Hacking

Pierluigi Paganini January 07, 2016
Unpatched Drupal flaws open websites to attacks

IOActive has uncovered a number of serious vulnerabilities affecting the Drupal CMS that could be exploited to completely takeover the vulnerable websites. A new vulnerability affecting Drupal could be exploited for code execution and database credentials theft (by Man-in-the-Middle), according to Fernando Arnaboldi, a senior security consultant working in IOActive. Fernando Arnaboldi says that the […]

Pierluigi Paganini January 07, 2016
Silent Circle promptly patched a critical flaw in the Blackphone I

Silent Circle released an update for its Blackphone 1 that fixes a critical flaw in the modem. Silent Circle has released an update for its Blackphone device that fixes several security vulnerabilities, including a flaw in its modem (CVE-2015-6841) that could have been exploited by threat actors to gain full control of the mobile device. […]

Pierluigi Paganini January 06, 2016
Security experts disclosed SCADAPASS, a list of default credentials for ICS and SCADA systems

Security experts from SCADA StrangeLove group disclosed SCADAPASS, a list of default credentials for ICS and SCADA systems. Recently I wrote about the SCADA StrangeLove research team reporting their study on the level of cyber security implemented in modern railroad systems . Now the SCADA StrangeLove group has published a list of default credentials, dubbed “SCADAPASS,” associated with industrial […]

Pierluigi Paganini January 06, 2016
Final rule implements the Executive Order 13694. US can apply economic sanctions in response to cyber attacks

The US Government issued a final rule implementing the Executive Order 13694. US can apply economic sanctions in response to cyber attacks. According to a final rule published in the Federal Register on the last day of 2015 (Dec. 31, 2015),  US can now apply economic sanctions in response to cyber attacks. The US Government assigned to […]

Pierluigi Paganini January 06, 2016
Zerodium offers $100,000 for bypass Flash Player heap isolation

The zero-day exploit broker Zerodium is offering up to $100,000 to security experts who can provide an exploit for bypassing the Flash heap isolation. Once again, the zero-day exploit trader Zerodium is in the headlines, this time the company is offering $100,000 for the Flash Exploit Mitigation bypass. Adobe announced in December the introduction of several Recently Adobe […]

Pierluigi Paganini January 03, 2016
Turkish hackers took over a Russian Govt Instagram account

Alleged Turkish hackers have taken over the Russian Communications and Mass Media Minister Nikolai Nikiforov’s Instagram account. Events in the cyberspace are strictly correlated with facts in the real life, in many cases, disputes between countries are associated with numerous cyber events that could be analyzed by intelligence analysts. The recent crisis in Crimea between Russia and Ukraine is just […]

Pierluigi Paganini January 03, 2016
@FFD8FFDB Twitter bot spies on poorly configured cameras

@FFD8FFDB is a Twitter bot that spies on poorly configured cameras tweeting the images captured by the connected devices. There is an air of mystery when you first notice @FFD8FFDB. However, the next thing you will see is that really gets on to you. There is a strange Twitter account, @FFD8FFDB, that every few minute tweets pictures taken […]

Pierluigi Paganini January 02, 2016
Anti-IS group ‘New World Hackers’ claims BBC website attack

A group of hackers named “New World Hackers” claims the DDoS attack on BBC’s website. They launched it to test their attack capabilities. On December 31th, the BBC website and iPlayer service went down due to a major “distributed denial of service” attack.” The attack started at 0700 GMT and paralyzed the websites for more than […]

Pierluigi Paganini January 02, 2016
Hackers fully controlled a PlayStation 4 running a Linux distro

The hacking crew dubbed Fail0verflow has managed to hack PlayStation 4 (PS4) to run a Linux kernel-based operating system. The PlayStation 4 is considered by the experts a fortress so the hacking community is always interested in any news regarding its hack. Recently a hacker who calls himself CTurt claimed to develop a fully jailbroken version of the PlayStation 4 […]

Pierluigi Paganini January 02, 2016
Modern railroad systems vulnerable to cyber attacks

A team of researchers has evaluated the level of cyber security implemented in modern railroad systems and discovered several vulnerabilities. A team of experts composed of Sergey Gordeychik, Alexander Timorin and Gleb Gritsai of SCADA StrangeLove, recently disclosed their findings at the 32nd Chaos Communication Congress (32C3) in Germany. Railroads belong to the critical infrastructure of a […]