Hacking

Pierluigi Paganini November 01, 2018
Cyber Defense Magazine – November 2018 has arrived. Enjoy it!

Cyber Defense Magazine November 2018 Edition has arrived. Sponsored by: Bosch We hope you enjoy this month’s edition…packed with 100+ pages of excellent content.  InfoSec Knowledge is Power. We have nearly 7 years of eMagazines online with timeless content.  Visit our online library by clicking here. Please tell your friends to subscribe – no strings, always free emagazines: […]

Pierluigi Paganini October 31, 2018
85 Millions of voter records available for sale ahead of the 2018 US Midterm Elections

Ahead of the 2018 US midterm elections, sellers are flooding the cybercrime underground markets with data from voter databases. Experts at cybersecurity company Carbon Black found tens of different state voter databases available for sale on the dark web. “Carbon Black researchers found 20 different state voter databases available for purchase on the dark web, several from swing states.” […]

Pierluigi Paganini October 30, 2018
A few hours after Apple released iOS 12.1, a researcher presented a Passcode Bypass issue

A few hours after Apple released iOS 12.1 the iPhone bug hunter Jose Rodriguez has found a new passcode bypass issue that could be exploited to see all contacts’ private information on a locked iPhone. “Jose Rodriguez, a Spanish security researcher, contacted The Hacker News and confirmed that he discovered an iPhone passcode bypass bug in the […]

Pierluigi Paganini October 30, 2018
Girl Scouts data breach exposed personal information of 2,800 members

A Girl Scouts of America branch in California suffered a security breach, hackers accessed data of 2,800 girls and their families. Hackers breached the Orange County, Calif. branch of the Girl Scouts of America, potentially exposing personal information for 2,800 members and their families. According to the Girl Scouts of Orange County, an unknown threat […]

Pierluigi Paganini October 30, 2018
Windows Defender is the first antivirus solution that can run in a sandbox

Windows Defender, the Windows built-in anti-malware tool, implemented the ability to run in a secure sandbox mode. The mechanisms allow detonating an application in a safe environment that is isolated from the operating system and other applications. This means that even if the application is compromised it will not affect the overall system if it […]

Pierluigi Paganini October 30, 2018
Recently discovered DemonBot Botnet targets Hadoop servers

Security experts from Radware have spotted a new botnet dubbed DemonBot that it targeting Hadoop clusters to launch DDoS attacks against third parties. Operators behind the DemonBot botnet target an unauthenticated remote command execution in Hadoop YARN (Yet Another Resource Negotiator). DemonBot bot only infects central servers, at the time of the report experts found over 70 active exploit servers […]

Pierluigi Paganini October 29, 2018
Systemd flaw could cause the crash or hijack of vulnerable Linux machines

Systemd is affected by a security vulnerability that can be exploited to crash a vulnerable Linux machine, and in the worst case to execute malicious code. An attacker can trigger the vulnerability using maliciously crafted DHCPv6 packets and modifying portions of memory of the vulnerable systems, potentially causing remote code execution. The flaw, tracked as CVE-2018-15688, […]

Pierluigi Paganini October 29, 2018
Crooks continue to abuse exposed Docker APIs for Cryptojacking

Cybercriminals continue to abuse unprotected Docker APIs to create new containers used for cryptojacking, Trend Micro warns. Crooks continue to abuse unprotected Docker APIs to create new containers used for cryptojacking. Earlier this year Sysdig and Aqua Security researchers started observing cyber attacks targeting Kubernets and Docker instances aimed at mining Monero cryptocurrency. A container is […]

Pierluigi Paganini October 28, 2018
Security Affairs newsletter Round 186 – News of the week

A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. Let me inform you that my new book, “Digging in the Deep Web” is online with a special deal 20% discount Kindle Edition Paper Copy Once again thank you! ·      DarkPulsar and other NSA hacking tools used […]

Pierluigi Paganini October 28, 2018
How to deliver malware using weaponized Microsoft Office docs embedding YouTube video

Researchers at Cymulate security firm devised a new stealthy technique to deliver malware leveraging videos embedded into weaponized Microsoft Office Documents. The technique could be used to execute JavaScript code when a user clicks on a weaponized YouTube video thumbnail embedded in a Weaponized Office document. Experts pointed out that no message is displayed by […]