Gozi Trojan Becomes Dark Cloud Botnet
The widely distributed Gozi ISFB banking Trojan has a new trick up its sleeve; it has been making use of the evasive Dark Cloud botnet for distribution in a seriesRead More →
The widely distributed Gozi ISFB banking Trojan has a new trick up its sleeve; it has been making use of the evasive Dark Cloud botnet for distribution in a seriesRead More →
The Memcached vulnerability has been used in record-breaking DDoS attacks. Various proof-of-concept scripts have been released to exploit the vulnerability. Hackers have recently been exploiting a vulnerability in the MemcachedRead More →
As per ongoing investigation of an information security training firm, a stolen external hard drive has led to the personal information of more than 15,000 people formerly and currently associated with CaliforniaRead More →
Mac users are often told that they don’t need antivirus software, because there are no Mac viruses. However, this is not true at all, as Macs actually are affected byRead More →
Researchers find 150 Ramnit-infected apps a year after a similar batch was discovered. Last year, researchers discovered 132 Android apps in the Google Play market that lamely attempted to infect users with… WindowsRead More →
A loophole in Facebook’s advertising targeting mechanism could have let attackers obtain users’ phone numbers after they visited websites the attackers controlled, a group of information security training professionals revealedRead More →
A previously undisclosed vulnerability in Nike’s website allowed anyone with a few lines of code to read server data like passwords, which could have provided greater access to the company’sRead More →
This days Cortana seems to be the perfect AI assistant, but according to the discoveries of Israeli information security researchers Tal Be’ery and Amichai Shulman, Cortana is far from perfectionRead More →
The 4G LTE is already the mobile network standard that is most used today, being responsible for 83.73% of coverage availability. Therefore, it is really dangerous that a group ofRead More →
A massive amplification DDoS attack hit an undisclosed US-based company, setting new record just days after a similar attack took down GitHub. A DDoS attack using the Memcached vulnerability toRead More →
Just days before its annual information security training summit starts in Cancun, Mexico, Kaspersky Lab announced an extension to its bug bounty program and plan to pay rewards of upRead More →
The number of Flash Player exploits has recently declined, due to Adobe’s introduction of various measures to strengthen Flash’s security. Occasionally, however, an exploit still arises. On January 31, Kr-Cert reported aRead More →
In modern Intel processors, there’s a hardware extension available named Software Guard Extension (SGX) to improve the security aspects. It provides a shielded execution environment called ‘enclaves’ to deal withRead More →
Widely used message transfer agent patched buffer overflow last month. A bug in an obscure but widely used email program may be putting as many as 400,000 servers around theRead More →
Vulnerability in Pivotal’s Spring Data REST allows remote hackers to execute arbitrary commands on any machine that runs an application built using its components. The vulnerability was tracked as CVE-2017-8046Read More →
RMH Franchise Holdings revealed on Friday afternoon that PoS (point of sale) systems at the Applebee’s restaurants were infected with a PoS malware. According to information security training specialists, the PoS malwareRead More →
It has always been written about website security certificates many times. This is because HTTPS certificates (TLS certificates) are one of the main parties in the security of online transactions.Read More →
A flight of new research papers show 4G LTE networks can be exploited for all sorts of badness. There have been lots of reasons to be concerned about how easilyRead More →
Introduction When performing an application assessment one of the areas within an app I pay particular attention to is any ability to define custom templates. By this I mean functionalityRead More →
Hole made it possible to trick users into double spending and hack smart contracts. Developers of Ethereum, the world’s No. 2 digital currency by market capitalization, have closed a seriousRead More →