Menu

Latest articles

Feds shut down tech support scammers, freeze assets
Jackware: When connected cars meet ransomware

2016 is already being dubbed “The Year of Ransomware” and ransomware features prominently in my upcoming “Mid-Year Threat Review” webinar. In that webinar I will also be talking about the IoT (Internet of Things) and more specifically the IoIT (the Internet of Insecure Things); mainly because risks arising from the latter are on the rise. […]

New HIPAA guidance addresses ransomware
Google says government requests for user data at all-time high
Russian security firm linked to cybercrime gang
Hacker shows Reg how one leaked home address can lead to ruin
What’s big and red and squashes 276 bugs, 19 of them critical?
Flaws found in security products from AVG, Symantec and McAfee
WordPress admin? Thinking of spending time with the family? Think again
WhatsApp gets another Brazilian whack as magistrate blocks it again

Scott Geary of VendHQ discovered that the Apache HTTPD server used the value of the Proxy header from HTTP requests to initialize the HTTP_PROXY environment variable for CGI scripts, which in turn was incorrectly used by certain HTTP client implementations to configure the proxy for outgoing HTTP requests. A remote attacker could possibly use this […]

Anonymous DDoS Rio Court Website for Blocking WhatsApp in Brazil
Apple kills eavesdrop bug in FaceTime
What keeps former New York Mayor Rudy Giuliani awake at night?

It was discovered that Django, a high-level Python web development framework, is prone to a cross-site scripting vulnerability in the admin’s add/change related popup. For the stable distribution (jessie), this problem has been fixed in version 1.7.7-1+deb8u5. We recommend that you upgrade your python-django packages.

A vulnerability was discovered in mysql-connector-java, a Java database (JDBC) driver for MySQL, which may result in unauthorized update, insert or delete access to some MySQL Connectors accessible data as well as read access to a subset of MySQL Connectors accessible data. The vulnerability was addressed by upgrading mysql-connector-java to the new upstream version 5.1.39, […]

The Troubling State of Security Cameras; Thousands of Devices Vulnerable
BlackBerry chief: We don’t have to make phones to make phones

Debian: 3622-1: python-django: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3622-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 18, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : python-django CVE ID : CVE-2016-6186 It was discovered that Django, a high-level Python web development framework, is prone to a cross-site scripting vulnerability in the […]

An update for httpd is now available for Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: httpd security update Advisory ID: RHSA-2016:1421-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2016:1421 Issue […]

An update for httpd is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: httpd security and bug fix update Advisory ID: RHSA-2016:1422-01 Product: Red […]

Debian: 3621-1: mysql-connector-java: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3621-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 18, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : mysql-connector-java CVE ID : CVE-2015-2575 A vulnerability was discovered in mysql-connector-java, a Java database (JDBC) driver for MySQL, which may result in unauthorized update, insert […]

Red Hat: 2016:1420-01: httpd24-httpd: Important Advisory Posted by Anthony Pell    An update for httpd24-httpd is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: httpd24-httpd security update Advisory ID: RHSA-2016:1420-01 Product: Red Hat Software Collections […]

DDoS trends: Bigger, badder but not longer

How are they a security threat? People, not computers, create computer threats. Computer predators victimize others for their own gain. Give them access to the internet — and to your PC — and the threat they pose to your security increases exponentially. Computer hackers are unauthorized users who break into computer systems in order to steal, […]

Google Chrome Malware Leads to Sketchy Facebook Likes
Carbon Black snaps up cloud-dwelling threat-sniffing ‘next-gen AV’
Ex-Cardinals Exec Sentenced Four Years for Astros Hack
Steemit experienced hack, theft of user funds, and DDoS attack
Baton Rouge City Website Hacked Against Alton Sterling’s Death
IoT baby monitor style hacks still a threat

APPLE-SA-2016-07-18-6 iTunes 12.4.2 Subject: APPLE-SA-2016-07-18-6 iTunes 12.4.2 From: Apple Product Security Date: Mon, 18 Jul 2016 17:26:55 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-07-18-6 iTunes 12.4.2 iTunes 12.4.2 for Windows is now available and addresses the following: libxml2 Impact: Multiple vulnerabilities in libxml2 Description: Multiple memory corruption issues were addressed through improved memory handling. […]

APPLE-SA-2016-07-18-5 Safari 9.1.2 Subject: APPLE-SA-2016-07-18-5 Safari 9.1.2 From: Apple Product Security Date: Mon, 18 Jul 2016 17:22:29 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-07-18-5 Safari 9.1.2 Safari 9.1.2 is now available and addresses the following: WebKit Available for: OS X El Capitan v10.11.6 Impact: Visiting a malicious website may disclose image data from another […]

APPLE-SA-2016-07-18-4 tvOS 9.2.2 Subject: APPLE-SA-2016-07-18-4 tvOS 9.2.2 From: Apple Product Security Date: Mon, 18 Jul 2016 17:21:14 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-07-18-4 tvOS 9.2.2 tvOS 9.2.2 is now available and addresses the following: CoreGraphics Available for: Apple TV (4th generation) Impact: A remote attacker may be able to execute arbitrary code Description: […]

APPLE-SA-2016-07-18-3 watchOS 2.2.2 Subject: APPLE-SA-2016-07-18-3 watchOS 2.2.2 From: Apple Product Security Date: Mon, 18 Jul 2016 17:20:02 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-07-18-3 watchOS 2.2.2 watchOS 2.2.2 is now available and addresses the following: CoreGraphics Available for: Apple Watch Sport, Apple Watch, Apple Watch Edition, and Apple Watch Hermes Impact: A remote attacker […]

APPLE-SA-2016-07-18-2 iOS 9.3.3 Subject: APPLE-SA-2016-07-18-2 iOS 9.3.3 From: Apple Product Security Date: Mon, 18 Jul 2016 17:17:26 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-07-18-2 iOS 9.3.3 iOS 9.3.3 is now available and addresses the following: Calendar Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later Impact: A […]

APPLE-SA-2016-07-18-1 OS X El Capitan v10.11.6 and Security Update 2016-004 Subject: APPLE-SA-2016-07-18-1 OS X El Capitan v10.11.6 and Security Update 2016-004 From: Apple Product Security Date: Mon, 18 Jul 2016 17:14:08 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-07-18-1 OS X El Capitan v10.11.6 and Security Update 2016-004 OS X El Capitan v10.11.6 and Security […]

If you find the FBI’s cybercrime webpage can you let them know?
Security software that uses ‘code hooking’ opens the door to hackers
Hacker Steals Amazon Marketplace Credentials from 3rd Party Server
Apple fixes FaceTime eavesdropping bug, other other flaws may remain
Your antivirus doesn’t like Ammyy. And fraudsters will use that to RAT you out (again)
Malicious scripts gaining prevalence in Brazil

Had we looked at a map of malware detections in Brazil a year ago, we would have seen that the two main computer threats were the downloaders that installed banking trojans, and the banking trojans themselves. Today the situation remains the same, but with an extra special ingredient – while threats used to be Windows .exe […]

Apple Fixes Vulnerabilities Across OS X, iOS, Safari
Neutrino exploit kit adds former IE zero-day flaw to its arsenal
IBM grows in cloud and data analytics but overall revenue slides
Sandia Labs Researchers Build DNA-Based Encrypted Storage
Flaw in vBulletin add-on leads to Ubuntu Forums database breach
Ubuntu Forums hack exposes 2 million users
Passwords not compromised by Ubuntu Forums data breach

A major data breach on the Ubuntu Forums has not compromised the passwords of its affected users. In an update to its announcement that an incident had taken place, its developer Canonical Ltd was keen to highlight that this information was not accessed. However, as Jane Silber, CEO of Canonical Ltd, revealed, usernames, emails addresses […]

4 basic security facts everyone should know

Today, almost all hacking is done by professional criminals. In many countries, illegal hacking accounts for more crime, dollar-wise, than noncomputer crime. The United Kingdom recently joined that club. Why is this important? First, if you find malware on your system, there’s a good chance it’s trying to steal your money. Second, no one is […]

MacKeeper threatens to sue 14-year-old YouTuber
Governments Googling Google about you more than ever says Google
Maxthon web browser blabs about your PC all the way back to Beijing
Guilt by ASN: Compiler’s bad memory bug could sting mobes, cell towers
World-Check terror suspect DB hits the web at just US$6750
Hardball hacker thrown in the cooler for 46 months for guessing rival team’s password
Alpine County Superior Court, CA Website Hacked Against Trump and Racism
For $800 you can buy internet engineers’ answer to US government spying
CGI Script Vulnerability ‘Httpoxy’ Allows Man-in-the-Middle Attacks

Gentoo: 201607-07 Chromium: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in the Chromium web browser, the worst of which allows remote attackers to execute arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201607-06 CUPS: Buffer overflow Posted by Anthony Pell    A buffer overflow in CUPS might allow remote attackers to execute arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201607-05 Cacti: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in Cacti, the worst of which could lead to the remote execution of arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201607-04 GD: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in GD, the worst of which allows remote attackers to execute arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Debian: 3620-1: pidgin: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3620-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 15, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : pidgin CVE ID : CVE-2016-2365 CVE-2016-2366 CVE-2016-2367 CVE-2016-2368 CVE-2016-2369 CVE-2016-2370 CVE-2016-2371 CVE-2016-2372 CVE-2016-2373 CVE-2016-2374 CVE-2016-2375 CVE-2016-2376 CVE-2016-2377 CVE-2016-2378 CVE-2016-2380 CVE-2016-4323 Yves Younan of Cisco Talos […]

Debian: 3619-1: libgd2: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3619-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 15, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libgd2 CVE ID : CVE-2016-5116 CVE-2016-5766 CVE-2016-6128 CVE-2016-6132 CVE-2016-6161 CVE-2016-6214 Debian Bug : 829014 829062 829694 Several vulnerabilities were discovered in libgd2, a library for […]

Researchers Crack Furtim, SFG Malware Connection
Two Million Passwords Breached in Ubuntu Hack
Pokémon GO goes down. Hackers claim responsibility
Adobe cockup means you may have two different versions of Flash installed on your PC
A smarter approach to password security ‘needed’

��}�r�Ʋ�o�*�0��5Ș�K&}d�>�9�㍜�͵��!0$!��Q��������j�j��ϭ�’��M�$�=3�E��h�ٲ�H$0��������3��Γ�����)�����on?�DS�8���j?�(��Ⱦ�)��L��?0o��Sf��]��z8a��߂O���SQ^Tcb�{n��H{3�BL�D�”2��CsB��E�8i� 1��p����v�M}�C’�����,_եS�S�m6� ʔ��V4�Y��6�ƿ4��ڑM-4��z�*Hc�;L�i�,�G� �xn�`ئ��:�%�{����Ģ�5z���q�^��o��1��©�y����۷,;�:?��rF��@�����k�ͅN(�U�v���$: -6Ϳ�ޙ��`�)r@�Do�_�E�n��C!�����0?�*||�%�?����C��Ȯ�Յ�E%��S=�v�S�}�Ln �J�*^]ۮ�Vh����)�s�Pε,|#�����-LU���*�>*�J��{���������̠90��y1���z��h�)i�o{�>�4�%i�h�*���pۘK/��F4v������|`E���7D}��BLQm�{͛`���L@�]f{d4���n���Eu��,�>�J_���Q@��`�n�$_�n �u�9H��=��5�’�� 5-}���fg�p;� v�����[2���= �Ƃ��iځ ���n�Y4�=�#:t��jRQo����j帷s5�YוZX��W�W���ӄ;&�.���j���0�?m����y�q[����: ULt���c�;�z�|6`y�Y���aP��?C]�#NC� l�P’b�K�y+V6���Wk`���a��’oE�1Zz��Ł�ê��9��3�W

Malicious macros arrive in phishing emails, steal banking information
Malicious macros made a comeback in 2015 to deliver malware. Now we’re seeing phishing emails use macros in Excel attachments to steal sensitive [...]
Firefighting, security and compliance

��}�v9��}N�L�d����fɔǖ�.��%W��:`&H��Ld�E˥s�q�w_v��u��?�/و��$E�tu�Ue���@D “�y����_�>c߾{����’��e.�ƃ���Ok��ȹ���M��?l���7���wkP��É���-�D�NEĩ�!~���A�Dz��”���5f�o�Z$.�66xdMx�hG#�����p����c�DN}9C7�ų��ǢX��S1�]8b�� ʕ�9v4��±�A_Z����Z��n���cW� �B�ȱ�� � {��g��d﹯zOm.������[���m����V�^��4��c�H��n�ɳ����㝽���n��|o����O”��X�� T���=K ��{Q� ㈅�6u”�/�� fK�D���Zp�����y����t�ڝ�v�G�H �m$�&�H_ќDו��9�����tTTD�劥�qr���e�~�÷�8ps8~�AD�9C.ϵ�`/�-�P����CG�p5�#n�����S~������Ǫr�2tcɐ����C��d��:�w�et�����a�s�ݹ��v:+�M� Z�Zh��^o4Y����q�|,�摜v�}Wr;L�f2���͏�8ז�x��H��ȵ��)�%������4�`(E9X�X���S�x�oI�/��8 ���֎�ĭ���rf��|1��S�H�l�>Ն

Tech leaders challenged daily to sort through a crush of new security apps
UKFast owner slurps app security biz Pentest
Euro IP study finds 25 Tor-and-Bitcoin-loving pirate business models
World’s worst exploit kit weaponises white hats’ proof of concept code
Tor veteran Lucky Green exits, torpedos critical ‘Tonga’ node and relays
Security firm clarifies power-station ‘SCADA’ malware claim
Intel’s SGX tiptoes towards Linux
Extortion trojan watches until crims find you doing something dodgy
Hacker Selling Entire US Voters’ Registration Records on Dark Net
OpenSSH has user enumeration bug
Matrimonial Matching Site Shadi.com Hacked; Data Dumped Online
Hackers Selling Terrorist Database on Dark Web, Claiming its ‘Proven Legit’
Android banking malware stops you calling customer service to cancel your cards
How you could steal money from Instagram, Microsoft and Google with help from a premium rate phone number

Yves Younan of Cisco Talos discovered several vulnerabilities in the MXit protocol support in pidgin, a multi-protocol instant messaging client. A remote attacker can take advantage of these flaws to cause a denial of service (application crash), overwrite files, information disclosure, or potentially to execute arbitrary code. For the stable distribution (jessie), these problems have […]

Several vulnerabilities were discovered in libgd2, a library for programmatic graphics creation and manipulation. A remote attacker can take advantage of these flaws to cause a denial-of-service against an application using the libgd2 library (application crash), or potentially to execute arbitrary code with the privileges of the user running the application. For the stable distribution […]

Ubuntu Forums hacked (again)
Ubuntu Forums Suffer Data breach; Credit Goes to SQL Flaw
Samsung spills beans on mystery username, password emails to devs

HSBC Sites Downed Briefly After Cyber Attack Earlier this week, it was reported that HSBC had been the victim of a cyber attack and both it’s US and UK sites had been taken offline. The messages remaining on both sites announced that an organization called OurMine had found a vulnerability and would only stop the […]

HSBC Website Suffers DDoS Attack

Several vulnerabilities were found in PHP, a general-purpose scripting language commonly used for web application development. The vulnerabilities are addressed by upgrading PHP to the new upstream version 5.6.23, which includes additional bug fixes. Please refer to the upstream changelog for more information: https://php.net/ChangeLog-5.php#5.6.23 For the stable distribution (jessie), these problems have been fixed in […]

Juniper Crypto Bug Let Attackers Eavesdrop on Router, Switch Traffic
Patched IE Zero Day Incorporated into Neutrino EK
McCain: Come to my encryption hearing. Tim Cook: No, I’m good. McCain: I hate you, I hate you, I hate you
Since you love Flash so much, Adobe now has TWO versions for you
Hackers steal millions from ATMs using ‘just their smartphones’