isco removed today a backdoor account from its IOS XE operating system that would have allowed a remote attacker to log into Cisco routers and switches with a high-privileged account. The company says the « undocumented user account » only impacts devices running Cisco XE Software 16.x —an operating system deployed mostly […]
Boeing Is Dealing With a Suspected WannaCry Ransomware Outbreak
In a baffling turn of events, computers at Boeing have allegedly been infected with the WannaCry Ransomware. According to the Seattle Times, a memo was sent out by a Boeing employee that states that systems have been affected and that their were concerns the ransomware would « spread to airplane software ». The Seattle Times reports that […]
Meltdown Patch Opened Bigger Security Hole on Windows 7
Microsoft’s Meltdown patch has opened an even bigger security hole on Windows 7, allowing any user-level application to read content from the operating system’s kernel, and even write data to kernel memory. Swedish IT security expert Ulf Frisk made the discovery earlier this month while working on PCI Leech, a device […]
Hajime Botnet Makes a Comeback With Massive Scan for MikroTik Routers
If you’ve been following the infosec Twitter community for the last few days, you couldn’t ignore the constant talk about the massive scans currently taking place online, carried out by a Hajime IoT botnet looking to mass-infect unpatched MikroTik devices. All of the hoopla started on Sunday, March 25, when […]
BranchScope is a new side-channel attack method against Intel chip
BranchScope is a new side-channel attack technique that like Meltdown and Spectre attacks can be exploited by an attacker to obtain sensitive information from vulnerable processors. A group of researchers from the College of William & Mary, University of California Riverside, Carnegie Mellon University in Qatar, and Binghamton University has discovered […]
VPN leaks users’ IPs via WebRTC. I’ve tested seventy VPN providers and 16 of them leaks users’ IPs via WebRTC (23%)
Cyber security researcher Paolo Stagno (aka VoidSec) has tested seventy VPN providers and found 16 of them leaks users’ IPs via WebRTC (23%) You can check if your VPN leaks visiting: http://ip.voidsec.com Here you can find the complete list of the VPN providers that I’ve tested: https://docs.google.com/spreadsheets/d/1Nm7mxfFvmdn-3Az-BtE5O0BIdbJiIAWUnkoAF_v_0ug/edit#gid=0 Add a comment or send me […]
A flaw in the iOS camera QR code URL parser could expose users to attacks
A vulnerability in the iOS Camera App could be exploited by hackers to redirect users to a malicious website, the issue affects the built-in QR code reader. The iOS Camera App is affected by a bug that could be exploited by hackers to redirect users to a malicious website, the issue resides […]
L’AUTEUR D’UN CYBERBRAQUAGE DE BANQUES À 1 MILLIARD D’EUROS A ÉTÉ ARRÊTÉ
Europol a annoncé l’arrestation en Espagne du n°1 d’un gang de cybervoleurs qui aurait volé, via des logiciels malveillants, près d’un milliard d’euros à une centaine de banques dans 40 pays. Le groupe opérait depuis plus de cinq ans. Le « cerveau » ukrainien d’un gang de cybervoleurs qui aurait volé près […]
Preventing the Next Ransomware Attack
2018 is quickly moving by us, and while we have yet to see an attack on the scale of 2017’s WannaCry or NotPetya, it’s clear that the adversaries are not letting up on their mission to line their pockets at our expense. Ransomware has dominated the headlines for the last two years, while […]
Police arrest members of cybercrime gang
ATM jackpot gang is thought to have infiltrated over 100 financial firms in 40 countries costing banks more than one billion dollars. Police say that they have arrested the head of a computer crime collective, alleged to have stolen millions of dollars from banks around the world after infecting them […]