Cisco has found over a dozen critical and high severity vulnerabilities in its Policy Suite, SD-WAN, WebEx and Nexus products. The tech giant has reported customers four critical vulnerabilities affecting the Policy Suite. The flaws tracked as CVE-2018-0374, CVE-2018-0375, CVE-2018-0376, and CVE-2018-0377 have been discovered during internal testing. Two of these flaws could be exploited by a […]
Année : 2018
ZoomEye IoT search engine cached login passwords for tens of thousands of Dahua DVRs
A security researcher discovered that the IoT search engine ZoomEye has cached login passwords for tens of thousands of Dahua DVRs. The IoT search engine ZoomEye has cached login passwords for tens of thousands of Dahua DVRs, the discovery was made by security researcher Ankit Anubhav, Principal Researcher at NewSky Security. Anubhav explained […]
Hackers Distributing Anubis Malware via Google Play Store to Steal Login credentials, E-wallets, and Payment Cards Details
Anubis banking malware re-emerges again and the threat actors distributing the malware on Google Play store apps to stealing login credentials to banking apps, e-wallets, and payment cards. Hackers always finding new ways to bypass the Google play store security and distributing malware via Android apps that will act as the first […]
CoinVault Ransomware Authors Have Their Day in Court in the Netherlands
The authors of the CoinVault ransomware have had their day in court today in the Netherlands, where their case was presented in front of a three-judge panel. During today’s hearing in Rotterdam, the judges heard from prosecutors, the defendants, and some of their victims. The sentencing hearing has been scheduled […]
Ukraine ‘s SBU Security Service reportedly stopped VPNFilter attack at chlorine station
Ukraine ‘s SBU Security Service reportedly stopped VPNFilter attack at chlorine station, the malware infected the network equipment in the facility that supplies water treatment and sewage plants. According to the Interfax-Ukraine media outlet, the VPNFilter hit the LLC Aulska station in Auly (Dnipropetrovsk region), according to the experts the malware aimed at disrupting operations at […]
Facebook faces £500,000 fine in the U.K. over Cambridge Analytica scandal
Facebook has been fined £500,000 ($664,000) in the U.K. for its conduct in the Cambridge Analytica privacy scandal. Facebook has been fined £500,000 in the U.K., the maximum fine allowed by the UK’s Data Protection Act 1998, for failing to protect users’ personal information. Political consultancy firm Cambridge Analytica improperly collected data of 87 […]
WORDPRESS CORRIGE UNE VULNÉRABILITÉ JOUR ZÉRO DANS SON CMS
Une vulnérabilité (0-day) importante a été corrigée à partir de la version 4.9.7 de WordPress. L’exploitation de cette vulnérabilité permettrait à un attaquant authentifié de supprimer des fichiers arbitraires sur le serveur, et d’exécuter du code arbitraire. Un utilisateur ayant des privilèges « auteur » ou supérieurs, pourrait, en supprimant définitivement la vignette d’une image téléversée, […]
Internet Transit Providers Disconnect Infamous « BGP Hijack Factory »
Several Internet transit providers —companies that route global Internet traffic between local ISPs, end users, and data centers— have banded together to ban a fellow transit provider that has carried out at least 130 Internet route (BGP) hijacks in the past few years, most of which, experts say, were with […]
China-based TEMP.Periscope APT targets Cambodia’s elections
FireEye uncovered a large-scale Chinese phishing and hacking campaign powered by Temp.periscope APT aimed at Cambodia’s elections. Security researchers at FireEye have uncovered a large-scale Chinese phishing and hacking campaign aimed at Cambodia’s elections. The hackers distributed a remote access trojan (RAT) and data exfiltration operation targeting the poll. The experts from FireEye attributed the attacks […]
Timehop Data Breach Affects 21million Users’
Timehop, an add-on app that reminisces people’s good old days on different social media platforms, has suffered a data breach on July 4th, that affected 21 million users. The stolen data includes names, email addresses, date of the birth, and over 4.7 million users phone number that they linked to […]