Hacking

Pierluigi Paganini June 27, 2016
Another victim of SWIFT attackers, they steal $10 million from a Ukrainian bank

Experts from the ISACA organization confirmed that SWIFT hackers have stolen $10 million from a Ukrainian bank through SWIFT system. It is happened again, unknown hackers have stolen $10 million from an unnamed Ukrainian bank through SWIFT loophole. The news was spread by the Kyiv branch of ISACA, the Information Systems Audit and Control Association, that confirmed […]

Pierluigi Paganini June 27, 2016
Hacker Interviews – Cesar Cerrudo

Today I propose you an interview with Cesar Cerrudo, CTO at IOActive Labs, famous for his research on ICS/SCADA, Smart Cities, IoT, software security. Cesar Cerrudo is CTO at IOActive Labs, leading the team in producing ongoing cutting edge research on ICS/SCADA, Smart Cities, IoT, software security. But Cesar, first of all, has chosen the […]

Pierluigi Paganini June 26, 2016
Locky Ransomware is back! 49 domains compromised!

Locky ransomware starts up again its illegal activity of stealing money from their victims after a temporary inactivity since the end of May. This time, it comes with hard-coded javascript A new Locky campaign appears in the wild with, experts observed million malicious email messages starting from June 20. Researchers at Proofpoint observed that this […]

Pierluigi Paganini June 25, 2016
Facebook logic flaw allowed an expert to delete any video

Facebook has fixed a serious logic flaw that could have been exploited by hackers to delete any video uploaded in comments on someone’s Facebook post. Facebook has fixed a serious security vulnerability in the Facebook’s platform that could have been exploited by hackers to delete any video uploaded in comments on someone’s Facebook post. The security […]

Pierluigi Paganini June 25, 2016
Hacker Interviews – Rahul Sasi (@fb1h2s)

Today I propose you an interview with Rahul Sasi, the Founder of Machine learning based cloud security company CloudSek. Rahul Sasi (@fb1h2s) is the Founder of Machine learning based cloud security company CloudSek. He was an Admin member for Garage4hackers.com. He is ePrior to founding CloudSek he was a Sr Engineer at Citrix where he held […]

Pierluigi Paganini June 25, 2016
PayPal fixed a flaw that allowed attackers to deliver malicious images

PayPal has fixed a vulnerability that could have been exploited by attackers to deliver malicious images through the payment pages of the website. The Security researcher Aditya K Sood discovered a vulnerability that could have been exploited by attackers to deliver malicious image through the payment pages of the PayPal website. The expert noticed that the […]

Pierluigi Paganini June 24, 2016
Fansmitter – exfiltrating data from Air-Gapped devices via fan noises

Fansmitter is a new acoustic data exfiltration method devised by a group of researchers from Ben-Gurion University of the Negev. We all know that air-gapped networks aren’t totally secure, in the past, many research groups have devised methods to steal data from computers disconnected from the Internet. It is possible, for example, to exfiltrate data […]

Pierluigi Paganini June 24, 2016
Apple confirms iOS 10 kernel source code left unencrypted intentionally

Apple confirms iOS 10 kernel code left unencrypted intentionally to improve OS performance and ensures that it will have no impact on security. The news is intriguing, while Apple announced the new release of its mobile operating system, the iOS 10, the experts discovered that its kernel is unencrypted. The researchers from MIT Technology who reviewed […]

Pierluigi Paganini June 24, 2016
Severe Swagger Remote Code Execution flaw compromises NodeJS, Ruby, PHP, Java

This disclosure of an unpatched Remote Code Exec flaw in the Swagger API framework compromises NodeJS, Ruby, PHP, and Java. Swagger is a representation of RESTful API that allows developers to get interactive documentation, client SDK generation and discoverability. The Swagger generators are privileged tools for organisations to offer developers easy access to their APIs. Currently, the […]

Pierluigi Paganini June 24, 2016
Hacking Uber – Experts found dozen flaws in its services and app

Researchers discovered more than a dozen flaws in Uber app and websites, many of them allow hackers to access driver and passenger info. Security experts from the Integrity firm have found more than a dozen flaws in the Uber website that could be exploited by hackers to access driver and passenger data. The researchers discovered a total […]