Security Affairs

Pierluigi Paganini June 02, 2018
Crashing HDDs by launching an attack with sonic and ultrasonic signals

A team of researchers from the University of Michigan and Zhejiang University has devised a method to cause physical damage to hard drives by using sonic and ultrasonic signals. An attacker just needs to play ultrasonic sounds through a built-in speaker of a target computer or by using a speaker in its proximity. The principle is […]

Pierluigi Paganini June 01, 2018
Visa payments DOWN: Millions affected by a service disruption

The Visa card payment system is suffering a widespread outage across Europe, millions of users were unable to make payments using their cards. Shoppers and travelers were unable to make payments with their cards since at around 2.30pm on Friday across Europe. At the time of writing, Visa confirmed the widespread problems but did not […]

Pierluigi Paganini June 01, 2018
Crooks expand the original Mirai botnet code base with new capabilities and improvements

Cybercriminals continue to improve the infamous Mirai botnet by adding new exploits and functionalities, experts warn new dangerous variant will appear in the wild. According to Netscout’s Arbor Security Engineering and Response Team (ASERT), cybercriminals continue to improve the dreaded Mirai IoT botnet by adding new exploits and functionalities. The time to market of new Mirai botnet […]

Pierluigi Paganini June 01, 2018
Ticketfly website was compromised, the hacker also stole customers’ data

The website of the events ticketing company Ticketfly was shut down after a hacker who calls himself “IsHaKdZ” compromised it.  The hacker defaced the Ticketfly website with a picture of Guy Fawkes and a warning that read “Your Security Down im Not Sorry.” The attacker also published a yandex.com email account along with the following message: […]

Pierluigi Paganini June 01, 2018
Yes, Germany BND foreign intelligence service can spy on the world’s biggest internet exchange

This week, a federal court has ruled that Germany’s BND foreign intelligence service can monitor major internet hubs for strategic security interests. Recently, the operator of the world’s top Internet Hub sued the BND foreign intelligence service for the surveillance activity conducted by the spy agency. The operator wants to be sure that the agency is […]

Pierluigi Paganini June 01, 2018
North Korea-linked Andariel APT Group exploited an ActiveX Zero-Day in recent attacks

A North Korea-linked APT group, tracked as  Andariel Group, leveraged an ActiveX zero-day vulnerability in targeted attacks against South Korean entities. According to a report published by South Korean cyber-security firm AhnLab, the Andariel Group is a division of the dreaded Lazarus APT Group, it  already exploited ActiveX vulnerabilities in past attacks The attackers exploited at […]

Pierluigi Paganini May 31, 2018
US Federal court judge rejected a lawsuit by Kaspersky against the ban on its products

A US Federal court judge, Colleen Kollar-Kotelly, rejected a lawsuit by Russian cybersecurity firm Kaspersky Lab against the ban on the use it solution by government agencies On Wednesday, the US Federal court judge Colleen Kollar-Kotelly rejected a lawsuit by Russian cyber security firm Kaspersky Lab against the ban on the use it solution by government agencies. The ban on […]

Pierluigi Paganini May 31, 2018
Miscreants hijacked the defunct SpamCannibal blacklist service

The SpamCannibal blacklist service was hijacked since Wednesday morning, attackers changed the DNS name server settings for the website overnight. The SpamCannibal was born to blacklist IP address of malicious servers involved in spam campaigns and DoS attacks. SpamCannibal was using a continually updated database containing the IP addresses of spam or DoS servers and blocks their […]

Pierluigi Paganini May 31, 2018
Expert found a zero-day RCE in Microsoft Windows JScript component

Dmitri Kaslov, a security researcher at Telspace Systems, discovered a vulnerability in the JScript component of the Windows operating system that can be exploited by an attacker to execute malicious code on a target computer. Kaslov disclosed the zero-day flaw through the Trend Micro Zero-Day Initiative (ZDI) back in January, then ZDI experts reported it […]

Pierluigi Paganini May 30, 2018
US-CERT issued an alert on two malware associated with North Korea-linked APT Hidden Cobra

The Department of Homeland Security (DHS) and the FBI issued a joint Technical alert on two strain on malware, the Joanap backdoor Trojan and Brambul Server Message Block worm, associated with the HIDDEN COBRA North Korea-linked APT group. The US-CERT alert reads: “Working with U.S. government partners, DHS and FBI identified Internet Protocol (IP) addresses and other indicators […]