The holidays are upon us and that means even ransomware developers are taking some time off. This showed this week with very few ransomware infections being released and for the most part we have only seen new variants of existing infections. The biggest news is the U.S. government officially attributing the […]
Hacking
Experts from Bleeping Computer spotted a new Cryptomix Ransomware variant
Security experts spotted a new variant of the CryptoMix ransomware that uses a different extension (.FILE) and a new set of contact emails. Security experts from BleepingComputer discovered a new variant of the CryptoMix ransomware that uses a different extension (.FILE) to append to the file names of the encrypted files and uses new contact emails. For […]
Cayla: A Toy That Connects Hackers To Your Life
Toys are amazing, and kids love them. They are being sold like hot cakes these days thanks to the holiday season. However, quite recently, a toy in the market has been doing a lot more than just make children happy. Cayla is a toy doll that responds to questions. That’s […]
Security Researchers prove that Windows 10 Facial Recognition can be breached with a Photo
Their spoofing attempts were declared on the cybersecurity site Seclists on Dec. 18. The cybersecurity experts bypassed Windows Hello which is Microsoft’s password-free security Lock on both a Dell and Microsoft laptop operating different versions of Windows 10, which is the reason for concern for anyone utilizing this feature to log into […]
Fake Prime Express Travel statement delivers Globeimposter ransomware
The next in the never ending series of malware downloaders from the Necurs botnet is an email with the subject of Outstanding Statement pretending to come from Prime Express Oldham <sales62@primeexpressuk.com> ( random numbers after sales) delivering Globeimposter ransomware They use email addresses and subjects that will entice, persuade, scare or shock a […]
Fortinet FortiClient Windows privilege escalation vulnerability (CVE-2017-7344) at logon
Summary Editor: Fortinet Product: FortiClient Title: Fortinet FortiClient Windows privilege escalation at logon CVE ID: CVE-2017-7344 Intrinsec ID: ISEC-V2017-01 Risk level: high Exploitable: Locally, or remotely if the logon screen is exposed (e.g. through RDP without NLA required). Requires non-default configuration on the client (« Enable VPN before logon »). Requires an invalid […]
DDE exploits still happening despite Microsoft updates to stop them
We are still seeing malware campaigns using the DDE exploit These are somewhat different to earlier versions and the word docs do contain macros with a very basic base64 encoded PowerShell script that contains the DDE exploit. Using Office Malscanner only shows the macro with a DDE Auto command not a separate DDE […]
Satori IoT Botnet Exploits Zero-Day to Zombify Huawei Routers
Satori IoT Botnet Exploits Zero-Day to Zombify Huawei Routers Although the original creators of the infamous IoT malware Mirai have already been arrested and sent to jail, the variants of the notorious botnet are still in the game due to the availability of its source code on the Internet. Hackers […]
A newly detected Ransomware called Retis
Retis: New Ransomware A security researcher has discovered a ransomware called Retis, which is a ransomware-type virus that secretly infiltrates the system. Shortly after executed, RETIS encrypts most saved data and adds filenames with the “.crypted” extension. It is a .NET ransomware, so its source code can be easily viewed. […]
Amateur Hacker Behind Satori Botnet
A so-called « script kiddie » is behind the recently discovered Satori botnet that has scared security researchers because of its rapid rise to a size of hundreds of thousands of compromised devices. Researchers say that a hacker named Nexus Zeta created Satori, which is a variant of the Mirai IoT malware […]