Showing posts with label security news. Show all posts
Showing posts with label security news. Show all posts

Friday, March 8, 2013

99% web-applications contain vulnerabilities


In the new report, researchers predict what users will be exposed to vulnerabilities in the current year.

According to a new report by Cenzic, existing vulnerabilities in web-applications are a major concern, as they are present in almost 99% of the products.

Researchers predict what vulnerabilities most likely be exposed to the victim in the current year.

"Ensuring the security level required in modern companies should be solved more realistically - said Cenzic CTO Scott Parcel. - This year, the increase in the number of threats faced by the corporation due to existing vulnerabilities, but most companies do not fully protect themselves from such dangers. And this trend is getting worse. "

Cenzic experts report also includes the results of a study of security threats of mobile devices.

Monday, February 18, 2013

Adobe will release emergency updates for Reader


Emergency vulnerability will be released during the week


This week, Adobe plans to release emergency patch for two critical zero-day vulnerabilities in the program Adobe Reader. The notification producer reported that gap is already being used by fraudsters. The exact release fixes the company is not known, but it should happen before the end of the week.

The first vulnerability is contained in the version of Reader for Windows, OS X and Linux. The second hole for the remote execution of malicious code on the target system, which is embedded in a specially created PDF-files.

Sunday, February 17, 2013

Japanese police arrested the alleged creator of the "virus-terrorist"


Japanese authorities arrested the alleged creator of the malware spread on bulletin boards and e-mail box of the various organizations and individual Internet users in Japan ads and emails with threats of kidnapping and terrorist acts. The threat spoke on behalf of the people infected with malicious information kompyuterov.Po Bangkok Post, the police suspect the virus to create a 30-year resident of Tokyo, Yusuke Katayama.

 Law enforcement authorities in Japan have discovered a malicious program in October last year, after the arrest of the owners of several computers that allegedly were sent threatening texts. In the sent text containing the threat of terrorist attacks in the shopping center, threats to blow up the plane, received one of the airlines, as well as threats to the royal family, in particular, the threat of a terrorist attack in the schools attended by members of the imperial family.

McAfee jeopardized the safety of MAC users


Administrator at McAfee accidentally withdrew digital key, which allows certification of desktop applications based on Apple OS X. Because of this, a huge number of consumers have difficulty installing or updating anti-virus products for Mac.

McAfee employees say they never lose control of special certificates, which are used to confirm that users are using the legitimate releases. Key revocation date - February 6, 2013. This means that for a week consumers were not able to confirm they bought McAfee-software for Mac.

"We were just told that we must accept unverified certificates until they sort out their problems," - says one IT-manager of a large company, who requested anonymity. "In fact, they offer us their own themselves to the threat."

Friday, January 11, 2013

NVIDIA has removed security vulnerability by releasing driver update


Exploit for the vulnerability was published on Pastebin, although the company has not been notified about the discovery holes.

The U.S. company has released an update for NVIDIA driver (310.90 WHQL), which fixes a security vulnerability, discovered at the end of December. Pre-existing flaw could allow attackers to gain administrator privileges on the versions of Windows, which were released after Vista.

Vulnerability in the driver NVIDIA Display Service has been discovered by researchers in the field of information security, Peter Winter-Smith. He posted to exploit vulnerabilities on Pastebin.

The flaw could cause a buffer overflow and the introduction of a certain code afforded privileges. The exploit provides an attacker to bypass DEP-and ASLR-protection on the target system.

Later exploit the vulnerability has been removed from Pastebin, which is related to the fact that researchers have published it without notifying representatives of NVIDIA's newly discovered vulnerability.

Wednesday, December 5, 2012

Researcher disclosed information about spoofing attack in Twitter


The owners of the accounts linked to mobile numbers without the PIN code are at risk of being compromised.

According to an independent security researcher Jonathan Rudenberg, users of Twitter, whose settings 'SMS-tweets' at the moment are open, are at risk of being compromised.

According to the expert, the information contained in the software social network vulnerability is that the service does not properly check the permissions of fake mobile numbers to the settings of the user account. Such a way, a remote attacker who knows the phone number of the victim, may conduct spoofing attack and take control over another microblog.

"To carry out an attack is enough to know the phone number attached to the user account. In this case, hackers can send messages with a fake number, "- said the expert.

Rudenberg also said that Twitter developers were notified of the presence of gaps in August of this year. Since then, however, they no effort to eliminate the threat.

Friday, November 30, 2012

The Japanese space agency is a victim of the Trojan


Japanese Space Agency Jaxa today announced that with the help of Trojan software unknown attackers stole private data on the latest Japanese space rocket. As reported in Jaxa, computer virus has been detected on the network at Tsukuba Space Center in the northeast of Tokyo. Said malicious code secretly collect and transmit data about the missile beyond Jaxa.

The agency said today that the malicious code was detected by anti-virus software is November 21, the same space agency employees took 'all necessary measures'. Also in Jaxa say spy code was detected in only one space center, the other systems have not been exposed to infection.

An official statement said that while it was unclear whether the virus is available on computers Jaxa employees or hit by cyberattacks. Previously, a number of Japanese military-industrial company claims that have been targets of cyber attacks, the traces of which were in China.

As for the information stolen by malicious code, it is associated with a new missile Epsilon, solid fuel and is a further development of modern Japanese rockets. Independent experts say that Epsilon was originally created as a solution for launching satellites and interplanetary spacecraft, but in principle it could have a dual purpose and be used as an intercontinental ballistic missile.

Epsilon first start is expected in autumn 2013.

Tuesday, November 13, 2012

New Windows Trojan - Trojan.Gapz.1


Trojan.Gapz.1 - is bootkit implements functions and the ability to hide its presence in the infected system. In this application are fairly interesting mechanisms infecting computers.

Trojan.Gapz.1 capable of running both 32-bit and 64-bit versions of Windows. the procedure of installing the malicious program varies depending on the platform. The Trojan is also able to actively use the vulnerability number of system components, which allows him to perform a specially crafted code.

The installer has been attempting bootkit bypassing the UAC (User Accounts Control, UAC), preventing unauthorized execution of executable files in the system by exploiting vulnerabilities Graphics Windows.

Trojan.Gapz.1 then analyzes the structure of the infected computer's hard drive, creates a special image and places it in the reserved sectors of the disk. The Trojan modifies one field in the boot sector of the disk, and thus makes the boot load up and run a malicious application.

Wednesday, October 17, 2012

McAfee offers security updates for the data center

McAfee has announced a new line of products Data Center Security Suite


 Attention to the client, the company offers high-quality solutions built on the most advanced and cutting-edge technological developments and allow secure servers and databases in corporate data centers.

According to the developer, the proposed products can be used to effectively protect enterprise servers and databases that are deployed in physical, virtualized and cloud environments. Key features of the solutions Data Center Security is exceptional reliability, high performance and low power consumption of server resources. Thus, these products are in full compliance with the essential requirements of client organizations to protection data center.

Product McAfee Data Center Security Suite for Server, intended to organize their basic protection of all types of servers, offers a complete set of tools for doing "black" and "white" lists, and boasts enhanced support for advanced virtualization technologies. The proposed solution is also available in the version Hypervisor Edition, which guarantees the security of virtual servers, and is licensed by the number of used hypervisors.

Antivirus for Andoid is available in Facebook AV Marketplace

Today, Facebook announced that the AV marketplace is getting a big expansion, more than doubling the number of antivirus companies whose software downloads will be available.


Facebook users were able to download from the social networking site antivirus software for mobile devices - smartphones and tablets.

Anti-virus software will be available on Facebook under AV Marketplace, which allows free download full version of antivirus software. Their period of free use is limited, after the end user can make a paid subscription. The resource was launched in April 2012. According to Facebook, over six months of its existence it used about 30 million users of the social network.

Tuesday, October 16, 2012

Found a mini-version of spyware Flame


Experts have found so far unknown malware aimed at stealing data from infected computers 

Interestingly, in the detected program specialists have found traces of spyware and Flame Gauss.

In the "Kaspersky Lab" is not taken argue who or what is the object of interest of a newly discovered virus. Rather, it comes to computers, which contain information that is "of particular value." Also, the experts there is no information as to whether or not they have incidents of this software, which resulted in the stolen confidential data, the magazine writes Digit.

As the press service of the company, a malicious program called experts miniFlame because of its similarity to known spyware Flame, designed to steal data and control infected systems in targeted attacks, carried out to cyber espionage.

"MiniFlame is a tool for precision attacks. Most likely, this cyber weapons with clear targets, used in the course of what may be called the second wave of cyber attacks, "- said in a news release.

Friday, October 12, 2012

Teenager found new critical vulnerability in Chrome


Young hacker Pinkie Pie can become a millionaire, receiving thousands of Google for each working exploit.

Yesterday at a conference Hack in the Box during the contest Pwnium 2 young talent has shown a couple of critical vulnerabilities in Chrome and working exploit for which he was awarded a monetary reward.

Vulnerability of an ID CVE-2012-5112, a detailed description of our issue tracker, tickets 117 715 and 117 736, as well as a blog Chromium. The first bug is associated with an error at rendering SVG-files engine WebKit, and the second bug was found in the system IPC (inter-process data transfer), which allowed to go beyond the sandbox. The result was to make NPAPI-browser plug-in that gets full privileges on the system.

This is the second time that Pinkie Pie earns thousand in the last time he scored in March 2012 for the first competition Pwnium. At the time, he was able to be chained six vulnerabilities to get out of the sandbox and get Chrome to execute arbitrary code on the system. Now, apparently, the exploit uses only two vulnerabilities, but the result is the same.

Tuesday, October 9, 2012

In Adobe Flash eliminated 25 vulnerabilities

Adobe has released security updates for Adobe Flash Player

Adobe has released a security alert, removing 25 security vulnerabilities in Adobe Flash Player and Adobe AIR.

Adobe has released Security Bulletin APSB12-22, which eliminated the 25 vulnerabilities, it does not reveal the details of vulnerabilities. At the time of publication of news, a company newsletter provides information only about the fact that 14 of the 25 vulnerabilities include buffer overflow, which can be used to execute arbitrary code. The rest can be exploited by an attacker to implement a memory corruption and also compromise a vulnerable system.

Monday, October 8, 2012

Vulnerability: Cross-site scripting in Opera

Vulnerability in Opera allows XSS attack on any site


For an attacker to exploit the vulnerability by placing a specially crafted link to the target resource.

The forum RDot.org has information about the dangerous vulnerabilities in the browser Opera, which allows XSS attack in the context of an arbitrary web-site. This vulnerability can also be exposed to the latest versions of the browser Mozilla Firefox.

Sunday, September 9, 2012

Hackers have not got hold tax returns Romney's


In PWC found no evidence of cyber attacks and data theft U.S. presidential candidate.

The company PricewaterhouseCoopers (PWC) denies hacking hacking and theft of tax returns U.S. presidential candidate Mitt Romney's. As a result of an internal investigation no evidence of cracking was found. It is reported by Computerworld.

"At the moment there is no evidence that our systems have been compromised, or that someone managed to get unauthorized access to documents Romney," - said the representative of PWC Maggie O'Donovan-Bolton .

Monday, September 3, 2012

New version of Trend Micro Deep Security 9

The new version of Trend Micro Deep Security 9 for server protection


Today Trend Micro announced a new version of the platform for the protection of servers, applications and data in physical, virtual and cloud environments - Trend Micro Deep Security 9. The solution enables companies and service providers IaaS ("Infrastructure as a Service") to increase return on investment in virtualization and cloud technologies.

The new version of Deep Security line does not need to install agents on virtual machines and is designed specifically for environments VMware ®. Developers managed to increase performance is achieved and convenience, as well as opportunities to protect the server level public and hybrid cloud environments. That allows you to dynamically handle the load while maintaining a high level of security and ensure regulatory compliance.

FinFisher learned to infect smartphones

FinFisher attacking mobile users


Company "Citizen's Lab" has detected a new spy software for mobile devices. According to company representatives, research has shown that the basis for a new spyware program served FinSpy, supplied software FinFisher, created by Gamma Group UK.

It is reported that this version FinSpy runs on almost any modern mobile devices. The victims of this spyware can be as owners of mobile devices based on Android OS and Windows Phone, and the owners of BlackBerry, and even the happy owners of the iPhone and iPad.

Oracle knew about the presence of 0-day Java vulnerabilities in April

Security Explorations company said it released Oracle solution does not correct all vulnerabilities in Java

Oracle has released a security alert, which eliminated the zero-day vulnerability in Java (CVE-2012-4681). Recall that last week of the first public exploit this vulnerability reported Atif Mushtaq from the company FireEye. According to experts, hackers used a gap in Java for the implementation of targeted attacks, but in the near future to exploit it was supposed to be accessible to a wide range of cyberhawks.

The next day, the company Rapid 7 said about adding a module to exploit CVE-2012-4681 for a tool to pentesterov Metasploit, and Brian Krebs, citing its own sources, said that his version of the exploit works and authors BlackHole. Quoting one of the leaders of BlackHole, Krebs wrote that the price of such an exploit could be about $ 100,000.

Sunday, September 2, 2012

Facebook will remove the counterfeit mark "Like"

Social network Facebook has decided to proceed with a large-scale clean-up of the fake "Likes."


Facebook began to introduce more stringent measures against spammers and malicious content - the company intends to further develop the marks "Like", removing bogus mark. The company said it will remove all the marks that were generated by automated or suspicious accounts. Typically, counterfeit mark used to promote certain products or bringing attention to the blogs of users.

Simply put, Facebook has launched a program, scrub cheated optimizers ranking points needed to attract increased interest on the part of users. Usually, fake "like" used to promote certain goods, attracting attention to the blog and other actions aimed at promoting a blog or an article in it.

Removing bogus stamps will implement special programs for the calculation of "Likes". In the Facebook note that these measures will improve the quality of content, which is really interesting to users, and tougher action against spammers.

Saturday, September 1, 2012

Oracle has released patches for urgent Java 6 and 7

Extraordinary patch for an 0-day vulnerability


Oracle has released extraordinary patch for an 0-day vulnerability, which in recent days have begun to actively exploit some cybercriminal groups.

Updates for JDK and JRE 6 Update 7, JDK and JRE 6 Update 34 contains patches for four vulnerabilities Java, including the notorious CVE-2012-4681. Oracle has emphasized: given the danger of this threat, it is strongly recommended that all users install the patch data as soon as possible.

The vulnerability affects only the desktop version of the plugin Java, working through a web browser, they do not touch the server version or separate Java-applications.