Security Affairs

Pierluigi Paganini August 01, 2019
CISA warns of critical flaws in Prima FlexAir access control system

The U.S. CISA published a security advisory to warn of multiple critical vulnerabilities affecting in Prima FlexAir access control system. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) published an advisory to warn of critical flaws affecting access control systems manufactured by Prima Systems. Prima access control has a wide range of solutions, including wall-mounted […]

Pierluigi Paganini July 31, 2019
Cyber attacks hit Louisiana schools ahead of year’s beginning

A wave of cyber attacks hit schools of Louisiana ahead of year’s beginning that is planned for the next week. Several schools of Louisiana were targeted by hackers ahead of year’s beginning that is planned for the next week. The AP press states that a fourth Louisiana school district is assessing damages caused by a […]

Pierluigi Paganini July 31, 2019
DHS warns of cyber attacks against small airplanes

A few hours ago, I have written about an interesting analysis of the possible hack of avionics systems, not DHS warns of cyber attacks against small airplanes. Today we introduced an interesting report published by researchers at Rapid7 about the hacking of avionics systems via CAN bus, now the DHS issues an alert to warn […]

Pierluigi Paganini July 31, 2019
Hacking avionics systems through the CAN bus

An expert analyzed the level of security of avionics systems used in small airplanes, and the results are disconcerting. Patrick Kiley, a senior security consultant at Rapid7 conducted an investigation into the security of avionics systems inside small airplanes. The results are disconcerting it is quite easy to hack a small plane. Kiley, which is […]

Pierluigi Paganini July 31, 2019
Hacking campaign is wiping Iomega NAS Devices exposed online

Experts warn of a new campaign carried out by threat actors that are wiping Iomega NAS devices exposed online. Security experts are warning of a campaign carried out by attackers that are deleting files on publicly accessible Lenovo Iomega NAS devices. Likely attackers use the Shodan search engine to find unprotected IOmega NAS exposed online […]

Pierluigi Paganini July 30, 2019
Malware researchers analyzed an intriguing Java ATM Malware

Experts spotted a Java ATM malware that was relying on the XFS (EXtension for Financial Service) API to “jackpot” the infected machine Introduction Recently our attention was caught by a really particular malware sample most probably linked toa recent cybercriminal operation against the banking sector. This piece of malicious code is a so-called ‘ATM malware‘: […]

Pierluigi Paganini July 30, 2019
Capital One data breach: hacker accessed details of 106M customers before its arrest

Capital One, one of the largest U.S. –card issuer and financial corporation suffered a data breach that exposed personal information from more than 100 million credit applications. A hacker that goes online with the handle “erratic” breached the systems at Capital One and gained access to personal information from 106 million Capital One credit applications. […]

Pierluigi Paganini July 29, 2019
WordPress Plugin Facebook Widget affected by authenticated XSS

Security experts at Plugin Vulnerabilities have discovered an authenticated Persistent Cross-Site Scripting (XSS) flaw in Facebook Widget. Researchers at Plugin Vulnerabilities have discovered an authenticated Persistent Cross-Site Scripting (XSS) flaw in the Facebook Widget (Widget for Facebook Page Feeds). The plugin is one of the 1,000 most popular plugins and it was closed on the […]

Pierluigi Paganini July 29, 2019
Prolific Dark Web dealer of drugs pleads guilty

One of the most active drug sellers on the Dark Web was charged by law authorities and ordered to forfeit over $4 million in cryptocurrency.  The US Department of Justice (DoJ) charged Richard Castro (36) (aka “Chemsusa,” “Chems_usa,” and “Jagger109”) with participating in a conspiracy to distribute carfentanil, fentanyl, and a fentanyl analogue over the […]

Pierluigi Paganini July 29, 2019
Sonicwall warns of a spike in the number of attacks involving encrypted malware and IoT malware

According to experts at Sonicwall, scanning of random ports and the diffusion of encrypted malware are characterizing the threat landscape. In 2018, global malware volume recorded by SonicWall hit a record-breaking 10.52 billion attacks. The situation is better in the first half of 2019, when SonicWall recorded 4.8 billion attacks, a 20% drop compared to […]