Pierluigi Paganini

Pierluigi Paganini August 17, 2017
Drupal maintainers fix several access bypass vulnerabilities in Drupal 8

Drupal maintainers this week released security updates to fix several access bypass vulnerabilities in Drupal 8. Update your installation. On Wednesday Drupal maintainers released security updates to fix several access bypass vulnerabilities in Drupal 8. The flaws affect several components, including the entity access system, the REST API and some views. The most severe vulnerability patched by Drupal 8.3.7 is a critical issue, tracked as CVE-2017-6925 that affects […]

Pierluigi Paganini August 15, 2017
CVE-2017-0199: Crooks exploit PowerPoint Slide Show files to deliver malware

According to Trend Micro, cyber criminals abuse the CVE-2017-0199 vulnerability to deliver malware via PowerPoint Slide Show. In April Microsoft fixed the CVE-2017-0199  vulnerability in Office after threat actors had been exploiting it in the wild. Hackers leveraged weaponized Rich Text File (RTF) documents exploiting a flaw in Office’s Object Linking and Embedding (OLE) interface to deliver malware such […]

Pierluigi Paganini August 13, 2017
Security Affairs newsletter Round 123 – News of the week

A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. ·      Flaws in solar panels potentially threatening European power grids ·      Hackers leak the fourth episode of Game of Thrones season 7 online ·      Security Affairs newsletter Round 122 – News of the week ·      US Army […]

Pierluigi Paganini August 06, 2017
Security Affairs newsletter Round 122 – News of the week

A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. ·      Apple removed iOS VPN apps from Chinese App Store in compliance to censorship law ·      Bypassing locking mechanisms of a smart gun with $15 worth of magnets ·      DEF CON 25 – BBC Micro:bit could be […]

Pierluigi Paganini August 03, 2017
Former Bupa employee offered 1 million customer records for sale on dark web

Former Employee of the Healthcare giant Bupa offered for sale records of 1 Million clients on Dark Web. A former employee of healthcare giant Bupa was selling between 500,000 and 1 million records on the healthcare giant Bupa was selling between 500,000 and 1 million records on the dark web. The former employee whose identity […]

Pierluigi Paganini August 01, 2017
TOPransom: From eMail Attachment to Powning the Attacker’s Database

TOPransom – Analyzing the entire process from getting an email attachment to powning the ransom server trying to stop the infection. Hi folks, today I want to share a quick but intensive experience in fighting cybercrime. I wish you would appreciate the entire process of getting an email attachment to powning the ransom server trying […]

Pierluigi Paganini July 27, 2017
Google experts blocked a new targeted malware family, the Lipizzan spyware

Google has identified a new strain of Android malware, the Lipizzan spyware, that could be used as a powerful surveillance tool. Malware researchers at Google have spotted a new strain of Android spyware dubbed Lipizzan that could exfiltrate any kind of data from mobile devices and use them as surveillance tools. The Lipizzan spyware is a project developed […]

Pierluigi Paganini July 26, 2017
New CowerSnail Windows Backdoor linked to SHELLBIND SambaCry Linux Malware

Malware researchers at Kaspersky Lab have found a new Windows Backdoor dubbed CowerSnail linked to the recently discovered SHELLBIND SambaCry Linux malware. Security experts at Kaspersky Lab have spotted a new Windows Backdoor dubbed CowerSnail linked to the recently discovered SHELLBIND SambaCry Linux malware. SHELLBIND has infected most network-attached storage (NAS) appliances, it exploits the Samba vulnerability (also known as SambaCry and EternalRed) to upload a shared […]

Pierluigi Paganini July 23, 2017
Security Affairs newsletter Round 120 – News of the week

A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. ·      Crooks used Infrared insert skimmers in a recent wave of ATM attacks ·      Did you receive a WhatsApp subscription ending email or text? Watch out! ·      Hackshit PhaaS platform, even more easy to power Phishing campaigns […]

Pierluigi Paganini July 09, 2017
Security Affairs newsletter Round 118 – News of the week

A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. ·      FBI hacked a US Darknet shopper who tried to purchase Mail Bomb ·      NATO attributed the massive NotPetya attack to a ‘state actor and call for a joint investigation ·      NATO CCD COE attributed the massive […]