Affichage des articles dont le libellé est News. Afficher tous les articles
Affichage des articles dont le libellé est News. Afficher tous les articles

A Critical Vulnerability in Inteno Routers

Security researchers are warning users regarding new critical vulnerabilities in Inteno routers, which could allow remote attackers to replace the firmware on a device to take complete control over it and monitor the internet traffic.

According to F-Secure, the issue affects the Inteno EG500, FG101, DG201 routers. However, more models could be affected, but it couldn’t be sure due to the vendor’s unwillingness to cooperate.

F-Measure claimed the issue in January but, when the vendor replied two months later it argued that software issues are dealt with the operators that sell the equipment to the end users.



The vulnerability itself is associated with the fact that several router models don’t validate the Auto Configuration Server (ACS) certificates. This means that it will allow an attacker to launch Man in the Middle (MITM) attack between ACS and the device and gain full administrative access to the router, allowing them to refresh the firmware.

The implications of such a flaw are potentially serious, according to F-Secure cyber security expert, Janne Kauhanen. He warned:

“By changing the firmware, the attacker can change any and all rules of the router. Watching video content you’re storing on another computer? So is the attacker. Updating another device through the router? Hopefully it’s not vulnerable like this, or they’ll own that too”.

Although, HTTPS traffic is encrypted and won’t be beneficial if hacked by the attacker, but they can still redirect all your traffic to malicious sites that enable them to drop malware on your machine.

However, if HTTPS is not implemented and the attacker is able to launch Man in the Middle attack, then there is no way left to prevent a successful exploitation. Janne Kauhanen told Infosecurity:

“Gaining a MitM position is not trivial, but it’s not outside the realm of possibilities either, whether physically attacking a whole building by breaking into the distribution trunk in the building or using software tricks to route network traffic through a malicious site”.

F-Secure recommended users to keep browsers and other software updated to prevent hackers exploiting any flaws. The use of effective and well known antivirus software is suggested to prevent any malware downloads and to use a VPN to encrypt internet traffic and prevent hackers gaining that initial foothold into the network.


~ vendredi 2 septembre 2016 0 commentaires

WikiLeaks Under Cyber Attack Due to Recent Failed Turkish Military Coup

On Monday July 18th, WikiLeaks tweeted about that they are going through a sustained attack on their infrastructure. All this start happening has after they announced to release a trove of documents detailing the Turkey’s political power structure.



WikiLeaks is best known for its release of classified government and military documents. Earlier on Monday it said that they are preparing to release 300,000 emails and 500,000 documents related to the failed coup operation in Turkey.


According to WikiLeaks, they suggest that the Turkish government is behind the attack on their organization. Furthermore, they said "We are unsure of the true origin of the attack. The timing suggests a Turkish state power faction or its allies”. In a subsequent tweet "We will prevail & publish”.


During the attempted coup in Turkey, it has been reported that Facebook, Twitter, YouTube was blocked. But many residents appear to have gotten around the blocks, posting messages and videos, likely using VPNs or other anonymizing services.

~ mardi 19 juillet 2016 0 commentaires

Malware Stealing Money by Pretending to be Whatsapp, GooglePlay and Other Famous Apps

Hackers always seek to steal money from credit cards and other financial information. They are actively stealing credit card and other financial information using malware. In Europe, a new malware is originated that can spoof the user interfaces of Uber, Whatsapp, Google Play, Youtube and few other messaging apps.

This malware is already spread in countries like Denmark, Italy and Germany. The old traditional Phishing technique is used to deploy and spread this malware.

Phishing is the attempt to acquire sensitive information such as usernames, passwords, and credit card details. In Phishing attack a clone is created of a website that acquires personal information from victim that is then emailed to the attacker.

In this case, the malware has been spreading through a Phishing campaign over SMS (Short Messaging Service). Once downloaded, the malware will create fake user interfaces of different apps on the phone. These interfaces further ask for credit card information and then send the entered data to the attacker.

This family of malware continues to evolve, earlier in February 2016 FireEyehad observed 55 malicious programs with same technique used. The earlier version was spoofing banking websites, but now this malware can spoof more popular applications like Youtube, Whatsapp and Google Play.

Users tend to input credit card information into these applications, FireEye researcher Wu Zhou said:
"Threat actors usually want to gain the largest financial benefit. So they typically target these apps that have a large user base”.

Nowadays, tricking victims into clicking on your malicious link is an easy task. The attacker used some easy tricks to make their links appealing to be clicked. To spread the malware, the hackers have sent a SMS messages with a link and tricked their victims into clicking on it. The SMS message said: “We could not deliver your order. Please check your shipping information here”.


According to research by FireEye, this malware is spread by five different campaigns and in one campaign hackers managed to get 130,000 clicks on their links where the malware was hosted.


Newer version of malware will be more powerful and undetectable, as only six out of 54 antivirus tools tested noticed the malicious coding behind these messages and emails. This malware is now has been found on servers in United Arab Emirates, Germany, Italy and the Netherland.


~ dimanche 10 juillet 2016 0 commentaires

OurMine Hacked CEO of Google and Others

Earlier this month, we heard that Facebook CEO Mark Zuckerberg’s Twitter, Instagram and Pineterest accounts got hacked by a hacker group “OurMine”. The hacker taunted “Hey @finkd we got access to your Twitter, Instagram and Pinterest, we are just testing your security, please DM us”. This news revealed the major security breach into accounts of different celebrities.


Google CEO Sundar Pichai has become the latest victim of this hacking group “OurMine” after his Twitter linked Quora account got compromised and filled with spam links and post.


After many spam posts on these accounts, this breach gone public as followed by many followers. OurMine group said it managed to breach Pichai’s account by exploiting Quora’s zero-day vulnerability. However, Quora has not responded yet on this flaw.

Surprisingly, OurMine has set up a website that displays a range of vulnerability scanning service and with a refund policy if the service didn’t work. In a short message they said “We are just testing people security, we never change their passwords, and we did it because there are other hackers who can hack them and change everything”.


It is believed that hackers are using the old exploited data dumps and also taking help from recent breaches and information leaks. The old passwords and credential that are still being used by many celebrities and individuals are the main factor behind these attacks.

A hacker “AlexPro” has exposed the hacker group “OurMine” by releasing the IP address and location they are operating from. It seems to be some Arabic people as traced location is Saudia Arab.



However, it is likely the team is using TOR and VPN to remain untraceable, as both are used to route internet traffic around the globe to hide the actual location.

On the rapid breaches on many social media sites, the Twitter spokesperson told the BBC: “A number of other online services have seen millions of passwords stolen in the past several weeks, and we know far too many people use the same password for multiple things online. We recommend people use a unique, strong password for Twitter”.

So it is highly recommended to use different passwords for all different accounts over internet to secure yourselves to some extent.


~ lundi 27 juin 2016 0 commentaires

US Teen Got Internship Offer after Hacking Pentagon’s Website

A high school graduate from Washington DC has been offered an internship by the Secretary of Defense Ash Carter. The Teen reportedly hacked into the Pentagon’s system, but instead of judicial sentence, rewarded and thanked by the Pentagon.



Ethical hacker named Dworken, spend 10-15 hour daily on his laptop attempting to break into different websites of law and enforcement. Dworken was one of two people praised by Ash Carter for finding bugs.

Dworken used his laptop from his high school “Maret High School” and exposed 6 vulnerabilities in the site. Carter said that it’s great that whitehat or ethical hacker exposed it before others.

"We know that state-sponsored actors and black hat hackers want to challenge and exploit our networks," he said according to Reuters. "What we didn't fully appreciate before this pilot was how many white hat hackers there are who want to make a difference."

Carter also signaled giving cash reward to the whitehat hackers for finding bugs in their system ranging from $100-$15000. For this Pentagon had asked 14000 people to work upon.

Unfortunately, Dworken did not receive any cash reward, as his bugs have already been found before this announcement. He says he will now study computer science along newly offered internship.


~ lundi 20 juin 2016 0 commentaires

Locky ransomware got hacked

Locky ransomware has raising destruction all over the world for past two months. Security researchers has already rated Locky as one of the most dangerous ransomware right now - researchers has failed to decrypt the files of Locky ransomware. However there is security holes in Locky ransomware also, which a White Hat hacker exploited according to Avira a German security firm.



Locky spread through email spam campaigns and encrypts the data of your computer once you download the infected attached file. Once the user clicks on attached file after downloading it; the Locky ransom the data and extort money from the user. There are many small and big business fallen victim to this deadly ransomware.

According to the German Cyber Security firm; an anonymous White Hat hacker was able to access and infiltrate a Locky C&C server and replace the ransomware payload with what it described as a dummy file which when downloaded on a victim's computer displays the message "Stupid Locky" rather than encrypting its contents.

Sven Carlsen an employee of Avira said; "I don’t believe that cyber criminals themselves would have initiated this operation because of the potential damage to their reputation and income stream,” He further added that; "He doesn't think that Locky Ransomware is dead after this security breach of their servers. The infiltration of a Locky C&C server does suggest that the operation is perhaps not as airtight as its operators might want to think".

This isn't the first time a White Hat hacker has hacked a ransomware or malware server. Dridex a well known banking Trojan has been previously suffered similar hacking attack. Hacking a Trojan or Ransomware is a unique thing because usually the skills of cyber criminals are much better than any White Hat or Security researcher. But, despite all those skills we are witnessing these cyber criminals out smarted by White Hat hackers time after time.

Details of White Hat hacker who hacked into Locky server are a big secret. The hack of Locky ransomware has showed the cyber criminals that, despite all their security measures they are vulnerable just like any organization in this era of security. 

Locky ransomware uses different servers established world wide to spread the malware; so hacking into a single server will not entirely impact the Locky ransomware threat. This Ransomware is spreading all over the world (specially in first world country) at an alarming speed. Every day the number of Locky ransomware victims are increasing and once you are infected user will consider paying those criminals what they demand to get his data back. 

Only way to secure yourself from this deadly ransomware is to take steps towards your security. There are many solutions available in the market; which can help you in securing your data from ransomware attack. 


~ mercredi 11 mai 2016 0 commentaires

Security researchers discovered 2900 new Ransomwares - Report

This era of technology will forever be remembered as the era when Ransomwares ruled the world. A security researcher from Kespersky Lab explained how Ransomware threat has taken over Advanced persistent threat (APT) as the most troublesome cyber threat.

In a report released by the Kespersky Lab; there has been a rise in new ransomware attacks by 14% in first three months of this year. The report explained how the security researchers has detected the 2,900 new ransomware between the Jan to March.



The cyber attack on Ukrainian energy sector is the most copious ransomware attack in the first quarter of this year. Even though the sector was attacked before the end of last year, but the bigger picture came to light after the year started. The attack enable hackers to disrupt the power distribution in some areas of Western Ukraine.

The increase of cyber threats has also hit hard on the banking sector. Carbank 2.0 has returned according to Kespersky Lab analysis. The cyber security firm has discovered the signs of Carbank in telecommunication and banking sectors. The new version of Carbank is not only targeting the banks; its prime targets now are accounting and budgeting sectors and firms. The new version of Carbank is still using the APT like tools and techniques, Kespersky Lab reported.

The reports received from various organizations by Kespersky researchers - the ransomware attacks organizations suffered this year is from well known Chinese groups; who are using APT techniques previously. There are many other similar cases where these groups are not involved, but a switch from APT techniques to ransomware development is pretty clear. The most destructive ransomware this year so far is PETYA; there are many cases where organizations whole data has been encrypted.

The criminals are using various techniques to spread the newly developed ransomware. Mass mailing is the most effective technique of encrypting data. Once an employee downloads the file; it will automatically install the ransomware in his computer and ransom every bit of his data. LOCKY ransomware is one which has used this technique with most effect.

At the end of fourth quarter last year; the number of ransomware attacks were 2549; which is now 2900. Further increase in new ransomware in expected in next quarter. One thing which disappointing the most is that the skills of cyber criminals is far better than security researchers. The increase of cyber attacks is the backing of my statement.


~ samedi 7 mai 2016 0 commentaires

World's youngest bounty winner lands $10,000 prize after hacking Instagram

A 10 year old Finish kid named Jani has won $10,000 prize money after he hacked into Instagram servers. Facebook the principal company has awarded the bounty after kid finds a way to delete other users comments from Instagram servers.



The young hacker claimed that; the security flaw he discovered could even allow him to delete pop-star Justin Bieber's comments and captions. The kid showed off the vulnerability to the Instagram security team after deleting a  comment on test account. The father of young hacker said, his young boys are very good at discovering security flaws in secure websites, but this one is their biggest accomplishment so far.

The $10k bounty prize was part of Facebook's Bug Bounty program, which offers rewards to White hat hackers  and other researchers who discover bugs or security flaws in their apps and websites. Last year, Facebook reportedly paid out $936k to 210 different researchers, out of a grand total of 13k submissions. 102 of those submissions were considered "high impact."

Bug bounty programs has been the most successful technique of their era to address security vulnerabilities. The lack of cyber security education in the world has raised concerns among organizations to develop secure products. Microsoft, Google, Apple and many other major giants are successfully fixing their security flaws by announcing bounty programs.


~ mercredi 4 mai 2016 0 commentaires

Linux Foundation introduces program to address open-source security issues

The Linux Foundation has launched a new open-source security program; which will boost the security of open-source software. In an announcement today by company; "The stakes have never been higher for open-source software security. With millions of people around the world relying on open source software — and vulnerabilities like Heartbleed putting everyone at risk — it's time to change the way we support, protect, and fortify open software."

In this project many tech firms, developers and stakeholders are brought together to create an ideal specifications and improve the security of critical open-source projects. GitLab, Curl, OpenBlox, OpenSSL, Zephyr are the early badge owner included.



The main motive behind this free program is to establish stability,quality and security of open-source software. The Linux Foundation further said; "The CII Best Practices online app enables developers to quickly determine whether they are following best practices and to receive a badge they can display on GitHub and other online properties when they pass. The app and its criteria are an open source project to which developers can contribute."

The open-source software is commonly used all over the world to manage and control database to web domain beckend online system. This free program will allow developers to have a direction of input and improvement; which can only improve security for users and vendors worldwide.


~ mardi 3 mai 2016 0 commentaires

Qatar National Bank Hacked; confidential data stolen by politically backed hackers

Qatar National Bank (QNB) has been targeted by the hackers; which have led to the 1.4GB of confidential data breach. The leaked data include the personal information of 1,200 account holders account and passwords.

Its hasn't yet been diagnosed that what vulnerabilities hackers exploited which resulted in this breach. QNB is the countries first financial institution, which has experienced a cyber attack of such high velocity.  The reason behind we rate this cyber attack of high velocity is because, the data has now entered the public realm and is available for download, reportedly containing sensitive corporate data and client financial information.



The Qatar news agencies has confirmed that; leaked data include the confidential files of Qatar secret service, security apparatus and even members of the ruling al-Thani family. We believe that hacking group behind the attack has been politically backed.

The deteriorating relationship between Iran and Middle East has been a big reason behind the attack. Iranian hackers has previously targeted Middle East corporations to create panic in the economy. The Bank released a small official statement that; "there is no financial impact on our clients or the bank."

QNB is the second major bank this year; which has been the victim of cyber attack. Bangladesh Central Bank has been targeted recently which resulted in the heist of $1 billion. The growing number of banking institutions victimized recently had raised concerns about the cyber defense of world's most powerful institutions.



~ jeudi 28 avril 2016 0 commentaires

IoT spending will reach $348 Million this year - Gartner Report

Cyber Security is the most lucrative business of this decade this makes security professionals the best paid people on the earth. The latest report by an analyst firm Gartner predicts an extraordinary growth of 23.7 percent this year. The report indicated that; global spending on Internet of Things (IoT) will reach a whopping $348 Million.

The Internet of Things (IoT) will revolutionize the Infosec Industry.


The report also indicated in next two years the IoT spending will reach $547 million worldwide. The growing number of IoT adaptation by companies and consumers will only increase the need of security products.


Products like connected cars, heavy machinery, commercial aircraft, farming and construction equipment all these things will increase the need of security; which will eventually result in the boom of security industry.

The research firm further predicts that; towards the end of this decade more than 25 percent of identified attacks in enterprises will involve IoT, despite IoT accounting for less than 10 percent of total IT security budgets.

According to Gartner researcher; "The effort of securing IoT is expected to focus more and more on the management, analytics, and provisioning of devices and their data. IoT business scenarios will require a delivery mechanism that can also grow and keep pace with requirements in monitoring, detection, access control and other security needs,"

He further said; "The future of cloud-based security services is in part linked with the future of the IoT. In fact, the IoT's fundamental strength in scale and presence will not be fully realized without cloud-based security services to deliver an acceptable level of operation for many organisations in a cost-effective manner."

The huge sum of spending in coming years will open huge opportunities for investors and young infosec professionals to startup their own firms and make a name for themselves in the industry. The infosec industry have been going through a revolutionary period and this has provided everyone great opportunities.

It doesn't matter if you setup a security business in a developed country or a third world country. The huge sum of spending will find its way to you. 

~ mardi 26 avril 2016 0 commentaires

JigSaw Ransomware: How to decrypt your encrypted data

A new kind of ransomware has emerged on the scene recently, which has been encrypting users data. If the user fails to meet the demands of attackers within 24 hour deadline, then their data will be deleted. Jigsaw is considered a big threat for corporations; because it will leave them empty handed if they fail to meet criminals demand. The attackers are demanding around $150 to release the encrypted data.



This breed of ransomware was first discovered by Jasen Sumalapao, a security researcher at Trend Micro. He described in a blogpost that; "Recent crypto-ransomware families have ransom amounts that grow as time passes, but not with the same increments as JIGSAW. To make matters worse, it deletes a larger amount of files with every hour while the amount to be paid also increases,”.

Jasen further described; "And with the exponential increase of files being permanently deleted, users may be pressured into paying the ransom so they may either save the remaining files, or avoid paying a larger ransom.”.

Jigsaw has been rated as the most vicious ransomware leaving Locky ( an equally threatening ransomware) behind. Jigsaw has been forcing the organizations to meet the attackers demand by leaving them with no time to look at the backups.

How to retrieve your data for FREE

In order to decrypt your data you need to follow the following steps:

Step 1: To stop any further files from delectation close the firefox.exe and drpbx.exe process from task manager.  

Step 2: Now user should run MSConfig and disable the start up entry called firefox.exe that points to the %UserProfile%\AppData\Roaming\Frfx\firefox.exe executable.

Step 3: Now download the Jigsaw ransomware encryption software  and extract the downloaded file. 

Step 4: Run the JigSawdecrypter.exe file and click on decrypt my files. 

Step 5: Select the drive you want to decrypt and do not check mark on the delete encrypted files. It can lead to data lose if tool fails to work properly. 

Step 6: Backup your data once all files decrypt successfully. 



~ jeudi 21 avril 2016 0 commentaires

SamSam malware puts 2,100 servers at risk of Ransomware attack

A new study by Cisco Talos revealed that more than about 2,100 servers across 1,600 different networks have been compromised. The research by Cisco security personnel shows that, 'In past few months a ransomware campaign is going on which has changed the landscape of ransomware delivery.'

Cisco researchers discovered this SamSam malware last month; researchers find SamSam pretty different from the previous malwares - which encrypted data and demand ransoms. SamSam is not launched via user focused attack vectors, such as phishing campaigns and exploit kits.



This particular family seems to be dispense via compromising servers and using them as a foothold to move laterally through the network to compromise additional machines which are then held for ransom. The industries which may be targeted in coming days because of SamSam server attacks are; government departments, aviation companies, schools and universities.

According to the Cisco Talos blog post, "we scanned for machines that were already compromised and potentially waiting for a ransomware payload. We found just over 2,100 backdoors installed across nearly 1600 ip addresses."

How to evade SamSam Malware from encrypting your data 

If you diagnose a webshell on your organization's server; you need to act immediately and take proper steps to address the threat. 
  • Your first step should be to remove the external access of your server. This will give you time to respond and also prevent outside access to your servers. 
  • Second step should be re-imaging the systems and install the latest version of software. This is the best solution to prevent outside breach or access of your server. 
  • In case you failed to re-build totally, your only option left is to restore backup before the server was compromised. Then, update the server to the updated version before returning it to production. 


~ mardi 19 avril 2016 0 commentaires

APAC CYBER SECURITY SUMMIT 2016 - Kuala Lumpur, Malaysia

Cyber Security have became one of the biggest issue in Asia and it needed to be addressed immediately. The lack of security awareness  among organizations hierarchy has been a roadblock while addressing these modern day cyber security issues.

 The need of having the knowledge of modern security threats and how to address these modern day threats becomes a necessary practice for security and IT professionals. Nispana Innovative Platforms Private Limited a global security provider has taken steps towards raising security awareness in Asia.

The APAC Cyber Security Summit 2016 by Nispana will be held on 2nd and 3rd June 2016 in Kuala Lumpur, Malaysia. This summit will address the modern cyber security issues; more than 25 speakers are invited and live hacking sessions will also demonstrates the modern security threats. The key agenda of APAC Cyber Security summit 2016 summit includes Data and Cloud Security, Mobile security, Risk and Governence, Security for critical infrastructure.

This is a big opportunity for leading organizations and their Cyber Security Managers to know how the landscape of the Cyber Security world has been changing in this modern era. 



~ dimanche 17 avril 2016 0 commentaires

Banking malware 'Halfbreed' targeting US and Canadian Banks

Halfbreed a new kind of banking malware has been targeting some US and Canadian. It has stolen more than $4 Million in past few days. The malware attacks was first discovered by the IBM Security Intelligence researchers.

Researcher defined in a blogpost on Security Intelligence; cyber criminals built this banking malware with the combination of Nymaim and Gozi ( two deadly malwares). Lior Keshet further explained that; It appears that the operators of Nymaim have recompiled its source code with part of the Gozi ISFB source code, creating a combination that is being actively used in attacks against more than 24 U.S. and Canadian banks, stealing millions of dollars so far. X-Force named this new hybrid GozNym.



The names of banks targeted by these criminals isn't disclosed yet, but the news has raised figures towards banking sector security infrastructure. Banking malware aren't a new invention; last year Kaspersky Lab researchers has discovered a malware dubbed as 'ATMZombie', which has stolen money and customer data from Israeli banks. Israeli organizations and banks are considered the most secure, when it comes to addressing the cyber threats. 

Halfbreed is different in many ways from ATMZombie, because of its combined source code and ability to steal money from banks. Cyber criminals today are more focused towards stealing data, but some of them are still there who are interested in real money. Banking sectors in US and Canada are on alert after this recent attacks on their servers and trying to fix the security holes, which are exploited by Halfbreed developers. 

The security researchers are trying their best to break the source code, but haven't succeeded yet. The number of target banks is expected to increase in coming weeks. 

~ samedi 16 avril 2016 0 commentaires

US Government departments are the most vulnerable to cyber attacks

Cyber Security is one of the biggest issues of Obama administration; but in all these years it's not wrong if we say the US government has failed to address these modern day cyber security threats. US government is failing badly to develop a security infrastructure, which can assure the security of its government departments and officials.



A new report published by a benchmarking firm shows; US government departments are ranked at the bottom among the major industries the real state, health care, retail and non-profit organizations. Last month a research was carried out by SecurityScorecard, which analyzed the 600 local, state, and federal government organizations which determined their security standards and ranked them accordingly.

Surprisingly the report showed government departments are in a really bad shape of defending them against these modern day cyber threats. Sectors which are most secured are technology, information security, construction and food. Telecommunication, Education and Pharmaceutical sectors are the ones who are also not secure from modern day threats.

Government departments have failed to meet up the security standards of any of these organizations. When you consider that big names like NASA, FBI and IRS are failing to secure themselves with those vast budgets it leaves you in shock. The increasing numbers of cyber attacks in US are a proof; how the lack of security knowledge have putting the common citizens data at risk.

Public sector organizations are more focused towards their security and paying top dollars just to provide the sense of security towards their customers.  While on the other hand government sectors officials data have been all over the dark web; just because the lack of security steps by Obama administration. More than 700,000 government officials data was breached last year; which included some high profile names like Hillary Clinton.

A huge spike in the Cyber Security budget is expected this year. Which may lead towards the positive growth of security industry - something we are predicting for a long time. A $5 billion increase is expected in the upcoming budget which makes the total spending reach to $19 billion.



~ vendredi 15 avril 2016 0 commentaires

Newest malware 'Treasurehunt' stealing Payment card data of Americans

Black hat hackers has developed a new malware 'Treasurehunt' which extracts the payment card data from the memory after enumerating the running process. After extracting the data from payment card, Treasurehunt forwards it to a command and control (CnC) server. Once the data of victim is stolen; hacker sell the extracted details in black markets.



There have been many malwares similar to the Treasurehunt which black hat hackers labelled as Point-of-sale (POS) in their underground forums. Last year security researchers has found more than dozen of POS malwares.

"Target" was one of the many big corporations targeted by these black hat hackers last year; it forces the retail giant to upgrade their systems. But not every business can afford the new certified systems because of the sky-high cost, it has now provided a big opportunity to hackers. That's why those small businesses now become the primary target of these criminals.

FireEye a cyber security firm was the first to discover this newest malware, which is targeting the thousands of U.S citizens all over the country. Nart Villeneuve security researcher on FireEye's blog post said, "Criminals appear to be racing to infected POS systems in the United States before U.S. retailers complete this transition".

He further wrote that "In a typical scenario, Treasurehunt would be implanted on a POS system through the use of previously stolen credentials or through brute forcing common passwords that allow access to poorly secured POS systems." 

These POS malwares including Treasurehunt are easily available on dark web if you are willing to pay the right price. Those tools available for FREE on dark web are not often as effective as the purchased ones. These free tools are mostly outdated or their source code may have been disclosed, which makes them easier to detect by security software. Average 60 million shoppers in U.S and Canada are effected from payment system hacks in past two years.






~ mardi 29 mars 2016 0 commentaires

FBI successfully unlocks San Bernardino shooter's iPhone

The U.S Dept of Justice has confirmed on Monday that it has dropped the case against the Silicon Valley tech giant Apple Inc. after FBI successfully unlocks the seized iPhone of San Bernardino shooter. The FBI didn't provided any information about how they bypassed the Apple security and unlocks the iPhone.



After U.S government drop the case - much anticipated showdown between the U.S government and Silicon Valley has been cancelled. The various sources confirmed that FBI seek help from a third party; which played a big part in unlocking the shooter's iPhone. The name of the third party source will remain confidential according to FBI.

The report FBI filled in court hasn't disclosed the methods used to unlock the iPhone nor it says that any evidence or lead found related to the San Bernardino attack. A government official accepted; the methods to unlock the iPhone wasn't developed by the FBI or government agency, but he refuses to comment whether the method can be used to unlock other OS devices.

U.S. Attorney Eileen M. Decker said in an official statement that; "Our decision to conclude the litigation was based solely on the fact that, with the recent assistance of a third party, we are now able to unlock that iPhone without compromising any information on the phone".

This may have ended the court case but the news have been damaging to Apple Inc. because now FBI have methods to unlock any iPhone the desire. The iOS developers must have their hands on their heads after these latest turn of events.

It will not be surprising if Apple launches a new iOS update in the coming month; which addressees the security issues which FBI have successfully exploited. The issues and methods remains undisclosed which makes it even harder for Apple Inc. to encounter them.



~ lundi 28 mars 2016 0 commentaires

Oracle releases patch to fixed highly critical bug

Oracle fixes a critical security flaw which leads to remote code execution without the need of its users credentials. The security flaw was around for more than two years, which is first reported by the Polish security firm Security Explorations back in 2013.



The firm earlier this month publicly announced that Oracle failed to patch the critical security flaw, which they reported two years ago. Oracle announced today in a security alert today that a patch has been released which will address the security flaw, which is affecting Java SE running in web browsers on desktops.

The security flaw is considered so severe as the flaw "can impact the availability, integrity, and confidentiality of the user's system." The severity level of this security flaw is so high that Oracle recommended its users to apply the latest update as soon as possible.

In their security alert report Oracle said, "This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator)."




~ jeudi 24 mars 2016 0 commentaires

Uber announces $10,000 bug bounty program

Uber announces their first ever bug bounty program on HackerOne platform on Tuesday. The rewards will be decided according to the severity of bug reported by the security researchers. There are three categories of  rewards; the researchers can take home maximum $10,000 bucks if the reported vulnerability is critical. While the minimum reward is worth $3,000.



Uber has followed the footsteps of some big tech organizations who are using the bug bounty programs to fix critical bugs in their products. The aim of Uber behind launching the bug bounty program is to secure the personal information of their riders and drivers.

The programs kick off from 1st May and security researchers have 90 days to report the bugs in Uber's systems. The Uber's bounty program is not totally identical to bounty program of other silicon valley firms like Facebook, Microsoft, Google, Twitter, Yahoo. Company has taken some unorthodox steps by announcing that it will even provide a “treasure map” for bug hunters designed to steer them toward potentially vulnerable areas of the company’s site.

Collin Greene Head of Uber's Product Security said; "By giving them a treasure map of the structure of our system, they can spend their time looking for really subtle bugs,”. 

Uber has published a list of vulnerabilities in which the company is interested. Some notable vulnerabilities are:

  • Cross-site Scripting (XSS)
  • Cross-site Request Forgery
  • Server-Side Request Forgery (SSRF)
  • SQL Injection
  • Server-side Remote Code Execution (RCE)

Last year the accounts of Uber's riders has been compromised, news comes out  in September last year when Uber car was on its way to pick their customer/rider in California, but the customer/rider didn't order the Uber's car service. The account of their customer was hacked which opened the Pandora box that hundreds of Uber's accounts has been compromised. The issue was fixed just after two weeks. 




~ mercredi 23 mars 2016 0 commentaires