Hacking

Pierluigi Paganini April 15, 2019
A new DDoS technique abuses HTML5 Hyperlink Audit Ping in massive attacks

Experts at Imperva discovered a new type of large-scale DDoS attack that abuses the HTML5 Ping-based hyperlink auditing feature. Experts at Imperva Vitaly Simonovich and Dima Bekerman observed a large-scale DDoS attack abusing the HTML5 Ping-based hyperlink auditing feature. The DDoS attack peaked at a massive 7,500 requests per second and delivered more than 70 […]

Pierluigi Paganini April 15, 2019
Apache fixed an important RCE flaw in Tomcat application server

The Apache Software Foundation has released new versions of the Tomcat application server that address an important remote code execution vulnerability. The new versions of the Tomcat application server address an important remote code execution vulnerability that could be exploited by a remote attacker to execute malicious code and take control of a vulnerable server. […]

Pierluigi Paganini April 15, 2019
Locked Shields 2019 – Chapeau, France wins Cyber Defence Exercise

Locked Shields 2019 – France wins, the world’s biggest and most advanced international cyber drills organized by NATO Cooperative Cyber Defence Center of Excellence (CCDCOE).  The international live-fire cyber defence exercise Locked Shields 2019(LS19) took place on April 8-12 in Tallinn, Estonia, and the figures behind this important competition are important. Locked Shields 2019 is organised […]

Pierluigi Paganini April 15, 2019
Yellow Pencil WordPress Plugin flaw expose tens of thousands of sites

Thousands of WordPress sites using the Yellow Pencil Plugin were exposed to hacking due to a privilege escalation vulnerability in the plugin. A privilege escalation vulnerability in the Yellow Pencil Visual Theme Customizer plugin exposes WordPress websites to hack. The flaw could be exploited by attackers to update arbitrary options on vulnerable installations. Early this […]

Pierluigi Paganini April 14, 2019
Security Affairs newsletter Round 209 – News of the week

A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. Kindle Edition Paper Copy Once again thank you! DNS hijacking campaigns target Gmail, Netflix, and PayPal users Rockwell Automation fixes multiple DoS flaws in Stratix Switch introduced by Cisco Software AeroGrow suffered a payment card data breach […]

Pierluigi Paganini April 13, 2019
These hackers have breached FBI-affiliated websites and leaked data online

Hackers publish personal data on thousands of US police officers and federal agents Media outlet Techcrunch reported that a hacker group has breached several FBI-affiliated websites and leaked the stolen info online. A hacker group claims to have hacked dozens of websites affiliated with the FBI and leaked online dozens of files containing the personal […]

Pierluigi Paganini April 13, 2019
The hacker behind Matrix.org hack offers advice to improve security

The hacker that hacked and defaced Matrix.org decided to disclose the security issues discovered during the attack and offers advice. This week, the hacker behind the hack of Matrix.org decided to disclose the vulnerabilities discovered during the attack. Matrix is an open network for secure, decentralized real-time communication that is also used for instant messaging, […]

Pierluigi Paganini April 12, 2019
Emsisoft released a free decryptor for CryptoPokemon ransomware

Good news for the victims of the CryptoPokemon ransomware, security experts at Emsisoft just released a free decrypter tool. Victims of the CryptoPokemon ransomware have a good reason to smile, security experts at Emsisoft have released a free decrypter tool. The ransomware was first discovered by experts at IntezerLabs, the CryptoPokemon ransomware is a new […]

Pierluigi Paganini April 12, 2019
Zero-day in popular Yuzo Related Posts WordPress Plugin exploited in the wild

According to experts a vulnerability in the popular WordPress plugin Yuzo Related Posts is exploited by attackers to redirect users to malicious sites. The XSS flaw allows attackers to inject a JavaScript into the sites that redirect visitors to websites displaying scams, including tech support scams, and sites promoting unwanted software. The Yuzo Related Posts […]

Pierluigi Paganini April 12, 2019
VSDC video editing software website hacked again

Users that have downloaded the VSDC multimedia editing software between 2019-02-21 and 2019-03-23, may have been infected with malware. Users that have downloaded the VSDC multimedia editing software between 2019-02-21 and 2019-03-23, may have been infected with a banking trojan and an information stealer. VSDC is a popular, free video editing and converting app and […]