Menu

Latest articles

Pirate swarms at risk from new patent
Hacking A Penetration Tester
Spotted! 9 signs of a malicious download

Most people’s computers get exploited in only a handful of ways. Among the most popular methods is tricking people into downloading and running Trojans. Often, unsuspecting users get socially engineered into running a malicious file or app by following a link in email or visiting a website. It can be tough to spot the fake […]

Nasty session stealing hole filled in WordPress All in One SEO plugin
Purloined password re-use checker pees in the security soup
Android Nougat may contain traces of NOT for users of custom CAs
Florida U boffins think they’ve defeated all ransomware
Aussie researcher claims ‘Antminer’ bitcoin boxen can be broken
Privacy scare over Pokémon Go app for iOS
Security analyst banned for disclosing vulnerabilities in web forums
Lawsuit filed against Snapchat for showing adult content to minors

Type: Vulnerability. Microsoft Edge and Internet Explorer are prone to a information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge and Internet Explorer are prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Edge and Internet Explorer are prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Risk Medium Date Discovered July 12, 2016 Description Microsoft Windows is prone to a local security-bypass vulnerability. Local attackers can exploit this issue to bypass certain security restrictions and perform unauthorized actions. Recommendations Permit local access for trusted individuals only. Where possible, use restricted environments and restricted shells. To exploit this vulnerability, an attacker requires […]

Risk High Date Discovered July 12, 2016 Description Microsoft Edge is prone to a security-bypass vulnerability. An attacker can leverage this issue to bypass certain security restrictions and execute arbitrary code by exploiting another vulnerability in the application. Technologies Affected Microsoft Edge Recommendations Block external access at the network boundary, unless external parties require service. […]

Risk High Date Discovered July 12, 2016 Description Microsoft Edge is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]

Risk High Date Discovered July 12, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]

Risk High Date Discovered July 12, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]

Risk High Date Discovered July 12, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]

Risk High Date Discovered July 12, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]

Discovered: July 12, 2016 Updated: July 12, 2016 3:41:32 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Infostealer.Pycerine is a Trojan horse that may steal information from the compromised computer. Antivirus Protection Dates Initial […]

Jigsaw Ransomware Decrypted, Again
‘Our Mine’ Hacks Twitter Account of Twitter CEO Jack Dorsey
Pokemon Go on, gissus your Google Gmail, Drive files, photos?
Datadog Forces Password Reset Following Breach

An update for thunderbird is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: thunderbird security update Advisory ID: RHSA-2016:1392-01 Product: Red Hat Enterprise […]

Gentoo: 201607-02 libpcre: Multiple Vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in libpcre, the worst of which could lead to arbitrary code execution, or cause a Denial of Service condition. – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201607-01 Squid: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in Squid, the worst of which could lead to arbitrary code execution, or cause a Denial of Service condition. – – – – – – – – – – – – – – – – – – – – – […]

Slackware: 2016-189-01: samba: Security Update Posted by Anthony Pell    New samba packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…] [slackware-security] samba (SSA:2016-189-01) New samba packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. Here are the details from the Slackware 14.2 […]

Debian: 3617-1: horizon: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3617-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff July 06, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : horizon CVE ID : CVE-2015-3219 CVE-2016-4428 Two cross-site scripting vulnerabilities have been found in Horizon, a web application to control an OpenStack cloud. For the […]

Serious flaw fixed in widely used WordPress plug-in
Malicious Pokémon Go App Installs Backdoor on Android Devices
Omni-shambles! Card-stealing malware checks into US hotel chain
Google Updates CA Trust Mechanisms in Android Nougat

Risk Level: Very Low. Type: Trojan, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

IoT Medical Devices: A Prescription for Disaster
Amazingly insecure industrial control systems + internet = Cupful of nope
91 Percent of Public-Facing ICS Components Are Remotely Exploitable
Drowning Dalek commands Siri in voice-rec hack attack
Lurk trojan takedown also took out Angler exploit kit
White hat banned for revealing vulns in news sites used by London councillors
Hacker bites Datadog, finds hard-to-chew bcrypt passwords
Teen thugs lure, rob Pokemon Go gamers
OpAfrica: Anonymous hacks South African arms procurement agency
Fake Pokémon Go app contains RAT; takes full control of infected device
Amazon Suffers Security Breach; 80,000 Login Credentials Leaked
Android users warned of malicious Pokémon Go app
Does Hacktivism Really Equal Terrorism?
Ukrainian Hacker Hacks Polish Telecom Giant Netia; Leaks Massive Data
Anonymous DDoS Zimbabwe Government Sites for #ShutDownZimbabwe
Android Mew-ware, I choose you: Code nasty poses as Pokemon GO
IDG Contributor Network: When your security products are insecure: Takeaways from the Symantec disclosure
Facebook offers end-to-end encrypted chat – if you find the right setting
Guccifer Hacker aka Marcel Lazăr Lehel is NOT dead
Google Testing Post-Quantum Cryptography in Chrome
The truth about bug finders: They’re essentially useless
BMW web portal vulns pose car hack risk – researchers
Watch Out for Keydnap Malware Stealing Mac Login Credentials
Facebook Messenger End-to-End Encryption Not On By Default
Facebook Messenger gets opt-in end-to-end encryption with Secret Conversations
Dropping Elephant APT Targets Old Windows Flaws
Threatpost News Wrap, July 8, 2016
Apple devices held for ransom, massive iCloud account hack rumours
Google Chrome tests future of encryption with post-quantum crypto
Malaysia-based credit card fraud ring broken, 105 arrested
CryptXXX, Cryptobit Ransomware Spreading Through Campaign
Copy paste slacker hackers pop corp locks in ode to stolen code
CloudFlare pros pen paranoid phone plan for pwn-free peregrination
Facebook ‘glitch’ that deleted the Philando Castile shooting vid: It was the police – sources
414,949 D-Link cameras, IoT devices can be hijacked over the net
1 in 20 Wendy’s burger joints hacked? No, make that 1 in 3 – 1,025 in total
Over 1000 Wendy’s restaurants hacked – customers’ credit card details stolen

Two cross-site scripting vulnerabilities have been found in Horizon, a web application to control an OpenStack cloud. For the stable distribution (jessie), these problems have been fixed in version 2014.1.3-7+deb8u2. For the testing distribution (stretch), these problems have been fixed in version 3:9.0.1-2. For the unstable distribution (sid), these problems have been fixed in version […]

CryptXXX Ransomware Updates Ransom Note, Payment Site

Discovered: July 6, 2016 Updated: July 6, 2016 11:32:15 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Asruex is a Trojan horse that steals information from the compromised computer. It may also download potentially […]

Risk Level: Very Low. Type: Trojan.

D-Link Wi-Fi Camera Flaw Extends to 120 Products
How Android Nougat will help protect your password from ransomware
How to remove your Windows 10 password
Android KeyStore Encryption Scheme Broken, Researchers Say
US government tells Symantec and Norton Antivirus users to apply security patches immediately
Cafe killer remote code execution affects 140 million MIUI Androids
Latest Intelligence for June 2016
Our latest intelligence reveals nearly a 30 percentage point drop in web attacks using Angler and a 20 percentage point increase in Manual Sharing social [...]
How your smartwatch or fitness tracker could reveal your ATM PIN
Antivirus merger: Avast offers $1.3 billion for AVG
Security Sessions: The state of cloud security
Ransomware: First files … now complete devices

A major threats to computer security is malicious code. In fact, over the years, it has become one of the main causes of security incidents, from the first viruses in 1986 to the most sophisticated malware of today. And this particular type of malware, although it is not new, has become increasingly troublesome for both businesses […]

Android’s full-disk encryption just got much weaker-here’s why
8 Reasons You Need a Security Penetration Test
5 Ways To Think Like A Hacker