Pierluigi Paganini

Pierluigi Paganini August 01, 2019
Cisco to pay $8.6 million fine for selling flawed surveillance technology to the US Gov

Cisco is going to pay $8.6 million to settle a legal dispute for selling vulnerable software to the US government. Back in 2008, a whistle-blower identifies a vulnerability in Cisco video surveillance software, but the tech giant continued to sell the software to US agencies until July 2013. The case was filed in the Federal […]

Pierluigi Paganini August 01, 2019
CISA warns of critical flaws in Prima FlexAir access control system

The U.S. CISA published a security advisory to warn of multiple critical vulnerabilities affecting in Prima FlexAir access control system. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) published an advisory to warn of critical flaws affecting access control systems manufactured by Prima Systems. Prima access control has a wide range of solutions, including wall-mounted […]

Pierluigi Paganini July 31, 2019
Cyber attacks hit Louisiana schools ahead of year’s beginning

A wave of cyber attacks hit schools of Louisiana ahead of year’s beginning that is planned for the next week. Several schools of Louisiana were targeted by hackers ahead of year’s beginning that is planned for the next week. The AP press states that a fourth Louisiana school district is assessing damages caused by a […]

Pierluigi Paganini July 31, 2019
DHS warns of cyber attacks against small airplanes

A few hours ago, I have written about an interesting analysis of the possible hack of avionics systems, not DHS warns of cyber attacks against small airplanes. Today we introduced an interesting report published by researchers at Rapid7 about the hacking of avionics systems via CAN bus, now the DHS issues an alert to warn […]

Pierluigi Paganini July 31, 2019
Hacking avionics systems through the CAN bus

An expert analyzed the level of security of avionics systems used in small airplanes, and the results are disconcerting. Patrick Kiley, a senior security consultant at Rapid7 conducted an investigation into the security of avionics systems inside small airplanes. The results are disconcerting it is quite easy to hack a small plane. Kiley, which is […]

Pierluigi Paganini July 31, 2019
Hacking eCommerce sites based on OXID eShop by chaining 2 flaws

Researchers at RIPS Technologies discovered vulnerabilities in the OXID eShop platform that could expose eCommerce websites to hack. Experts at RIPS Technologies discovered several flaws in the OXID eShop platform that could be exploited by unauthenticated attackers to compromise eCommerce websites. OXID eShop is a popular e-commerce software platform used by important brands like Mercedes […]

Pierluigi Paganini July 31, 2019
Hacking campaign is wiping Iomega NAS Devices exposed online

Experts warn of a new campaign carried out by threat actors that are wiping Iomega NAS devices exposed online. Security experts are warning of a campaign carried out by attackers that are deleting files on publicly accessible Lenovo Iomega NAS devices. Likely attackers use the Shodan search engine to find unprotected IOmega NAS exposed online […]

Pierluigi Paganini July 30, 2019
Google Project Zero hackers disclose details and PoCs for 4 iOS RCE flaws

Security experts at Google disclosed details and proof-of-concept exploit codes for 4 out of 5 security vulnerabilities in Apple iOS. Researchers at Google disclosed details and proof-of-concept exploit codes for 4 out of 5 security vulnerabilities in Apple iOS that could be exploited by attackers to hack Apple devices by sending a specially-crafted message over […]

Pierluigi Paganini July 30, 2019
Malware researchers analyzed an intriguing Java ATM Malware

Experts spotted a Java ATM malware that was relying on the XFS (EXtension for Financial Service) API to “jackpot” the infected machine Introduction Recently our attention was caught by a really particular malware sample most probably linked toa recent cybercriminal operation against the banking sector. This piece of malicious code is a so-called ‘ATM malware‘: […]

Pierluigi Paganini July 30, 2019
Capital One data breach: hacker accessed details of 106M customers before its arrest

Capital One, one of the largest U.S. –card issuer and financial corporation suffered a data breach that exposed personal information from more than 100 million credit applications. A hacker that goes online with the handle “erratic” breached the systems at Capital One and gained access to personal information from 106 million Capital One credit applications. […]