Hacking

Pierluigi Paganini June 29, 2017
Notpetya – The Petya variant used in the massive attack is a wiper disguised by a ransomware

According to the researchers, the Petya variant (NotPetya) used in the massive attack is a wiper disguised by a ransomware. In these hours the massive global attack based on Petya variant made the headlines, computers in many countries were infected, including Russia, Ukraine, France, India and the US. A new analysis conducted on the ransomware […]

Pierluigi Paganini June 29, 2017
Shadow Brokers sent out first round of exploits and threaten to dox former NSA hacker

Shadow Brokers has sent out the first round of exploits to the subscribers of its service, the hackers also threaten to dox former NSA hacker. In May the notorious Shadow Brokers group announced the launch of a monthly subscription model for its data dumps, 0-Day Exploit Subscriptions goes for $21,000 per month. The group claimed […]

Pierluigi Paganini June 29, 2017
A critical flaw allows hacking Linux machines with just a malicious DNS Response

A remote attacker can trigger the buffer overflow vulnerability to execute malicious code on affected Linux systems with just a malicious DNS response. Chris Coulson, Ubuntu developer at Canonical, has found a critical vulnerability Linux that can be exploited to remotely hack machines running the popular OS. The flaw, tracked as CVE-2017-9445, resides in the Systemd init system […]

Pierluigi Paganini June 28, 2017
Experts found a critical remote buffer overflow vulnerability in Skype

The security expert Benjamin Kunz-Mejri from security firm Vulnerability Lab discovered a remote zero-day stack buffer overflow vulnerability in Skype. The security expert Benjamin Kunz-Mejri from security firm Vulnerability Lab discovered a Skype zero-day stack buffer overflow vulnerability, tracked as CVE-2017-9948, that could be exploited by a remote attacker to execute malicious code. Vulnerability Lab reported the […]

Pierluigi Paganini June 27, 2017
Human error is the root cause of password reset email sent to AA customers

UK car insurance company AA accidentally sent out a ‘password update’ email to its customers, the incident was caused by a human error. UK car insurance company AA accidentally sent out a “password update” email to its customers, the messages led the motorists to log into the motoring organization’s website to change their passwords. The concurrent […]

Pierluigi Paganini June 26, 2017
Pro-ISIS group defaced US Government websites in 3 states

Several government websites were hacked by a pro-ISIS group that is calling itself Team System DZ, including those of the Ohio Governor John Kasich. Several government websites in Ohio and Maryland, including the one belonging to Ohio Governor John Kasich, had to be shut down Sunday after being defaced by pro-ISIS hackers. The hackers breached the websites […]

Pierluigi Paganini June 26, 2017
Google Hacker found a new way to bypass Microsoft Windows Defender

The Google Project Zero expert Tavis Ormandy has found a flaw in Windows Defender that allow attackers to bypass the Microsoft anti-virus tool. The popular Google Project Zero hacker Tavis Ormandy has discovered a new bug in Windows Defender that allow attackers to circumvent the Microsoft anti-virus tool. Ormandy publicly disclosed the news of the vulnerability in […]

Pierluigi Paganini June 25, 2017
UK Parliament shut down external access to email accounts after cyberattack

The UK Parliament has suffered the biggest ever cyber attack against the email systems, it shut down external access to mitigate the threat. The UK Parliament has shut down external access to e-mail accounts on Saturday after a cyberattack. According to the authorities, the attack was “sustained and determined,” hackers launched a prolonged brute-force attack against […]

Pierluigi Paganini June 24, 2017
Stealing AES-256 keys in seconds using €200 of off-the-shelf components

Security experts at Fox‑IT have demonstrated that is possible sniff AES-256 encryption keys from a distance of one meter (3.3 feet) with a cheap equipment. Security experts at Fox‑IT have demonstrated that is possible to power a side-channel attack to wirelessly extract secret AES-256 encryption keys from a distance of one meter (3.3 feet). The […]

Pierluigi Paganini June 24, 2017
32TB of Windows 10 internal builds and portions of core source code leaked online

A massive dump of Microsoft’s confidential Windows 10 internal builds, and the source codes for private software has been leaked online. A huge trove of Microsoft internal Windows operating system builds and portions of core source code have leaked online. The news was first reported by The Register, the 32TB of official and non-public installation images […]