The Drupal CMS team has fixed a highly critical security flaw that allows hackers to take over a site just by accessing an URL. Drupal site owners should immediately —and we mean right now— update their sites to Drupal 7.58 or Drupal 8.5.1, depending on the version they’re running. […]
Hacking
New ThreadKit exploit builder used to spread banking Trojan and RATs
A recently discovered Microsoft Office document exploit builder kit dubbed ThreadKit has been used to spread a variety of malware, including RATs and banking Trojans. Security experts at Proofpoint recently discovered a Microsoft Office document exploit builder kit dubbed ThreadKit that has been used to spread a variety of malware, including banking […]
Boeing Is Dealing With a Suspected WannaCry Ransomware Outbreak
In a baffling turn of events, computers at Boeing have allegedly been infected with the WannaCry Ransomware. According to the Seattle Times, a memo was sent out by a Boeing employee that states that systems have been affected and that their were concerns the ransomware would « spread to airplane software ». The Seattle Times reports that […]
Meltdown Patch Opened Bigger Security Hole on Windows 7
Microsoft’s Meltdown patch has opened an even bigger security hole on Windows 7, allowing any user-level application to read content from the operating system’s kernel, and even write data to kernel memory. Swedish IT security expert Ulf Frisk made the discovery earlier this month while working on PCI Leech, a device […]
Hajime Botnet Makes a Comeback With Massive Scan for MikroTik Routers
If you’ve been following the infosec Twitter community for the last few days, you couldn’t ignore the constant talk about the massive scans currently taking place online, carried out by a Hajime IoT botnet looking to mass-infect unpatched MikroTik devices. All of the hoopla started on Sunday, March 25, when […]
BranchScope is a new side-channel attack method against Intel chip
BranchScope is a new side-channel attack technique that like Meltdown and Spectre attacks can be exploited by an attacker to obtain sensitive information from vulnerable processors. A group of researchers from the College of William & Mary, University of California Riverside, Carnegie Mellon University in Qatar, and Binghamton University has discovered […]
VPN leaks users’ IPs via WebRTC. I’ve tested seventy VPN providers and 16 of them leaks users’ IPs via WebRTC (23%)
Cyber security researcher Paolo Stagno (aka VoidSec) has tested seventy VPN providers and found 16 of them leaks users’ IPs via WebRTC (23%) You can check if your VPN leaks visiting: http://ip.voidsec.com Here you can find the complete list of the VPN providers that I’ve tested: https://docs.google.com/spreadsheets/d/1Nm7mxfFvmdn-3Az-BtE5O0BIdbJiIAWUnkoAF_v_0ug/edit#gid=0 Add a comment or send me […]
A flaw in the iOS camera QR code URL parser could expose users to attacks
A vulnerability in the iOS Camera App could be exploited by hackers to redirect users to a malicious website, the issue affects the built-in QR code reader. The iOS Camera App is affected by a bug that could be exploited by hackers to redirect users to a malicious website, the issue resides […]
L’AUTEUR D’UN CYBERBRAQUAGE DE BANQUES À 1 MILLIARD D’EUROS A ÉTÉ ARRÊTÉ
Europol a annoncé l’arrestation en Espagne du n°1 d’un gang de cybervoleurs qui aurait volé, via des logiciels malveillants, près d’un milliard d’euros à une centaine de banques dans 40 pays. Le groupe opérait depuis plus de cinq ans. Le « cerveau » ukrainien d’un gang de cybervoleurs qui aurait volé près […]
Police arrest members of cybercrime gang
ATM jackpot gang is thought to have infiltrated over 100 financial firms in 40 countries costing banks more than one billion dollars. Police say that they have arrested the head of a computer crime collective, alleged to have stolen millions of dollars from banks around the world after infecting them […]