Menu

Latest articles

Managing agile virtual machine security across the enterprise: A closer look

Moving security to different digital intersections may serve to reduce the load on the endpoint – thereby avoiding duplicate scans, say, during a malware storm. However, it is just as important to understand how and when an agile approach to deploying your network defenses in real-time should be performed, and how attacks might dictate that approach. […]

PHP ransomware attacks blogs, websites, content managers and more…
Apple and FBI testify in hearing on locked iPhone: What we learned
IRS issues warning to HR professionals over phishing scam

��}ے�8�������I]��*K>v�=]s|�u�����U@”$��”i�*��]�{“v#�6b���̗l&R�E�R���=�L� $��D”�H<�����O_�߽z�����Q<���YLyQ�}�8�m���b��ƻY�4���Z̮buY�Qi��C��3㒅���”��@����ߦ����p��j>�)k^g’�SzZ�����~�uQ��8���cӘ�������A������qs���ao�^o��p�l���FK�”��t�mkQg��?��?��ϵ�x8�|FF4″6�a�p�Z��QD:2�����t��y�N�eK�ةr�),j�O� z4 ]�’�?�HwQ�4~b�%4N�d�u%/���xͦ��*��n��Q��Qo�k����V�!�]�/7�m��ˡ��4�C��Py��3�C��*Zy�>��t�’��B`�����PiN(��/0�a����0�3mA�?�-����΂PH���Ņ������Ղ�_��O�h�+:�F�E~�i��oH�N��g�i !�T��rN/�x�u�ĝ������N6�ϝ3�@��g�G#�t���/�/VdNM?�bqrD�X}?d�X��/�~�j���4h ���7��? �L;�Ag���U��D���x}wbcK��+0u3��Coϣ’@���4���#�ֽ���*�Bk�Z��9�M� �~��!�{&�2{������:Z�f�����ʾ� � X�������b ��C��nS�����`� �A菏�?�mV��m���v��Z�߯��z��7c�9���/+U�e�0uZ�U=�>�j�JX�{�=�F���^ �_kTM���C�c�zx�q�Ҕ-��d��Qߌ�~�”���X�a��^�l�_�HT4iUhդA�<�x�v�_���!B�� �ڟ#g��cC�� ��/8��׀��7���Y�^~��xL]�G��q��Ղu��4c ���+���o�a@v�Զ_B_:6�T��*�,�x/A{0[� k��-)��E~��qL�#^����Ŷ�_8vQ��E�[MA�; J8�'zr�e���~U�� 3B����um`*���U2���Sj�f�P���>kOu��ϗ�:q�����#5a��*�U’b��=?�9V�~�X�ћ*|+�k��sů��Փ���RՉ�~OPU��`�������G,�Cޮ’�L�V���K�pQJP���v�™;q�����l@’n��E� �Xѣ��-Q��T�)��h�6��o�P����l��}�L���!��, @Q@�m#�w����=ߏ�8��v�CWj �����z�H��=�4a��LTAj�������v찡ζ��dz w{F#���ó�}�����g���P�i�endHE};�:��{�(����X�����(]�jP�9���#j�ߵ��HX�eϷg$Il�6s�Vv�#��������.�O5=U煞[-���i����D� ;O(�h�M�3_/|�v��3q7J�z�F�Lιqq��Cw@�,�@ɠQ��u�]����} J����h��Mw�A�n�B���S��+wL�0�^�]�ע_��=;#M�N~`�� �^E&�ݛ��BB�0=��.��%4�-�y1����m`�(��P뤒,7�e��J�BБ��>�6I�����HE��&>V�Dg@*���r�H K@�l�a&��sJ�R�`��7)t���p²_@��nY����0?���D�u/x�G*$J�[).�Ӫ�)��׾�LX�?c?dl�F�9� ��_���`�*tX�:W�=�������G����G�$�u�”��ύ̇��2I+`f�/�і��ix��Z6��8�����cg<$�M��q����4�Y��%��ih!r^��FJ�9���{�#v�~� �n��`�ţ0� �1�尝K���|�<��K��m��)��^�9K��B$�@��Z���Į�*~g^H���6�|0�ǖ�$kK8�/��_ zc��x�[Б�e�liྐ/e�pp�S� Vz�;^x�B���wi���G/q��|A����}5 o�)q>��N�O5�ʗɗ��B�&�5ƶ�?DcxdEeͥ�&���tS�� F{�$6&���O� y8$O�- �@o����},�q��� ��}ے�8�������I]��*K>v�=]s|�u�����U@”$��”i�*��]�{“v#�6b���̗l&R�E�R���=�L� $��D”�H<�����O_�߽z�����Q<���YLyQ�}�8�m���b��ƻY�4���Z̮buY�Qi��C��3㒅���”��@����ߦ����p��j>�)k^g’�SzZ�����~�uQ��8���cӘ�������A������qs���ao�^o��p�l���FK�”��t�mkQg��?��?��ϵ�x8�|FF4″6�a�p�Z��QD:2�����t��y�N�eK�ةr�),j�O� z4 ]�’�?�HwQ�4~b�%4N�d�u%/���xͦ��*��n��Q��Qo�k����V�!�]�/7�m��ˡ��4�C��Py��3�C��*Zy�>��t�’��B`�����PiN(��/0�a����0�3mA�?�-����΂PH���Ņ������Ղ�_��O�h�+:�F�E~�i��oH�N��g�i !�T��rN/�x�u�ĝ������N6�ϝ3�@��g�G#�t���/�/VdNM?�bqrD�X}?d�X��/�~�j���4h ���7��? �L;�Ag���U��D���x}wbcK��+0u3��Coϣ’@���4���#�ֽ���*�Bk�Z��9�M� �~��!�{&�2{������:Z�f�����ʾ� � X�������b ��C��nS�����`� �A菏�?�mV��m���v��Z�߯��z��7c�9���/+U�e�0uZ�U=�>�j�JX�{�=�F���^ �_kTM���C�c�zx�q�Ҕ-��d��Qߌ�~�”���X�a��^�l�_�HT4iUhդA�<�x�v�_���!B�� �ڟ#g��cC�� ��/8��׀��7���Y�^~��xL]�G��q��Ղu��4c ���+���o�a@v�Զ_B_:6�T��*�,�x/A{0[� k��-)��E~��qL�#^����Ŷ�_8vQ��E�[MA�; J8�'zr�e���~U�� 3B����um`*���U2���Sj�f�P���>kOu��ϗ�:q�����#5a��*�U’b��=?�9V�~�X�ћ*|+�k��sů��Փ���RՉ�~OPU��`�������G,�Cޮ’�L�V���K�pQJP���v�™;q�����l@’n��E� […]

FBI director admits mistake was made with San Bernardino iCloud reset
As encryption debate rages, inventors of public key encryption win prestigious Turing Award
Is a Facebook friend tracking your sleeping habits?
NSA seeks to combine offense and defense in its spy efforts
Brothers jeer judge on Facebook, get sent to jail
RSA: Can crypto save your life?

The stage is set: the wily Apple facing off against the heavyweight FBI bruiser. The contest: industry argues unbreakable crypto should be just that – unbreakable. In the other corner, the suits at the FBI argue that if someone REALLY needs to know what’s on your phone, there needs to be a way to know. […]

Review: 5 application security testing tools compared
RSA president slams crypto backdoors as useful only against petty criminals
DROWN Attack – More than 11 Million OpenSSL HTTPS Websites at Risk

Discovered: March 2, 2016 Updated: March 2, 2016 3:55:49 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows NT, Windows Vista, Windows XP Trojan.Ransomcrypt.AE is a Trojan horse that encrypts files on the compromised computer and asks the user to pay in order to decrypt them. For […]

Discovered: March 2, 2016 Updated: March 2, 2016 9:33:30 PM Type: Trojan Systems Affected: Linux, Mac OS X, Solaris, Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Vista, Windows XP Java.Bozmub is a Trojan horse that may steal information from the compromised computer and download malicious files. Antivirus Protection Dates […]

Stephane Chazelas discovered a bug in the environment handling in Perl. Perl provides a Perl-space hash variable, %ENV, in which environment variables can be looked up. If a variable appears twice in envp, only the last value would appear in %ENV, but getenv would return the first. Perl’s taint security mechanism would be applied to […]

Several vulnerabilities were discovered in OpenSSL, a Secure Socket Layer toolkit. CVE-2016-0702 Yuval Yarom from the University of Adelaide and NICTA, Daniel Genkin from Technion and Tel Aviv University, and Nadia Heninger from the University of Pennsylvania discovered a side-channel attack which makes use of cache-bank conflicts on the Intel Sandy-Bridge microarchitecture. This could allow […]

The DROWN security hole – what you need to know
OpenSSL update fixes Drown vulnerability
FBI director admits mistake in San Bernardino iCloud reset
New TLS decryption attack affects one in three servers due to legacy SSLv2 support
Snapchat staff payroll data leaked in phishing scam

��}�r۸���j�aN��D$u�-��|��9���mc��ΗdU I�)��Ų&���g�߼�V�̾�y��@�7ɲ�dfv���”�F���h4��{O_���������ww����!uG]��ڻ��ڗ]��q���|}�7��@�;GcF��x��MXDyQ�}�틮r�s#�t�3���WW��ed`���!��q4��b���W��c�؛�4�N��g]f�X��K’���l�{A�)=��hܵ؅m2��h۵#�:ZhR�u[U�F�7r���.X`m�����M/�s�K����]�e�EYk��?y>xC�4l����l_vΫZ��Ա-1��ʀ=~��������{��iu~��m6[{�??�}�����0�=’s�J��D@Iv32a�M���.|�@w9���T�2Ǿ`!3��f��M���I��h�&,4�;�f�4K��E��G�4���� ����=�a��ј0�M��=���a���� #:���q����s�h���c��ɑ!���R�b��~a�R�c (Q����)�C{�{aj&u=��YmX��֮��͖ʮi�p�DLC�5A8-������$��gA4���x( �1���t�mD�鰅�q���c��^�/3��’���v�>�N��ym��xe]9��a���4Zŏ�Ƭ>(�l��A��њ����As�`��f�� n�Y���C{x��[K��X�oǞ�[yT3:6n�V��Q����Q�}��”P���& �L�a��o���3�]˛���&ޙ}¢F”$]�YА��x z���`��T����’�`�^�>��c�}���`( ��j���G�Łɔ�� t7^:������k:��-������T�;}�=�M�����ruu�ݺ7�]�k�1h����ob�h�� �������p��(��5����|mmeՔ������ڲ��8���Q�ұ�@ , ���+ (����H:m��s���X5�~�-#�����CP�0Y�0��D*�N�� ���˷tֽׂ_>S�P�2N�s�`�%��6�E� ���km���]��:��g��v�͂G��-˵�P’�R�ƽV�A+ʢ‘�aġDQs��ϕ���v���R�@C����AX���u�C�”X�]�W�2#$��_?_5�zF��Z�w�`�K���5ԣ�|�a9����T�^�� ]հ�,�� `�*HMK�ٺ���n�Q�y�lsxK��p7Ga4�X�9_�³T�S�j�������u”�����ja��r��’������ i�M�cVa��*����8pQ�r�8�mW/�Q�(�̍���_n�Fy�J/�d�9-�4’5P?����p�tI���_��Jj��]��c�PT���v������Bf2���*%)Fxy�BWL�1����aS�`���l2�)�u�ķ�^�,T�x䐨to���o~L����s_y�Ax`��� ��հ� �gh�G�J�ſ�q8��Wa��ƾd�sKm����o>|�i�o�a�y�J�^�k�!O��ȼ�X,��f�y� ����>n8û�W�����ד���Ɉ7IWi)D��0WQg����gЧ�p��y9�)d�(x|Z�������;���H�� �GW��c�a���-��y^�s[0J (�S0���q���P2�`�l�’��V �Չ�;�BT���5�n#7ؖ,’XY��u�{�r8�8��h�:ҽh�������U��$w�SҢvBKj�~�����w�A��%ua��F|̰�0B�C-BC”:��*|��P����޼|���ww�j��լd��;��z�`l[�/0Ԣ����Kh+0BҪ��s8��!g�z�u��E��:+���k!�� A�4�]e���x�r_P����|_���(���O�N�M�*�)���B�b�hK{�� <.�.ê�Rp���+/�ؽ#JV����#-��&x�o�;�!y:2(�3�`N:3�X�����E������P�”D������G"�<;yv��~���k@� 3�[ޜ�m�c���<��5����n� ���*T��"&�tn���.�X DxHD�Y�|%/x�pΒX�6KX�X�s�ܶp�|V0�1�6��@t����j+�Pa��P9�s���0����Pz/$�P#�qAB-�A��K%5��5K1�j0��d�y�HЮ

5 ways to stop malware in the cloud
Spam offering fake Visa benefits, rewards leads to TeslaCrypt ransomware
Malvertising campaigns are becoming harder to detect
Verizon releases first-ever data breach digest with security case studies
Say hello to Kiddle: the child-protecting search engine
Companies detect breaches sooner, but attackers have gotten nastier
Microsoft unveils Windows 10 feature to stymie advanced hack attacks
Surveillence outfit Hacking Team may have released a new piece of OS X malware
Public Facebook event for house party leads to berserk scenes
Why the feds’ iPhone-cracking loss is our gain
Cybercriminals face hacker talent shortage
SSL visibility: decrypt and conquer
More than 11 million HTTPS websites imperiled by new decryption attack
How hackers are making the worst-case security scenario ever worse
Joomla Sites Join WordPress As TeslaCrypt Ransomware Target
Some websites turning law-abiding Tor users into second-class citizens
Judge confirms CMU researchers were paid to unmask Tor users
The Sony Hackers Were Causing Mayhem Years Before They Hit the Company
Nissan Leaf hackable through insecure APIs
How the FBI could use acid and lasers to access data stored on seized iPhone
Asus lawsuit puts entire industry on notice over shoddy router security
Ricochet – Most Secure Peer-to-Peer Encrypted Messenger that Sends No Metadata

Discovered: March 1, 2016 Updated: March 1, 2016 2:44:09 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Backdoor.Elpman is a Trojan horse that opens a back door on the compromised computer. Antivirus Protection […]

Markus Krell discovered that xymon, a network- and applications-monitoring system, was vulnerable to the following security issues: CVE-2016-2054 The incorrect handling of user-supplied input in the config command can trigger a stack-based buffer overflow, resulting in denial of service (via application crash) or remote code execution. CVE-2016-2055 The incorrect handling of user-supplied input in the […]

Multiple security vulnerabilities have been found in Pillow, a Python imaging library, which may result in denial of service or the execution of arbitrary code if a malformed FLI, PCD or Tiff files is processed. For the oldstable distribution (wheezy), this problem has been fixed in version 1.1.7-4+deb7u2 of the python-imaging source package. For the […]

Multiple security vulnerabilities have been found in the Drupal content management framework. For additional information, please refer to the upstream advisory at https://www.drupal.org/SA-CORE-2016-001 For the oldstable distribution (wheezy), this problem has been fixed in version 7.14-2+deb7u12. For the stable distribution (jessie), this problem has been fixed in version 7.32-1+deb8u6. For the unstable distribution (sid), this […]

IBM to buy Resilient Systems, bringing security guru Bruce Schneier on board
Node.js 5.7 released ahead of impending OpenSSL updates
Five things you need to know about the EU-US Privacy Shield agreement
UC Berkeley makes third data breach disclosure in past 15 months
The “HawkEye” attack: how cybercrooks target small businesses for big money
Apple spells out what it would take to comply with government’s iPhone order
Google knows where your photos were taken
5 threats every company needs to pay attention to
How mobile apps leak user data that’s supposedly off-limits
Tor users being actively blocked on some websites
“Acceptable Ads”: Are there any? And who gets to monetize them?
How to avoid common travel and vacation scams
IRS: Actually, that breach last year was way worse than we thought
Disney rumored to be using anti-drone drones to protect Star Wars filming
Going to RSA? Get exclusive free swag!
UC Berkeley hit with another cyberattack

The University of California (UC), Berkeley, has revealed that it was the victim of a major cyberattack. It explained that the incident, which took place in December 2015, has affected close to 80,000 current and former members of staff and students. The victims have been notified with notice letters, which includes details about free credit […]

Monday review – the hot 24 stories of the week
Encryption still a low priority for too many cloud users
Most software already has a “golden key” backdoor: the system update
Hackers did indeed cause Ukrainian power outage, US report concludes

It was discovered that php-horde, a flexible, modular, general-purpose web application framework written in PHP, is prone to a cross-site scripting vulnerability. For the stable distribution (jessie), this problem has been fixed in version 5.2.1+debian0-2+deb8u3. For the testing distribution (stretch), this problem has been fixed in version 5.2.9+debian0-1. For the unstable distribution (sid), this problem […]

It was discovered that php-horde-core, a set of classes providing the core functionality of the Horde Application Framework, is prone to a cross-site scripting vulnerability. For the stable distribution (jessie), this problem has been fixed in version 2.15.0+debian0-1+deb8u1. For the testing distribution (stretch), this problem has been fixed in version 2.22.4+debian0-1. For the unstable distribution […]

Two SQL injection vulnerabilities were discovered in cacti, a web interface for graphing of monitoring systems. Specially crafted input can be used by an attacker in parameters of the graphs_new.php script to execute arbitrary SQL commands on the database. For the oldstable distribution (wheezy), these problems have been fixed in version 0.8.8a+dfsg-5+deb7u8. For the stable […]

Fixing the Internet’s routing security is urgent and requires collaboration

Intro from the 2016 Threat Brief: “2015 was yet another record year for cybercrime, during which more malware, malicious IPs, websites, and mobile apps were discovered than in any previous year. It comes as no surprise that the cybercrime ecosystem continues to thrive, given new innovations and little in the way of risk for those […]

Get into RSA 2016 free, meet our experts, hear great talks!
Why cybercrime isn’t fun and (video) games

For young people, the Internet can be a vital source of information, recreation, escape and more, but without the right guidance it can also be unsafe. Online games particularly make prime targets for cybercriminals, and there are also concerns that gaming networks can lead players astray, or even act as a criminal breeding ground. Whatever the reasons might […]

Apple will unbrick iPhones bricked by “1970” bug
Apple responds in iPhone unlocking case: US seeks “dangerous” powers
Facebook, Google, Microsoft to join tech industry in supporting Apple in court
Hospitals vulnerable to cyber attacks on just about everything
FBI, keep out! How to encrypt everything
Computers can tell if you’re bored

A lot happens in the security world and many stories get lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. Linux Distro Compromised This week, one of the largest Linux distro’s for Mint was targeted […]

Discovered: February 26, 2016 Updated: February 26, 2016 6:06:10 PM Type: Trojan Infection Length: Varies W97M.Downloader.F is a Word macro Trojan that downloads additional malware. For more information, please see the following resources: Antivirus Protection Dates Initial Rapid Release version February 26, 2016 revision 024 Latest Rapid Release version February 26, 2016 revision 024 Initial […]

Gustavo Grieco discovered that xerces-c, a validating XML parser library for C++, mishandles certain kinds of malformed input documents, resulting in buffer overflows during processing and error reporting. These flaws could lead to a denial of service in applications using the xerces-c library, or potentially, to the execution of arbitrary code. For the oldstable distribution […]

Daniel Gultsch discovered a vulnerability in Gajim, an XMPP/jabber client. Gajim didn’t verify the origin of roster update, allowing an attacker to spoof them and potentially allowing her to intercept messages. For the oldstable distribution (wheezy), this problem has been fixed in version 0.15.1-4.1+deb7u1. For the stable distribution (jessie), this problem has been fixed in […]

Multiple security issues have been found in Icedove, Debian’s version of the Mozilla Thunderbird mail client: Multiple memory safety errors, integer overflows, buffer overflows and other implementation errors may lead to the execution of arbitrary code or denial of service. For the oldstable distribution (wheezy), these problems have been fixed in version 38.6.0-1~deb7u1. For the […]

APPLE-SA-2016-02-25-1 Apple TV 7.2.1 Subject: APPLE-SA-2016-02-25-1 Apple TV 7.2.1 From: Apple Product Security <email@hidden> Date: Thu, 25 Feb 2016 10:58:54 -0800 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-02-25-1 Apple TV 7.2.1 Apple TV 7.2.1 is now available and addresses the following: bootp Available for: Apple TV (3rd Generation) Impact: A malicious Wi-Fi network may be […]

Apple appeals order to unlock iPhone, saying it would ‘violate the Constitution’
Microsoft strengthens security tools for Azure, Office 365
Nissan LEAF cloud security fail leaves drivers exposed
Why Facebook is using satellites to map every building in 20 countries
Tim Cook: The FBI is asking us to write the software equivalent of cancer
With few options, companies pay hush money to data thieves
Lawmakers push for encryption commission to find compromise
Breach of millions of kids’ images and messages sparks disclosure spat at uKnowKids
Exclusive: Go inside a security operations center
Celebrity nude photo hacker pleads guilty