Breaking News

Pierluigi Paganini September 08, 2015
Hundreds million legit websites could serve Ransomware because of Script Injection compromise

Heimdal Security published an interesting post on the increase in malicious scripts that are being injected into legit websites in order to serve ransomware. Heimdal Security recently published an interesting blog post on the increase in malicious scripts that are being injected into legit websites in order to serve malware. The attackers compromise websites running […]

Pierluigi Paganini September 08, 2015
Tough weekend for Kaspersky patching a buffer overflow vulnerability

Last week, Kaspersky Lab was informed about a buffer overflow flaw that affects its antivirus products version 2015 and 2016 and released a patch within 24 hours. Last week, Kaspersky Lab was informed about a buffer overflow flaw that affects its antivirus products version 2015 and 2016 by one of information security engineers working in […]

Pierluigi Paganini September 07, 2015
Authentication Flaw affects the PayPal Mobile App

Security experts at Vulnerability Lab have discovered a restriction filter bypass vulnerability affecting the PayPal mobile app. Under specific conditions, PayPal can ask users to confirm their identity to prevent frauds. When users are asked to verify their identity, their account is not accessible and in order to unblock it PayPal request them to make […]

Pierluigi Paganini September 07, 2015
Chinese law enforcement arrested 15,000 for cybercrime under the op “Cleaning the Internet”

The Government of Beijing has arrested nearly 15,000 people involved in cybercrime as part of the operation “Cleaning the Internet.” The Chinese authorities have arrested nearly 15,000 people involved in criminal activities online as part of the operation against the cybercrime is dubbed “Cleaning the Internet.” The Chinese Government accused the suspect to have “jeopardized Internet security.” According […]

Pierluigi Paganini September 07, 2015
Researcher disclosed 0day flaw in FireEye and offers others for sale

The expert Kristian Erik Hermansen disclosed a zero-day flaw in the FireEye core appliance that could be exploited to gain remote root file system access. Yesterday security researcher Kristian Erik Hermansen disclosed a zero-day vulnerability in the FireEye core appliance that could be exploited to gain remote root file system access. Hermansen told to CSOonline that he […]

Pierluigi Paganini September 07, 2015
Stealing all files from Seagate wireless disks is too easy

The CERT_org issued an alert on Seagate wireless disks because they contain multiple flaws that could be exploited to download their entire content. CERT.org issued a warning related Seagate wireless disk because they include a hidden login, most exactly a Telnet services that is not documented. This security issue allows anonymous attackers to download every file on […]

Pierluigi Paganini September 07, 2015
Fiat Chrysler recalls thousands Jeep Renegade SUVs due to hacking risks

Fiat Chrysler has recalled nearly 8,000 Jeep Renegade SUVs in the US to update the software that could be exploited by attackers to hack the vehicles. No peace for Fiat Chrysler Automobiles after the disclosure of the attack against its Jeep Cherokee model made by the popular hackers Charlie Miller and Chris Valasek. The duo of […]

Pierluigi Paganini September 07, 2015
Ashley Madison Users victims of extortion and phishing

Security researchers have observed a spike in extortion attempts and phishing campaigns against the Ashley Madison users … are they effective? The hack of the Ashley Madison website has demonstrated us how much dangerous could be a cyber attack against a website that manage sensitive and confidential information of millions users. The disclosure of the Ashley Madison dump has […]

Pierluigi Paganini September 06, 2015
DoJ defines new rules for spying with the Stingray technology

The US Justice Department issued guidelines for StingRay Surveillance devices, new rules define aim to ensure privacy protection and transparency. Do you know what is a StingRay? If you want further details give a look to a post I wrote for the Infosec Institute on the StingRay Technology: “StingRay is an IMSI-catcher (International Mobile Subscriber […]

Pierluigi Paganini September 06, 2015
Security Affairs newsletter Round 25– Best of the week from best sources

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from the best sources free for you in your email box. Report: How Iranian hackers attempt to takeover your Gmail How Employees Become Pawns for Hackers Point-of-Sale Payment Security Teenagers arrested after using the Lizard Squad DDoS tool Friday beers […]