Security Affairs

Pierluigi Paganini September 10, 2017
Mexican tax refund MoneyBack site exposed 400GB of sensitive customer data

Experts from security firm Kromtech discovered the Mexican VAT refund site MoneyBack exposed 400GB of sensitive information. Another huge data leak made the headlines, experts from security firm Kromtech discovered the Mexican VAT refund site MoneyBack exposed sensitive customer information online. because of a misconfigured database. Kromtech discovered the unsecured CouchDB during a routine security audit. The Mexican VAT refund […]

Pierluigi Paganini September 03, 2017
Security Affairs newsletter Round 126 – News of the week

A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. ·      Defray Ransomware used in targeted attacks on Education and Healthcare verticals ·      Security Affairs newsletter Round 125 – News of the week ·      Tor relay of a Brazilian University was banned after harvesting .onions ·      Chinese […]

Pierluigi Paganini September 02, 2017
DragonOK APT is adopting new tactics, techniques and procedures

Researchers at Palo Alto Networks recently observed the DragonOK APT group adopting new tactics, techniques and procedures. China-linked cyber espionage group DragonOK is back, security experts from Palo Alto Networks have uncovered a new campaign leveraging the KHRAT remote access Trojan (RAT). The DragonOk group (also known as NetTraveler (TravNet), PlugX, Saker, Netbot, DarkStRat, and ZeroT i) was first spotted September […]

Pierluigi Paganini August 31, 2017
Expert discovered 2,893 Bitcoin miners left exposed on the Internet

The popular Dutch security researcher Victor Gevers has discovered thousands of Bitcoin miners left exposed on the Internet. The popular security researcher Victor Gevers, the founder of the GDI Foundation, has discovered 2,893 Bitcoin miners left exposed on the Internet. I see about 2,893 Chinese Bitcoin "Thunder mining machines" online which are accessible via telnet […]

Pierluigi Paganini August 27, 2017
Security Affairs newsletter Round 125 – News of the week

A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. ·      Hackers can completely hijack a mobile device via replacement of a touchscreen ·      Learning About ISIS Intentions Using Open Source Intelligence ·      Security Affairs newsletter Round 124 – News of the week ·      Enigma platform hacked, […]

Pierluigi Paganini August 21, 2017
Enigma platform hacked, hackers stole over $470,000 worth of Ethereum

Enigma platform hacked – Another cyber heist made the headlines, this time an unknown hacker has stolen more than $471,000 worth of Ethereum cryptocurrency. The hacker has stolen it from the cryptocurrency investment platform, Enigma. According to an announcement made on Enigma website, an “unknown entity” has hacked their website, slack accounts and email newsletter accounts. “WARNING: ENIGMA SLACK […]

Pierluigi Paganini August 20, 2017
Security Affairs newsletter Round 124 – News of the week

A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. ·      Anti-Israel and pro-Palestinian IsraBye wiper spreads as a ransomware ·      Kenya opposition claims election results manipulated in cyber attack ·      MUGHTHESEC, a signed Mac adware that hijacks the victims browser for profit ·      Security Affairs newsletter […]

Pierluigi Paganini August 17, 2017
Drupal maintainers fix several access bypass vulnerabilities in Drupal 8

Drupal maintainers this week released security updates to fix several access bypass vulnerabilities in Drupal 8. Update your installation. On Wednesday Drupal maintainers released security updates to fix several access bypass vulnerabilities in Drupal 8. The flaws affect several components, including the entity access system, the REST API and some views. The most severe vulnerability patched by Drupal 8.3.7 is a critical issue, tracked as CVE-2017-6925 that affects […]

Pierluigi Paganini August 15, 2017
CVE-2017-0199: Crooks exploit PowerPoint Slide Show files to deliver malware

According to Trend Micro, cyber criminals abuse the CVE-2017-0199 vulnerability to deliver malware via PowerPoint Slide Show. In April Microsoft fixed the CVE-2017-0199  vulnerability in Office after threat actors had been exploiting it in the wild. Hackers leveraged weaponized Rich Text File (RTF) documents exploiting a flaw in Office’s Object Linking and Embedding (OLE) interface to deliver malware such […]

Pierluigi Paganini August 13, 2017
Security Affairs newsletter Round 123 – News of the week

A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. ·      Flaws in solar panels potentially threatening European power grids ·      Hackers leak the fourth episode of Game of Thrones season 7 online ·      Security Affairs newsletter Round 122 – News of the week ·      US Army […]