Security Affairs http://securityaffairs.co/wordpress Read, think, share … Security is everyone's responsibility Tue, 11 Aug 2015 13:11:07 +0000 en-US hourly 1 0-Day Deserialization flaw impacts more than 55 percent Android users http://securityaffairs.co/wordpress/39277/hacking/android-0-day-deserialization-flaw.html http://securityaffairs.co/wordpress/39277/hacking/android-0-day-deserialization-flaw.html#comments Tue, 11 Aug 2015 13:11:07 +0000 http://securityaffairs.co/wordpress/?p=39277 Security Experts at IBM have discovered a new critical vulnerability affecting Android OS and impacting more than 55 percent users. There is no peace for the Android users, recently experts discovered the critical Stagefright vulnerability and other serious flaws like the Certifi-gate vulnerability and CVE-2015-3823 flaw. Now experts from IBM have discovered another critical bug in the Google Android OS that impacts more […]

The post 0-Day Deserialization flaw impacts more than 55 percent Android users appeared first on Security Affairs.

]]>

Security Experts at IBM have discovered a new critical vulnerability affecting Android OS and impacting more than 55 percent users.

There is no peace for the Android users, recently experts discovered the critical Stagefright vulnerability and other serious flaws like the Certifi-gate vulnerability and CVE-2015-3823 flaw.

Now experts from IBM have discovered another critical bug in the Google Android OS that impacts more than 55 percent of all the mobile devices.

The researchers explained that the new bug, coded as CVE-2015-3825 is a privilege escalation vulnerability in the Android platform that could be exploited to allow “a malicious app with no privileges, the ability to become a ‘super app’ and help the cybercriminals own the device.”

The flaw, dubbed Android serialization vulnerability, affects Android versions 4.3 and above, including the latest release Android M.

The vulnerability resides in the Android OS component called OpenSSLX509Certificate, the attackers can exploit it to compromise the system_server process and gain powerful system-level access to the mobile device.

The researchers published a video proof-of-concept for the exploitation of the flaw, in the video the attacker exploits the flaw using a malicious app by replacing the legitimate Facebook app to steal victim’s credentials.

When the victim runs the app, it downloads additional code to replace the existing app with a malicious code, including an exploit used to escalate permissions using the vulnerability.

Security experts from IBM also discovered other vulnerabilities in a series of third-party Android Software Development Kits (SDKs) that could allow attackers to execute remote arbitrary code from the apps that use these SDKs.

The IBM has already reported the flaws to Google, more information is available in a detailed analysis presented in a paper published by the researchers.

Android desarialization flaw

Pierluigi Paganini

(Security Affairs – Deserialization flaw, macros)

The post 0-Day Deserialization flaw impacts more than 55 percent Android users appeared first on Security Affairs.

]]>
http://securityaffairs.co/wordpress/39277/hacking/android-0-day-deserialization-flaw.html/feed 0
VBE files on the rise in Brazil leading to Financial Fraud http://securityaffairs.co/wordpress/39270/cyber-crime/vbe-files-financial-fraud.html http://securityaffairs.co/wordpress/39270/cyber-crime/vbe-files-financial-fraud.html#comments Tue, 11 Aug 2015 12:11:25 +0000 http://securityaffairs.co/wordpress/?p=39270 Security experts at Kaspersky Lab recently observed a big wave of malicious VBE files targeting Brazilian users to distribute Financial Trojan. Recently security experts have seen old tricks rising from the dead (like for example word/excel macros attachment in e-mails) and malicious VBE files are being spread via email targeting Brazilian users. This VBE files […]

The post VBE files on the rise in Brazil leading to Financial Fraud appeared first on Security Affairs.

]]>

Security experts at Kaspersky Lab recently observed a big wave of malicious VBE files targeting Brazilian users to distribute Financial Trojan.

Recently security experts have seen old tricks rising from the dead (like for example word/excel macros attachment in e-mails) and malicious VBE files are being spread via email targeting Brazilian users.

This VBE files end up to be downloaded by users and when opened serve a banking Trojan malware on the victim’s machine.

Talking about the attack itself, all starts with an email with a .ZIP attachment or including a link to the malicious VBE file. These emails can be related with many subjects, recently attackers are using the Windows 10 release as subject.

The malicious file attached or downloaded is very small, normally less than 1KB. Analyzing the file, we may find it encoded and looking like this:

malicious VBE file email 3

After decoding, it will be possible to see the real intentions of the person or group who wrote the malicious file, in the specific case we see a reference to a website:

malicious VBE file email 4

This malware belongs to the family of Banload and looking worldwide we see Brazil, Portugal and Spain as the most targeted countries:

malicious VBE file email 2

This is another case among many others, it is necessary to adopt mitigation techniques that can help security departments to control such kind of attacks.

The images used in this post were taken from a blog post published by the security expert Fabio SecureList post.

Elsio Pinto (@high54security) is at the moment the Lead Mcafee Security Engineer at Swiss Re, but he also as knowledge in the areas of malware research, forensics, ethical hacking. He had previous experiences in major institutions being the European Parliament one of them. He is a security enthusiast and tries his best to pass his knowledge. He also owns his own blog Mcafee Security Engineer at Swiss Re, but he also as knowledge in the areas of malware research, forensics, ethical hacking. He had previous experiences in major institutions being the European Parliament one of them. He is a security enthusiast and tries his best to pass his knowledge. He also owns his own blog http://high54security.blogspot.com/

Pierluigi Paganini

(Security Affairs – VBE file, macros)

The post VBE files on the rise in Brazil leading to Financial Fraud appeared first on Security Affairs.

]]>
http://securityaffairs.co/wordpress/39270/cyber-crime/vbe-files-financial-fraud.html/feed 0
Aerial Assault Drone, the new Hacking Weapon presented at the Defcon http://securityaffairs.co/wordpress/39265/hacking/aerial-assault-drone.html http://securityaffairs.co/wordpress/39265/hacking/aerial-assault-drone.html#comments Tue, 11 Aug 2015 08:07:42 +0000 http://securityaffairs.co/wordpress/?p=39265 A new hacking machine is available in the arsenal of hackers it is an Aerial Assault drone that is able to automatically crack into wireless networks. David Jordan of US-based Aerial Assault presented was the Def Con conference an assault drone equipped with hacking tools. The vehicle could be used in hacking missions, for example by […]

The post Aerial Assault Drone, the new Hacking Weapon presented at the Defcon appeared first on Security Affairs.

]]>

A new hacking machine is available in the arsenal of hackers it is an Aerial Assault drone that is able to automatically crack into wireless networks.

David Jordan of US-based Aerial Assault presented was the Def Con conference an assault drone equipped with hacking tools. The vehicle could be used in hacking missions, for example by landing atop buildings and probing for cracks in the internal networks.

An Aerial Assault drone is displayed during a Def Con hacker gathering August 9, 2015 in Las Vegas.  The Aerial Assault drone can land atop buildings or hover outside walls and hunt for ways to break into computer networks through wireless connections.      AFP PHOTO /  GLENN CHAPMAN

An Aerial Assault drone is displayed during a Def Con hacker gathering August 9, 2015 in Las Vegas. The Aerial Assault drone can land atop buildings or hover outside walls and hunt for ways to break into computer networks through wireless connections. AFP PHOTO / GLENN CHAPMAN

According to Jordan this drone is unique,

“There has never been this capability before,” Jordan said as he showed the drone to AFP.

The drone was equipped any kind of hacking software used by hackers in penetration testing, it is able to discover vulnerabilities in the target network and exploit it.

The Aerial Assault drone scans for unsecured wireless connections to networks, as explained by Jordan, assessing weaknesses of computer networks and tracking the GPS coordinates of a target.

The Aerial Assault drone is available for sale at a price of $2,500 each.

Pierluigi Paganini

(Security Affairs – Aerial Assault drone, hacking)

The post Aerial Assault Drone, the new Hacking Weapon presented at the Defcon appeared first on Security Affairs.

]]>
http://securityaffairs.co/wordpress/39265/hacking/aerial-assault-drone.html/feed 0
Internal modem can be exploited by malware to gain persistence http://securityaffairs.co/wordpress/39252/hacking/internal-modem-hacking.html http://securityaffairs.co/wordpress/39252/hacking/internal-modem-hacking.html#comments Tue, 11 Aug 2015 06:38:41 +0000 http://securityaffairs.co/wordpress/?p=39252 Two security experts at the last Def Con hacking conference have demonstrated how Internal LTE/3G modems can be hacked to help malware survive OS reinstalls Many users totally ignore that LTE/3G modems built into new business laptops and tablets have a dedicated processor and operating system that could be exploited by threat actors to maintain persistent […]

The post Internal modem can be exploited by malware to gain persistence appeared first on Security Affairs.

]]>

Two security experts at the last Def Con hacking conference have demonstrated how Internal LTE/3G modems can be hacked to help malware survive OS reinstalls

Many users totally ignore that LTE/3G modems built into new business laptops and tablets have a dedicated processor and operating system that could be exploited by threat actors to maintain persistent access to a compromised device.

The security researchers Mickey Shkatov and Jesse Michael from Intel’s security group in a talk at the DEF CON security conference in Las Vegas demonstrated how a malware that infect a machine could rewrite the firmware of a popular Huawei LTE modem.

insecure internal modem LTE talk

The expert explained that Huawei LTE modem runs a Linux-based OS, a modification of the Android OS, and is connected to the host system through an internal USB interface. The use of an internal USB interface means that the module could be used by attackers to emulate a number of devices connected to the primary OS, including keyboard, mouse, CD-ROM drive, network card, or other USB device.

The researchers were able to rewrite the firmware because the update process is weak, in fact, the updates aren’t protected by digital signature neither by encryption mechanisms. The two researchers developed their malicious firmware and served it through the Windows update utility provided by the vendor.

The updates could be served in various ways, by exploiting malicious programs already running on the target machine, or by tricking victims into thinking that they are legitimate security patches.

Once the attacker has rewritten the firmware running on the modem it will be able to maintain the infection even if the host OS is reinstalled. The experts also explained that the malicious firmware could be also instructed to ignore any subsequent firmware update, in this case, the unique way to restore the infected PC is to remove the infected modem module.

Huawei promptly fixed the issue, introducing a secure boot that blocks the flashing of unauthorized firmware images.

The presentation made by the security experts raises the question about the possible exploitation of dedicated processors and operating systems that equip any device connected to a system. Malware authors can exploit them to ensure persistence of their malicious code.

Pierluigi Paganini

(Security Affairs – Internal LTE/3G modems, hacking)

The post Internal modem can be exploited by malware to gain persistence appeared first on Security Affairs.

]]>
http://securityaffairs.co/wordpress/39252/hacking/internal-modem-hacking.html/feed 0
IT giants join forces to combat child sexual abuse imagery http://securityaffairs.co/wordpress/39259/cyber-crime/it-giants-child-sexual-abuse.html http://securityaffairs.co/wordpress/39259/cyber-crime/it-giants-child-sexual-abuse.html#comments Mon, 10 Aug 2015 17:02:07 +0000 http://securityaffairs.co/wordpress/?p=39259 Facebook, Google, Twitter, Microsoft and Yahoo and the Internet Watch Foundation (IWF) are joining their efforts in the fight against child sexual abuse. Facebook, Google, Twitter, Microsoft and Yahoo are joining their effort in the fight against child sexual abuse. The IT giants child after joining forces with a the UK charity, the Internet Watch Foundation […]

The post IT giants join forces to combat child sexual abuse imagery appeared first on Security Affairs.

]]>

Facebook, Google, Twitter, Microsoft and Yahoo and the Internet Watch Foundation (IWF) are joining their efforts in the fight against child sexual abuse.

Facebook, Google, Twitter, Microsoft and Yahoo are joining their effort in the fight against child sexual abuse.

The IT giants child after joining forces with a the UK charity, the Internet Watch Foundation (IWF), will remove sexual abuse images from the web.

The news was reported by the Internet Watch Foundation (IWF) that announced it will share hashes of child sexual abuse imagery with the IT giants. The initiative aim to improve and speed up the identification of the despicable images and consequent removal.

The knowledge of the hash of the child sexual abuse imagines will allow companies to rapidly identify the content once published and shared on the Internet.

“The IWF will provide hashes of child sexual abuse images to the online industry to speed up the identification and removal of this content worldwide.

This enables the internet industry to actively protect their customers and help victims of child sexual abuse.”

  • Victims’ images can be identified and removed more quickly, preventing them from being shared time and time again.
  • Child sexual abuse images will be prevented from being uploaded to the internet in the first place.
    This gives internet companies the power to stop people from repeatedly sharing the images on their services.
  • Men, women and children of all ages are protected from accidentally stumbling across the images online.

The Internet Watch Foundation states that its experts will assist the IT companies to create three different types of hashes, PhotoDNA (A technology developed by Microsoft to identify a child abuse image), MD5 and SHA-1.

child sexual abuse images Hash-list-explanation-flow-diagram

The hashed will be calculated starting from the images discovered during its investigations as well as those provided by the IT giants and by the public. Another source for the IWF analysts will be the archive of the UK Home Office’s new Child Abuse Image Database (CAID).

Thanks to the initiative it will be possible to identify and remove as many as 500 child sex abuse web pages every day, an impressive result against the most villain kind of online crimes. The IWF highlighted that each of those pages will host multiple images, so the initiative will potential allow to remove millions of child sex abuse images.

The Internet Watch Foundation notes that this is a first step against child sex abuse, unfortunately, there are billions of such images online.

“The IWF Hash List could be a game-changer and really steps up the fight against child sexual abuse images online. …It means victims’ images can be identified and removed more quickly, and we can prevent known child sexual abuse images from being uploaded to the internet in the first place.” The Internet Watch Foundation’s CEO, Susie Hargreaves

Unfortunately, paedophiles prefer to exploit anonymizing networks like Tor to share child sexual abuse images, a territory difficult to explore despite the effort of the British Government recently announced by Prime Minister Cameron.

The sharing of hash lists of child sexual abuse images has been welcomed by other child protection groups, including the National Society for the Prevention of Cruelty to Children (NSPCC).

Pierluigi Paganini

(Security Affairs – child sexual abuse, cybercrime)

The post IT giants join forces to combat child sexual abuse imagery appeared first on Security Affairs.

]]>
http://securityaffairs.co/wordpress/39259/cyber-crime/it-giants-child-sexual-abuse.html/feed 0
Certifi-Gate, a new Android flaw allows hackers to control your mobile http://securityaffairs.co/wordpress/39246/hacking/certifi-gate-android-flaw.html http://securityaffairs.co/wordpress/39246/hacking/certifi-gate-android-flaw.html#comments Mon, 10 Aug 2015 14:12:42 +0000 http://securityaffairs.co/wordpress/?p=39246 Certifi-Gate is the name of a new vulnerability affecting Android mobile devices discovered by Check Point security that could be exploited to control them. Android users had a bad time after discovering the “Stagefright” vulnerability, but unfortunately other security issues are warning them. It was recently discovered a new vulnerability dubbed Certifi-Gate which could be […]

The post Certifi-Gate, a new Android flaw allows hackers to control your mobile appeared first on Security Affairs.

]]>

Certifi-Gate is the name of a new vulnerability affecting Android mobile devices discovered by Check Point security that could be exploited to control them.

Android users had a bad time after discovering the “Stagefright” vulnerability, but unfortunately other security issues are warning them. It was recently discovered a new vulnerability dubbed Certifi-Gate which could be exploited by hackers to control a mobile device by using a pre-installed plugin in Android devices.

You may know that almost all manufacturers pre-install “Remote Support Tool (mRST)” plugins in order to aid users to use tools such TeamViewer, RSupport, etc etc.

What this vulnerability does is using the mRTS plugin as entry point for “bad” applications that can control the mobile device, even if it is not rooted.

Android certifi-gate flaw

Researchers at Check Point explained that the “Certifi-Gate” vulnerability lies in the way manufacturers of Android devices use certificates to sign the mRST tools.

Another problem is that even if your phone is not rooted, this type of applications have root level access, so easily can gain access to:

  • screen scraping
  • keylogging
  • exfiltrating private information
  • installing malware apps, and more

As said before, this vulnerability affects millions of Android users, and the sad part about it is that users cannot uninstall the mRST plugin because it’s part of the core system.

“An attacker can exploit mRATs to exfiltrate sensitive information from devices such as location, contacts, photos, screen capture, and even recordings of nearby sounds.”

“While analyzing and classifying mRATs, our research team found some apps share common traits with mRST. Known mRAT players include HackingTeam, mSpy, and SpyBubble.” reports the Check Point’s paper

Ho to verify if the mobile device is vulnerable?

Check Point has released a mobile app that can be found here:

https://play.google.com/store/apps/details?id=com.checkpoint.capsulescanner

The app detects if your android phone is vulnerable or not to the Certifi-Gate vulnerability, and shows if the mobile was already hit by attackers.

Since Android manufacturers are known to take time in releasing patching to the users, this many take some time until is fixed.

Check out the videos:

 

Elsio Pinto (@high54security) is at the moment the Lead Mcafee Security Engineer at Swiss Re, but he also as knowledge in the areas of malware research, forensics, ethical hacking. He had previous experiences in major institutions being the European Parliament one of them. He is a security enthusiast and tries his best to pass his knowledge. He also owns his own blog Mcafee Security Engineer at Swiss Re, but he also as knowledge in the areas of malware research, forensics, ethical hacking. He had previous experiences in major institutions being the European Parliament one of them. He is a security enthusiast and tries his best to pass his knowledge. He also owns his own blog http://high54security.blogspot.com/

Edited by Pierluigi Paganini

(Security Affairs – Certifi-Gate, Android)

The post Certifi-Gate, a new Android flaw allows hackers to control your mobile appeared first on Security Affairs.

]]>
http://securityaffairs.co/wordpress/39246/hacking/certifi-gate-android-flaw.html/feed 0
Hacking airport security systems with a common laptop http://securityaffairs.co/wordpress/39239/cyber-crime/hacking-airport-with-laptop.html http://securityaffairs.co/wordpress/39239/cyber-crime/hacking-airport-with-laptop.html#comments Mon, 10 Aug 2015 06:59:25 +0000 http://securityaffairs.co/wordpress/?p=39239 Hackers can compromise airport security networks by using a common laptop, this is the disconcerting discovery of the popular expert Billy Rios. Cyber security from I-Team investigation revealed that hackers could have the ability to shut down an airport’s security network just using a laptop. It is embarrassing read that system designed to improve security of the […]

The post Hacking airport security systems with a common laptop appeared first on Security Affairs.

]]>

Hackers can compromise airport security networks by using a common laptop, this is the disconcerting discovery of the popular expert Billy Rios.

Cyber security from I-Team investigation revealed that hackers could have the ability to shut down an airport’s security network just using a laptop.

It is embarrassing read that system designed to improve security of the airports could represent the entry point for attackers.

“Walking by these devices and knowing how poorly secure they are, it doesn’t sit well with me,” explained the popular cyber security expert Billy Rios. “It’s pretty bad — probably no thought has been given to cyber security at all.”

In 2013, Billy Rios tested various machines deployed at airports throughout the world discovering numerous security vulnerabilities. The list of machines tested includes an X-ray scanner, an explosives detector, also known as itemiser, and a time clock.

Rios explained that the vulnerabilities affecting the machine could be exploited to access the airport’s network, for example, is discovered very common to discover hard-coded passwords into the software running on these security systems.

“So anyone that knew the username and password, which we know, could just log into the device and get access to an airport network,” said Rios. “It just takes one second to abuse some of the vulnerabilities that we’ve seen.”

The unauthorized access to an X-ray machine could be exploited by a terrorist or a criminal to hide weapons from screeners.

airport security

Rios reported the flaws to the US authorities that prompted the Department of Homeland Security to issue a warning about password vulnerabilities in some explosive detection machines. According to NBCNewYork , Rios has found many other flaws in the itemiser and in the time clocks.

“One machine Rios examined is called the itemiser. The company that makes itemisers says the version Rios bought was only used at foreign airports and the company recently released an update to correct the flaw, it said.

Rios maintains the broader concern continues at domestic airports, where he says he found three time clocks with vulnerable passwords.” states the NBCNewYork.

The company that produces the time clocks have already fixed the flaws and personnel at the airports can now change the passwords.

The most disconcerting aspect of the story is that it is likely that the vulnerabilities discovered by Rios have already been exploited, this is the opinion of the cyber security strategist from Cylance, Jon Miller.

“Now that we have extremists that are gaining these capabilities, they’re going to start using information for other types of attacks we haven’t seen before. It’s going to be a sobering couple of years,” said Miller.

The Cylance firm recently published a report on an Iranian hacking crew, which run a cyber espionage campaign exfiltrating sensitive information from many organizations and environments, including the airports.

“We were following them for 18 to 24 months, but it wasn’t until we started seeing them pull things like emergency response times and information that could put the physical safety of people at harm we knew we had to stop it,” says Miller.

“Anyone who has a copy of the plan on how an airport or any facility responds to an emergency now has a blueprint on how to beat that system,” said Kenneth Honig, a former commanding officer for the police department of the Port Authority of New York and New Jersey.

“Now that it’s been brought out into the open, hopefully they will take steps to fix it, but it will take time.” added Honig, who has 20 years leadership on the force.

Rios urges Transportation Security Administration to adopt more stringent requirements in term of cyber security of the equipment used in any airport.

“The bar is too low,” Rios said. “There will always be security issues, we can’t solve every single security issue, but we shouldn’t have the bar be so low that anybody can hack into these devices. The bar has to be a lot higher.”

Pierluigi Paganini

(Security Affairs – security, airport)

The post Hacking airport security systems with a common laptop appeared first on Security Affairs.

]]>
http://securityaffairs.co/wordpress/39239/cyber-crime/hacking-airport-with-laptop.html/feed 0
Hackers can remotely steal fingerprints from Android devices http://securityaffairs.co/wordpress/39235/digital-id/steal-fingerprints-android.html http://securityaffairs.co/wordpress/39235/digital-id/steal-fingerprints-android.html#comments Mon, 10 Aug 2015 06:17:47 +0000 http://securityaffairs.co/wordpress/?p=39235 Researchers from FireEye have revealed that it is possible to attack Android smartphone to remotely steal user’s fingerprints on a “large scale.” Security experts have often expressed concerns regarding the fingerprint management implemented by the principal mobile vendors. Hackers have demonstrated that it is not difficult to trigger vulnerabilities inside systems that manage fingerprints in […]

The post Hackers can remotely steal fingerprints from Android devices appeared first on Security Affairs.

]]>

Researchers from FireEye have revealed that it is possible to attack Android smartphone to remotely steal user’s fingerprints on a “large scale.”

Security experts have often expressed concerns regarding the fingerprint management implemented by the principal mobile vendors. Hackers have demonstrated that it is not difficult to trigger vulnerabilities inside systems that manage fingerprints in order to bypass authentication mechanisms, in April 2015 a group of security researchers at FireEye have discovered a vulnerability in the Samsung Galaxy S5 that allows hackers to clone fingerprints.

Now security experts from FireEye have discovered four new methods to hack Android devices and extract user fingerprints remotely.

The researchers Tao Wei and Yulong Zhang presented the findings of their hack in a talk titled, Fingerprints on Mobile Devices: Abusing and Leaking, at the Black Hat conference last week.

The techniques are very insidious because the victim will never notice the disconcerting theft of its fingerprints.

Cognitive Fingerprints authentication

The researchers dubbed the attack “Fingerprint Sensor Spying attack” and it could allow attackers to “remotely harvest fingerprints in a large scale from the handset of the major manufacturers including HTC, Samsung and Huawei.

The experts avoided to release  any “proof-of-concept” for obvious reason.
The targets of the attack are Android devices equipped with Fingerprint Sensors that allow users to authenticate themselves by simply touching the display of their smartphone.

Let’s note that Google doesn’t yet officially support the authentication mechanism based on fingerprints based on its mobile operating system, but the company will soon implement the support in the next release Android M.

The researchers tested their attack on the HTC One Max and Samsung’s Galaxy S5, the succeeded to steal a fingerprint image from the device due to the lack of a proper implementation of a locking mechanism for the fingerprint sensor.

I have explained several times the risks related to a wrong implementation of biometric authentication, the theft of a biometric data like fingerprints would be more dangerous compared the theft of a stolen password.

Users can reset their compromised password, but cannot change fingerprints neither the iris in the case of data breach.

“In this attack, victims’ fingerprint data directly fall into attacker’s hand. For the rest of the victim’s life, the attacker can keep using the fingerprint data to do other malicious things,” said Zhang.

Fortunately, the security issue is quite easy to fix, for example by encrypting fingerprint data on Android devices, and a number of vendors are already working to a security update.

The measure is already adopted by Apple iOS that encrypts data acquired by the Touch ID sensor. The experts explained that Apple iOS is “quite secure” because it encrypts fingerprint data from the scanner with a crypto key, making it unreadable even if hackers gain access.

Pierluigi Paganini

(Security Affairs – Android, fingerprints)

The post Hackers can remotely steal fingerprints from Android devices appeared first on Security Affairs.

]]>
http://securityaffairs.co/wordpress/39235/digital-id/steal-fingerprints-android.html/feed 0
Security Affairs newsletter Round 21 – Best of the week from best sources http://securityaffairs.co/wordpress/39233/cyber-crime/security-affairs-newsletter-21.html http://securityaffairs.co/wordpress/39233/cyber-crime/security-affairs-newsletter-21.html#comments Sun, 09 Aug 2015 15:37:22 +0000 http://securityaffairs.co/wordpress/?p=39233 A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from the best sources free for you in your email box. Hacking Industrial Ethernet Switches to take over nuclear plants Microsoft Windows 10 spies on you by default Operation Potao – hackers used a trojanized version of TrueCrypt Mt Goxs […]

The post Security Affairs newsletter Round 21 – Best of the week from best sources appeared first on Security Affairs.

]]>

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from the best sources free for you in your email box.

Hacking Industrial Ethernet Switches to take over nuclear plants
Microsoft Windows 10 spies on you by default
Operation Potao – hackers used a trojanized version of TrueCrypt
Mt Goxs Mark Karpeles arrested in Japan
Hijacking Satellite Communications with a $1,000 Device
FDA says healthcare providers to stop using older drug infusion pumps made by Hospira
Hacktivists congratulate Daily Shows Jon Stewart via Donald Trumps website
Global spy system ECHELON confirmed at last – by leaked Snowden files
Sysadmin jailed for a decade after slurping US military docs
A secure employee departure checklist
The Snowball Effect of Data Breaches
Zscaler Raises $100 Million to Expand Cloud Security Business
Windows 10 Upgrade Spam Carries CTB-Locker Ransomware
Exploits start against flaw that could hamstring huge swaths of Internet
A secret NSA map shows successful Chinese attacks
EFF, AdBlock and Others Launch New Do Not Track Standard
RIG Exploit Kit 3.0 infected over 1.3 Million PC worldwide
0-day bug in fully patched OS X comes under active exploit to hijack Macs
New US cyber laws will hit privacy and security, says Homeland Security
Malvertising Attack Hits Yahoo! Ad Network
Researchers Uncover ‘Terracotta’ Chinese VPN Service Used by APT Crews for Cover
Terracotta VPN hijacks servers for commercial gain
Kaspersky DDoS Intelligence Report Q2 2015
Yahoo tackles large malvertising campaign in its ad network
Operation Lotus Blossom APT – Elise Malware
Hackers use cartons with sticks, may be foiled by watermelons
Hacker sends woman pictures of herself from her own webcam
Interpol is training Police officers to fight crime on the Darknet
Terracotta VPN Piggybacks on Network of Compromised Windows Servers
Thunderstrike 2 rootkit infects Mac firmware
Symantec Patches Critical Vulnerabilities in Endpoint Protection
Terracotta VPN, the Chinese VPN Service as Hacking Platform
Researchers make SHODAN of the skies to probe internet-of-things
TaiG Jailbreak for Mac, tool for jailbreaking iOS 8.4 (Mac OS X version) Released
China Jails TV Hacker for 12 Years Over Anti-Govt Broadcast
CVE-2015-3823 Android bug phones in endless reboots
SDN switches arent hard to compromise, researcher says
IDG Contributor Network: What I learned from resetting over 300 passwords
Lightbulb moment: Why the Internet of Things is a security watershed
What is the core idea behind applying ISO 27001?
Biggest software update in history coming up: Google patches Android
Thunderstrike 2 rootkit uses Thunderbolt accessories to infect Mac firmware [Updated]
Google pushes fixes for critical code-execution bug in Android
From The Black Hat Keynote Stage: Jennifer Granick
Google to Issue Over The Air Updates to Nexus Devices
Newly discovered Chinese hacking group hacked 100+ websites to use as watering holes
APT Group Gets Selective About Data it Steals
Government Asks for Security Community’s Help on Technical Issues
Iranian, Syrian Hackers Hit Gas Gauges
ICANN Website Security Breached
The Panda Emissary APT specialized in defence aerospace projects
GameOver Zeus Gang Leader Engaged in Espionage: Researchers
FBI may pillory Hillary with email spillery grillery
Global Internet Authority — ICANN Hacked Again!
ICANN urges passwords reset due an external service provider breach
BLEKey Device Breaks RFID Physical Access Controls
Oh no ZigBee, as another front opens on home networking insecurity
Black Hat 2015: Salted Hash live blog (Day 2)
Hacked Opinions: Vulnerability disclosure – Chris Lord
Hacker-friendly Chrysler hauled into court for class-action showdown
Hackers Turn Square Readers into Crime Tools
Black Hat: Hackers urged to protect Internet freedom
Why it’s time to say goodbye to passwords
Crooks exploit public bug to plant adware on Yosemite Macs
Black Hat 2015: Hacker shows how to alter messages on satellite network
Black Hat 2015: IoT devices can become transmitters to steal data
Consumers still don’t get two-factor authentication
Android faces SECOND patching crisis, on the same scale as Stagefright
Hackers Can Remotely Steal Fingerprints From Android Phones
Updated DGA Changer Malware Generates Fake Domain Stream
Meet RollJam, the $30 device that jimmies car and garage doors
Hacking Team compromised non-jailbroken iOS devices
Mozilla Patches Firefox Zero-Day Exploited in the Wild
Ubiquiti Networks Victim of $39 Million Social Engineering Attack
Looking for lessons in the aftermath of the Hacking Team incident
Email addresses in DNS records? Well make a hash of it, says IETF
Researchers find way to steal Windows Active Directory credentials from the Internet
Attack on Sabre reportedly conducted by Anthem, OPA hackers
The NSA Playset: 5 Better Tools To Defend Systems
IDG Contributor Network: The best of times and worst of times in security education
Salted Hash: Live from DEF CON 23
Google Disables Inline Installation of Chrome Extensions for Deceptive Developers
0-day attack on Firefox users stole password and key data: Patch now!
Certifi-Gate Android Vulnerability Lets Hackers Take Complete Control of Your Device
Universal remote can ‘hack into any car’
DGA.Changer Malware Uses New Tricks to Throw Researchers Off Track
Blackhat USA and Defcon 2015
Hack a garage and the car inside with a childs toy and a few chips
Hackers are targeting Gas Tanks worldwide
Rush to Put Death Records Online Lets Anyone be Killed
Leading to a secure cloud – panel discussion recording, slides & transcript (downloads)
Phony death wish? Its incredibly easy to bump someone off online – infosec bod
RollJam — $30 Device That Unlocks Almost Any Car And Garage Door
Researchers to Share Details of Cyber-Terrorists Targeting Indian Government Officials
How Drones Can Find and Hack Internet-of-Things Devices From the Sky
0-day attack on Firefox stole sensitive data and password
Update Firefox NOW to foil FILE-STEALING vulnerability exploit, warns Mozilla
Hackers Broadcast Porn on TV Screens at Brazil Bus Depot
Hacking Windows Server Update Services to infect enterprises
Carphone Warehouse coughs to MONSTER data breach – 2.4 MEELLION Brits at risk

Email address: Hurry up, subscribe to the newsletter, next Sunday you will receive all the news directly in your inbox.

newsletter

Once again thank you!

Pierluigi Paganini

(Security Affairs – Newsletter, SecurityAffairs)

The post Security Affairs newsletter Round 21 – Best of the week from best sources appeared first on Security Affairs.

]]>
http://securityaffairs.co/wordpress/39233/cyber-crime/security-affairs-newsletter-21.html/feed 0
Carphone Warehouse hacked: 2.4 million customer records at risk http://securityaffairs.co/wordpress/39222/cyber-crime/carphone-warehouse-hacked.html http://securityaffairs.co/wordpress/39222/cyber-crime/carphone-warehouse-hacked.html#comments Sun, 09 Aug 2015 14:57:58 +0000 http://securityaffairs.co/wordpress/?p=39222 Carphone Warehouse has taken three days to disclose about a sophisticated attack that may have impacted more than 2.4 million customers. The British mobile phone retailer Carphone Warehouse has been hacked and nearly 2.4 million customers records could have been compromised. On 5 August 2015 the experts of the company discovered that the IT infrastructure […]

The post Carphone Warehouse hacked: 2.4 million customer records at risk appeared first on Security Affairs.

]]>

Carphone Warehouse has taken three days to disclose about a sophisticated attack that may have impacted more than 2.4 million customers.

The British mobile phone retailer Carphone Warehouse has been hacked and nearly 2.4 million customers records could have been compromised.

On 5 August 2015 the experts of the company discovered that the IT infrastructure of three of its online UK businesses had been victim of a sophisticated cyber attack. Data accessed by the hackers may include some personal details and encrypted credit card details.

The hackers breached the websites onestopphoneshop.com, e2save.com and mobiles.co.uk, which also provide a number of services related to mobile phone contracts to iD mobile, TalkTalk mobile, Talk mobile and Carphone Warehouse.

The company added that up to 90,000 subscribers may have had their encrypted credit card details swiped during the cyber attack.

Carphone Warehouse hack

The Carphone company has issued the following statement following the cyber attack:

What has happened?
On 5 August 2015 we discovered that the IT systems of three of our online UK businesses had been subject to a sophisticated cyber attack. At this stage, our investigation indicates that some of the data held on our systems has been accessed and this may include some personal details, including customer name, address, date-of-birth, bank and encrypted credit card details.

Who is affected?
The three websites affected are onestopphoneshop.com, e2save.com and mobiles.co.uk. These websites also provide a number of services related to mobile phone contracts to iD mobile, TalkTalk mobile, Talk mobile and Carphone Warehouse.

We don’t believe that any other Carphone Warhouse customer data or Currys PC World data has been accessed.

How will I know if I’ve been affected?
We’ve emailed all customers who we believe may have been affected with information and advice.

If you have not received a communication from us regarding your data security, your information should not be impacted and this message does not apply to you.

The disconcerting aspect of the new data breach is that even individuals that aren’t a direct customer of Carphone Warehouse may have been affected. The list of victims may include nearly 480,000 Talk Talk Mobile customers.

The attack may have compromised data belonging to many customers of Carphone Warehouse, Talk Talk, mobiles.co.uk, and the companies.

The website of mobiles.co.uk was down in the last days, officially due to “technical difficulties,” but the reality is quite different.

Carphone Warehouse hack

Sebastian James, group chief executive of Dixons Carphone, also confirmed the attack in a official in a statement.

“We take the security of customer data extremely seriously, and we are very sorry that people have been affected by this attack on our systems,” said James.

Sebastian James, group chief executive of Dixons Carphone, also confirmed the attack in an official in a statement.

“We take the security of customer data extremely seriously, and we are very sorry that people have been affected by this attack on our systems,” said James.

Unfortunately, victims are exposed to identity theft and other type of scams, expert suggest victims to carefully monitor their bank accounts.

The Register confirmed that the firm wanted to be sure of the number of people impacted by the incident before notifying customers about the data breach, but according security expert this delay could expose customers to further attacks.

There is no information about the specific attack, users urge to change their passwords, especially if the same credentials are shared among different web services and websites.

Stay Tuned!

Pierluigi Paganini

(Security Affairs – Carphone Warehouse, data breach)

The post Carphone Warehouse hacked: 2.4 million customer records at risk appeared first on Security Affairs.

]]>
http://securityaffairs.co/wordpress/39222/cyber-crime/carphone-warehouse-hacked.html/feed 0