Hacking

Pierluigi Paganini March 11, 2020
Bugs in Avast AntiTrack expose users to cyber attacks

A flaw in the impacting Avast and AVG AntiTrack privacy software could expose users to browser hijacking and Man-in-The-Middle (MiTM) attacks. Security expert David Eade has discovered a vulnerability (CVE-2020-8987) in Avast and AVG AntiTrack privacy software that could expose end-users to Man-in-The-Middle (MiTM) attacks, browser session hijack, with consequent exposure of sensitive data. “A […]

Pierluigi Paganini March 10, 2020
Microsoft accidentally reveals Wormable Win SMBv3 CVE-2020-0796 Flaw

Today Microsoft accidentally leaked info about a new wormable vulnerability (CVE-2020-0796) in the Microsoft Server Message Block (SMB) protocol. Today Microsoft accidentally leaked info on a security update for a wormable vulnerability in the Microsoft Server Message Block (SMB) protocol. The issue, tracked as CVE-2020-0796, is pre- remote code execution vulnerability that resides in the Server […]

Pierluigi Paganini March 10, 2020
Hackers use hackers spreading tainted hacking tools in long-running campaign

Who is hacking the hackers? Experts from Cybereason a mysterious hackers group is targeting other hackers by spreading tainted hacking tools. Experts from security firm Cybereason warn of a mysterious group of hackers that are distributing trojanized hacking tools on an almost daily basis for the past years. These hacking tools are used by fellow […]

Pierluigi Paganini March 10, 2020
FBI arrested a Russian citizen suspected to be the mastermind of Deer.io

The FBI announced the arrest of a Russian national that is suspected to be the mastermind behind Deer.io, a Shopify-like platform. The FBI arrested Kirill Victorovich Firsov, the alleged main operator behind Deer.io which is a Shopify-like platform that has been hosting hundreds of online shops used for the sale of hacked accounts and stolen […]

Pierluigi Paganini March 10, 2020
Microsoft warns of Human-Operated Ransomware as a growing threat to businesses

Microsoft is warning of human-operated ransomware, this kind of attack against businesses is becoming popular in the cybercrime ecosystem. Human-operated ransomware is a technique usually employed in nation-state attacks that is becoming very popular in the cybercrime ecosystem. In human-operated ransomware attack scenario, attackers use stolen credentials, exploit misconfiguration and vulnerabilities to access target networks, […]

Pierluigi Paganini March 09, 2020
Former CIA employee Joshua Schulte was convicted of only minor charges

Joshua Schulte, the former CIA employee accused of leaking secret agency’s hacking tools to WikiLeaks was convicted of only minor charges Joshua Schulte, the former CIA software engineer that was accused of stealing the agency’s hacking tools and leaking them to WikiLeaks, was convicted of only minor charges. On November 2018, Joshua Adam Schulte was charged with 13 […]

Pierluigi Paganini March 09, 2020
Revista Factum suffered week-long cyber attacks for denouncing corruption by the president of El Salvador

Revista Factum was under prolonged cyber attacks for denouncing corruption, the government of El Salvador had banned it. The government of El Salvador had banned Factum Magazine from attending its press conferences and was subjecting them to a smear campaign The alleged perpetrator of the attacks has been identified as a computer engineer acting, from […]

Pierluigi Paganini March 09, 2020
Nation-state actors are exploiting CVE-2020-0688 Microsoft Exchange server flaw

Multiple state-sponsored hacking groups are attempting to exploit a vulnerability recently addressed in Microsoft Exchange email servers. Cybersecurity firm Volexity is warning that nation-state actors are attempting to exploit a vulnerability recently addressed in Microsoft Exchange email servers tracked as CVE-2020-0688. The experts did not provide details on the threat actors that are exploiting the […]

Pierluigi Paganini March 08, 2020
Netgear fixes a critical RCE that could allow to takeover Flagship Nighthawk routers

Netgear is warning users of a critical remote code execution flaw that could allow an unauthenticated attacker to take control of its wireless routers. Netgear has addressed a critical remote code execution vulnerability that could be exploited by an unauthenticated attacker to take over AC Router Nighthawk (R7800) hardware running firmware versions prior to 1.0.2.68. […]

Pierluigi Paganini March 08, 2020
Security Affairs newsletter Round 254

A new round of the weekly newsletter arrived! The best news of the week with Security Affairs 49 million unique email addresses of Straffic Marketing firm exposed online Russian spies are attempting to tap transatlantic undersea cables $1B to help telecom carriers to rip and replace Huawei and ZTE equipment Karkoff 2020: a new APT34 […]