Post

Visualizzazione dei post da maggio, 2018

''iPhone X a 1 euro'', attenti alle truffa: falsi articoli usati per rubare i dati delle carte degli utenti

http://www.repubblica.it/tecnologia/sicurezza/2018/04/24/news/_iphone_x_a_1_euro_attenti_alle_truffa_falsi_articoli_usati_per_rubare_i_dati_delle_carte_degli_utenti-194691806/

Russian State-Sponsored Cyber Actors Targeting Network Infrastructure Devices

https://www.us-cert.gov/ncas/alerts/TA18-106A

No, Panera Bread Doesn’t Take Security Seriously

https://medium.com/@djhoulihan/no-panera-bread-doesnt-take-security-seriously-bf078027f815

The dots do matter: how to scam a Gmail user

https://jameshfisher.com/2018/04/07/the-dots-do-matter-how-to-scam-a-gmail-user.html

Vulnerability Note VU#578598

https://www.kb.cert.org/vuls/id/578598

OSINT from ship satcoms

https://www.pentestpartners.com/security-blog/osint-from-ship-satcoms/

Tracking & hacking ships with Shodan & AIS

https://www.pentestpartners.com/security-blog/tracking-hacking-ships-with-shodan-ais/

Remotely hacking ships shouldn't be this easy, and yet ...

http://mashable.com/2017/07/18/hacking-boats-is-fun-and-easy/

Hacking train Wi-Fi may expose passenger data and control systems

https://www.theregister.co.uk/2018/05/11/train_wifi_hackable_on_some_networks/

IBM bans all removable storage, for all staff, everywhere

https://www.theregister.co.uk/2018/05/10/ibm_bans_all_removable_storage_for_all_staff_everywhere/

L'ultima frontiera delle cybertruffe: Pec false di banche online, svuotati centinaia di conti correnti

http://palermo.repubblica.it/cronaca/2018/05/08/news/l_ultima_frotiera_delle_cybertruffe_pec_false_di_banche_online_svuotati_centinaia_di_conti_correnti-195790638/

Over a Million Dasan Routers Vulnerable to Remote Hacking

https://www.securityweek.com/over-million-dasan-routers-vulnerable-remote-hacking

New Hacking Tool Lets Users Access a Bunch of DVRs and Their Video Feeds

https://www.bleepingcomputer.com/news/security/new-hacking-tool-lets-users-access-a-bunch-of-dvrs-and-their-video-feeds/

Hyperoptic's ZTE-made 1Gbps routers had hyper-hardcoded hyper-root hyper-password

https://www.theregister.co.uk/2018/04/26/hyperoptics_zte_routers/

Single single-sign-on SNAFU threatens three Cisco products

https://www.theregister.co.uk/2018/04/23/cisco_saml_bug_hits_firepower_anyconnect_asa/

A $152, 000 Ether Theft Just Exploited A Massive 'Blind Spot' In Internet Security

https://www.forbes.com/sites/thomasbrewster/2018/04/24/a-160000-ether-theft-just-exploited-a-massive-blind-spot-in-internet-security/

Windows-powered medical scanners are being hit by health care hackers

https://finance.yahoo.com/news/windows-powered-medical-scanners-being-132041620.html

An Elaborate Hack Shows How Much Damage IoT Bugs Can Do

https://www.wired.com/story/elaborate-hack-shows-damage-iot-bugs-can-do/

Securing wireless neurostimulators

https://blog.acolyer.org/2018/04/17/securing-wireless-neurostimulators/

Android apps prove a goldmine for dodgy password practices

https://www.theregister.co.uk/2018/04/16/android_apps_prove_a_goldmine_for_dodgy_password_practices/

Exposed: Lazy Android mobe makers couldn't care less about security

https://www.theregister.co.uk/2018/04/13/slow_android_security_fixes/

UK And US Accuse Russia Of Hacking Home Routers In Global Cyberattacks

https://www.forbes.com/sites/thomasbrewster/2018/04/16/russia-accused-of-hacking-network-infrastructure/

Thousands of compromised websites spreading malware via fake updates

https://www.tripwire.com/state-of-security/security-data-protection/cyber-security/thousands-compromised-websites-spreading-malware-via-fake-updates/

Flaw in Microsoft Outlook Lets Hackers Easily Steal Your Windows Password

https://thehackernews.com/2018/04/outlook-smb-vulnerability.html

Finland probing 130,000 login credentials breach

http://www.ehackingnews.com/2018/04/finland-probing-130000-login.html

‘FakeUpdates’ campaign leverages multiple website platforms

https://blog.malwarebytes.com/threat-analysis/2018/04/fakeupdates-campaign-leverages-multiple-website-platforms/

Secret Service Warns of Chip Card Scheme

https://krebsonsecurity.com/2018/04/secret-service-warns-of-chip-card-scheme/

“Open sesame”: Industrial network gear hackable with the right username

https://arstechnica.com/information-technology/2018/04/open-sesame-industrial-network-gear-hackable-with-the-right-username/

Cambridge Analytica website running an critically vulnerable version of Drupal

https://drupal.sh/cambridge-analytica-drupal-vulnerable

Saks, Lord & Taylor Hit With Data Breach

https://www.wsj.com/articles/saks-lord-taylor-hit-with-data-breach-1522598460

Be wary when scanning QR codes with iOS 11’s camera app

https://www.welivesecurity.com/2018/03/28/scanning-qr-codes-ios-11s/

Qualcuno ha rubato 2 milioni di euro alla Lazio?

https://www.ilpost.it/2018/03/28/lazio-de-vrij-feyenoord-hacker/

State-Sponsored Cyber Theft

https://www.fbi.gov/news/stories/nine-iranians-charged-in-hacking-scheme-032318

DOJ Indicts 9 Iranians for Cyber Heists Against 144 Colleges

https://www.wired.com/story/iran-cyberattacks-us-universities-indictment/

Update Samba Servers Immediately to Patch Password Reset and DoS Vulnerabilities

https://thehackernews.com/2018/03/samba-server-vulnerability.html

Anonymous ha attaccato il Miur e pubblicato le mail di 26 mila insegnanti

https://www.agi.it/cronaca/anonymous_attacco_hacker_miur_mail_insegnanti_cybersecurity-3604700/news/2018-03-08/

Nine Iranians Charged With Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps

https://www.justice.gov/opa/pr/nine-iranians-charged-conducting-massive-cyber-theft-campaign-behalf-islamic-revolutionary

Nine Iranians accused of hacking 320 unis, 47 businesses in 22 nations on Tehran's orders

https://www.theregister.co.uk/2018/03/23/iranians_charged_university_corporate_hacking/

Hackers steal banking & personal data of 800,000 Orbitz customers

https://www.hackread.com/hackers-steal-banking-personal-data-of-orbitz-users/

Suspicious likes lead to researcher lighting up a 22, 000-strong botnet on Twitter

https://techcrunch.com/2018/03/16/suspicious-likes-lead-to-researcher-lighting-up-a-22000-strong-botnet-on-twitter/

Off-the-Shelf Smart Devices Found Easy to Hack

https://aabgu.org/off-shelf-smart-devices-found-easy-hack/

Israeli Security Attacks AMD by Publishing Zero-Day Exploits

https://www.schneier.com/blog/archives/2018/03/israeli_securit.html

Attacks on 4G LTE networks could send fake emergency alerts

http://www.purdue.edu/newsroom/releases/2018/Q1/attacks-on-4g-lte-networks-could-send-fake-emergency-alerts.html

It's March 2018, and your PC can be pwned by reading an article

https://www.theregister.co.uk/2018/03/13/patch_tuesday_march_2018/

Pre-Installed Malware Found On 5 Million Popular Android Phones

https://thehackernews.com/2018/03/android-botnet-malware.html

A Cyberattack in Saudi Arabia Had a Deadly Goal. Experts Fear Another Try.

https://www.nytimes.com/2018/03/15/technology/saudi-arabia-hacks-cyberattacks.html

AMDFLAWS

https://amdflaws.com/

Poisoned peer-to-peer app kicked off Dofoil coin miner outbreak

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/poisoned-peer-to-peer-app-kicked-off-dofoil-coin-miner-outbreak/

Attacco hacker, il MIUR precisa: dati pubblicati non sono riconducibili a componenti dei sistemi informatici del Ministero

http://www.miur.gov.it/web/guest/-/attacco-hacker-il-miur-precisa-dati-pubblicati-non-sono-riconducibili-a-componenti-dei-sistemi-informatici-del-ministero

Crooks Created 28 Fake Ad Agencies to Disguise Massive Malvertising Campaign

https://www.bleepingcomputer.com/news/security/crooks-created-28-fake-ad-agencies-to-disguise-massive-malvertising-campaign/

EFF and Lookout Uncover New Malware Espionage Campaign Infecting Thousands Around the World

https://www.eff.org/press/releases/eff-and-lookout-uncover-new-malware-espionage-campaign-infecting-thousands-around

British 15-year-old gained access to intelligence operations in Afghanistan and Iran by pretending to be head of CIA, court hears

https://www.telegraph.co.uk/news/2018/01/19/british-15-year-old-gained-access-intelligence-operations-afghanistan/

Brazilian government providing warm waters for shoals of phish

https://news.netcraft.com/archives/2018/01/18/brazilian-government-providing-warm-waters-for-shoals-of-phish.html

UPDATE 1-Schneider Electric says bug in its software exploited in hack

https://www.reuters.com/article/schneider-cyber-attack/update-1-schneider-electric-says-bug-in-its-software-exploited-in-hack-idUSL1N1PD0ZR

Schneider Electric says software bug exploited in watershed hack

https://www.reuters.com/article/us-schneider-cyber-attack/schneider-electric-says-software-bug-exploited-in-watershed-hack-idUSKBN1F7228

Lebanese Government Hackers Hit Thousands of Victims With Incredibly Simple Campaign

https://motherboard.vice.com/en_us/article/gyw3n9/lebanese-government-hackers-hit-thousands-of-victims-with-incredibly-simple-campaign

How I exploited ACME TLS-SNI-01 issuing Let's Encrypt SSL-certs for any domain using shared hosting

https://labs.detectify.com/2018/01/12/how-i-exploited-acme-tls-sni-01-issuing-lets-encrypt-ssl-certs-for-any-domain-using-shared-hosting/

Researchers: SCADA Mobile Apps Continue to Have ‘Shocking’ Number of Vulnerabilities

https://securityledger.com/2018/01/researchers-scada-mobile-apps-continue-shocking-number-vulnerabilities-leaving-ics-systems-wide-open-attack/

Hidden Backdoor Found In WordPress Captcha Plugin Affects Over 300, 000 Sites

https://thehackernews.com/2017/12/wordpress-security-plugin.html

1 out of 5 USBs given away to promote Taiwan's cybersecurity campaign contain virus

https://www.taiwannews.com.tw/en/news/3336023

Correggio, attacco hacker di Anonymus contro gli autovelox

http://gazzettadireggio.gelocal.it/reggio/cronaca/2017/12/31/news/correggio-attacco-hacker-di-anonymus-contro-gli-autovelox-1.16298267

Hackers Broke Into Forever 21's Payment System For Over Half of 2017

https://gizmodo.com/hackers-broke-into-forever-21s-payment-system-for-over-1821668357

WhatsApp Flaws Could Allow Snoops to Slide Into Group Chats

https://www.wired.com/story/whatsapp-security-flaws-encryption-group-chats/

ESET research: Appearances are deceiving with Turla’s backdoor-laced Flash Player installer

https://www.welivesecurity.com/2018/01/09/turlas-backdoor-laced-flash-player-installer/

Western Digital My Cloud drives have a built-in backdoor

https://www.techspot.com/news/72612-western-digital-cloud-drives-have-built-backdoor.html

Critical Unpatched Flaws Disclosed In Western Digital 'My Cloud' Storage Devices

https://thehackernews.com/2018/01/western-digital-mycloud.html

US Homeland Security breach compromised personal info of 200, 000+ staff

https://www.theregister.co.uk/2018/01/04/us_homeland_security_breach_exposed_personal_info_of_200000_staff/

CoffeeMiner: Hacking WiFi to inject cryptocurrency miner to HTML requests

http://arnaucode.com/blog/coffeeminer-hacking-wifi-cryptocurrency-miner.html

New Android trojan targeting over 60 banks and social apps

https://clientsidedetection.com/new_android_trojan_targeting_over_60_banks_and_social_apps.html

Android banking Trojan targets more than 232 apps including Indian Banks : Quick Heal Technologies Security Blog : Latest computer security news, tips, and advice

http://blogs.quickheal.com/android-banking-trojan-targets-232-apps-including-indian-banks/

Kernel-memory-leaking Intel processor design flaw forces Linux, Windows redesign

https://www.theregister.co.uk/2018/01/02/intel_cpu_design_flaw/

Multiple vulnerabilities in the online services of (GPS) location tracking devices

https://0x0.li/trackmageddon/#advisories

Nintendo Switch Hacked to Run Pirated Games

https://www.hackread.com/nintendo-switch-hacked-to-run-pirated-games/

That Game on Your Phone May Be Tracking What You’re Watching on TV

https://www.nytimes.com/2017/12/28/business/media/alphonso-app-tracking.html

LastPass Authenticator Android app is easy to break into

https://www.slashgear.com/lastpass-authenticator-android-app-is-easy-to-break-into-28513035/

Mirai Variant "Satori" Targets Huawei Routers

http://www.securityweek.com/mirai-variant-satori-targets-huawei-routers

JexBoss - JBoss (and others Java Deserialization Vulnerabilities) verify and EXploitation Tool

https://www.kitploit.com/2017/12/jexboss-jboss-and-others-java.html

NotPetya’s Cost to FedEx: $400 Million and counting

https://securityledger.com/2017/12/notpetyas-cost-fedex-400-million-counting/

Washington DC’s surveillance cameras hacked… to send spam

https://nakedsecurity.sophos.com/2017/12/22/washington-dcs-surveillance-cameras-hacked-to-send-spam/

Romanian hackers infiltrated 65% of DC's outdoor surveillance cameras

http://www.cnn.com/2017/12/20/politics/romanian-hackers-dc-cameras/index.html

Home Economics: How Life in 123 Million American Households Was Exposed Online

https://www.upguard.com/breaches/cloud-leak-alteryx

How a Dorm Room Minecraft Scam Brought Down the Internet

https://www.wired.com/story/mirai-botnet-minecraft-scam-brought-down-the-internet/

Forever 21 clothing stores hit by credit card data breach after encryption failure

https://hotforsecurity.bitdefender.com/blog/forever-21-clothing-stores-hit-by-credit-card-data-breach-after-encryption-failure-19227.html

With deletion of one wallet, $280M in Ethereum wallets gets frozen

https://arstechnica.com/information-technology/2017/11/with-deletion-of-one-wallet-280-m-in-ethereum-wallets-gets-frozen/

Flaw crippling millions of crypto keys is worse than first disclosed

https://arstechnica.com/information-technology/2017/11/flaw-crippling-millions-of-crypto-keys-is-worse-than-first-disclosed/

Code Execution via Insecure Lenovo Objects

http://riscy.business/2017/12/lenovos-unsecured-objects/

Mailsploit: using emails to attack mail software

https://nakedsecurity.sophos.com/2017/12/11/mailsploit-using-emails-to-attack-mail-software/

Microsoft leaks TLS private key for cloud ERP product

https://medium.com/matthias-gliwka/microsoft-leaks-tls-private-key-for-cloud-erp-product-10b56f7d648

Mailsploit: it's 2017, and you can spoof the 'from' field in e-mail

https://www.theregister.co.uk/2017/12/06/mailsploit_email_spoofing_bug/

Modern-day “Ferris Bueller” hacks school, changes grades, applies to Ivy League colleges

https://hotforsecurity.bitdefender.com/blog/modern-day-ferris-bueller-hacks-school-changes-grades-applies-to-ivy-league-colleges-19300.html

CVE-2017-11826 Exploited in the Wild with Politically Themed RTF Document

https://blog.fortinet.com/2017/11/22/cve-2017-11826-exploited-in-the-wild-with-politically-themed-rtf-document

Man-in-the-Middle Attack against Electronic Car-Door Openers

https://www.schneier.com/blog/archives/2017/11/man-in-the-midd_8.html

Imgur breached back in 2014, wasn’t storing your passwords properly

https://nakedsecurity.sophos.com/2017/11/27/imgur-breached-back-in-2014-wasnt-storing-your-passwords-properly/

Bitcoin Gold wallet compromised, users may have downloaded malware

http://www.ehackingnews.com/2017/11/bitcoin-gold-wallet-compromised-users.html

17-Year-Old MS Office flaw CVE-2017-11882 could be exploited to remotely install malware without victim interaction

http://securityaffairs.co/wordpress/65588/breaking-news/cve-2017-11882.html

Oracle Products Affected by Critical JOLTandBLEED Vulnerabilities

https://www.bleepingcomputer.com/news/security/oracle-products-affected-by-critical-joltandbleed-vulnerabilities/

Confusion reigns over crypto vuln in Spanish electronic ID smartcards

https://www.theregister.co.uk/2017/11/15/spanish_id_card/

BlueBorne Vulnerability Also Affects 20Mil Amazon Echo and Google Home Devices

https://www.bleepingcomputer.com/news/security/blueborne-vulnerability-also-affects-20mil-amazon-echo-and-google-home-devices/

How AV can open you to attacks that otherwise wouldn’t be possible

https://arstechnica.com/information-technology/2017/11/how-av-can-open-you-to-attacks-that-otherwise-wouldnt-be-possible/

Google says hackers steal almost 250,000 logins each week

http://money.cnn.com/2017/11/09/technology/google-hackers-research/index.html

Silence – a new Trojan attacking financial organizations

https://securelist.com/the-silence/83009/

Day trader indicted for 'cyber boiler room' scheme targeting hacked online brokerage accounts

http://www.ibtimes.co.uk/day-trader-indicted-cyber-boiler-room-scheme-targeting-hacked-online-brokerage-accounts-1646546

Microsoft issues advisory to users after macro-less malware attacks

https://www.tripwire.com/state-of-security/security-data-protection/microsoft-advisory-office-dde-malware/

Critical Tor flaw leaks users’ real IP address—update now

https://arstechnica.com/information-technology/2017/11/critical-tor-flaw-leaks-users-real-ip-address-update-now/

It took Russian hackers just over a week to penetrate Clinton campaign email

http://www.pressherald.com/2017/11/03/it-took-russian-hackers-just-over-a-week-to-penetrate-clinton-campaign-email/

Stuxnet-style code signing is more widespread than anyone thought

https://arstechnica.com/information-technology/2017/11/evasive-code-signed-malware-flourished-before-stuxnet-and-still-does/

Falsi F24 via e-mail, ecco il malware che "si traveste" da Agenzia delle Entrate

http://www.corrierecomunicazioni.it/digital/49581_falsi-f24-via-e-mail-ecco-il-malware-che-si-traveste-da-agenzia-delle-entrate.htm

HomeHack: How Hackers Could Have Taken Control of LG’s IoT Home Appliances

https://blog.checkpoint.com/2017/10/26/homehack-how-hackers-could-have-taken-control-of-lgs-iot-home-appliances/

Savitech USB audio drivers install a new root CA certificate

http://www.kb.cert.org/vuls/id/446847

CryptoShuffler Trojan has quietly stolen $140,000 worth of Bitcoin

https://www.kaspersky.com/blog/cryptoshuffler-bitcoin-stealer/19976/