Fake Prime Express Travel statement delivers Globeimposter ransomware

Haythem Elmir

The next in the never ending series of malware downloaders from the Necurs botnet is an email with the subject of   Outstanding Statement  pretending to come from Prime Express Oldham <sales62@primeexpressuk.com>  ( random numbers after sales) delivering Globeimposter ransomware They use email addresses and subjects that will entice, persuade, scare or shock  a […]

Fortinet FortiClient Windows privilege escalation vulnerability (CVE-2017-7344) at logon

Haythem Elmir

Summary Editor: Fortinet Product: FortiClient Title: Fortinet FortiClient Windows privilege escalation at logon CVE ID: CVE-2017-7344 Intrinsec ID: ISEC-V2017-01 Risk level: high Exploitable: Locally, or remotely if the logon screen is exposed (e.g. through RDP without NLA required). Requires non-default configuration on the client (« Enable VPN before logon »). Requires an invalid […]

A newly detected Ransomware called Retis

Haythem Elmir

Retis: New Ransomware A security researcher has discovered a ransomware called Retis,  which is a ransomware-type virus that secretly infiltrates the system. Shortly after executed, RETIS encrypts most saved data and adds filenames with the “.crypted” extension. It is a .NET ransomware, so its source code can be easily viewed. […]

Amateur Hacker Behind Satori Botnet

Haythem Elmir

A so-called « script kiddie » is behind the recently discovered Satori botnet that has scared security researchers because of its rapid rise to a size of hundreds of thousands of compromised devices. Researchers say that a hacker named Nexus Zeta created Satori, which is a variant of the Mirai IoT malware […]