Security Affairs

Pierluigi Paganini June 30, 2017
NotPetya – Ukraine secret service announces a joint investigation with Europol, FBI, and NCA

Ukraine secret service announces joint investigation with Europol, FBI, and NCA to attribute the recent Notpetya massive attack. While security experts are investigating real motivation behind the massive NotPetya attack, Ukrainian authorities called for support in the investigation from European and US intelligence and law enforcement agencies. The country’s security service SBU announced the international co-operation […]

Pierluigi Paganini June 25, 2017
Security Affairs newsletter Round 116 – News of the week

A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. ·      BAE Systems accused of selling mass surveillance software Evident across the Middle East ·      Facebook inadvertently revealed moderators identities to suspected terrorists ·      Kasperagent malware used in a new campaign leveraging Palestine-Themed decoy files ·      Security […]

Pierluigi Paganini June 24, 2017
Stealing AES-256 keys in seconds using €200 of off-the-shelf components

Security experts at Fox‑IT have demonstrated that is possible sniff AES-256 encryption keys from a distance of one meter (3.3 feet) with a cheap equipment. Security experts at Fox‑IT have demonstrated that is possible to power a side-channel attack to wirelessly extract secret AES-256 encryption keys from a distance of one meter (3.3 feet). The […]

Pierluigi Paganini June 24, 2017
US intelligence claims Russian hackers probed electoral networks in 21 US states

According to the US intelligence, Russian hackers tried to compromise electoral networks in 21 unnamed US states, but voting tallies hadn’t been hacked. According to Homeland Security officials, the attack against the 2016 Presidential election was more sophisticated than first thought. In a public hearing into the Russian interference in the 2016 Presidential election held by […]

Pierluigi Paganini June 22, 2017
Drupal fixes the CVE-2017-6922 flaw exploited in spam campaigns in the wild

Drupal team released security updates to fix several vulnerabilities, including the critical access bypass flaw CVE-2017-6922 exploited in spam campaigns. The Drupal development team has released security updates to fix several vulnerabilities, including the critical access bypass flaw tracked as CVE-2017-6922 that has been exploited in spam campaigns. The CVE-2017-6922 flaw was fixed with the […]

Pierluigi Paganini June 18, 2017
Security Affairs newsletter Round 115 – News of the week

A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. ·      Critical kernel command line injection flaw found in Motorola handsets MOTO G4, G5 ·      Police seized two Tor relays investigating WannaCry attack, others disappeared in the same period ·      US Defense is working on new multifactor […]

Pierluigi Paganini June 09, 2017
CISCO Prime Data Center Network Manager affected by two critical flaws

Cisco èiblished two security advisories to warn customers of the presence of two critical vulnerabilities in the CISCO Prime Data Center Network Manager, Cisco warns its customers of the presence of two critical vulnerabilities in the CISCO Prime Data Center Network Manager (DCNM) that can be exploited by remote attackers for code execution and to access […]

Pierluigi Paganini June 08, 2017
Comey hearing: Former FBI director talks about Russia interference in US Presidential Election

Former FBI Director Comey hearing: Comey Has ‘No Doubt’ on the Russia’s Involvement in cyber attacks against 2016 US Presidential Election.  James Comey today testified before the Senate Intelligence Committee that he believes that Russia Government is behind the cyber attacks aimed to interfere with the 2016 US election. Former FBI Director James Comey today […]

Pierluigi Paganini June 06, 2017
The Active Cyber Defense Certainty Act Makes Hacking Back Anything But “Certain”

Is the hack back legal? There is a heated debate about the concept of active defense. What about the Active Cyber Defense Certainty (ACDC) Act? In a time where attribution of cyber crimes is all but impossible, the idea of allowing companies to ‘hack back‘ at their attackers seems far-fetched. However, Tom Graves (R-GA) has […]

Pierluigi Paganini June 05, 2017
A new report warns UK’s Trident submarines ‘vulnerable to catastrophic hack’

According to a report published by the London-based think tank Basic, the UK Trident submarines are vulnerable to cyber-attacks. According to a report published by the London-based think tank British American Security Information Council (Basic), the UK Trident submarine fleet is vulnerable to cyber-attacks. According to the report “Hacking UK Trident, A Growing Threat,” a cyber […]