Menu

Latest articles

East Euro crims pwning ‘high profile’ victims with Flash zero day

There’s a lot that happens in the security world, with many stories getting lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. Human Error Remains Top Security Threat In a study conducted over the course of 3 […]

Chinese loan sharks seek salacious selfies as collateral

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Russian government hackers spent a year in our servers, admits DNC
North Korea stole F-15 blueprints and 42,000 defense-related documents from South Korea
Hackers Found Their Way Inside Telegram App

Multiple security issues have been found in Icedove, Debian’s version of the Mozilla Thunderbird mail client: Multiple memory safety errors may lead to the execution of arbitrary code or denial of service. Debian follows the extended support releases (ESR) of Thunderbird. Support for the 38.x series has ended, so starting with this update we’re now […]

Microsoft June Patch Tuesday Fixes 44 Vulnerabilities
Verizon Patches Serious Email Flaw That Left Millions Exposed
It’s [insert month] of 2016, and your Windows PC can still be owned by [insert document type]
Telegram bug allows attackers to crash devices, jack up phone bills
Apple quietly launches next-gen encrypted file system
DNC Hacked, Research on Trump Stolen

Red Hat: 2016:1225-01: kernel: Important Advisory Posted by Anthony Pell    An update for kernel is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory […]

Debian: 3601-1: icedove: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3601-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 13, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : icedove CVE ID : CVE-2016-2806 Multiple security issues have been found in Icedove, Debian’s version of the Mozilla Thunderbird mail client: Multiple memory safety errors […]

Security products may seem like ‘snake oil’, but that’s OK

Risk Level: Very Low. Type: Trojan.

Buggy vote-counting software borks Australian govenment election
Someone is hacking traffic signs in US and replacing them with their own messages
Fix Coming for Flash Vulnerability Under Attack
RAA Ransomware Composed Entirely of JavaScript
Don’t run JS email attachments: ​they​ can carry potent ransomware
Clueless s’kiddies using exploit kits are behind ransomware surge
Meaningful Surveillance Reform Risks Defeat
D-Link Patches Weak Crypto in mydlink Devices
Half of Brit small biz hit by cyber crime. 10% spend zilch on infosec
Greenwich University target of revenge hack; results in huge data breach
Quantum Computation: A cryptography armageddon?

Cryptography is a cornerstone of information security. It is used to encode and decode data in order to fulfill the requirement for confidentiality, integrity, authenticity as well as non-repudiation. Together, these are frequently referred to as cryptography services. Advances in cryptanalysis, computer science and engineering are always pushing the limits of what is considered secure. […]

Yes, even smart TVs can be hit by Android ransomware
Apple looks into the benefits of differential privacy

��}��Ȳ�o��w(Ĺ�,�_�n��9�����=gv.pe�l��%�>��a:��F���7b�`�MΓlfUI֗�n�a� 8g@�����2����*�y����/o��N_�|w��4�9ġ0W��D!~���E_�&�dE��ax_�1� �*P���)���

House Poised to Advance Privacy and Defend Encryption…If Allowed to Vote
NSA Looking to Exploit Internet of Things, Including Biomedical Devices, Official Says
Hacker puts 51 million file sharing accounts for sale on dark web
Big data will fix internet security … eventually

I’ve always thought that improved computer security controls would “fix” the internet and stop persistent criminality — turns out it might be big data analytics instead. I’ve long written that only a large-scale improvement of the internet’s authentication mechanisms (that is, pervasive identity) could significantly reduce crime. If everyone on the internet had a default, […]

Man-in-the-middle biz Blue Coat bought by Symantec: Infosec bods are worried
Hack the Pentagon shutters 100 bugs
Telegram crammed: Hackers find way to send massive messages
North Korea hacks 140k computers in planned mass attacks on Seoul

Type: Vulnerability. Microsoft Windows is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Risk High Date Discovered June 14, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]

Risk High Date Discovered June 14, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]

Risk High Date Discovered June 14, 2016 Description Microsoft Windows is prone to a local privilege-escalation vulnerability that occurs in the Windows kernel. A local attacker can exploit this issue to execute arbitrary code in kernel mode with elevated privileges. Technologies Affected Microsoft Windows 10 for 32-bit Systems Microsoft Windows 10 for x64-based Systems Microsoft […]

Discovered: June 14, 2016 Updated: June 14, 2016 2:51:29 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows NT, Windows Vista, Windows XP Trojan.Cryptolocker.AR is a Trojan horse that encrypts files on the compromised computer. Symantec Security Response is currently investigating this threat and will […]

Discovered: June 13, 2016 Updated: June 13, 2016 11:42:17 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP JS.Ransomcrypt.B is a Trojan horse that encrypts files on the compromised server and downloads […]

Update your buggy Samsung PC bloatware to plug privilege bug
Forget Game of Thrones as Android ransomware infects TVs
Dell France, Ireland, Netherlands and UK Subdomains Hacked
Let’s Encrypt Accidentally Spills 7,600 User Emails
Orlando shootings bring Facebook’s safety check to US soil
Siemens Firmware Updates Patch SIMATIC Vulnerabilities

Risk Level: Very Low. Type: Trojan.

Tech Giant Microsoft Acquires Social Media Giant LinkedIn
51 Million iMesh Accounts Available on Black Market
One Year After Hack, IRS Debuts Updated Get Transcript Service
Study: Most companies can’t protect confidential documents
From Hacking into NASA to having his own TV Show, the Journey of Walter O’Brien
Tell us, evil phisherfolk: What’s wrong with Angler Exploit Kit?
Let’s Encrypt lets 7,600 users… see each other’s email addresses
Jigsaw ransomware uses live chat to relay payment instructions
Fresh hell for TalkTalk customers: TeamView trap unleashed
How to protect your Office 365 users with multi-factor authentication
Facebook activates ‘Safety Check’ after Orlando massacre
Symantec to acquire Blue Coat for $4.65 billion

Discovered: June 13, 2016 Updated: June 13, 2016 2:09:30 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP PHP.Ransomcrypt.C is a Trojan horse that encrypts files on the compromised server. Antivirus Protection […]

Anonymous Deface ISIS Twitter Accounts with Pornographic Content
Cyber Criminals Running Sophisticated Malware Campaign Via Skype
Netgear Router Update Removes Hardcoded Crypto Keys
10 security TED Talks you can’t miss
Crafty plan to give FBI warrantless access to browser histories axed

Discovered: June 10, 2016 Updated: June 10, 2016 11:27:56 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Munidub is a Trojan horse that may download potentially malicious files on the compromised computer. Antivirus Protection […]

Multiple security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors, buffer overflows and other implementation errors may lead to the execution of arbitrary code or spoofing. Wait, Firefox? No more references to Iceweasel? That’s right, Debian no longer applies a custom branding. Please see these links for further information: […]

Marcin Icewall Noga of Cisco Talos discovered an out-of-bound read vulnerability in the CInArchive::ReadFileItem method in p7zip, a 7zr file archiver with high compression ratio. A remote attacker can take advantage of this flaw to cause a denial-of-service or, potentially the execution of arbitrary code with the privileges of the user running p7zip, if a […]

Debian: 3600-1: firefox-esr: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3600-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 09, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : firefox-esr CVE ID : CVE-2016-2818 CVE-2016-2819 CVE-2016-2821 CVE-2016-2822 CVE-2016-2828 CVE-2016-2831 Multiple security issues have been found in the Mozilla Firefox web browser: Multiple memory safety […]

Debian: 3599-1: p7zip: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3599-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 09, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : p7zip CVE ID : CVE-2016-2335 Debian Bug : 824160 Marcin ‘Icewall’ Noga of Cisco Talos discovered an out-of-bound read vulnerability in the CInArchive::ReadFileItem method in […]

Discovered: June 9, 2016 Updated: June 10, 2016 1:42:34 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows NT, Windows Vista, Windows XP Trojan.Ransomcrypt.AY is a Trojan horse that encrypts files on the compromised computer and asks the user to pay in order to decrypt […]

Risk Level: Very Low. Type: Trojan.

Government regulation will clip coders’ wings, says Bruce Schneier
Decryption Utilities Unlock Files Encrypted by All TeslaCrypt Versions
Mozilla’s new fund will prevent the next Heartbleed, Shellshock
Threatpost News Wrap, June 10, 2016
32 million Twitter account credentials up for grabs – but site says it wasn’t hacked
Twitter Forces Password Reset on Some Exposed Accounts
How a boobytrapped PDF file could exploit your Chrome browser – and it’s not Adobe’s fault!
Did you know there’s a mega cybercrime backlog in Ireland? Now you do
$90K Windows Zero Day Gets a Price Cut
Securing the server programs hiding in your Docker containers
Why you don’t have to fix every vulnerability
Firefox 47 fixes 13 vulnerabilities, boosts YouTube playback, HTML5 support
Crysis creeps: Our ransomware locks network drives and PCs. Bargain
Android malware embeds into browsers, intercepts and changes URLs
EMC and VMware both suffer malicious user access messes
China pledges tighter privacy as it centralises personal health data