Menu

Latest articles

Facebook’s Twin in North Korea Identified and Hacked within a Single day
Revealed: 65 million Pre-Yahoo Acquisition Tumblr Accounts Were Hacked
Anonymous Did Not Release Donald Trump’s Tax Returns
65 million Tumblr users should probably be careful…

Earlier this month, Tumblr revealed that it had recently become aware that user addresses and salted and hashed passwords dating back to 2013 had fallen into the hands of hackers. We recently learned that a third party had obtained access to a set of Tumblr user email addresses with salted and hashed passwords from early […]

How to protect your Hootsuite account from hackers

Risk Level: Very Low. Type: Trojan.

What the CISSP? 20 years as a Certified Information Systems Security Professional

CISSP stands for Certified Information Systems Security Professional, a qualification that I obtained on this day in 1996. Back then, very few people had heard of CISSP or the organization that created it, the International Information Systems Security Certification Consortium. This non-profit professional body is known as (ISC)2 which is pronounced “I-S-C-squared” (because the name […]

Researchers Validate Link Between Cancer and Cellphone Radiations
MySpace Hacked, 427 Million Users’ Emails Passwords Dumped Online
Pakistan’ Real Estate Giant Zameen.com Hacked, Entire Database Leaked
Researcher Pockets $30,000 in Chrome Bounties
Reddit forces password reset of 100,000 users

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Worm.

Fiverr Removes Attacker’s Adverts, Gets Non-stop DDoS Attacks
Reddit Hacking Saga Continues As Company Resets 100k Passwords

Ubuntu: 2985-2: GNU C Library regression Posted by Anthony Pell    USN-2985-1 introduced a regression in the GNU C Library. ========================================================================== Ubuntu Security Notice USN-2985-2 May 26, 2016 eglibc, glibc regression ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: […]

Discovered: May 26, 2016 Updated: May 26, 2016 5:44:20 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Zekapab is a Trojan horse that downloads potentially malicious files and steals information from […]

Discovered: May 26, 2016 Updated: May 26, 2016 8:16:42 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Backdoor.Zekapab is a Trojan horse that opens a back door on the compromised computer and may perform […]

Government IT Systems Long Outdated In a recent study done by the Government Accountability Office, a large portion of the US government’s critical business systems have been found to be requiring an increasing amount for maintaining their basic operation, but also they are a major security risk. From defense systems to scientific research systems, these […]

What Controls the US Nuclear Operation? Floppy Disks and Outdated Computers
New JavaScript spam wave distributes Locky ransomware
Aerospace firm loses $47 million in cyber fraud, fires CEO
How to better protect your Tumblr account from hackers with two-step verification (2SV)
Beware the Android Adult Player app – ransomware lies within!
Decision makers at banks ‘in the dark’ about data breaches

Decision makers at banks are in the dark when it comes to data breaches at their organization, according to KPMG’s 2016 Banking Outlook Survey. It revealed that this is especially the case when it comes to the second tier of senior management. For example, while 12% of CEOs were unaware as to whether their networks […]

Major DNS provider hit by mysterious, focused DDoS attack
Hacker faces 10 years in prison for hacking highway sign with “Drive Crazy Yall”
FBI refuses to release Tor exploit details, evidence thrown out of court
5 active mobile threats spoofing enterprise apps

Several vulnerabilities were discovered in libgd2, a library for programmatic graphics creation and manipulation. A remote attacker can take advantage of these flaws to cause a denial-of-service against an application using the libgd2 library. For the stable distribution (jessie), these problems have been fixed in version 2.1.0-5+deb8u3. For the unstable distribution (sid), these problems have […]

South Korean Air Force Website Faces Cyber Attack
Google’s Abacus API adds security by subtracting passwords
PayPal Users Hit with ”Account Limitation” Phishing Scam

An update for rh-mariadb100-mariadb is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: rh-mariadb100-mariadb security update Advisory ID: RHSA-2016:1132-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2016:1132 Issue date: 2016-05-26 CVE Names: CVE-2015-3210 CVE-2015-3217 CVE-2015-4792 […]

Ubuntu: 2985-1: GNU C Library vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the GNU C Library. ========================================================================== Ubuntu Security Notice USN-2985-1 May 25, 2016 eglibc, glibc vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS […]

Ubuntu: 2950-5: Samba regression Posted by Anthony Pell    USN-2950-1 introduced a regression in Samba. ========================================================================== Ubuntu Security Notice USN-2950-5 May 25, 2016 samba regression ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS Summary: USN-2950-1 introduced a regression in Samba. […]

Slackware: 2016-145-01: libarchive: Security Update Posted by Anthony Pell    New libarchive packages are available for Slackware 14.1 and -current to fix a security issue. [More Info…] [slackware-security] libarchive (SSA:2016-145-01) New libarchive packages are available for Slackware 14.1 and -current to fix a security issue. Here are the details from the Slackware 14.1 ChangeLog: +————————–+ […]

Red Hat: 2016:1106-01: jq: Moderate Advisory Posted by Anthony Pell    An update for jq is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: jq security update Advisory ID: RHSA-2016:1106-01 Product: Red Hat […]

Several security issues were fixed in PHP. ========================================================================== Ubuntu Security Notice USN-2984-1 May 24, 2016 php5, php7.0 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several security issues were fixed in PHP. Software Description: […]

An update for kernel is now available for Red Hat Enterprise Linux 6.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security, bug fix, and enhancement update Advisory ID: RHSA-2016:1100-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1100.html […]

GDPR Day: countdown to a global privacy and security regimen?

On this day, May 25, in the year 2018, the General Data Protection Regulation will go into effect. Commonly referred to as GDPR or the Regulation, this set of rules governing the privacy and security of personal data is being laid down by the European Commission, but it has serious implications for companies in countries […]

Another malware wave hits Europe, mainly downloading ransomware Locky

ESET LiveGrid® telemetry shows a spike in detections of the JS/Danger.ScriptAttachment malware in several European countries. The most notable detection ratios are seen in Luxembourg (67%), Czech Republic (60%), Austria (57%), Netherlands (54%) and the UK (51%), but also in other European states. After arriving as an email attachment, the threat behind these detections is designed […]

Leading DNS Provider NS1 Targeted with DDoS Attacks
Hire a DDoS attack for as little as five dollars
What’s old is new again with MIT’s latest bug finder
VIDEO: Should you really change your passwords frequently?
Researcher warns of ‘pastejacking’ hack attacks targeting users’ clipboards
Twitter accounts are getting hacked and spreading adult content
Tor Developers collaborate to accelerate development of Next Gen Onion Service
Good Bye Passwords as Google Plans a Different Verification Option
Paul Vixie on IPv6 NAT, IPv6 security and Internet of Things

Risk Level: Very Low. Type: Trojan.

Cyber Criminals Targeting Users with WhatsApp Gold Version Malware Scam
PGP co-founder rejoins Apple to bring better encryption to the masses
The Answer is always the same: Layers of Security
Expert insight from the author of the ESET TeslaCrypt decryptor

Our news about ransomware TeslaCrypt operators shutting up shop attracted a lot of attention and prompted several additional questions. So we’ve approached the best-placed person to address them – Igor Kabina, the ESET malware researcher who first noticed that things had started to change around TeslaCrypt ransomware and ultimately created the universal ESET TeslaCrypt decryption […]

Apple hires mobile encryption pioneer amid encryption debate
Don’t want ransomware to rock your universe? Add this to your towel

What is the most important thing you should take with you on a cosmic trip? As highlighted by an annual celebration on May 25th, dubbed Towel Day, it is the humble towel. As the late author Douglas Adams put it in his famous Hitchhiker’s Guide to the Galaxy: “A towel, it says, is about the […]

Linux 4.7 Gets a Security Boost with ChromeOS Feature
LinkedIn password change flaw poses threat to at-risk accounts
Download VASCO’s Mobile Banking Security eBook [Sponsor]
Facebook Facing Lawsuit for Scanning Users’ Private Messages for Likes

Discovered: May 25, 2016 Updated: May 25, 2016 11:17:28 AM Type: Trojan Infection Length: 126,976 bytes Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Backdoor.Psiload is a Trojan horse that opens a back door on the compromised […]

Discovered: May 25, 2016 Updated: May 25, 2016 1:22:17 PM Also Known As: Bloccato [Trend] Type: Trojan Infection Length: Varies Systems Affected: Windows 7, Windows 8, Windows Vista Trojan.Ransomcrypt.AV is a Trojan horse that encrypts files on the compromised computer and asks the user to pay in order to decrypt them. Antivirus Protection Dates Initial […]

Risk Level: Very Low. Type: Trojan.

Watchout for this USB Device Charger, it could be Keystroke Logger: FBI

It was discovered that a buffer overflow in the XMLRPC response encoding code of the Atheme IRC services may result in denial of service. For the stable distribution (jessie), this problem has been fixed in version 6.0.11-2+deb8u1. For the testing distribution (stretch), this problem has been fixed in version 7.0.7-2. For the unstable distribution (sid), […]

Red Hat: 2016:1098-01: jq: Moderate Advisory Posted by Anthony Pell    An update for jq is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: jq security update Advisory […]

Red Hat: 2016:1099-01: jq: Moderate Advisory Posted by Anthony Pell    An update for jq is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: jq security update Advisory […]

Debian: 3586-1: atheme-services: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3586-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 23, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : atheme-services CVE ID : CVE-2016-4478 It was discovered that a buffer overflow in the XMLRPC response encoding code of the Atheme IRC services may result […]

An update for kernel is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2016:1096-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1096.html Issue […]

By the numbers: Cyber attack costs compared
Microsoft has a dirty little Windows 10 upgrade trick up its sleeve
How to protect your LinkedIn account from hackers with two-step verification (2SV)
New DMA Locker ransomware is ramping up for widespread attacks
Critical infrastructure: It’s time to make security a priority

��ݒ�F�0x-E�J���O�b�Z�Xg%[������Ej���lZVļ��칛۽܈}���d�d3�����lJ�7�K P�U������������N����3���W/����h�L=����_����ˆ�ܫ~-�I�����Cs�-?�_�:wM��߁’��є’65�/�{ٯ�~���x;y� ů~-�W�� ‘v�

Poisoned Word document attack refuses to work if it believes it is being watched
New Surveillance System May Let Cops Use All of the Cameras
Boston BSides needs more space to grow
Where Should Security Keys be Kept in the Cloud?
5 steps to stronger data security

Nearly everything we do in computer security is meant to protect data. After all, we don’t deploy antimalware software, tighten security configurations, or implement firewalls to protect users, per se. Job No. 1 is to protect the organization’s data — including employee and (especially) customer data. But guess what? People need to work with that […]

20 million Instagram accounts were put at risk through sloppy security hole

Risk Level: Very Low. Type: Trojan.

Hacker Sentenced for Reporting Flaws in Police Communications System
Teenager charged over Mumsnet hack and DDoS attack

Multiple vulnerabilities were discovered in the dissectors/parsers for PKTC, IAX2, GSM CBCH and NCP which could result in denial of service. For the stable distribution (jessie), these problems have been fixed in version 1.12.1+g01b65bf-4+deb8u6. For the testing distribution (stretch), these problems have been fixed in version 2.0.3+geed34f0-1. For the unstable distribution (sid), these problems have […]

Hackers Destroy Fur Affinity Art Gallery Website

Debian: 3585-1: wireshark: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3585-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 22, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : wireshark CVE ID : CVE-2016-4006 CVE-2016-4079 CVE-2016-4080 CVE-2016-4081 CVE-2016-4082 CVE-2016-4085 Multiple vulnerabilities were discovered in the dissectors/parsers for PKTC, IAX2, GSM CBCH and NCP which […]

Slackware: 2016-141-01: curl: Security Update Posted by Anthony Pell    New curl packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. [More Info…] [slackware-security] curl (SSA:2016-141-01) New curl packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. Here are […]

LinkedIn’s poor handling of 2012 data breach comes back to haunt it
Recently patched Flash Player exploit is being used in widespread attacks
How data virtualization delivers on the devops promise
VIDEO: How one ISP discouraged users from enabling two-step verification
Criminals Steal 1.44 billion Yen ($13 million) from 1,400 ATMs in 2½ hours

Risk Level: Very Low. Type: Trojan.

Attackers can pwn 60% of Android phones using critical flaw
How to review your privacy on Windows 10
Stay Away from Google’s New Messaging App Allo—Alerts Edward Snowden
Teacher’s Email Hacked, Distributes Porn to Staff, Students and Parents