid cachemgr.cgi was vulnerable to a buffer overflow when processing remotely supplied inputs relayed through Squid. CVE-2016-4052: CESG discovered that a buffer overflow made Squid vulnerable to a Denial of Service (DoS) attack when processing ESI […]

Google Fixes 48 Bugs, Sandbox Escape, in Chrome
Firefox to Block Flash in August, Disable in 2017

An update for java-1.6.0-sun is now available for Oracle Java for Red Hat Enterprise Linux 5, Oracle Java for Red Hat Enterprise Linux 6, and Oracle Java for Red Hat Enterprise Linux 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: java-1.6.0-sun security update Advisory ID: RHSA-2016:1477-01 Product: Oracle Java for Red Hat Enterprise Linux […]

An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 5, Oracle Java for Red Hat Enterprise Linux 6, and Oracle Java for Red Hat Enterprise Linux 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.7.0-oracle security update Advisory ID: RHSA-2016:1476-01 Product: Oracle Java for Red Hat Enterprise Linux […]

An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.8.0-oracle security update Advisory ID: RHSA-2016:1475-01 Product: Oracle Java […]

Red Hat: 2016:1474-01: openstack-neutron: Low Advisory Posted by Anthony Pell    An update for openstack-neutron is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Low: openstack-neutron security, bug fix, […]

Red Hat: 2016:1473-01: openstack-neutron: Low Advisory Posted by Anthony Pell    An update for openstack-neutron is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Low: openstack-neutron security and bug fix update Advisory ID: RHSA-2016:1473-01 […]

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.8.0-openjdk security update Advisory ID: RHSA-2016:1458-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2016:1458 Issue […]

Gentoo: 201607-16 arpwatch: Privilege escalation Posted by Anthony Pell    arpwatch is vulnerable to the escalation of privileges. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – Gentoo […]

Gentoo: 201607-15 NTP: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in NTP, the worst of which could lead to Denial of Service. – – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201607-14 Ansible: Privilege escalation Posted by Anthony Pell    A vulnerability in Ansible may allow local attackers to gain escalated privileges or write arbitrary files. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201607-13 libbsd: Arbitrary code execution Posted by Anthony Pell    A buffer overflow in libbsd might allow remote attackers to execute arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201607-12 Exim: Arbitrary code execution Posted by Anthony Pell    A local attacker could execute arbitrary code by providing unsanitized data to a data source or escalate privileges. – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201607-11 Bugzilla: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in Bugzilla, the worst of which could lead to the escalation of privileges. – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Bosses at UK infosec biz Quadsys confess to hacking rival reseller

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

EFF Files Lawsuit Challenging DMCA’s Restrictions on Security Researchers
15 Vulnerabilities in SAP HANA Outlined
Tinder safe dating spam uses safety to scam users out of money
Scammers drive users to fake verification site that signs them up to adult webcam and erotic video websites. Read More
Playstation chief Shuhei Yoshida has his Twitter hacked by OurMine
GOP delegates suckered into connecting to insecure Wi-Fi hotspots
How to secure your cyber infrastructure from threats like ransomware?
Ransomware gang: How can I extort you today?
Turns out that you can’t trust ‘Trump free Wifi’ at the Republican National Congress
Cisco patches critical exposure in management software
Petition urges Apple not to release technology for jamming phone cameras
IoT Insecurity: Pinpointing the Problems
Hackers are targeting the Rio Olympics, so watch out for these cyberthreats
Drupalgeddon hits Warframe – nearly 800,000 gamers’ account details being sold on the net
Analyzing Mr. Robot: S02E01

��}ے�F���(QsD�”�[߻�:RKkF����h����$� ƥٴ���p�m^�e#6b����OΗlfV���l�c�J3�@�*+++3+3+�����oO�~x�}}�����&��a��5�jߟ֘��}5������w�n���Oy� ֠ν� 7��{�D�MyhPQ��ٗ�ډpC�����5f�_�Zȯ�66xhN?�� G�^������g��ډ�zFh�,��/��|Uט�A���3O�a��̶���◶�5��b�k���h�i8|Э�4b�p-�C�]r��& “���aϸ�/����}�G;���s����7�����M����o.��U����ipi8�e��t3`O^�����n����vv:����W’�v�=��%,��L�v/�ϝA-�&�B��”�56�mj�o��u=��!��f�;�%��v8�M1m�����$�”봻z�MOO”�`��?��W��j�#��Og�������V��74dWS�w���GŸ��-�*�~|��آ2�K�8���� �ӹLJ7>0]jPa!oO��܈B;�r%y�5p(�n��&*”ܸ,��?��5b߻)#�$^�&x���*{Ԛz�����T�%̼J����ta��E��?�%�6L�n��Z��1�)-�Wm�w����w�W�$r#x���0�]�0uR�CGкu���Z0wC�jN9J����v�DT������c;= b~��/��F��{�в���Kh+1B��ۏ-�p��)Z#b�f)���E�V=�z�;^��bQfNN�����t����������v:{�>�v��C(ߦc�6s�Ks��/����wJ>0�{�k�4��O��/f5�-�)�S��”�hSKۧ�` �������,�J%���`+0�PD��İx�o��C�t�6�����tf�|G���”x��)[��C˅�H�Y�PP�~����q��M ���`��� plm�3iiZw���j|d8?�B��䌘��}Z���Fԁ�d�M�/�+{E=‰OQ`�,a��B��’�e�s�€�p�l�|c���!��ۓ�h��R)1�@����a2ԡ����R�@�1� �hyAhK%5�� ����u�J�>5C�Y��}uʸ�^����K8�㥟�#V���Q�����M ��]�`3nN���J`�)���n�m�����M �0�n�V���l����A��1� y����@�WF5U=.�uo��a�t%�k�u@�I������ ��.��^��%����&>/�roE5*K�,Pd�3�2��@�%o?�*]v�a�A��R�X;���E�A?Wi��yN���O �������OJ’oY�)��Q��[1����,�G��~��O��Y�-� ��8��`�e�� ��u�ܡ���nw#]�}���Fk���l)ӡWFȃ�}�cy[�[��JykO��5L8�-{mt�r@o���fF���f�B�wrc�5L�gU}U�Be?�%蛬��K������$j�TPMq� �la�=`�s|*w���l2��?.mn ӿM+��+`�,_x���Y��N*ĴyX�V�Zq���,l�� � /�@U�H} 8?����d�A��G!-�8i’����)�}g���w3’�B�� +6�!��`$Ŋ���߾��E�j�E����b����i���d�X�7�*��b� f�gp�gh���F>���0/�ͮ��P�f{_-s�Q��bVWղ�U s/]�J˜�V�Ug��f��d{m�7�G����彁R�z5����YW_��)1�9m7: ��>��8�E��`�����=���8�D�F�D�9�^�lu��b~K�z�ա��i��9Pd�1�z�@oR�d�pl�=4���L~�|ò���i�ţm(ߣգfY�i�e �֓�;��2�`�N~ti!IWg0.VX�?~�ﰼLӸBF3��`�}M�V⽘6����@.yB=��šIB�7&��] [ph�v��Mj�`_̡����Eǒ�.�~�ygt� ���A1��2x/���;�铱�9Q@)�R�a 6g�*,Iõ��4�W�Gn�f[��t�%M���gՑz)1�V�R��29�>�`�,�cp/V@��=�])}lQX9;n9�’ ��r�sv^��-���c�%uOlTB� 7��v��&o���}*E�Ȁ���k��qՅ��2�oGߺ�On2͖7 ��e���$�Fhw�b��1xt��f���ի��T}���MUW8*���ٌ`� �}a�Di=�zŴ��x��-��§�휏|&YF?nd#YcFVӔF�.Q�#�4:��”�5LF+� ���+��M���tL�?M0i /��*�e#_fb oQuzr�)Ώ�~C��3��e`Tb����~�}##]��7�����ӥ���㧴��w�ɽ��xL�+}Q�����նU/��L�x�T��:s|���;?�����[�?o���5����U������[���5{ �|ޚ�yk�j��fޚ}b}ޚ�yk��ٹ&>o���5������P��7����?�� “6�t(1p�et�rw��Q -�!�ۉ�-�5�D�g�F�ϻID��I=�DӡKr�⁘��_�6f-�J��~F4O�p����B��9�F�H�J�kof�{�!������o��o����U

Microsoft and pals re-write arms control pact to save infosec industry
Asian nations mull regional ‘Europol’ in fight against cybercrime
Kickass Torrents Goes Down; Owner Arrested
Massive DDoS Attack Shut Down Several Pro-ISIS Websites

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Users of iPhones and Macs must update to avoid Stagefright-like bug
Everyone’s favorite infosec biz – Blue Coat – must cough up $40m to rival in patent rip-off row
Salesforce will only support Nexus and Samsung Galaxy phones to avoid Android fragmentation
Firefox to banish hidden Flash files – and kill off sneaky ad snoopers
Oracle’s monster security update fixes Java, database bugs
SoakSoak Botnet Pushing Neutrino Exploit Kit and CryptXXX Ransomware

Anti-virus software is a program or set of programs that are designed to prevent, search for, detect, and remove viruses, and other forms of malware such as worms, trojans, adware, and more. As our world continues to become ever more connected, anti-virus remains critical for users seeking to keep their devices protected. However, it’s vital that the […]

US Congress websites recovering after three-day DDoS attack
Oracle issues largest patch bundle ever, fixing 276 security flaws
Oracle Patches Record 276 Vulnerabilities with July Critical Patch Update
How Bad is the North Korean Cyber Threat?