Menu

Latest articles

Lenovo scrambling to get a fix for BIOS vuln

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. CVE-2014-9904 It was discovered that the snd_compress_check_input function used in the ALSA subsystem does not properly check for an integer overflow, allowing a local user to cause a denial of service. CVE-2016-5728 Pengfei […]

Shmuel H discovered that GIMP, the GNU Image Manipulation Program, is prone to a use-after-free vulnerability in the channel and layer properties parsing process when loading a XCF file. An attacker can take advantage of this flaw to potentially execute arbitrary code with the privileges of the user running GIMP if a specially crafted XCF […]

Watch 2 Chinese Installing ATM Skimmer in a Pakistani Bank
Internet Bot Exposes 20 Million MTN Irancell Users’ Data
11 ways to fight off ransomware

Multiple vulnerabilities were discovered in the dissectors/parsers for PKTC, IAX2, GSM CBCH and NCP, SPOOLS, IEEE 802.11, UMTS FP, USB, Toshiba, CoSine, NetScreen, WBXML which could result in denial of service or potentially the execution of arbitrary code. For the stable distribution (jessie), these problems have been fixed in version 1.12.1+g01b65bf-4+deb8u7. For the testing distribution […]

The TERASOLUNA Framework Development Team discovered a denial of service vulnerability in Apache Commons FileUpload, a package to make it easy to add robust, high-performance, file upload capability to servlets and web applications. A remote attacker can take advantage of this flaw by sending file upload requests that cause the HTTP server using the Apache […]

Vivian Zhang and Christoph Anton Mitterer discovered that setting an empty VNC password does not work as documented in Libvirt, a virtualisation abstraction library. When the password on a VNC server is set to the empty string, authentication on the VNC server will be disabled, allowing any user to connect, despite the documentation declaring that […]

There’s a lot that happens in the security world, with many stories getting lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. Hard Rock Las Vegas Confirms Credit Card Breach Recently, the Hard Rock Cafe in Las […]

Locky Variant Zepto Debuts with Big Spam Push
Dating Website “Muslim Match” Hacked; Everything Leaked Online
Firmware exploit can defeat new Windows security features on Lenovo ThinkPads
Oculus chief latest social media hack victim
Siemens Patches Password Reconstruction Vulnerability in SICAM PAS
How to secure your social media accounts

Courtesy of Facebook, Twitter, Instagram and Snapchat – to name but a few – we are increasingly living digital lives, where we interact and engage with our friends and family online. Social media has, without a shadow of a doubt, become central to our way of life. And yet, while millions use these platforms on a […]

<div>Hard Rock Hotel & Casino Las Vegas experiences data breach</div>

��}�r۸���j�a� ��H��_�#�$Nr&��kǞ���d] It(��˞���kl��Cl�>���’�n��ɲ�d2w�s&�H��ht7�F�ᝧo�}��p�����’��#��}���OG #6r��Z0�’�$ �-+��Y~|W�:�Nu����p�ʋ��=�k���0?1�/B�[��k ;O,l���(fI?MFƞF�A=��j���8�!Mܡ��z�Ϝ1+V���3��� J��3�I&}���63�q}7q�g�6�X�Sic���0�E�ȵ��W �����f�G��(��^u�:�uF�ã÷�m��/�?����Ǻ����&�lw���vw�{��vv�۝��v��{����Γǝ��E����G1���Ʌ�� c@��/�nDZF��qi_#ׇ��&�x6��3�g,fv�ɅiSk)+��)�-�ΡY�!��29t�=����;�A�’nL�x� �ĝ��3���dB1�an?L��c�h��#�!H�G��ix@i��yIc�3���M�I��RP�I���b X`��>�05p��M��n�V�n��c�w���1″�a�3z��!��p�$��(�2��x/@qP���T �|�(qm�-,�C��ِ/j�/5��F���{���_y -�#�dm]9��W���,^Z%L����9�6��2�;F��qgk��~�w���o����h�E�v�v��lm�w�A�Q)��;�c��X*�6 ��:q>�I$���p��%]*5a�>��V�N�4����K ʂ>lX�,hCi��ő[H�`J]�,-��Yxf�@Ǔ ��w8�[�׀� 9z�^:v}���h�FR͍SzF�[m%n�� f��,d���=bI�����’mHc�h�}��x���ފ͙D��’F�޲����x���n�|����Z����Ï8H#�i�4� �j��ˡ֓�=���m/u��Ә�� ���gN����#��[���./�_wF�ϕ^���-��)�M�m~:��[N��F�ɉ͞yy����}�]'{�f��E-d���z��Ʈl͹��3��؝����t �ۖm����֡e8��~o9;�}���eο,��*�J�n�f�}ڲ�z�o �eY/~rqLǯA�44AjMh٤a�|�p�zN�n^b��ָ5i�� j���QD/A[�9[s:�ƂQ4�4��_�����E2�ٿ�n�=;�Y�

Not using Adobe’s PDF reader doesn’t mean you’re avoiding PDF malware
Study reveals security gap in big data projects
How a hacker stole a Facebook user’s account with just a fake passport
UEFA’s Euro 2016 app is airing football fans’ privates in public
700,000 Muslim Match dating site private messages leaked online
Attackers rely on legit IT tools to carry out their plans
11 essential data security tips for travelers

I travel all over the world for my job, and for my hobbies. Although there are still plenty of places I haven’t been, I’ve visited enough foreign countries that I don’t deny it when someone calls me a world traveler. Over the years, I’ve experienced my fair share of foreign spying. I know what it’s […]

Chinese gambling site served near record-breaking complex DDoS
Cracking Android’s full-disk encryption is easy on millions of phones – with a little patience
Hydra hacker bot spawns internet of things DDoS clones
400 million Foxit users need to catch up with patched-up reader

Risk Level: Very Low. Type: Trojan.

LizardStresser IoT Botnet Part of 400Gbps DDoS Attacks
WA government still hopeless at infosec
Turkish Hacker Defaces Arizona State Representatives and Legislature Sites
Russia, China fight UN effort to extend human rights onto the internet
Massachusetts General Hospital Confirms Third-Party Breach

Brandon Perry discovered that xerces-c, a validating XML parser library for C++, fails to successfully parse a DTD that is deeply nested, causing a stack overflow. A remote unauthenticated attacker can take advantage of this flaw to cause a denial of service against applications using the xerces-c library. Additionally this update includes an enhancement to […]

Multiple security vulnerabilities have been discovered in the Tomcat servlet and JSP engine, which may result in information disclosure, the bypass of CSRF protections, bypass of the SecurityManager or denial of service. For the stable distribution (jessie), these problems have been fixed in version 8.0.14-1+deb8u2. For the unstable distribution (sid), these problems have been fixed […]

Aleksandar Nikolic discovered that missing input sanitising in the RTF parser in Libreoffice may result in the execution of arbitrary code if a malformed documented is opened. For the stable distribution (jessie), this problem has been fixed in version 1:4.3.3-2+deb8u5. For the testing distribution (stretch), this problem has been fixed in version 1:5.1.4~rc1-1. For the […]

Encryption, wiretaps and the Feds: THE TRUTH
Some social engineering skills and Facebook will gift your account to hackers

Debian: 3611-1: libcommons-fileupload-java: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3611-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 30, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libcommons-fileupload-java CVE ID : CVE-2016-3092 The TERASOLUNA Framework Development Team discovered a denial of service vulnerability in Apache Commons FileUpload, a package to make it […]

Ubuntu: 3022-1: LibreOffice vulnerability Posted by Anthony Pell    LibreOffice could be made to crash or run programs as your login if itopened a specially crafted file. ========================================================================== Ubuntu Security Notice USN-3022-1 June 29, 2016 libreoffice vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu […]

Debian: 3610-1: xerces-c: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3610-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 29, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : xerces-c CVE ID : CVE-2016-4463 Debian Bug : 828990 Brandon Perry discovered that xerces-c, a validating XML parser library for C++, fails to successfully parse […]

Debian: 3609-1: tomcat8: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3609-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 29, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : tomcat8 CVE ID : CVE-2015-5174 CVE-2015-5345 CVE-2015-5346 CVE-2015-5351 CVE-2016-0706 CVE-2016-0714 CVE-2016-0763 CVE-2016-3092 Multiple security vulnerabilities have been discovered in the Tomcat servlet and JSP engine, […]

Debian: 3608-1: libreoffice: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3608-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 29, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libreoffice CVE ID : CVE-2016-4324 Aleksandar Nikolic discovered that missing input sanitising in the RTF parser in Libreoffice may result in the execution of arbitrary […]

Foxit Patches 12 Vulnerabilities in PDF Reader

Risk Level: Very Low. Type: Trojan.

Conficker Used in New Wave of Hospital IoT Device Attacks
LizardStresser recruits an army of zombie webcams to launch DDoS attacks
Hackers: Ditch the malware, we’re in… Just act like a normal network admin. *Whistles*
Security Sessions: Is hospital security on life support?
Muslim Match dating site hacked. Private messages and profiles posted online
Fight back! Learn to hunt threats with free tools
Mingis on Tech: The ethics of self-driving cars — and killer robots
The Android ransomware threat has quadrupled in just one year
Hackers abused SWIFT to steal $10 million from Ukrainian bank
Big Blue finds big green in derailing transport
SSH Keys
General tips for working with iptables
Install DenyHosts on a CentOS box
Hopeless Vic agencies have two years to hit infosec best practice

The TERASOLUNA Framework Development Team discovered a denial of service vulnerability in Apache Commons FileUpload, a package to make it easy to add robust, high-performance, file upload capability to servlets and web applications. A remote attacker can take advantage of this flaw by sending file upload requests that cause the HTTP server using the Apache […]

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Discovered: June 29, 2016 Updated: June 30, 2016 12:54:57 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows NT, Windows Vista, Windows XP Trojan.Cryptolocker.AU is a Trojan horse that encrypts files on the compromised computer and demands payment to decrypt the files. Antivirus Protection Dates […]

Honey, why are porno apps on your Android?! Er, um, malware did it!
While you filled your face at Noodles and Co, malware was slurping your bank cards
FTC Closes 70 Percent of Data Breach Investigations, Weighing PCI-DSS Standard
Alleged Brit hacker Lauri Love bailed amid US extradition battle lull
How RASP protects applications from attacks
IDG Contributor Network: Israeli cybersecurity prowess on display in DC and Tel Aviv
Hard Rock Las Vegas, Noodle and Co. Confirm Hacks
Kremlin hackers and the Democratic National Committee: How deep is the rabbit-hole?

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Flaws in Symantec products expose millions of computers to hacking
InfiniBand-on-die MIA in Oracle’s new ‘Sonoma’ Sparc S7 processor
The iPhone is nine years old – and still no significant malware outbreaks
Fancy hacking Man City? Happy days: Footy club to host hackathon
Hard Rock Cafe experiences data breach

The Hard Rock Cafe and Casino Las Vegas has released a statement alerting customers that their data may have been compromised if they visited the resort between October 27th, 2015 and March 21st, 2016. After receiving several reports of unauthorized activity associated with payment cards, the resort started an investigation into their card payment methods. […]

Planes, Trains and Automobiles Increasingly in Cybercriminal’s Bullseye
Stay cyber safe on the road: 10 tips for this summer season

��}�۶��o�*���R,��/�X��Ήϵco�I6��NQ$$q�”~�Fq������[�O��Or�d��?��hd’ٲωM�@��_h4��{��������ׯ_�}��`��h`�p��0�#ﲯ��!�$IxhYl�Sj�} ��y

Hacker puts 9.3M U.S. patient records up for sale
Digital patch kit: How to protect yourself from data leaks

��}�۶��o�*���ZR,��/�X��N�s�؛qN��;E��DE0�Yq����٭ڭ�Wت}��or�d� ER�F��N�e��”�F��_h4��w��:}�����wo^��u��8�x̳�QO���Ƃ��=M���8��c���pӏ�jP���1���-x��NxlQQ�����=�T�1�c��,��寞��� ��c+�x�K�~�1�_ �?�?>�O�$�bw��A=��Έ��ք�K�Oƹ�S׉�=�_�6��G������G���^� �H����ȍ�~�Cw�ڀ��s����ߧ���D�x/;O����g���׭�Z?}aw>t/�Z�D���:V̍V;�����Q������ig������j�~s�����vW�b��������iQL�?K����pb�=����*���B��K0o

New CryptXXX ransomware variant made authors $50K in two weeks
Please stop spreading the Facebook privacy notice hoax
Body of evidence: Biometrics and YOU
Zero-interaction remote wormable hijack hole blasts Symantec kit
Global terror database World-Check leaked
Play Store malware roots phones, installs an app every two minutes
US Senator Wyden: Why I had to halt FBI’s latest internet spying push
Thousands of CCTV Devices Found DDoSing Small-Business Websites