Hacking

Pierluigi Paganini April 19, 2016
IBM warns a spike in the number of PHP C99 Webshell Attacks

IBM Security has warned the WordPress community about a spike in the number of attacks leveraging a specific variant of the PHP C99 Webshell. Security experts at IBM reported a spike in the number of cyber attacks pushing a variant of the popular C99 webshell in February and March, a 45 percent increase compared to the previous period. […]

Pierluigi Paganini April 18, 2016
Experts discovered a number of flaws in the Avactis PHP Shopping Cart

A group of experts at VoidSec used a Grey Box approach to assess the security posture of some important aspects of Avactis PHP Shopping Cart. Avactis is an open source ecommerce Shopping Cart platform most used in US and UK. Security experts from VoidSec analyzed the e-commerce software discovered an impressive number of vulnerabilities. The group of experts […]

Pierluigi Paganini April 17, 2016
Lottery security director hacked random-number generator to rig lotteries

New evidence collected by prosecutors shows lottery machines were rigged to generate predictable numbers on specific days of the year. Last year, the security director of a US lottery was discovered hacking the mechanism of the extraction in order to predict the winning tickets. According to new details revealed by The Des Moines Register, the […]

Pierluigi Paganini April 17, 2016
American company lost $100 million to BEC fraud

US prosecutors confirmed on Thursday that an American firm lost nearly $100 million in a BEC (business email compromise) scam. The Reuters Agency reported that an unidentified American company was the victim of a clamorous email fraud, scammers have stolen from the firm nearly $100 million. According to the US authorities, fraudsters used a fake […]

Pierluigi Paganini April 16, 2016
Watch out! URL shorteners could leak sensitive content

Two security researchers from Cornell Tech discovered that web URL shorteners operate in predictable way exposing sensitive data. The security researchers Vitaly Shmatikov and Martin Georgiev from Cornell Tech discovered that web URL shorteners operate in predictable way, and this could result in the disclosure of sensitive information. The duo analyzed the most popular URL shorteners, […]

Pierluigi Paganini April 16, 2016
Urgent, Uninstall QuickTime for Windows Now

Apple abandons the support for the Windows version of quicktime, everyone should follow Apple’s guidance to uninstall it to avoid attacks. It is official, Apple will no longer provide security updates for the Windows version of the popular QuickTime. It is important to uninstall the product that remains vulnerable to cyber attacks, recently experts discovered […]

Pierluigi Paganini April 16, 2016
JBOSS Backdoor opens 3 million servers at risk of attacks

Experts at Cisco Systems discovered more than 3 million vulnerable servers exposed on the Internet while scanning for the presence of JBOSS Backdoor According to Cisco Systems, more than 3 million servers exposed on the Internet are potentially open to Samsam ransomware-based attacks because they’re running vulnerable software. Attackers are targeting vulnerabilities in servers to […]

Pierluigi Paganini April 15, 2016
Former Reuters Matthew Keys sentenced to 2 years for hacking

This week the former Reuters journalist Matthew Keys was sentenced to two years in prison for helping the Anonymous collective in computer hacking. Matthew Keys, a former Reuters journalist, who was convicted in October 2015 of supporting the Anonymous collective, has been sentenced to 24 months in prison for computer hacking charges. Keys has been […]

Pierluigi Paganini April 14, 2016
CISCO fixed a high risk security flaw in the UCS software

CISCO has recently issued a security update to fix a high-risk security vulnerability affecting the UCS software and exploitable with a simple HTTP poke. Cisco has recently patched a “high” risk security vulnerability (CVE-2016-1352) affecting its Unified Computing System (UCS) Central Software that could allow a remote attacker to gain remote control of the machines. […]

Pierluigi Paganini April 14, 2016
iOS date bug could be triggered over Wi-Fi spoofing an NTP server

A couple of security experts demonstrated that iOS date bug was still present in iOS devices and it was exploitable by spoofing an Apple NTP server. Do you remember the Apple iOS date bug? In February, the security community highlighted the existence of the embarrassing problem for Apple iOS mobile devices running 64-bit iOS 8 or higher, […]