Security Affairs

Pierluigi Paganini September 25, 2014
Bash Bug is a critical risk to entire Internet infrastructure

Bash Bug is a critical flaw  remotely Exploitable which affects Linux, Unix and Apple Mac OS X and that is threatening the global Internet infrastructure. A new critical vulnerability dubbed Bash Bug in Linux and Unix command-line shell, aka the GNU Bourne Again Shell, is threatening the IT world. The flaw, coded as CVE-2014-6271, is remotely exploitable and affects Linux […]

Pierluigi Paganini September 21, 2014
DoJ proposal wants legitimate FBI hacking ops against anonymity

DoJ proposal is trying to legitimate FBI hacking operations against Internet users that make use of any kind of anonymizing technology. The FBI wants greater authority to hack overseas computers, according to a law professor. The Department of Justice (DoJ) is declaring war to online anonymity, its proposal to amend Rule 41 of the Federal […]

Pierluigi Paganini September 13, 2014
DNS cache poisoning attacks to steal emails are reality

CERT warns that DNS Cache Poisoning attacks could be used also to hijack email to a rogue server and not only to divert the Internet traffic. DNS attacks are very popular in hacking community, they could be run by cyber criminals and state-sponsored hackers for various purposes, including cyber espionage and financially motivated attacks. A DNS […]

Pierluigi Paganini August 25, 2014
FBI warns healthcare industry on possible cyber attacks

FBI is warning businesses operating in the healthcare industry on possible cyber attacks. The FBI is alerting the healthcare industry companies on potential cyber attacks, the law enforcement are warning companies after the attack on U.S. hospital group Community Health Systems Inc that caused the theft of millions of patient records. “The FBI has observed malicious actors targeting healthcare related systems, […]

Pierluigi Paganini August 21, 2014
Hackers have stolen credit card data from 51 UPS stores in the US

Hackers have compromised with a malware the system at 51 UPS Stores across the United States, customers’ credit card data may have been exposed. UPS is the last clamorous victim of a gang of cybercriminals from Eastern Europe, the bad actors behind the cyber attack has compromised 51 UPS Stores across the United States. The investigators […]

Pierluigi Paganini August 17, 2014
Grocery giants ALBERTSONS and SUPERVALU confirmed data breach

US Grocery giants ALBERTSONS and SUPERVALU have confirmed a data breach that could impact customers who acquired product in national stores. The Grocery giants Albertsons and SUPERVALU posted on Thursday a data breach notification related to an Incident Involving Payment Card Data Processing. Albertsons is the second largest grocery store chain in the US, meanwhile SUPERVALU is […]

Pierluigi Paganini August 14, 2014
AdThief malware infected jailbroken Apple devices

Malware expert Axelle Apvrille explained how the iOS AdThief malware infected more than 75000 jailbroken iOS devices hijacking millions advertisements. More than 75,000 jailbroken iPhones have been infected by a Chinese malware which were used by cyber criminals to hijack nearly 22 million advertisements and steal revenue from developers on the iOS jailbreak community. The […]

Pierluigi Paganini August 06, 2014
Russian crime ring amasses over a Billion credentials

Experts at Hold Security firm discovered a Russian group of hackers that collected 1.2B stolen credentials obtained in different data breaches worldwide. Experts at Hold Security revealed to have discovered the biggest database of stolen user names and passwords and email addresses, the news is reported by The New York Times that hired an independent security expert who verified […]

Pierluigi Paganini August 04, 2014
Analysis of the Stuxnet Cyber Weapon Family and Dragonfly

Cyber weapons like Stuxnet will only grow in prevalence, use and sophistication and it is therefore in the interest of national security to develop advanced mitigation techniques and capabilities. The progenitors of Duqu, Flame, and Gauss are reported as the authors of STUXNET. As illustrated, the trend of advancements between these four cyber weapons suggests […]

Pierluigi Paganini July 29, 2014
Misusing Digital Certificates

Excerpt from the post “How Cybercrime Exploits Digital Certificates” which details means and motivation of illicit activities which abuses digital certificates. Digital certificates have been misused many times during recent years. Bad actors abused them to conduct cyber attacks against private entities, individuals and government organizations. The principal abuses of digital certificates observed by security […]