Breaking News

Pierluigi Paganini March 14, 2016
CVE-2013-5838 Java flaw is back two-year later due to broken patch

The patch for the critical Java CVE-2013-5838 vulnerability released by Oracle in 2013 is ineffective and can be easily bypassed. Bad news for Java users, in 2013 Oracle released a patch to fix theĀ CVE-2013-5838 vulnerability, but security experts discovered that it could be easily bypassed to compromise the latest versions of the software. This means […]

Pierluigi Paganini March 13, 2016
Reuters – Malware suspected in the Bangladesh central bank heist

Investigators suspect the attackers behind the Bangladesh central bank ‘s hack have used a malware to gather information for the Fed’s heist. One of most intriguing stories this week is theĀ hack ofĀ the Bangladesh account at theĀ Federal Reserve Bank of New York. The Bangladesh’s Finance Minister Abul Maal Abdul Muhith accused the U.S. Federal Reserve of […]

Pierluigi Paganini March 13, 2016
Security Affairs newsletter Round 51 – News of the week

A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs Anonymous hacked the Donald Trump ā€˜s voicemails The popular Romanian Hacker Guccifer will be extradited to US soon Operation Transparent Tribe targets Indian diplomats and military Which are principal cybercriminal ecosystems in the Deep Web? KeRanger, the […]

Pierluigi Paganini March 13, 2016
CISCO warns customers of high-severity flaws in modems and gateways

Cisco released a series of software updates to patch several high severity flaws in its cable modems, residential gateways and security appliances. Cisco just patched critical vulnerabilities in itsĀ cable modems, residential gateways and security appliances. The security updates released this week fix serious flaws inĀ Cisco residential reported by Kyle Lovett, and Chris Watts from Tech […]

Pierluigi Paganini March 13, 2016
A new massive spam campaign is spreading Locky ransomware downloaders

Experts at Trustwave observed a new massive spam campaign that was sending a JavaScript attachment that downloads Locky ransomware. Ransomware continues to be among most insidious threats in this first part of the year, security researcher have recently observed a spike in the number of Locky ransomwareĀ infections. The experts from Trustwave security firm highlighted the […]

Pierluigi Paganini March 12, 2016
DARPA Improv program, weaponizing the off-the-shelf electronics

The Defense Advanced Research Projects Agency is launching a new project dubbed Improv that aims to develop new techniques to hack into everyday technology. TheĀ IoTĀ paradigm is enlarging as never before our surface of attack, it is obvious that cyber criminals and nation-state hackers are looking at it with an increasing interest. The US Military Defense […]

Pierluigi Paganini March 12, 2016
The Pentagon used military drones for domestic surveillance

A report published by the DoD Inspector General revealed that military drones have been used for Non-Military domestic Surveillance. The US Government has admitted the use ofĀ dronesĀ for operations of domesticĀ surveillance. The US Military clarified that all the operations were authorized by a regular warrant confirming thatĀ no legalĀ violations were found. The news was revealed by theĀ USA […]

Pierluigi Paganini March 12, 2016
Typos stopped hackers stealing $1bn from Federal Reserve Bangladesh account

Hackers who allegedly infiltrated the Federal Reserve Bangladesh’s account were attempting to steal almost $1 billion, but typos thwarted the plan. This week the principal news agencies shared the news of the hack ofĀ the Bangladesh account at theĀ Federal Reserve Bank of New York. The Bangladesh’s Finance Minister Abul Maal Abdul Muhith accused the U.S. Federal […]

Pierluigi Paganini March 11, 2016
SAP Download Manager flaw exposed user password

An attacker who manages to get access to a user’s configuration file for SAP Download Manager might be able to obtain the stored proxy password. Are you a SAP user? Do you use the SAP Download Manager that allows downloading of software packages and support notes? You urgently need to update it in orderĀ to fix […]

Pierluigi Paganini March 11, 2016
Adobe issues emergency out-of-band update for actively exploited 0Day

Adobe has released an emergency out-of-band update to fix a zero-day vulnerability that is being used in targeted attacks. It’s happened again, Adobe hasĀ Issued an emergency Out-of-Band update For Flash Zero-Day that is being exploited in targeted attacks. The unfortunate thing is that theĀ Out-of-Band Patch For Flash Zero-Day comes just a couple of days after […]