NIST Site Search
Search NIST.GOV
Custom Search
[Official NIST.GOV TIME]
Product Research

Advertise on this site
Newsfeeds
Help Net Security
  • BrickerBot bricked 2 million IoT devices, its author claims

    The author of BrickerBot, which “bricks” IoT devices by rewriting the flash storage space and wiping files, has emerged to explain that the malware first attempts to secure the units without damaging them. Failing that, it reverts to “plan B”, i.e. actions that result in the device being rendered temporarily or permanently unusable. He also claims that since the malware was deployed – sometime before January 2017 – it has bricked over two million of … More

    click to view

  • Locky ransomware makes a comeback, courtesy of Necurs botnet

    The Necurs botnet has, once again, begun pushing Locky ransomware on unsuspecting victims. The botnet, which flip-flops from sending penny stock pump-and-dump emails to booby-trapped files that lead to malware (usually Locky or Dridex), has been spotted slinging thousand upon thousand of emails in the last three or four days. “Talos has seen in excess of 35K emails in the last several hours associated with this newest wave of Locky,” Cisco Talos researchers noted on … More

    click to view

  • Tens of thousands Windows systems implanted with NSA’s DoublePulsar

    Has your Windows machine been implanted with NSA’s DoublePulsar backdoor? If you haven’t implemented the security updates released by Microsoft in March, chances are good that it has. What is DoublePulsar? DoublePulsar is a backdoor implant that enables the injection and running of DLLs – potentially malicious ones – on Windows computers. It was recently leaked by the Shadow Brokers, and hackers have been using it – in conjunction with the EternalBlue exploit – to … More

    click to view

  • Alleged Kelihos botmaster indicted

    36-year-old Pyotr Levashov was charged on Friday in the US with one count of causing intentional damage to a protected computer, one count of conspiracy, one count of accessing protected computers in furtherance of fraud, one count of wire fraud, one count of threatening to damage a protected computer, two counts of fraud in connection with email and one count of aggravated identity theft. Levashov stands accused of controlling and operating the Kelihos botnet to, … More

    click to view

  • Russian carding industry pioneer sentenced to 27 years in prison

    32-year-old Roman Valeryevich Seleznev, aka Track2, has been handed the longest US hacking sentence to date: 27 years in prison. He was convicted in August 2016, of 38 counts (intentional damage to a protected computer, obtaining information from a protected computer, possession of unauthorized access devices and aggravated identity theft) related to his scheme to hack into point-of-sale computers to steal credit card numbers and sell them on dark market websites. The unprecedentedly long prison … More

    click to view

  • Week in review: Open source security threats, secure C++ coding

    Here’s an overview of some of last week’s most interesting news and articles: Will blockchain liability be similar to Bitcoin liability? Blockchain can be used for cryptocurrencies other than Bitcoin, and can be used for more than just cryptocurrencies. A Blockchain is a list of transactional records on a distributed ledger technology. Blockchain can be used to record real estate transactions, testing records, health care record storage and more. Rules for secure coding in the … More

    click to view

  • What motivates youngsters to get into cybercrime?

    A UK National Crime Agency report, which is based on debriefs with offenders and those on the fringes of criminality, explores why young people assessed as unlikely to commit more traditional crimes get involved in cyber crime. Motives and opportunities It emphasises that financial gain is not necessarily a priority for young offenders. Instead, the sense of accomplishment at completing a challenge, and proving oneself to peers in order to increase online reputations are the … More

    click to view

  • RawPOS malware has new data-grabbing capabilities

    RawPOS continues to evolve, and has recently been equipped with the capability to steal data contained in the victims’ driver’s license’s 2-dimensional barcode. “Although the use of this barcode is less common than credit card swipes, it is not unheard of. Some people might experience getting their driver’s license barcode scanned in places like pharmacies, retail shops, bars, casinos and others establishments that require it,” Trend Micro researchers explained. “Traditionally, PoS threats look for credit … More

    click to view

  • Top-ranked programming Web tutorials introduce vulnerabilities into software

    Researchers from several German universities have checked the PHP codebases of over 64,000 projects on GitHub, and found 117 vulnerabilities that they believe have been introduced through the use of code from popular but insufficiently reviewed tutorials. The process The researchers identified popular tutorials by inputing search terms such as “mysql tutorial”, “php search form”, “javascript echo user input”, etc. into Google Search. The first five results for each query were then manually reviewed and … More

    click to view

  • Be careful on Google Play

    An often repeated piece of advice given to users of mobile devices says that they should stick to well-reputed, official app stores if they want to avoid malware. But while the chance of downloading malware from Google Play might be lower than the chance of doing the same through third-party Android app markets, it’s still easy to get saddled with iffy and outright malicious apps even if you only ever use Google’s official app store. … More

    click to view

| Date published: Tue, 25 Apr 2017 00:21:24 +0000
Back to newsfeed list
Translate to: {GOOGLETRANS}
Google Ads




Headlines

»CVE-2007-6761
drivers/media/video/videobuf-vmalloc.c in the Linux kernel before 2.6.24 does not initialize videobu ...
»CVE-2010-1776
Find My iPhone on iOS 2.0 through 3.1.3 for iPhone 3G and later and iOS 2.1 through 3.1.3 for iPod t ...
»CVE-2010-5321
Memory leak in drivers/media/video/videobuf-core.c in the videobuf subsystem in the Linux kernel 2.6 ...
»CVE-2010-5329
The video_usercopy function in drivers/media/video/v4l2-ioctl.c in the Linux kernel before 2.6.39 re ...
»CVE-2011-3428
Buffer overflow in QuickTime before 7.7.1 for Windows allows remote attackers to execute arbitrary c ...
»CVE-2011-3438
WebKit, as used in Safari 5.0.6, allows remote attackers to cause a denial of service (process crash ...
»CVE-2013-7463
The aescrypt gem 1.0.0 for Ruby does not randomize the CBC IV for use with the AESCrypt.encrypt and ...
»CVE-2014-9654
The Regular Expressions package in International Components for Unicode (ICU) for C/C++ before 2014- ...
»CVE-2014-9680
sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo fi ...
»CVE-2014-9907 (imagemagick)
coders/dds.c in ImageMagick allows remote attackers to cause a denial of service via a crafted DDS f ...
»CVE-2015-0104
IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration ...
»CVE-2015-0107
IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration ...
»CVE-2015-1521
analyzer/protocol/dnp3/DNP3.cc in Bro before 2.3.2 does not properly handle zero values of a packet ...
»CVE-2015-1522
analyzer/protocol/dnp3/DNP3.cc in Bro before 2.3.2 does not reject certain non-zero values of a pack ...
»CVE-2015-7245
Directory traversal vulnerability in DLink DVGN5402SP with firmware W1000CN00, W1000CN03, or W2000EN00 allows remote attackers to read sensitive information via a .. (dot dot) in the errorpage parameter.


Date published: 2017-04-25T00:00:01Z
Details

»Drupal Releases Security Updates
Original release date: April 19, 2017 Drupal has released an advisory to address a vulnerabil ...
»Cisco Releases Security Updates
Original release date: April 19, 2017 Cisco has released updates to address several high-impa ...
»Mozilla Releases Security Updates
Original release date: April 19, 2017 Mozilla has released security updates to address a vuln ...
»Google Releases Security Updates for Chrome
Original release date: April 19, 2017 Google has released Chrome version 58.0.3029.81 for Win ...
»VMware Releases Security Updates
Original release date: April 18, 2017 VMware has released security updates to address vulnera ...
»Oracle Releases Security Bulletin
Original release date: April 18, 2017 Oracle has released its Critical Patch Update for April ...
»Microsoft Addresses Shadow Brokers Exploits
Original release date: April 15, 2017 | Last revised: April 17, 2017 The Microsoft Security R ...
»VMware Releases Security Updates
Original release date: April 14, 2017 VMware has released security updates to address a vulne ...
»ISC Releases Security Updates for BIND
Original release date: April 12, 2017 The Internet Systems Consortium (ISC) has released upda ...
»Apache Software Foundation Releases Security Updates
Original release date: April 12, 2017 | Last revised: April 18, 2017 The Apache Foundation ha ...


Date published: not known
Details

»VB2016 paper: Debugging and monitoring malware network activities with Haka
In their VB2016 paper, Stormshield researchers Benoît Ancel and Meh ...
»VB2017: a wide ranging and international conference programme
We are proud to announce a very broad and very international progra ...
»John Graham-Cumming and Brian Honan to deliver keynote addresses at VB2017
Virus Bulletin is excited to announce John-Graham Cumming and Brian ...
»Virus Bulletin says a fond farewell to John Hawes
As VB's COO John Hawes moves on to new challenges, the team wish hi ...
»VB2016 paper: One-Click Fileless Infection
Symantec researchers Himanshu Anand and Chastine Menrige explain ho ...
»Mostly blocked, but still good enough: Necurs sending pump-and-dump spam
The Necurs botnet has started sending pump-and-dump spam. Almost al ...
»Why the SHA-1 collision means you should stop using the algorithm
Realistically speaking, if your software or system uses the SHA-1 h ...
»VB2017 Call for Papers: frequently asked questions
The call for papers for VB2017, which takes place 4 to 6 October i ...
»Throwback Thursday: Michelangelo - Graffiti Not Art
This week marked the 25th anniversary of the trigger date of the in ...


Date published: not known
Details
Main Menu
· Home
Current Security News
 
US-CERT Current Activity

» Drupal Releases Security Updates
[19 Apr 2017 06:17pm]

» Cisco Releases Security Updates
[19 Apr 2017 06:14pm]

» Mozilla Releases Security Updates
[19 Apr 2017 06:04pm]

» Google Releases Security Updates for Chrome
[19 Apr 2017 06:02pm]

» VMware Releases Security Updates
[18 Apr 2017 02:34pm]

» Oracle Releases Security Bulletin
[18 Apr 2017 02:30pm]

» Microsoft Addresses Shadow Brokers Exploits
[15 Apr 2017 07:09pm]

» VMware Releases Security Updates
[14 Apr 2017 04:13pm]

» ISC Releases Security Updates for BIND
[12 Apr 2017 08:19pm]

» Apache Software Foundation Releases Security Updates
[12 Apr 2017 12:11pm]

***
US-CERT Alerts

» TA17-075A: HTTPS Interception Weakens TLS Security
[16 Mar 2017 06:40am]

» TA16-336A: Avalanche (crimeware-as-a-service infrastructure)
[30 Nov 2016 10:00pm]

» TA16-288A: Heightened DDoS Threat Posed by Mirai and Other Botnets
[14 Oct 2016 05:59pm]

» TA16-250A: The Increasing Threat to Network Infrastructure Devices and Recommended Mitigations
[06 Sep 2016 04:29pm]

» TA16-187A: Symantec and Norton Security Products Contain Critical Vulnerabilities
[05 Jul 2016 08:50am]

» TA16-144A: WPAD Name Collision Vulnerability
[23 May 2016 05:38am]

» TA16-132A: Exploitation of SAP Business Applications
[11 May 2016 05:31am]

» TA16-105A: Apple Ends Support for QuickTime for Windows; New Vulnerabilities Announced
[14 Apr 2016 01:48pm]

» TA16-091A: Ransomware and Recent Variants
[31 Mar 2016 04:00pm]

» TA15-337A: Dorkbot
[03 Dec 2015 04:40pm]

***
Computerworld Security

» Customers roast Microsoft over security bulletins' demise
[24 Apr 2017 12:49pm]

» Researchers remotely kill the engine of a moving car by hacking vulnerable car dongle
[24 Apr 2017 10:54am]

» Russian man receives longest-ever prison sentence in the U.S. for hacking
[24 Apr 2017 09:17am]

» FAQ: What is blockchain and how can it help business?
[24 Apr 2017 04:01am]

» There's now a tool to test for NSA spyware
[22 Apr 2017 05:43am]

» Hackers use old Stuxnet-related bug to carry out attacks
[20 Apr 2017 02:57pm]

» Developer lifts Windows 7's update blockade with unsanctioned patch
[20 Apr 2017 02:28pm]

» DHS's ICS-CERT warns of BrickerBot: IoT malware that will brick vulnerable devices
[19 Apr 2017 09:21am]

» Experts contend Microsoft canceled Feb. updates to patch NSA exploits
[18 Apr 2017 02:06pm]

» How one personal cyber insurance policy stacks up
[18 Apr 2017 05:00am]

» IDG Contributor Network: Most of the Windows zero-day exploits have already been patched
[17 Apr 2017 01:46pm]

» Microsoft confirms it's patched most of the NSA's Windows exploits
[17 Apr 2017 01:05pm]

» 1,175 hotels listed in payment card breach of Holiday Inn parent company
[17 Apr 2017 11:11am]

» Profiling 10 types of hackers
[17 Apr 2017 05:00am]

» An introduction to six types of VPN software
[15 Apr 2017 04:44pm]

***
Microsoft Security Advisories

» 3123479 - SHA-1 Hashing Algorithm for Microsoft Root Certificate Program - Version: 2.0
[14 Mar 2017 11:00am]

» 4010983 - Vulnerability in ASP.NET Core MVC 1.1.0 Could Allow Denial of Service - Version: 1.0
[27 Jan 2017 11:00am]

» 3214296 - Vulnerabilities in Identity Model Extensions Token Signing Verification Could Allow Elevation of Privilege - Version: 1.0
[10 Jan 2017 11:00am]

» 3181759 - Vulnerabilities in ASP.NET Core View Components Could Allow Elevation of Privilege - Version: 1.0
[13 Sep 2016 11:00am]

» 3174644 - Updated Support for Diffie-Hellman Key Exchange - Version: 1.0
[13 Sep 2016 11:00am]

» 3179528 - Update for Kernel Mode Blacklist - Version: 1.0
[09 Aug 2016 11:00am]

» 2880823 - Deprecation of SHA-1 Hashing Algorithm for Microsoft Root Certificate Program - Version: 2.0
[18 May 2016 11:00am]

» 3155527 - Update to Cipher Suites for FalseStart - Version: 1.0
[10 May 2016 11:00am]

» 3152550 - Update to Improve Wireless Mouse Input Filtering - Version: 1.1
[22 Apr 2016 11:00am]

» 3137909 - Vulnerabilities in ASP.NET Templates Could Allow Tampering - Version: 1.1
[10 Feb 2016 11:00am]

» 2871997 - Update to Improve Credentials Protection and Management - Version: 5.0
[09 Feb 2016 11:00am]

» 3118753 - Updates for ActiveX Kill Bits 3118753 - Version: 1.0
[12 Jan 2016 11:00am]

» 3109853 - Update to Improve TLS Session Resumption Interoperability - Version: 1.0
[12 Jan 2016 11:00am]

» 2755801 - Update for Vulnerabilities in Adobe Flash Player in Internet Explorer and Microsoft Edge - Version: 53.0
[05 Jan 2016 11:00am]

» 3057154 - Update to Harden Use of DES Encryption - Version: 1.1
[08 Dec 2015 11:00am]

***


***
Network World Security

» Customers roast Microsoft over security bulletins' demise
[24 Apr 2017 03:57pm]

» 7 patch management practices guaranteed to help protect your data
[24 Apr 2017 02:59pm]

» More Windows PCs infected with NSA backdoor DoublePulsar
[24 Apr 2017 08:50am]

» Bring Your Own Authentication is upending online security practices
[24 Apr 2017 08:37am]

» Fight firewall sprawl with AlgoSec, Tufin, Skybox suites
[10 Apr 2017 04:32am]

» Review: Canary Flex security camera lives up to its name
[24 Mar 2017 07:01am]

» Smackdown: Office 365 vs. G Suite management
[16 Mar 2017 07:01am]

» Zix wins 5-vendor email encryption shootout
[13 Mar 2017 04:00am]

» Review: vArmour flips security on its head
[06 Mar 2017 03:50am]

» 5 open source security tools too good to ignore
[21 Feb 2017 07:12am]

» Review: Samsung SmartCam PT network camera
[15 Feb 2017 07:00am]

» Review: Arlo Pro cameras offer true flexibility for home security
[09 Feb 2017 07:01am]

» Face-off: Oracle vs. CA for identity management
[26 Jan 2017 10:30am]

» 7 patch management practices guaranteed to help protect your data
[24 Apr 2017 02:59pm]

» More Windows PCs infected with NSA backdoor DoublePulsar
[24 Apr 2017 08:50am]

***


More IT Security
News Feeds
More Sponsors

Advertise on this site
RSS Feeds
Our news can be syndicated by using these rss feeds.
rss1.0
rss2.0
rdf
Welcome
Username:

Password:




Remember me

[ ]

NIST.org is in no way connected to the U.S. government site NIST.gov

This site is © John Herron, CISSP. All Rights Reserved.

Please visit daily to stay up to date on all your IT Security compliance issues.

http://www.nist.org -
Hosted by BlueHost. We've never had a better hosting company.
{THEMEDISCLAIMER}