Skip to content

Information Security Newspaper

Secondary Navigation Menu
Menu
  • Home
  • Data Security
    • Mobile Security
    • Technology
    • Important
  • Vulnerabilities
  • Tools
    • Network Tools
      • DNSMap
      • DNSENUM
      • URLCRAZY
      • DNSRECON
      • DNSTRACER
      • TWOFI
      • ONIOFF
      • EXITMAP
      • PROXYCHAINS
      • DIG
      • NSLOOKUP
      • john the ripper
      • P0f
      • Sparta
      • arpSpoof
      • Photon
      • Justsniffer
      • Trevorc2
      • Vemon
      • GoScan
      • Masscan
      • OSNIT-Search
      • nbtstat
    • Web Scanners
      • NIKTO
      • HTTRACK
      • WAPITI
      • Fierce
      • GoBuster
      • w3af
      • DIRBUSTER
      • WPSCAN
      • Joomscan
      • WHATWEB
      • MassBleed
      • CRUNCH
    • Android
      • TheFatRat
      • EvilDroid
      • ANDROID DEBUG BRIDGE(ADB) – Part I
      • ANDROID DEBUG BRIDGE(ADB) – Part II
    • OSINT Tools
      • THEHARVESTER
      • DATASPLOIT
      • recon-ng
      • Babysploit
      • Shodan
      • Trape
      • Infoga
      • Metagoofil
      • Zoomeye
      • Devploit
      • Tinfoleak
      • BadMod
      • H8mail
      • Stardox
    • CTF Tools
    • CTF Challenges
      • Mr. Robot 1, walk through
    • DDoS Tools
    • Defense Evasion Tools
      • Getwin
    • Forensics
      • Steghide LSBstege
      • knock
    • Hash Cracking Hacking Tools
      • twofi
      • John the Ripper
      • Crunch
    • Linux Utilities
      • Terminator
      • Procdump
      • Termshark
    • Malware Analysis
      • AUTOMATER
      • Shed
    • Reverse Engineering Tools
    • Anonymity Tools
      • onioff
      • Proxychains
      • Exitmap
      • Deep Explorer
      • Hosting your own .onion domain
      • Send Anonymous Emails
      • OnionShare – startup in dark web
    • Vulnerability Scanners
      • Pocsuite
      • Mercury
      • Jok3r
      • FreeVulnsearch
      • Pompem
      • Phantom Evasion
    • Web Exploitation
      • XSS Shell
      • Wafw00f
      • Remote3d
    • Web Scanners
    • Windows Utilities
      • ENUM4LINUX
      • NETBIOS ENUMERATOR
      • Medusa
    • Wireless Hacking
      • Wigle
      • WiFiBroot
      • Hashcat
      • Aircrack-ng
    • Social Engineering Tools
      • blackeye
      • Seeker
      • BYOB
      • QRLJacker
      • phemail
      • Cuteit
      • Spooftel
  • Incidents
  • Malware
  • News Videos
  • Facebook
  • Twitter
  • YouTube
  • Telegram

OSX/Proton spreading again through supply-chain attack

2017-10-20
On: October 20, 2017
In: Incidents

During the last hours, ESET researchers noticed that Eltima, the makers of the Elmedia Player software, have been distributing a version of their application trojanized with the OSX/Proton malware on their official website.Read More →

Necurs Botnet malspam pushes Locky using DDE attack

2017-10-20
On: October 20, 2017
In: Vulnerabilities

I’ve seen Twitter traffic today about malspam from the Necurs Botnet pushing Locky ransomware using Word documents as their attachments.  These Word documents use the DDE attack technique, something I already wroteRead More →

Magnitude Exploit Kit Now Targeting South Korea With Magniber Ransomware

2017-10-20
On: October 20, 2017
In: Incidents

A new ransomware is being distributed by the Magnitude exploit kit: Magniber (detected by Trend Micro as RANSOM_MAGNIBER.A and TROJ.Win32.TRX.XXPE002FF019), which we found targeting South Korea via malvertisements on attacker-owned domains/sites. TheRead More →

Attacking a co-hosted VM: A hacker, a hammer and two memory modules

2017-10-20
On: October 20, 2017
In: Vulnerabilities

Row-hammer is hardware bug that can cause bit-flips in physical RAM. Mark Seaborn and Thomas Dullien were the first to exploit the DRAM row-hammer bug to gain kernel privileges. Kaveh Razavi et al. pushed the exploitation ofRead More →

Securing printed data in the ‘paperless’ office

2017-10-18
On: October 18, 2017
In: Incidents, Vulnerabilities

While we are supposedly in the era of the paperless office, intentional leaks via printed documents remain very common and can be just as damaging as their digital counterparts. WhileRead More →

Google introduces new Advanced Protection feature to protect its users

2017-10-18
On: October 18, 2017
In: Incidents

Google continues working to improve the security of its users, the last measure introduced by the company it the ‘Advanced Protection’ feature. The Advanced Protection feature was designed to improve theRead More →

Microsoft never disclosed 2013 hack of secret vulnerability database

2017-10-18
On: October 18, 2017
In: Vulnerabilities

Database contained details required to carry out highly advanced software attacks. Hackers broke into Microsoft’s secret, internal bug-tracking database and stole information related to vulnerabilities that were exploited in laterRead More →

BlackOasis APT leverages new Flash zero-day exploit to deploy FinSpy

2017-10-18
On: October 18, 2017
In: Vulnerabilities

Security researchers from Kaspersky Labs spotted the BlackOasis APT group exploiting a new zero-day RCE vulnerability in Adobe Flash. Security researchers from Kaspersky Labs have discovered a new zero-day remote code executionRead More →

ATM malware is being sold on Darknet market

2017-10-17
On: October 17, 2017
In: Malware

ATM systems appear to be very secure, but the money can be accessed fairly easily if you know what you are doing. Criminals are exploiting hardware and software vulnerabilities toRead More →

Even With The Best Email Spoofing Defences in The World, HMRC is Spoofed

2017-10-17
On: October 17, 2017
In: Vulnerabilities

Even with the most advanced email protections in place and an entire government organization to support them, the bad actors were able to spoof Her Majesty’s Revenue and Customs (HMRC)Read More →

These fake tax documents spread jRAT malware

2017-10-17
On: October 17, 2017
In: Malware

Data hungry malware tries to hook you with bogus forms and fake PDFs. jRAT malware users targeted US taxpayers with fake IRS tax documents, and now the same trick is beingRead More →

ROCA: Vulnerable RSA generation (CVE-2017-15361)

2017-10-17
On: October 17, 2017
In: Vulnerabilities

A newly discovered vulnerability in generation of RSA keys used by a software library adopted in cryptographic smartcards, security tokens and other secure hardware chips manufactured by Infineon Technologies AGRead More →

Key Reinstallation Attacks Breaking WPA2 by forcing nonce reuse

2017-10-16
On: October 16, 2017
In: Incidents, Vulnerabilities

We discovered serious weaknesses in WPA2, a protocol that secures all modern protected Wi-Fi networks. An attacker within range of a victim can exploit these weaknesses using key reinstallation attacks (KRACKs). Concretely, attackersRead More →

Linux-fight! Dev's plan to bundle kernel patches sparks debate

Linux kernel affected by a local privilege escalation vulnerability

2017-10-16
On: October 16, 2017
In: Vulnerabilities

Cisco issued a security advisory on a local privilege escalation vulnerability in the Linux Kernel, patch it as soon as possible. On Friday, Cisco issued a security advisory on aRead More →

How To Create a Keylogger using Notepad

2017-10-16
On: October 16, 2017
In: Incidents

Create an amazing hacking tool (Keyloggger) just by using Notepad. A keylogger is a hacking tool of the newbie but sometimes highly skilled hackers also use them. These are very easy toRead More →

Flaws in Siemens Building Automation Controllers open to hack. Fix them asap

2017-10-16
On: October 16, 2017
In: Vulnerabilities

Siemens has released a firmware update that addresses two vulnerabilities in its BACnet Field Panel building automation controllers. This week Siemens has released a firmware update for its BACnet FieldRead More →

Mayhem Malware Server Botnet Continues to Evolve

2017-10-14
On: October 14, 2017
In: Malware

Three years ago, researchers at Yandex discovered a complex server infection, dubbed Mayhem, that embeds itself deep within a system by compiling a shared object and running as a service. ThisRead More →

Security Service of Ukraine of a new wave of large-scale NotPetya-like attack

2017-10-14
On: October 14, 2017
In: Malware

The Security Service of Ukraine warning their citizens of a new “large-scale” cyber attack similar to NotPetya that could take place between Oct 13 and 17 In June the NotPetya ransomware compromised thousands ofRead More →

Someone Created a Tor Hidden Service to Phish my Tor Hidden Service

2017-10-14
On: October 14, 2017
In: Incidents

SMS Privacy is available as a Tor hidden service, and it turns out ~10% of users actually use it that way. This post details what I found when somebody created aRead More →

DOWN THE RABBIT HOLE WITH A BLU PHONE INFECTION

2017-10-14
On: October 14, 2017
In: Data Security

When network administrator James Lockmuller bought 11 dirt-cheap Android phones via Amazon he thought he had a perfect solution for communicating with his warehouse team stretched across a 73,000 square-footRead More →

Posts pagination

Previous 1 … 263 264 265 … 415 Next

Latest Videos

How Hackers Intercept Mobile OTP and Calls Without ‘Hacking’ — The Shocking Power of SIM Boxes

TunnelCrack: Two serious vulnerabilities in VPNs discovered, had been dormant since 1996

How to easily hack TP-Link Archer AX21 Wi-Fi router

US Govt wants new label on secure IoT devices or wants to discourage use of Chinese IoT gadgets

24,649,096,027 (24.65 billion) account usernames and passwords have been leaked by cyber criminals till now in 2022

View All

Vulnerabilities

How to hack the current version of Windows in 5 minutes

Learn how hackers code zero-days and make money

This Hidden Comet/Atlas AI Browser Flaw That Hackers Are Exploiting

How to Use Google’s OSS Rebuild: A New Open Source Software Supply Chain Security Tool

MFA? Irrelevant. CitrixBleed 2 Lets Hackers Take Over Without Logging In

View All

Tutorials

Steps to hack Active Directory of your company

A Single Web Page Could Spy on Your Other Tabs – Hidden Code Inside

How AI Phishing Emails Are Created and Sent (Step by Step – Training Article)

Learn how hackers code zero-days and make money

What are “Bulletproof VPN” vs “No Logs VPN”

How Scammers Make Fake Calls? (Step-by-Step Explained)

Best Free VPN Apps

Your WiFi Router might be watching your movements at home?

Recover Deleted Photos from Mobile – Top 5 Free Android Apps

The Process of Tracing People on the Internet

Forget Metasploit: Inside Predator’s Zero-Click Advertising-Driven Phone Hacking System

How Hackers Intercept Mobile OTP and Calls Without ‘Hacking’ — The Shocking Power of SIM Boxes

13 Insanely Easy Techniques to Hack & Exploit Agentic AI Browsers

How to Use Google’s OSS Rebuild: A New Open Source Software Supply Chain Security Tool

Phishing 2.0: AI Tools Now Build Fake Login Pages That Fool Even Experts

How TokenBreak Technique Hacks OpenAI, Anthropic, and Gemini AI Filters — Step-by-Step Tutorial

Comparing Top 8 AI Code Assistants: Productivity Miracle or Security Nightmare. Can You Patent AI Code Based App?

No Login Required: How Hackers Hijack Your System with Just One Keystroke: utilman.exe Exploit Explained

View All

Malware

Live Malware Code Mutation: How AI Generates Evasive Malware

Backdooring ATMs via Bootloader? These Hackers Showed It’s Still Possible in 2025”

How Lynx Ransomware Extorts Millions from U.S. Companies

A Malware That EDR Can’t See?If You Rely on Antivirus for Protection, Read This Before It’s Too Late!

Top 2 Malicious Python Packages You Must Avoid! Zebo-0.1.0 & Cometlogger-0.1

View All

Cyber Security Channel

How to easily hack TP-Link Archer AX21 Wi-Fi router

US Govt wants new label on secure IoT devices or wants to discourage use of Chinese IoT gadgets

24,649,096,027 (24.65 billion) account usernames and passwords have been leaked by cyber criminals till now in 2022

  • Facebook
  • Twitter
  • YouTube
  • Telegram
  • Foursquare
info@securitynewspaper.com    Privacy Policy
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.