Security

Pierluigi Paganini November 17, 2014
State Department network hacked, email system shut down

The State Department has taken the unprecedented step of shutting down its entire unclassified email system in response to a suspected cyber attack. The State Department has decided of shutting down its entire unclassified email system in response to a suspected cyber attack. A senior department official at the State Department, which reported the facts on […]

Pierluigi Paganini November 12, 2014
NHS Trusts fail to Extend Outdated Windows XP Security Support with Microsoft

Thousands of patient records in UK are vulnerable to cyber fraudsters after up to 20 trusts under the National Hospital Service failed to extend security support for outdated Windows XP with Microsoft. Trusts running on the outdated OS risks reversed engineered attacks from hackers exploiting vulnerabilities on the unsupported OS. Hundreds of Thousands of Patient […]

Pierluigi Paganini November 12, 2014
MS14-066 – A critical bug potentially affects all Windows versions. Patch it!

MS14-066 – A critical vulnerability affects all versions of Microsoft Windows systems, its exploitation could have catastrophic consequences. Microsoft has revealed the existence of a critical vulnerability in all versions of Windows operating systems, the flaw is particularly dangerous for users that servers that expose website. Microsoft issued a security advisory (Microsoft Security Bulletin MS14-066) on the vulnerability […]

Pierluigi Paganini November 12, 2014
Internal Internet traffic routed outside the Russia by a Chinese operator

Russian Internet Traffic redirected by a Chinese operator due to routing errors caused by a weakness in the Border gateway protocol (BGP). The Russian Internet traffic in several circumstances has been re-routed outside the country, the incidents seem to be caused by routing errors made by China Telecom. The news has been published by the Internet monitoring service Dyn in a blog […]

Pierluigi Paganini November 11, 2014
Masque Attack – every iOS app could be compromised

Researchers at FireEye identified a new attack dubbed the Masque, which allows attackers to replace a genuine app with a malicious one. In these days Apple the community has discovered that is vulnerable to WireLurker, a new strain of malware that is able to infect Apple iPhone and iPad syphoning user’data. The malware was discovered for the […]

Pierluigi Paganini November 11, 2014
Happy BirthDay Security Affairs – three years together!

Happy BirthDay Security Affairs! Three years together, it all began the 11/11/2011, a dream that becomes more and more real every day with your loving support. And it is just the beginning! I’m very happy and proud to be here with you for the third year of SecurityAffairs. We are a growing community that has tens of […]

Pierluigi Paganini November 06, 2014
Telstra Fined $18K for violating the privacy Act

Telstra to pay a whopping $18,000 fine for listing the contact information of a Sydney Judge without his consent. The Australian Telco contravened the Privacy Act and risked the safety of the Judge who has since applied for an interstate transfer due to security concerns. Australia’s telecommunication giant, Telstra to pay a whopping $18,000 fine […]

Pierluigi Paganini November 05, 2014
Are Contactless Visa Cards exposed to risk of theft for 1M?

Researchers at the Newcastle University discovered a flaw in contactless Visa cards that can be exploited to steal up to 1M from cardholders without the PIN. A group of researchers at Newcastle University in the UK has discovered a hole in Contactless Visa Cards that could be exploited by cyber criminals to steal $1M per Card without knowing their PIN. The contactless credit […]

Pierluigi Paganini November 05, 2014
Two Linksys routers running SMART Wi-Fi Firmware are still vulnerable to remote attacks

Two models of Linksys routers running SMART Wi-Fi Firmware remain vulnerable to a pair of vulnerabilities recently patched by the company. Linksys EA2700 and EA3500 are the two routers running Linksys SMART Wi-Fi firmware that are still affected by a couple of vulnerabilities recently patched in different models of the Belkin-owned networking gear. On October 31th, […]

Pierluigi Paganini November 04, 2014
uIP and lwIP DNS resolver exposed to cache poisoning attacks

The DNS resolver implemented in the open source TCP/IP stacks uIP and lwIP is vulnerable to cache poisoning, the flaw could be exploited to divert traffic to malicious websites. The security researcher Allen D. Householder has reported  a serious vulnerability related to the uIP and lwIP DNS resolver, according to the Vulnerability Note VU#210620 it is exposed to cache […]