Timeframe: Dienstag 14-02-2017 18:00 − Mittwoch 15-02-2017 18:00
*** Amnesty International uncovers phishing campaign against human rights activists ***
Attacker targeted groups in Qatar, Nepal using extensive fake social media profile.
*** Siemens SIMATIC Authentication Bypass ***
This advisory contains mitigation details for an authentication bypass in Siemens SIMATIC.
*** Attacking the Windows NVIDIA Driver ***
Modern graphic drivers are complicated and provide a large promising attack surface for EoPs and sandbox escapes from processes that have access to the GPU (e.g. the Chrome GPU process). In this blog post we’ll take a look at attacking the ..
*** Ransomware: a declining nuisance or an evolving menace? ***
The volume of ransomware encounters is on a downward trend. Are we seeing the beginning of the end of this vicious threat? Unfortunately, a look at the attack vectors, the number of ..
*** New ASLR-busting JavaScript is about to make drive-by exploits much nastier ***
A property found in virtually all modern CPUs neuters decade-old security protection.
*** Adobe-Patchday: Flash Player wie üblich in kritischem Zustand ***
Im Flash Player und Adobe Digital Editions klaffen kritische Lücken. Aktuell sind vor allem Windows-Nutzer von den Flash-Lücken bedroht. Adobe Campaign erhält ebenfalls Sicherheitsupdates.
*** Researchers Discover Self-Healing Malware That Targets Magento Stores ***
Dutch malware experts have found a new malware strain that targets online shops running on the Magento platform, ..
*** Cisco: Zwei VPN-Lücken und eine Schwachstelle, die offiziell keine ist ***
Cisco hat Sicherheitslücken im AnyConnect-VPN und auf seinen ASA-Firewalls gestopft. Ein Sicherheitsproblem mit dem SMI-Protokoll, welches es aus der Ferne erlaubt, neue Betriebssystem-Images auf Switches zu laden, sieht die Firma allerdings nicht.
*** Are Windows Registry Fixers Safe? ***
Before I got into cybersecurity, I spent years as a technical support agent for Windows end users of Windstream, an American ISP. Although Windstream is an ISP, they also offered a general Windows client OS remote support service for their predominantly ..
*** Xagent: Russische Hackergruppe setzt auch auf Mac-Spionage-Software ***
Eine auf macOS abzielende Version der Malware Xagent stammt offenbar von der Hackergruppe APT28, die mit dem Angriff auf die Demokratische Partei im US-Wahlkampf in Verbindung gebracht wird. Xagent soll unter anderem iPhone-Backups entwenden.
*** Researchers trick CEO email scammer into giving up identity ***
Businesses targeted in email scams don’t always have to play the victim. They can actually fight back.Researchers at Dell SecureWorks have documented how they identified a ..
Timeframe: Montag 13-02-2017 18:00 − Dienstag 14-02-2017 18:00
*** Shirebrook man arrested in connection to Sports Direct breach ***
A 27-year-old man has been arrested in connection with the hack of Sports ..
*** A look into the Russian-speaking ransomware ecosystem ***
In other words, crypto ransomware is a fine tuned, user friendly and constantly developing ecosystem. In the last few years we, at Kaspersky Lab, have been monitoring the development of this ecosystem. This is what we’ve learned.
*** Top phishing targets in 2016? Google, Yahoo, and Apple ***
For every new phishing URL impersonating a financial institution, there were more than seven impersonating technology companies. Comparison of most impersonated companies ..
*** Metadata: The secret data trail ***
Every phone call, text message, even activated cell phones, leaves a trail of data across a network. In many cases this data is aggregated with other data and metadata including ..
*** Worried about hacks, senators want info on Trump’s personal phone ***
Two senators have written to the U.S. Department of Defense about reports that President Donald Trump may still be using an old unsecured Android phone, including to communicate ..
*** 25% of web apps still vulnerable to eight of the OWASP Top Ten ***
69 percent of web applications are plagued by vulnerabilities that could lead to sensitive data exposure, and 55 percent by cross-site request forgery flaws, the results ..
*** Sicherheitslücke in GarageBand für den Mac ***
Apple hat einen potenziell problematischen Fehler in seiner populären Audioanwendung geschlossen. Angreifer hätten wohl Code ausführen können.
*** University DDoSed by Its Own IoT Devices ***
An unnamed university has suffered a DDoS attack at the hand of its own IoT devices, according to a sneak preview of Verizons upcoming yearly data breach report.
*** DSA-3788 tomcat8 - security update ***
It was discovered that a programming error in the processing of HTTPSrequests in the Apache Tomcat servlet and JSP engine may result indenial of service via an infinite loop.
*** DSA-3787 tomcat7 - security update ***
It was discovered that a programming error in the processing of HTTPSrequests in the Apache Tomcat servlet and JSP engine may result indenial of service via an infinite loop.
*** DSA-3786 vim - security update ***
Editor spell files passed to the vim (Vi IMproved) editormay result in an integer overflow in memory allocationand a resulting buffer overflow which potentiallycould result in the execution of arbitrary code or denial ofservice.
*** Jetzt patchen! Angriffe auf WordPress-Seiten nehmen zu und werden gefährlicher ***
Nach der Verunstaltung von verwundbaren WordPress-Webseiten versuchen Angreifer nun Schadcode auszuführen, warnen Sicherheitsforscher.
*** Staying safe online on Valentine’s Day ***
We give some advice on how to steer clear of scams and other bad things on Valentines Day. Everything from ..
*** Chrome: Google zahlt 20 Millionen US-Dollar für Anti-Malware-Patente ***
Auch für Google sind 20 Millionen Dollar nicht wenig Geld. Ein US-Gericht verurteilte das Unternehmen zur Zahlung dieser Summe, weil es Patente zur Sicherung vor Malware im ..
*** Tracking the Decline of Top Exploit Kits ***
The latter half of 2016 saw a major shift in the exploit kit landscape, with many established kits suddenly dropping operations or switching business models. Angler, which has ..
*** Gefälschte Post.at-Sendungsverfolgung im Umlauf ***
Mit einer gefälschten Post.at-Sendungsverfolgung wollen Kriminelle Schadsoftware auf fremden Computern hinterlegen. Dazu fordern sie Empfänger/innen auf, Informationen ..
*** Security Bulletins posted for Flash Player, Digital Editions and Adobe Campaign ***
Adobe has published security bulletins for Adobe Flash Player (APSB17-04), Adobe Digital Editions (APSB17-05) and Adobe Campaign (APSB17-06). Adobe recommends users update their ..
*** Nation States Distancing Themselves from APTs ***
Increasingly, governments are outsourcing state-sponsored attacks to mitigate risk and maximize intelligence.
*** February 2017 security update release ***
Our top priority is to provide the best possible experience for customers in maintaining and protecting their ..
Timeframe: Freitag 10-02-2017 18:00 − Montag 13-02-2017 18:00
*** State-sponsored Hackers Targeting Prominent Journalists, Google Warns ***
State-sponsored hackers are attempting to steal email passwords of a number of prominent journalists, Google has warned. The hackers are suspected to be Russians, reports POLITICO. Some of the journalists who have received such warnings from Google as ..
*** Unique Office Loader Deploying Multiple Malware Families ***
*** Sports Direct hacked but it still hasn't disclosed the breach to its staff ***
Sports Direct, the UK's largest sports retail business, was hacked last year, and still hasn't disclosed the incident to its staff. The Register confirmed that the Sports Direct, the UK's largest sports retail business, was hacked last ..
*** Think Twice before Posting Data on Pastebin! ***
Pastebin.com is one of my favourite playground. I'm monitoring the content of all pasties posted on this website. My goal is to find juicy data like configurations, database ..
*** Lazarus & Watering-hole attacks ***
On 3rd February 2017, researchers at badcyber.com released an article that detailed a series of ..
*** Do You Use VirusTotal? Give PacketTotal a Spin!, (Mon, Feb 13th) ***
Packettotal ( http://www.packettotal.com ) is a new site that does some nifty analysis of Packet Captures for you if youre not so familiar with Wireshark or other analysis tools Out of the gate, this site maps out connections, certificates, ..
*** Firefox für Android kann sich an Schadcode verschlucken ***
In der Version 51.0.3 haben die Firefox-Entwickler eine kritische Sicherheitslücke geschlossen. Von der Schwachstelle ist ausschliesslich die Android-Version betroffen.
*** Mirai Widens Distribution with New Trojan that Scans More Ports ***
Late last year, in several high-profile and potent DDoS attacks, Linux-targeting Mirai (identified by Trend Micro as ELF_MIRAI family) revealed just how broken the Internet ..
*** Project Zero: NTFS-Treiber ermöglicht Linux-Rootzugriff ***
Eine fehlerhafte Konfiguration des Userspace-Treibers für NTFS unter Linux ermöglicht einfachen Root-Zugriff. Davon betroffen waren Standardinstallationen von Debian ..
*** Mexiko soll Gegner von Softdrinks mit Spyware ausgespäht haben ***
Aktivisten, die für eine höhere Besteuerung von zuckerhaltigen Getränken und fettreichen Speisen kämpften, wurden ausgehorcht
*** Dateilose Infektion: Einbruch ohne Spuren ***
Sicherheitsforscher warnen, dass vermutlich die Carbanak-Gang einen neuen Trick verwendet, der viele Schutz- und Analyse-Programme ins Leere laufen lässt. Sie brechen in Computer und Netze ein, ohne dass dabei verdächtige Dateien auf der Platte landen.
Timeframe: Donnerstag 09-02-2017 18:00 − Freitag 10-02-2017 18:00
*** ENISA study on the security aspects of virtualization ***
The report provides an analysis on the current status of security of virtualization, by presenting current technologies affected, risks, efforts, gaps, and the impact the latter have on environments based on virtualization technologies.
*** A Feeding Frenzy to Deface WordPress Sites ***
In this report we share data on the ongoing flood of WordPress REST-API exploits we are seeing in the wild. We include data on 20 different site defacement campaigns we are currently tracking.
*** RCE Attempts Against the Latest WordPress REST API Vulnerability ***
We are starting to see remote command execution (RCE) attempts trying to exploit the latest WordPress REST API Vulnerability. These RCE attempts started today after a few days of attackers (mostly defacers) rushing to vandalize as many pages as they could. The RCE attempts we are seeing in the wild do not affect every WordPress sites, only the ones using plugins that allow for PHP execution from within posts and pages.
*** De-Anonymizing Browser History Using Social-Network Data ***
Interesting research: "De-anonymizing Web Browsing Data with Social Networks":Abstract: Can online trackers and network adversaries de-anonymize web browsing data readily available to them? We show -- theoretically, via simulation, and through experiments on real user data -- that de-identified web browsing histories can\ be linked to social media profiles using only publicly available data. Our approach is based on a simple observation: each person has a distinctive social network,...
*** CERT updates insider threat guidebook ***
The CERT Division of the Software Engineering Institute (SEI) at Carnegie Mellon University released the fifth edition of the Common Sense Guide to Mitigating Insider Threats. The guide describes 20 practices that organizations should implement across the enterprise to prevent and detect insider threats, as well as case studies of organizations that failed to do so.
*** ENISA issues Smartphone Development Guidelines ***
ENISA publishes an update of the Smartphone Development Guidelines.
*** Hacking Guatemala's DNS - Spying on Active Directory Users By Exploiting a TLD Misconfiguration ***
In search of new interesting high-impact DNS vulnerabilities I decided to take a look at the various top-level domains (TLDs) and analyze their configurations for errors. Upon some initial searching it turns out there is a nice open source service which helps DNS administrators scan their domains for misconfigurations called DNSCheck written by The Internet Foundation in Sweden. This tool helps highlight all sorts of odd DNS misconfigurations such as having an...
*** Unpatched (0day) jQuery Mobile XSS ***
TL;DR - Any website that uses jQuery Mobile and has an open redirect is now vulnerable to XSS - and theres nothing you can do about it, theres not even patch
*** Multiple cross-site scripting vulnerabilities in Webmin ***
Webmin contains multiple cross-site scripting vulnerabilities.
*** Western Digital My Cloud 2.21.119 Authentication Bypass ***
Topic: Western Digital My Cloud 2.21.119 Authentication Bypass Risk: High Text: Authentication bypass vulnerability in Western Digital My Cloud Remco Verm...
*** Hanwha Techwin Smart Security Manager ***
This advisory contains mitigation detail for remote code execution vulnerabilities in Hanwha Techwins Smart Security Manager.
*** DFN-CERT-2017-0251: Xen, QEMU: Eine Schwachstelle ermöglicht das Ausspähen von Informationen und die Eskalation von Privilegien ***
*** IBM Security Bulletins ***
*** IBM Security Bulletin: Potential Cross-site scripting vulnerability in WebSphere Application Server (CVE-2017-1121) ***
*** IBM Security Bulletin: IBM Flex System Manager (FSM) is affected by multiple php5 vulnerabilities (CVE-2016-6911, CVE-2016-8670) ***
*** IBM Security Bulletin: IBM Flex System Manager (FSM) is affected by a kernel vulnerability ***
*** IBM Security Bulletin: IBM Flex System Manager (FSM) is affected by multiple cURL/libcURL vulnerabilities (CVE-2016-5419, CVE-2016-5420, CVE-2016-7141) ***
*** IBM Security Bulletin: IBM Flex System Manager (FSM) is affected by a libgcrypt vulnerability (CVE-2016-6313) ***
*** IBM Security Bulletin: Vulnerability in OpenSSL affect Rational Tau (CVE-2016-2180) ***
*** IBM Security Bulletin: Vulnerability in OpenSSL affect Rational Tau (CVE-2016-2177) ***
*** IBM Security Bulletin: IBM Flex System Manager (FSM) is affected by multiple glibc vulnerabilities (CVE-2016-1234, CVE-2016-3706, CVE-2016-4429) ***
Timeframe: Mittwoch 08-02-2017 18:00 − Donnerstag 09-02-2017 18:00
*** Lifting the (Hyper) Visor: Bypassing Samsung's Real-Time Kernel Protection ***
Posted by Gal Beniamini, Project ZeroTraditionally, the operating system's kernel is the last security boundary standing between an attacker and full control over a target system. As such, additional care must be taken in order to ensure the integrity of the kernel.
*** FortiManager TLS certificate validation failure ***
FortiManager does not properly validate TLS certificates when probing for devices to administer. This leads to potential pre-shared secret exposure.
*** Gefälschte iTunes-Rechnung: Danke für Ihren Einkauf ***
Mit einer gefälschten iTunes-Rechnug wollen Kriminelle Empfänger/innen dazu bewegen, dass sie eine Website aufrufen. Auf dieser sollen Besucher/innen Kreditkarteninformationen bekannt geben, damit sie einen nicht gewollten Einkauf stornieren können. Es handelt sich um einen Datendiebstahlsversuch. Sie dürfen die Daten nicht bekannt geben.
*** Security Advisory - Privilege Escalation Vulnerability in Huawei Smart Phones ***
*** Analysis of security measures deployed by e-communication providers ***
ENISA's new report provides a collection of good practices, implemented security measures and approaches by e-communication providers in the EU, to mitigate the main types of incidents in the telecommunication sector.
*** Security and Privacy Guidelines for the Internet of Things ***
Lately, I have been collecting IoT security and privacy guidelines. Heres everything Ive found:
*** iCloud schlampt offenbar beim Löschen des Browser-Verlaufs ***
Aus dem Verlauf von Apples Browser Safari gelöschte Webseiten-Besuche verschwinden zwar von den synchronisierten Geräten, lassen sich aber noch rund ein Jahr später aus iCloud rekonstruieren, warnt der Hersteller eines Forensik-Tools.
*** Brute Force RDP Attacks Plant CRYSIS Ransomware ***
... brute force RDP attacks are still ongoing, affecting both SMEs and large enterprises across the globe. In fact, the volume of these attacks doubled in January 2017 from a comparable period in late 2016.
*** DFN-CERT-2017-0237: ISC BIND: Eine Schwachstellen ermöglicht einen Denial-of-Service-Angriff ***
Das Internet Systems Consortium (ISC) ... veröffentlicht die neuen Programmversionen BIND 9.9.9-P6, 9.10.4-P6, 9.11.0-P3 und 9.9.9-S8 (letztere nur für ISC Support Kunden), in denen die Schwachstellen behoben sind. Die Schwachstelle kann durch Deaktivierung von DNS64 oder RPZ umgangen werden, bis das Sicherheitsupdate eingespielt werden kann.
*** GNU Bash code execution vulnerability in path completion ***
GNU Bash from version 4.4 contains two bugs in its path completion feature leading to a code execution vulnerability. An exploit can be realized by creating a file or directory with a specially crafted name. A user utilizing GNU Bash's built-in path completion by hitting the Tab button (f.e. to remove it with rm) triggers the exploit without executing a command itself.
*** DFN-CERT-2017-0240: F5 Networks BIG-IP Systeme: Eine Schwachstelle ermöglicht das Ausspähen von Informationen ***
F5 Networks BIG-IP Protocol Security Module (PSM) >= 11.4.0, <= 11.4.1
Ein entfernter, einfach authentifizierter Angreifer kann durch Wiederaufnahme einer SSL-Verbindung zu einer betroffenen F5 BIG-IP-Appliance Informationen ausspähen, da der Server abhängig von der Größe des gesendeten Sitzungsidentifizierers (Session ID) als Antwort bis zu 31 Bytes aus nicht initialisiertem Speicher zurücksendet.
*** Erpressungs-Trojaner Erebus umgeht erfolgreich UAC-Abfrage von Windows ***
Sicherheitsforschern zufolge verbiegt Erebus die Windows-Registry dahingehend, sodass der Schädling schlimmstenfalls mit Admin-Rechten operieren kann. Dank einer Windows-Einstellung kann man das aber unterbinden.
*** BSI veröffentlicht Leitfaden für sicheres Android mit Samsung Knox ***
Administratoren können sich von der Website des BSI Empfehlungen für Samsungs Sicherheitsplattform laden. Zweck ist der Schutz von Android-Geräten.
*** Manipuliertes Word-Dokument: Makro-Malware geht den Mac an ***
Mit manipulierten Word-Dokumenten wollen Angreifer nun auch Schadcode auf Macs einschleusen. Damit wird die macOS-Schutzfunktion Gatekeeper umgangen.
*** IBM Security Bulletins ***
*** IBM Security Bulletin: Vulnerability in GNU C Library affects IBM Flex System EN6131 40Gb Ethernet / IB6131 40Gb Infiniband Switch firmware (CVE-2016-1234) ***
*** IBM Security Bulletin: Vulnerabilities in NTP affect IBM Flex System FC3171 8Gb SAN Switch and SAN Pass-thru, QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter and QLogic Virtual Fabric Extension Module for IBM ***
*** IBM Security Bulletin: Vulnerabilities in NTP affect IBM Flex System FC3171 8Gb SAN Switch and SAN Pass-thru, QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter and QLogic Virtual Fabric Extension Module for IBM ***
Timeframe: Dienstag 07-02-2017 18:00 − Mittwoch 08-02-2017 18:00
*** As Valve eradicates serious bug in Steam, here's what you need to know ***
Steam, an online game platform with more than 125 million active accounts, is in the process of fixing a serious security hole that opens users to hacks that could redirect them to attack sites, spend their market funds, or possibly make malicious changes to their user profiles.
*** Fileless attacks against enterprise networks ***
This threat was originally discovered by a bank's security team, after detecting Meterpreter code inside the physical memory of a domain controller (DC). Kaspersky Lab participated in the forensic analysis, discovering the use of PowerShell scripts within the Windows registry. Additionally it was discovered that the NETSH utility as used for tunnelling traffic from the victim's host to the attacker's C2.
*** Strategies to Mitigate Cyber Security Incidents ***
The Australian Signals Directorate (ASD) has developed prioritised mitigation strategies to help technical cyber security professionals in all organisations mitigate cyber security incidents. This guidance addresses targeted cyber intrusions, ransomware and external adversaries with destructive intent, malicious insiders, business email compromise and industrial control systems.
*** ESA-2017-001: EMC Isilon InsightIQ Authentication Bypass Vulnerability ***
An attacker can exploit the vulnerability to bypass authentication and thereby gain administrator privileges.
*** When A Pony Walks Out Of A Pub ***
Talos has observed a small email campaign leveraging the use of Microsoft Publisher files.
Unlike other applications within the Microsoft Office suite, Microsoft Publisher does not support a Protected View mode.
The file used in this campaign was aimed at infecting the victim with the, well known, Pony malware
*** Multiple Vulnerabilities in Trend Micro Control Manager (TMCM) 6.0 ***
CVSS 2.0 Score(s): 4.0 - 6.8
Severity Rating(s): Medium
Trend Micro has released a new build for Trend Micro Conrol Manager 6.0. This build resolves multiple vulnerabilities related to potential remote code execution, directory traversal, SQL injections, and unauthorized access to XML files.
*** SAP Security for Beginners Part 5: SAP Risks - Sabotage ***
Sabotage attacks on SAP systems were promised as a today's topic, so, let's look at potential sabotage vectors.
*** Sielco Sistemi Winlog SCADA Software ***
This advisory contains mitigation details for an uncontrolled search path vulnerability in Sielco Sistemis Winlog SCADA Software.
*** BD Alaris 8000 Insufficiently Protected Credentials Vulnerability ***
This advisory was originally posted to the NCCIC Portal on January 17, 2017, and is being released to the NCCIC/ICS-CERT web site. This advisory contains mitigation details for an insufficiently protected credentials vulnerability in BD's Alaris 8000 Point of Care unit, which provides a common user interface for programming intravenous infusions.
*** BD Alaris 8015 Insufficiently Protected Credentials Vulnerabilities ***
This advisory was originally posted to the NCCIC Portal on January 17, 2017, and is being released to the NCCIC/ICS-CERT web site. This advisory contains mitigation details for protected credentials vulnerabilities in BD's Alaris 8015 Point of Care unit, which provides a common user interface for programming intravenous infusions.
*** BINOM3 Electric Power Quality Meter (Update A) ***
This updated advisory is a follow-up to the original advisory titled ICSA-17-031-01 BINOM3 Electric Power Quality Meter that was published January 31, 2017, on the NCCIC/ICS-CERT web site. This updated advisory contains mitigation details for vulnerabilities in BINOM3s electric power quality meter.
*** Citrix NetScaler Nonce Generation Flaw Lets Remote Users Obtain Potentially Sensitive Information on the Target System ***
*** Huawei Security Advisories ***
*** Security Advisory - Buffer Overflow Vulnerability in Emergdata Driver of Huawei Smart Phones ***
*** Security Advisory - Buffer Overflow Vulnerability in Goldeneye Driver of Huawei Smart Phones ***
*** Security Advisory - MITM Vulnerability in Huawei Vmall APP ***
*** Cisco Security Advisories ***
*** Cisco AnyConnect Secure Mobility Client for Windows SBL Privileges Escalation Vulnerability ***
*** Cisco ASA Clientless SSL VPN CIFS Heap Overflow Vulnerability ***
*** IBM Security Bulletins ***
*** IBM Security Bulletin: Vulnerabilities in OpenSSL affect IBM InfoSphere Information Server ***
*** IBM Security Bulletin: Vulnerability in Rational DOORS Next Generation with potential for Cross-Site Scripting attack (CVE-2016-6055) ***
*** IBM Security Bulletin: Vulnerability in Rational Rhapsody Design Manager with potential for Denial of Service attack ***
*** IBM Security Bulletin: Multiple vulnerabilities in IBM Java Runtime may affect IBM Mobile Connect as a product bundler ***
*** IBM Security Bulletin: Vulnerability in SSLv3 affects Multiple N series products (CVE-2014-3566) ***
*** IBM Security Bulletin: Vulnerabilities in OpenSSH affect AIX (CVE-2016-8858, CVE-2016-10009, CVE-2016-10011, CVE-2016-10012) ***
Timeframe: Montag 06-02-2017 18:00 − Dienstag 07-02-2017 18:00
*** Heute ist es soweit: Es ist Internationaler Safer Internet Day! ***
Der jährliche Aktionstag wurde 2004 von der Europäischen Kommission im Rahmen des Safer Internet-Programms ins Leben gerufen und findet seitdem jeden Februar statt. Mehr als 100 Länder beteiligen sich weltweit am Safer Internet Day, um über die sichere und verantwortungsvolle Internetnutzung aufzuklären. International organisiert das europäische Netzwerk Insafe den Safer Internet Day.
*** DFN-CERT-2017-0216/">Google Android Operating System: Mehrere Schwachstellen ermöglichen u.a. die komplette Systemübernahme ***
*** Got an OpenBSD Web server? Better patch it ***
DoS-able bugs splatted OpenBSD and two of its SSL libraries need patches against a pair of denial-of-service bugs that can crash Web-facing servers
*** Vuln: PEAR HTML_AJAX CVE-2017-5677 PHP Object Injection Vulnerability ***
*** New Attack, Old Tricks ***
A Word document targets Mac users with malicious macros and an open-source payload.
*** Citrix License Server for Windows and License Server VPX CVE-2017-5571 Open Redirect Vulnerability ***
*** DFN-CERT-2017-0217/">BlackBerry powered by Android: Mehrere Schwachstellen ermöglichen u.a. die komplette Systemübernahme ***
*** [2017-02-07] Multiple vulnerabilities in JUNG Smart Visu server ***
Attackers can dump password hashes and other available data from the operating system of the JUNG Smart Visu Server. An attacker is able to access and control all Smart Visu server installation if he is able to crack the hashes. The group address password can be removed by using a single PUT request.
*** IBM Security Bulletins ***
*** IBM Security Bulletin: Multiple Vulnerabilities in OpenSSL affect IBM i ***
*** IBM Security Bulletin: Multiple Vulnerabilities in Oracle Outside In Technology affect IBM Rational DOORS Next Generation ***
*** IBM Security Bulletin: Multiple vulnerabilities have been identified in IBM Flex System Manager (FSM) Storage Manager Install Anywhere (SMIA) Configuration tool ***
*** IBM Security Bulletin: Multiple Vulnerabilities in OpenSSH affect IBM i ***
*** IBM Security Bulletin: Security Vulnerability in OpenSSL affects IBM Spectrum Control (formerly Tivoli Storage Productivity Center) ***
*** IBM Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect AppScan Standard (CVE-2016-5597, CVE-2016-5542) ***
*** IBM Security Bulletin: Fix Available for IBM iNotes Cross-site Scripting Vulnerability (CVE-2016-5883) ***
*** IBM Security Bulletin: Multiple vulnerabilities in OpenSSL affect IBM Cisco Switches and Directors. ***
*** IBM Security Bulletin: Multiple vulnerabilities in OpenSSL affect IBM Campaign, IBM Contact Optimization ***
*** IBM Security Bulletin: Vulnerabilities in OpenSSL affect multiple N series products ***
Timeframe: Freitag 03-02-2017 18:00 − Montag 06-02-2017 18:00
*** Vuln: Barracuda NextGen Firewal F-Series Denial of Service Vulnerability ***
*** Vuln: Multiple GStreamer Plug-ins Buffer Overflow and Denial Of Service Vulnerabilities ***
*** Honeywell SCADA Controllers Exposed Passwords in Clear Text ***
A series of remotely exploitable vulnerabilities - including clear text passwords - exist in a set of Honeywell SCADA systems.
*** [remote] - Netwave IP Camera - Password Disclosure ***
*** Security Advisory: Apache vulnerability CVE-2016-8743 ***
*** Security Advisory: OpenSSL vulnerability CVE-2016-7055 ***
*** [SANS ISC Diary] Detecting Undisclosed Vulnerabilities with Security Tools & Features ***
I published the following diary on isc.sans.org: "Detecting Undisclosed Vulnerabilities with Security Tools & Features". I'm a big fan of OSSEC. This tools is an open source HIDS and log management tool. Although often considered as the "SIEM of the poor", it integrates a lot of interesting features and is fully configurable ...
*** Kodi-Erweiterung machte Anwender zu Botnetz-Zellen ***
Anwender des Plug-ins "Exodus" für das Media-Center Kodi wurden zu unfreiwilligen Teilnehmern eines Botnets, das gezielte DDoS-Angriffe fuhr. Deren Ziel: Websites von Konkurrenten.
*** NATO presents the Tallinn Manual 2.0 on International Law Applicable to cyberspace ***
NATO's Cooperative Cyber Defense Centre of Excellence (CCDCOE) has published "Tallinn Manual 2.0 on the International Law Applicable to Cyber Operations." Its world launch will be in Washington DC, February 8 at The Atlantic Council; followed by Europe at The Hague, February 13; and Tallinn, February 17.
*** Slammer worm slithers back online to attack ancient SQL servers ***
If you get taken down by this 13-year-old malware, you probably deserve it One of the worlds most famous net menaces, SQL Slammer, has resumed attacking servers some 13 years after it set records by infecting 75,000 servers in 10 minutes, researchers say.
*** Microsofts DRM can expose Windows-on-Tor users IP address ***
Anonymity-lovers best not watch movies as .WMV files Windows users running the Tor browser can be tricked into uncloaking themselves, with a pretty straightforward trick based on Microsofts DRM system.
*** Bugtraq: ZoneMinder - multiple vulnerabilities ***
*** Anbieter des WordPress-Plugin BlogVault gehackt ***
Hacker haben bei einem Server-Einbruch Daten von BlogVault-Nutzern abgezogen. Anschließend sollen einige Webseiten, die auf das Plugin setzen, mit Malware infiziert worden sein, warnt der Anbieter.
*** Lurk: Retracing the Group's Five-Year Campaign ***
Fileless infections are exactly what their namesake says: theyre infections that dont involve malicious files being downloaded or written to the system's disk. While fileless infections are not necessarily new or rare, it presents a serious threat to enterprises and end users given its capability to gain privileges and persist in the system of interest to an attacker - all while staying under the radar.
*** Überwachungsfirma Cellebrite: Hacker veröffentlicht iPhone-Cracking-Tools ***
Wenn Software zum Knacken von Smartphones existiert, dann gelangt diese auch in die Hände Dritter, erklärt der Hacker, der die angeblich von einer Überwachungsfirma stammenden Tools veröffentlicht hat. Ähnlich argumentierte zuletzt auch Apple.
*** Hacker hijacks thousands of publicly exposed printers to warn owners ***
Following recent research that showed many printer models are vulnerable to attacks, a hacker decided to prove the point and forced thousands of publicly exposed printers to spew out rogue messages.
*** ENISA: Challenges of security certification in emerging ICT environments ***
ENISA issues today its report on the Challenges of security certification in emerging ICT environments. The report is targeted at EU Member States (MS), the Commission, certification bodies and the private sector, and provides a thorough description of the cyber security certification status concerning the most critical equipment in various critical business sectors.
*** Chrome 57 [...] will no longer trust any StartSSL/Wosign issued certificates [...] ***
Previous communication from Google (https://security.googleblog.com/2016/10/distrusting-wosign-and-startcom.html) had read as though it would only be certificates issued since October 21, 2016 wouldnt be trusted. It then went onto say that it may not trust other certificates but didnt really say what that meant.
*** Six Best Practices for Securing a Robust Domain Name System (DNS) Infrastructure ***
The Domain Name System (DNS) is an essential component of the Internet, a virtual phone book of names and numbers, but we rarely think about it until something goes wrong.
*** IBM Security Bulletins ***
*** IBM Security Bulletin: Vulnerabilities in Apache Tomcat affect Power Hardware Management Console (CVE-2016-6816, CVE-2016-6817, and CVE-2016-0762) ***
*** IBM Security Bulletin: Multiple vulnerabilities in Oracle Outside In Technology (OIT) affect FileNet Content Manager and IBM Content Foundation ***
*** IBM Security Bulletin: IBM Sterling Order Management and IBM Sterling Configure Price Quote are vulnerable to cross-site request forgery. ***
Timeframe: Donnerstag 02-02-2017 18:00 − Freitag 03-02-2017 18:00
*** How Google fought back against a crippling IoT-powered botnet and won ***
Behind the scenes defending KrebsOnSecurity against record-setting DDoS attacks.
*** Improved scripts in .lnk files now deliver Kovter in addition to Locky ***
Cybercriminals are using a combination of improved script and well-maintained download sites in trying to install Locky and Kovter on more computers. A few ..
*** Underground Scams: Cutting the Head Off a Snake ***
Shortly after publishing our post about Terror EK, "King Cobra" (a Twitter account that we mentioned ..
*** Cisco - Issue with Clock Signal Component ***
One of our readers, Dalibor Cerar, sent us an email about an issue impacting Cisco...at this point. While its a hardware issue, the result if it occurs is a self inflicted Denial of Service. Cisco released a notice on February 2 that some of ..
*** G-Suite: Google bringt S/MIME für Enterprise-Gmail ***
Google hat ein umfangreiches Update für die Enterprise-Version seiner G-Suite angekündigt: Mit dabei sind verpflichtende Hardwareschlüssel, S/MIME für Gmail und erweiterte Funktionen, um Datenverlust zu verhindern.
*** Hacker veröffentlichen gestohlene Cellebrite-Software ***
Programme, die von den israelischen Sicherheitsexperten von Cellebrite zum Knacken von Smartphones genutzt werden, wurden nun veröffentlicht.
*** Rechnung in ZIP-Datei ist Schadsoftware ***
In ihrem E-Mailpostfach finden Internet-Nutzer/innen eine Nachricht mit dem Betreff „Rechnung Nr. xxxxx“. Darin heißt es, dass die Empfänger/innen das beigefügte Dokument als ..
*** The power of sharing: ENISA report on cyber security information sharing in the energy sector ***
*** Someone Tried to Resurrect 14-Year-Old SQL Slammer Worm ***
For a week in November and December 2016, someone tried to resurrect the 14-year-old SQL Slammer worm, ..
*** Patch-Tag für Jenkins ***
Aktuelle Versionen beseitigen insgesamt 19 Security-Probleme in Jenkins, von denen eines als schwerwiegend eingestuft ist.
*** SQL-Injection-Lücke in McAfee ePolicy Orchestrator ***
McAfees Lösung für zentrales Security-Management in Firmen und Konzernen weist selbst ein schwerwiegendes Sicherheitsproblem auf. Ein Hotfix des Herstellers sorgt für Abhilfe.
*** Kritische Lücke in Microsoft Windows ermöglicht DoS / Remote Code Execution via SMB - noch keine Updates verfügbar ***
Im SMB-Code von Microsoft Windows wurde eine Schwachstelle entdeckt, die im harmlosesten Fall einen Absturz des Betriebsystems zur Folge haben kann, im schlimmsten Fall sogar Remote Code Execution erlaubt.
Timeframe: Mittwoch 01-02-2017 18:00 − Donnerstag 02-02-2017 18:00
*** DSA-3780 ntfs-3g - security update ***
Jann Horn of Google Project Zero discovered that NTFS-3G, a read-writeNTFS driver for FUSE, does not scrub the environment before executingmodprobe with elevated privileges. A local user ..
*** Netherlands reverts to hand-counted votes to quell security fears ***
Windows XP? SHA-1? USB sneakernet? What were they thinking? Or smoking? The Netherlands has decided its vote-counting software isnt ready for prime time, and will revert to ..
*** Extrem kritische Lücke in Ciscos Prime Home könnte unzählige Router gefährden ***
Internet- und Service-Anbieter sollten zügig ein Sicherheitsupdate für Cisco Prime Home installieren. Angreifer könnten Geräte mit wenig Aufwand missbrauchen und von da aus Router von Kunden übernehmen.
*** Gmail Drops Support for Windows XP and Vista Users on Chrome ***
Google says that starting with February 8, Chrome users will have to use version 54 or 55 (current) if they want to access their Gmail accounts.
*** DDoS attacks in Q4 2016 ***
2016 was the year of Distributed Denial of Service (DDoS) with major disruptions in terms of technology, ..
*** Jugendliche gehen schludrig mit Passwörtern um ***
Der Sicherheitsbewusstsein von österreichischen Jugendlichen und Unter-30-Jährigen ist schlecht ausgeprägt. Jeder Zweite hat sein Passwort schon einmal weitergegeben.
*** Security: Der Secret Service gibt Tipps für Rechenzentrumsbetreiber ***
Ein Rechenzentrum behandeln wie das Weiße Haus? Diesen Tipp gab ein ehemaliger Mitarbeiter des Secret ..
*** KopiLuwak: A New JavaScript Payload from Turla ***
A new, unique JavaScript payload is now being used by Turla in targeted attacks. This new payload, dubbed KopiLuwak, is being delivered using embedded macros within Office documents.
*** Hackerangriff auf Tschechiens Außenamt offenbar größer als gedacht ***
*** Panne bei Handysignatur: Dokumentenname einsehbar ***
Laut "Die Presse" waren 14 Stunden lang der Name aller unterzeichneten Dokumente abrufbar
*** Microsoft Windows SMB Tree Connect Response memory corruption vulnerability ***
Microsoft Windows contains a memory corruption bug in the handling of SMB traffic, which may allow a remote, unauthenticated attacker to cause a denial of service or potentially execute arbitrary code on a vulnerable system.