Breaking News

Pierluigi Paganini July 10, 2018
Just using a $39 device it is possible to defeat new iOS USB Restricted Mode

Once USB Restricted Mode is enabled on a device, no data communications occur over the Lightning port, but experts found a way to reset the countdown timer. Recently Apple released the iOS 11.4.1 that introduced a new security feature, dubbed USB Restricted Mode, designed to protect your devices against USB accessories used by forensics experts and […]

Pierluigi Paganini July 10, 2018
BlackTech APT using stolen D-Link certificates to spread malware

A cyber-espionage group tracked as BlackTech is abusing code-signing certificates stolen from D-Link for the distribution of their malware. Security experts from ESET discovered that an APT group tracked as BlackTech is using code-signing certificates stolen from Taiwanese-based tech firm D-Link and the security company Changing Information Technology Inc. According to the experts, the cyber espionage group […]

Pierluigi Paganini July 10, 2018
Polar fitness app broadcasted sensitive data of intelligence and military personnel

The Mobile fitness app Polar has suspended its location tracking feature due to the leakage of sensitive data on military and intelligence personnel. A new privacy incident involved Fitness application and military. this time the Mobile fitness app Polar has suspended its location tracking feature due to the leakage of sensitive data on military and intelligence […]

Pierluigi Paganini July 09, 2018
GoDaddy-owned hosting company Domainfactory hacked

The hosting company Domainfactory has taken down its forums after hackers posted messages claiming to have breached into its infrastructure. While I was writing about the Timehope security breach, another incident is making the headlines, the victim is the German hosting company Domainfactory. The hosting company, that was owned by GoDaddy since 2016, has taken […]

Pierluigi Paganini July 09, 2018
HP iLO servers running outdated firmware could be remotely hacked

Hewlett Packard Integrated Lights-Out 4 (HP iLO 4) servers are affected by a critical Bypass Authentication vulnerability, technical details and a PoC code have been published online. The flaw, tracked as CVE-2017-12542, received a severity score of 9.8 out of 10 because it is very simple to exploit. “Integrated Lights-Out, or iLO, is a proprietary embedded server management […]

Pierluigi Paganini July 09, 2018
Timehop data breach, data from 21 million users exposed

Timehop, the service that aims to help people in finding new ways to connect with each other by analyzing past activities, has been hacked. Timehop is a service that aims to help people in finding new ways to connect with each other by analyzing past activities. “Timehop created the digital nostalgia category and continues to […]

Pierluigi Paganini July 09, 2018
Hacker hijacked original LokiBot malware to sell samples in the wild

An expert found evidences that demonstrate the current distributed LokiBot malware samples were “hijacked” by a third actor. According to the researcher who goes online by the Twitter handle “d00rt,” samples of the LokiBot malware samples being distributed in the wild are modified versions of the original sample. I just released an article where are […]

Pierluigi Paganini July 08, 2018
Smart Speaker Banking Is Coming to a Device Near You, But Is It Secure?

Smart speaker Banking Is coming to a device near you, Which are the cyber risks associated with their use? Are they a new opportunity for attackers? The popularity of voice-activated smart speakers like the Google Home and Amazon Echo has made brands, and industries realize there’s adequate demand for introducing technology that lets people accomplish […]

Pierluigi Paganini July 08, 2018
Security Affairs newsletter Round 170 – News of the week

A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. Let me inform you that my new book, “Digging in the Deep Web” is online with a special deal 20% discount Kindle Edition Paper Copy Once again thank you! ·      Data Broker Exactis data breach, one of […]

Pierluigi Paganini July 08, 2018
HNS Botnet evolves and targets cross-platform database solutions

The HNS IoT botnet (Hide and Seek) originally discovered by BitDefender in January evolves and now targets cross-platform database solutions. Do you remember the Hide ‘N Seek (HNS) botnet? The IoT botnet Hide ‘N Seek botnet appeared in the threat landscape in January, when it was first spotted on January 10th by malware researchers from Bitdefender. It was first discovered […]