Post

Visualizzazione dei post da aprile, 2017

Clamoroso ricatto hacker a Netflix: rubate e messe in rete nuove puntate della serie cult

http://www.repubblica.it/spettacoli/2017/04/29/news/clamoroso_ricatto_hacker_a_netflix_rubate_e_messe_in_rete_puntate_della_nuova_serie_cult-164232880/

Mysterious Hajime botnet has pwned 300,000 IoT devices • The Register

https://www.theregister.co.uk/2017/04/27/hajime_iot_botnet/

Homebrew crypto SNAFU on electrical grid sees GE rush patches • The Register

https://www.theregister.co.uk/2017/04/27/ge_rushing_patches_to_grid_systems_ahead_of_black_hat_demonstration/

Australia' Smart meter leaders lag in securing devices • The Register

https://www.theregister.co.uk/2017/04/27/oz_smart_meter_leaders_lag_in_securing_devices/

Interpol unplugs nearly 9,000 Asian command and control networks • The Register

https://www.theregister.co.uk/2017/04/26/interpol_unplugs_command_and_control_networks_across_asia/

Hyundai app security blunder allowed crooks to 'steal victims' cars' • The Register

https://www.theregister.co.uk/2017/04/25/hyundai_blink_link_app_security/

Hackers uncork experimental Linux-targeting malware • The Register

https://www.theregister.co.uk/2017/04/25/linux_malware/

Vai sul sito ANVUR? Uno script maligno registra il tuo profilo e lo manda a Singapore

http://www.roars.it/online/vai-sul-sito-anvur-uno-script-maligno-registra-il-tuo-profilo-e-lo-manda-a-singapore/

Alert: If you're running SquirrelMail, Sendmail... why? And oh yeah, remote code vuln found • The Register

https://www.theregister.co.uk/2017/04/24/squirrelmail_vuln/

Webroot antivirus goes bananas, starts trashing Windows system files • The Register

https://www.theregister.co.uk/2017/04/25/webroot_windows_wipeout/

HipChat SlipChat lets hackers RipChat • The Register

https://www.theregister.co.uk/2017/04/25/hipchat_users_exposed/

Attacco hacker al sito dell’Anvur: «Attività sospette di alterazione dei contenuti»

http://www.scuola24.ilsole24ore.com/art/universita-e-ricerca/2017-04-10/attacco-hacker-sito-dell-anvur-attivita-sospette-alterazione-contenuti-133515.php?uuid=AEm6ph2

“Buy VQR”, la pillola azzurra della valutazione

http://www.roars.it/online/buy-vqr-la-pillola-azzurra-della-valutazione/

Oracle patch update for April 2017 also fixed Struts and Shadow Brokers exploits

http://securityaffairs.co/wordpress/58142/hacking/oracle-patch-update-for-april.html

Flaws found in Linksys routers that could be used to create a botnet • The Register

https://www.theregister.co.uk/2017/04/20/linksys_router_vulns/

Half-baked security: Hackers can hijack your smart Aga oven 'with a text message'

https://www.theregister.co.uk/2017/04/13/aga_oven_iot_insecurity/

ShadowBrokers: The NSA compromised the SWIFT Network

https://medium.com/@msuiche/the-nsa-compromised-swift-network-50ec3000b195

The Latest Dump of Alleged NSA Tools Is ‘The Worst Thing Since Snowden’

https://motherboard.vice.com/en_us/article/the-latest-shadow-brokers-dump-of-alleged-nsa-tools-is-awful-news-for-the-internet

Hackers hijack Airbnb account and burgle homes

http://www.ehackingnews.com/2017/04/hackers-hijack-airbnb-account-and.html

NSA-leaking Shadow Brokers just dumped its most damaging release yet

https://arstechnica.com/security/2017/04/nsa-leaking-shadow-brokers-just-dumped-its-most-damaging-release-yet/

InterContinental Hotel Chain Breach Expands

https://krebsonsecurity.com/2017/04/intercontinental-hotel-chain-breach-expands/

301 Moved Permanently

https://www.theregister.co.uk/2017/04/19/oracle_patches_some_solaris_systems_for_shadow_brokers_exploits_but_only_v10_11/

Profit with just one infection! Crook sells ransomware for $175 • The Register

https://www.theregister.co.uk/2017/04/18/ransomware_offers_infection_dashboard/

Inside the 'Stalkerware' Surveillance Market, Where Ordinary People Tap Each Other's Phones

https://motherboard.vice.com/en_us/article/inside-stalkerware-surveillance-market-flexispy-retina-x

Chrome and Firefox Phishing Attack Uses Domains Identical to Known Safe Sites

https://www.wordfence.com/blog/2017/04/chrome-firefox-unicode-phishing/

Hotpoint service sites hacked

https://news.netcraft.com/archives/2017/04/17/hotpoint-service-sites-hacked.html

Linux remote root bug menace: Make sure your servers, PCs, gizmos, Android kit are patched • The Register

https://www.theregister.co.uk/2017/04/14/new_critical_linux_kernel_flaw/

DTMF replay phreaked out the Dallas tornado alarm, say researchers • The Register

https://www.theregister.co.uk/2017/04/13/dtmf_replay_phreaked_out_the_dallas_tornado_alarm_say_researchers/

Booby-trapped Word documents in the wild exploit critical Microsoft 0-day

https://arstechnica.com/security/2017/04/booby-trapped-word-documents-in-the-wild-exploit-critical-microsoft-0day/

How I hacked my IP camera, and found this backdoor account

https://jumpespjump.blogspot.com/2015/09/how-i-hacked-my-ip-camera-and-found.html

Hacking the Aldi IP CCTV Camera (part 2) | Pen Test Partners

https://www.pentestpartners.com/blog/hacking-the-aldi-ip-cctv-camera-part-2/

Nifty XSS in Annke SP1 HD wireless camera | Pen Test Partners

https://www.pentestpartners.com/blog/nifty-xss-in-annke-sp1-hd-wireless-camera/

Multiple vulnerabilities found in Wireless IP Camera (P2P) WIFICAM cameras and vulnerabilities in custom http server - A slice of Kimchi - IT Security Blog

https://pierrekim.github.io/blog/2017-03-08-camera-goahead-0day.html

Microsoft Word 0-day used to push dangerous Dridex malware on millions

https://arstechnica.com/security/2017/04/microsoft-word-0day-used-to-push-dangerous-dridex-malware-on-millions/

Hackers use FAFSA application to steal tax info

http://money.cnn.com/2017/04/07/technology/hackers-irs-fafsa-data/index.html

How I Hacked my Smart TV from My Bed via a Command Injection

https://www.netsparker.com/blog/web-security/hacking-smart-tv-command-injection/

Callisto Group hackers targeted Foreign Office data

http://www.bbc.com/news/technology-39588703

Five Inmates Built Two PCs and Hacked a Prison From Within

https://www.bleepingcomputer.com/news/security/five-inmates-built-two-pcs-and-hacked-a-prison-from-within/

CVE-2017-0199 Used as Zero Day to Distribute FINSPY Espionage Malwareand LATENTBOT Cyber Crime Malware « Threat Research Blog

https://www.fireeye.com/blog/threat-research/2017/04/cve-2017-0199_useda.html

Buggy Riverbed portal needs patching – now

https://www.theregister.co.uk/2017/04/11/patch_for_riverbed_portal/

Il virus che attacca le smart tv passando dal digitale terrestre: la risposta di Samsung

http://www.corriere.it/tecnologia/cyber-cultura/17_aprile_05/virus-che-attacca-smart-tv-passando-digitale-terrestre-risposta-samsung-20c23506-1a25-11e7-9076-8d7d92d4815c.shtml

Moodle cross-site scripting CVE-2017-7298 Report vulnerabilità

https://exchange.xforce.ibmcloud.com/vulnerabilities/123997

Attacks Detected with New Microsoft Office Zero-Day

https://www.bleepingcomputer.com/news/security/attacks-detected-with-new-microsoft-office-zero-day/

156 Hacked Emergency Sirens Show Dallas Officials That They Have a Security Problem

http://gizmodo.com/156-hacked-emergency-sirens-show-dallas-officials-that-1794155445

OLE-y hell. Bug in MSFT Word allows total PC p0wnage • The Register

https://www.theregister.co.uk/2017/04/09/microsoft_word_ole_bug/

Apple finally teaches Android music app to validate certificates • The Register

https://www.theregister.co.uk/2017/04/10/apple_music_vulnerability/

Over The Air: Exploiting Broadcom’s Wi-Fi Stack (Part 1)

https://googleprojectzero.blogspot.com/2017/04/over-air-exploiting-broadcoms-wi-fi_4.html

Pandavirtualization: Exploiting the Xen hypervisor

https://googleprojectzero.blogspot.com/2017/04/pandavirtualization-exploiting-xen.html

Found: Quite possibly the most sophisticated Android espionage app ever

https://arstechnica.com/security/2017/04/found-quite-possibly-the-most-sophisticated-android-espionage-app-ever/

Rash of in-the-wild attacks permanently destroys poorly secured IoT devices

https://arstechnica.com/security/2017/04/rash-of-in-the-wild-attacks-permanently-destroys-poorly-secured-iot-devices/

'Amnesia' IoT botnet feasts on year-old unpatched vulnerability • The Register

https://www.theregister.co.uk/2017/04/07/amnesia_iot_botnet/

Businesses could lose $16.4 billion to online advertising fraud in 2017: Report

http://www.cnbc.com/2017/03/15/businesses-could-lose-164-billion-to-online-advert-fraud-in-2017.html

How an Unprecedented Heist Hijacked a Bank’s Entire Online Operation

https://www.wired.com/2017/04/hackers-hijacked-banks-entire-online-operation/

Schneider Electric still shipping passwords in firmware • The Register

https://www.theregister.co.uk/2017/04/05/schneider_istilli_shipping_passwords_in_firmware/

Patch Qubes to prevent pwnage via Xen bug • The Register

https://www.theregister.co.uk/2017/04/05/patch_qubes_to_prevent_pwnage_via_xen_bug/

RAT-catchers spot new malware attacking South Korean word processor • The Register

https://www.theregister.co.uk/2017/04/05/rokrat_malware/

Hackers Can Easily Hijack This Dildo Camera and Livestream the Inside of Your Vagina (Or Butt)

https://motherboard.vice.com/en_us/article/camera-dildo-svakom-siime-eye-hacked-livestream

Power plant cyber threat: Lock up your ICSs and SCADAs

https://www.theregister.co.uk/2017/04/03/power_plant_cyber_threat_warning/

New York Post apologizes after app apparently hacked

http://www.reuters.com/article/us-newscorp-newyorkpost-idUSKBN17404K

Drive-by Wi-Fi i-Thing attack, oh my! • The Register

https://www.theregister.co.uk/2017/04/03/driveby_wifi_ithing_fix/

Hackers Using Fake Cellphone Towers to Spread Android Banking Trojan

http://thehackernews.com/2017/03/rogue-bts-android-malware.html

Smart TV hack embeds attack code into broadcast signal—no access required

https://arstechnica.com/security/2017/03/smart-tv-hack-embeds-attack-code-into-broadcast-signal-no-access-required/

Exploit attacks your smart TV through over-the-air signals

https://www.engadget.com/2017/04/01/smart-tv-broadcast-security-exploit/

Skype users hit by ransomware through in-app malicious ads

http://www.zdnet.com/article/skype-served-up-malware-through-in-app-malicious-ads/

Three words to set alarm bells off for every firm - BBC News

http://www.bbc.com/news/business-39429819