Showing posts with label Security Company. Show all posts
Showing posts with label Security Company. Show all posts

Monday, 9 October 2017

WordPress Sites Vulnerable By Leak Into Postman SMTP Plug-In



Over 100,000 WordPress sites are vulnerable due to a vulnerability in the Postman SMTP plug-in, and a developer security update is not yet available. Postman is an SMTP mailer that helps send emails generated by the WordPress site.

The plug-in is vulnerable to reflected cross-site scripting, which allows an attacker to steal the content of cookies from, for example, the administrator, according to security company White Fir. Due to the unpatched vulnerability, WordPress decided to remove the plug-in from the database with available plug-ins on WordPress.org . Meanwhile, GitHub has published a patched version of Postman, but it has not been developed by the original author. The original developer would have been informed about the problem.

Thursday, 5 May 2016

Stolen Passwords 272 Million Email Accounts Found


An American security company claims to have discovered the stolen usernames and passwords of 272 million email accounts. A large part relates to accounts of Russian mail service Mail.ru, let the company hold Security across news agency Reuters to know.

How the data is not stated precisely captured. According to Alex Holden Security Hold the stolen credentials were offered a forum for cyber criminals. He managed to get the data and verified. It turned out to be nearly 57 million Mail.ru accounts, 40 million Yahoo accounts, Microsoft 33 million accounts and nearly 24 million Gmail accounts and hundreds of thousands accounts of Chinese and German email providers.

Mail.ru, in response to the discovery launched an investigation to see which users are affected, to warn subsequently. A preliminary audit showed that did not work the leaked usernames and passwords.

Wednesday, 7 October 2015

Apple: YiSpecter-Malware Only Works On Old iOS Versions


The YiSpecter malware that security company Palo Alto Networks warned only works on older iOS versions, and only if users themselves downloading malware from untrusted sources, says Apple. The malware is mainly active in China and Taiwan, but the number of infections is unknown.

To spread the malware uses different methods, but a user action is still required to download and install the malware. In a statement to The Loop, Apple says that the problem affects only users of older iOS versions of the malware itself from unreliable sources have downloaded. The specific problem could be resolved in iOS 8.4. This version was published on June 30 of this year.

In addition, Apple has the apps that were used to block the spread of malware. Apple recommends that iPhone owners to install the latest version of iOS apps only from trusted sources such as downloading the App Store. Also, users should be careful when they get warnings when downloading apps.

Thursday, 27 August 2015

Trainee Security Company FireEye Developed Malware


A trainee of the American security company FireEye has developed malware that cyber criminals Android phones infected and could control completely. It is a 20-year-old American who was arrested in July as part of an operation against the Darkode forum.

This was a great forum for cyber criminals. The American was active in this forum and sold here, along with a Dutch accomplice, his Dendroid malware. Facing a US judge the man known to be guilty and made his apologies to the victims of his malware. He also said that he would use his skills in the future to protect computer users. FireEye security company had already announced in July that the trainee was sued by the authorities.

The Dendroid malware was offered at a cost of $ 300. Once active on a machine could steal the malware files and text messages, take pictures, surf the history readout and record conversations without casualties this had passed. The American was in his own words over a year working on the development of the malware. If convicted, the men could be imprisoned up to 10 years and a fine of $ 250,000, so inform the AP and the Pittsburgh Post-Gazette. The judge will rule on December 2.

Wednesday, 12 August 2015

Great Spam Botnet Suddenly Disappeared From Radar



A spam botnet that was last year for a large portion of all spam messages containing malware responsible suddenly disappeared and never returned. It involves ASPROX botnet since 2008 became operational. Over the years there appeared many variations of the malware, which spread mainly through infected e-mail attachments. 80% of all e-mail malware was sent via the botnet.

For example, last year emails with voicemails, send confirmations of courier companies, airline tickets and coupons used to allow users to open the attachment piggybacked. Once the attachment is opened the computer is part of the botnet. At peak times knew the botnet 2 million sessions per week. The end of 2014 the botnet suddenly disappeared from the radar.However, a clear reason missing.

For example, there are no operations of investigative services took place and there are no indications that the botnet operators were arrested. Earlier this year discovered the Internet Storm Center all that the botnet was gone. Security company Palo Alto Networks confirms that the botnet was shut down in January. One possible reason is that the trustees have decided to regroup the botnet and re-deploy. Although the botnet is gone, there are still ASPROX infected "computers" that continue to send e-mails with malware.

Friday, 17 July 2015

Trainee Security Company FireEye Suspected Of Cyber Crime


A trainee of the American security company FireEye is suspected by the US government to develop and distribute Android malware. The 20-year-old man Dendroid the malware could have developed. With this malware, it is possible to infect Android devices and to control remotely. According to the indictment , the trainee would Dendroid-malware offered by the Darkode Forum, yesterday by the FBI offline was extracted.

The man is studying at Carnegie Mellon University in Pittsburgh and was twice an intern at FireEye. There he was engaged in researching Android malware. In a statement to CNN FireEye confirms that the trainee is indeed indicted by US authorities and that his training has been discontinued for the time being. There is now an investigation into the activities of the man's place. According to CNN, there are concerns that the intern has compromised software FireEye and has the knowledge and tools of the company used to commit cyber crime.

Anti-virus firms Symantec and Trend Micro warned in the past for the Dendroid malware, which attackers full access to can get an Android device. Then data from the device can be stolen and it is possible to listen in on calls and take pictures.Dendroid was for a sum of $ 300 on forums offered for cyber criminals.