Breaking News

Pierluigi Paganini January 30, 2017
Last Dridex Trojan variant uses a new tactic to bypass Windows UAC

A new variant of the Dridex Trojan recently observed is leveraging a new tactic to bypass the UAC (User Account Control). Researchers at the security firm Flashpoint have discovered a new campaign leveraging on a new variant of the Dridex Trojan that uses a new tactic to bypass the UAC (User Account Control). The Dridex Trojan […]

Pierluigi Paganini January 29, 2017
Ransomware infected systems at a luxury hotel locking guests in and out of the rooms

The Romantik Seehotel Jäegerwirt 4-Star Superior Luxury Hotel was hit by a ransomware attack that locked guests in and out of the rooms. Another singular incident involved a ransomware, the victims are hundreds of guests of a luxurious hotel in Austria, the Romantik Seehotel Jäegerwirt 4-Star Superior Hotel. The guests were locked in or out of […]

Pierluigi Paganini January 29, 2017
Security Affairs newsletter Round 97 – News of the week

A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. First of all, let me inform you that at the #infosec16 SecurityAffairs was awarded as The Best European Personal Security Blog http://securityaffairs.co/wordpress/48202/breaking-news/securityaffairs-best-european-personal-security-blog.html Cyber crimes spike in England and Wales, says ONS The author of the NeverQuest banking Trojan arrested […]

Pierluigi Paganini January 29, 2017
Uber pays $9,000 bug bounty payoff for partner firm’s vulnerability

A security expert discovered a flaw in a ransomware protection service that opened Uber service, and many others, to cyber attacks. The Russian penetration tester Vladimir Ivanov from the security firm Positive Technologies has discovered a vulnerability in anti-ransomware backup service Code42. The flaw could be exploited by attackers to steal data from the organizations using […]

Pierluigi Paganini January 29, 2017
Hong Kong brokers blackmailed by hackers with DDoS Attacks

The Hong Kong Securities and Futures Commission revealed some brokerage websites have been hit by DDoS attacks and blackmailed by crooks. The Hong Kong’s SFC (Securities and Futures Commission) confirmed several brokers in the city has suffered DDoS attacks and were blackmailed by hackers. “We are alerted by the Police that some securities brokers have […]

Pierluigi Paganini January 28, 2017
CVE-2017-3792 – Cisco TelePresence MCU affected by a Remote Code Execution issue

A critical flaw tracked as CVE-2017-3792 affects three different models of the CISCO TelePresence MCU platform, MCU 5300 Series, MSE 8510 and MCU 4500. A critical vulnerability tracked as CVE-2017-3792 affects three different models of the CISCO TelePresence MCU platform. Cisco TelePresence MCU platform is a high-definition multimedia conferencing bridge that is widely adopted due to its […]

Pierluigi Paganini January 28, 2017
Europol coordinated operation against international cybercrime ring

Five members of an international cybercrime gang have been arrested as a result of an investigation coordinated by the Europol. A joint operation conducted by the Europol and the Asian law enforcement allowed to arrest five members of an international organised cybercrime gang focused on cyber attacks on ATMs, three of them have been convicted. […]

Pierluigi Paganini January 28, 2017
Business Driven Security: The Case of Building an Advanced Security Operations Centre

In the journey towards business-driven security one of the niche weapon is the roadmap to Advanced Security Operations Centre (ASOC). Now that we have gotten over from new year’s greetings– let’s get to the basics to refresh as what is required in terms of achieving maturity within your organisations. There is no doubt that this […]

Pierluigi Paganini January 27, 2017
A hacker confirmed that President Trump Twitter account is linked to a private account

A security researcher has discovered that the President Trump’s Twitter account is exposed to the risk of hack due to security misconfigurations. While the experts are warning the press about the fact that the American President Trump is still using his personal insecure Android smartphone, we have discovered that his Twitter is exposed to the risk […]

Pierluigi Paganini January 27, 2017
Hacker discovered security flaws in Amazon, Apple and Google epub services

A hacker discovered a XXE flaw in the EpubCheck library that affects major epub services causing information disclosure and denial of service conditions. The security expert and bug hunter Craig Arendt (@craig_arendt) has discovered flaws in major eBook readers including the ones commercialized by Amazon, Apple, and Google. The expert discovered different XML external entity (XXE) […]