Showing posts with label Zero-Day Vulnerabilities. Show all posts
Showing posts with label Zero-Day Vulnerabilities. Show all posts

Thursday, 12 November 2015

Oracle Warns Of Zero-Day Vulnerability In WebLogic Server


Software company Oracle has a warning issued to a zero-day vulnerability in Oracle WebLogic Server and the Apache Commons Library, which can take over a vulnerable attacker WebLogic Servers and a security update is not yet available.

The problem is caused by a vulnerability in the Apache Commons Library. This is a project of the Apache Software Foundation provides a number of commonly used Java components. Several products from Oracle and other software vendors and open source software projects, making this library use. Internet is now published detailed information about the vulnerability and how to use.

Besides Oracle WebLogic Server is the additional problem with the WebSphere Application Server, JBoss Application Server, Jenkins and OpenNMS. In the case of WebLogic Server is the vulnerability to attack from a distance and does not require authentication. In case the attack is successful, the attacker could execute arbitrary code in Oracle WebLogic Server. In anticipation of an emergency patch, Oracle temporarily advice put online and advises customers to update, once available, as fast to install as possible.

Wednesday, 11 November 2015

Microsoft Patches 53 Vulnerabilities In Windows, IE And Office


During the November Patch Tuesday, Microsoft has 53 vulnerabilities in Windows, Internet Explorer, Microsoft Edge, Office and several other products poem, including four zero-day vulnerabilities. The total contribution amounts to four twelve security updates, which are labeled as critical.

Critical updates address vulnerabilities that could allow an attacker to run arbitrary code on the computer can perform, without much user interaction. These four are updates for Internet Explorer, Edge and Microsoft Windows. There are also updates for Office, Lync, Skype for Business and .NET Framework appeared. Most leaks are fixed in Internet Explorer, namely 25.

In the case of the four zero-day vulnerabilities were those found in Windows and Office. It involved vulnerabilities that had already been announced for the release of the patches. According to Microsoft, there are no indications that the vulnerability for the appearance of the updates are attacked. An overview of all published Security Bulletins on this page to find. Updating via the Automatic Update feature, which is enabled on most Windows computers.

Wednesday, 23 September 2015

Business Lauds $ 1 Million For Zero-Day Vulnerability In iOS 9



A company that zero-day vulnerabilities from researchers buys and prepares them to government agencies and large enterprises to sell through has a reward of one million dollars promised for a zero-day vulnerability in iOS 9. This is a vulnerability that needs to be through the browser are attacked and the attacker gives permanent access to the iOS device.

There should be no further user interaction is required, except to visit the web page. In addition, researchers get paid even if the attack can be performed via SMS or MMS. Zerodium, as the company is called, says that the vulnerability should be exclusive. In its own text with the requirement for zero-day talk of an "untethered jailbreak", but according to security expert Robert Graham, this is a red herring because it Zerodium not a jailbreak to do.

"A 'browser-based jailbreak is the same as a browser-based zero day", says Graham. According to the expert, there is intelligence from a high demand for these types of vulnerabilities. Especially now, half of iPhone users now iOS 9 installed would intelligence lose access can get into the systems of targets. Unless they have a new zero-day attack, says Graham. Since Zerodium states that the zero-day vulnerability to be exclusive, he expects the company's vulnerability will then sell them to multiple parties.

Thursday, 20 August 2015

Developer Encryption Software Targeted By Cyber Espionage



The director of a Russian company that develops encryption software has been attacked by a group who are more concerned with attacking NATO, the White House and the German parliament. It claims the Japanese anti-virus company Trend Micro. It would go to a group of Russian spies.

Although several organizations abroad were the target group, there are attacks carried out in Russia. This involves phishing attacks whereby refined manner attempts to steal login details for email accounts. According to Trend Micro, members of the rock band Pussy Riot, politicians, journalists and software developers have been targeted. Besides the director of the company that develops encryption software was also a developer of web mail service Mail.ru attacked.

Phishing

The attacks on the Russian people were part of a larger campaign involving tens of thousands of people were targeted with phishing emails. This relates to users of well-known webmail providers such as Gmail, Yahoo, Hushmail, Outlook and other providers in the Ukraine, Iran, Norway and China. The way the attacks occur varies. Some campaigns use malware and vulnerabilities. The group of attackers have used at least six zero-day vulnerabilities in the past.

In addition, also targeted phishing attacks used to obtain login details. The phishing e-mails claim, for example that a new service is to deliver guaranteed emails. It then attempts to get through OAuth, an open authentication protocol for example, Yahoo offers to app developers to access the user's mailbox. The links in the phishing email while pointing to a legitimate website of Yahoo for OAuth. So users may think that it is a harmless link. What is the goal of the attackers know Trend Micro, but they may try to keep potential threats to Russia in the eye.

Thursday, 9 July 2015

Criminals Hacked Apple And Microsoft Still Active



A group of cyber criminals in 2013 Microsoft , Apple , Facebook and Twitter hacked is still active and has provided the large companies, which both malware for Windows and Mac OS X is used. Before the attack on the US Internet companies at the time the attackers used a zero-day vulnerability in Java. At the time of the attack there was no update available for the leak.

After all the attention to the burglaries, the attackers vanished in 2013 for almost a year, but now they are back and they use a previously unknown vulnerability in Adobe Flash Player and use a certificate from the Taiwanese manufacturer Acer to sign with malware. That report anti-virus firms Symantec and Kaspersky Lab today. Both virus fighters have put a group of the analysis.

This is according to anti-virus companies to a group of cyber criminals who operates on a much higher level than other cyber criminals. So is wanted there for credit card information, but to very valuable information. The attacks were the past few years aimed at law firms, Bitcoin-related companies, investment companies, IT companies, health companies and brokers, as well as individual users. Most victims are located in Canada, Europe and the United States.

Attacks

To infect victims they have used the aforementioned zero-day vulnerability in Java and at least one vulnerability in Internet Explorer 10, says Symantec. Kaspersky Lab reports that the attackers have used an unknown vulnerability in Flash Player.The victims are attacked by the leak is unknown. At the first attacks in 2012 and 2013 were hacked websites which targets already visited by itself. How the attackers in the new series of attacks proceed in 2014 and 2015, however, a mystery. In case the attack is successful, the attackers use various tools, including a backdoor for Mac OS X and Windows.

The attackers have mostly provided on mail servers. Once access to the Microsoft Exchange or Lotus Domino servers obtained the e-mail traffic probably bugged, says Symantec. There may also be "fraudulent e-mails" are injected.Furthermore, Kaspersky Lab discovered the malware that was used this year by the group signed with a legitimate certificate from Acer. The certificate has been obtained is unknown. The certificate authority that issued the certificate has been asked to withdraw the certificate.

"Compared with other intelligence groups, this group is one of the most exciting we have analyzed and monitored," Kaspersky Lab says. The virus fighter warns that the criminals are still active. Symantec also warns companies of the group, which not only has excellent operational security, but also succeeded in expanding the activities and not be noticed. "The group is a threat that companies should take seriously," said the virus fighter. The data that the group steals the possible uses for their own financial gain, or by selling to the highest bidder.

Friday, 12 June 2015

Registry Malware Infecting Nearly 200,000 Computers



Malware that only in the Windows Registry is hiding in order to avoid detection and removal has in recent months nearly 200,000 infected computers. It is the Poweliks malware that infected computers used for click fraud and even a zero-day vulnerability in Windows applied to take over a computer completely.Once active Poweliks will first check whether Windows PowerShell is present.

This is a scripting language that allows system administrators to automate many tasks. It is present by default in Windows 7 and can also be installed on other versions of Windows. In case PowerShell is not present is downloaded and installed. Power Shell will later be used to conduct an encoded script file.



This script file contains malware, and makes it possible to download and install additional malware. Then, a key in the Windows Registry created so that the malware is also loaded at the next reboot of the system. By not using a file, like most malware does, but who are completely in the Windows Registry to hide would be more difficult to detect and remove Poweliks.

Ransomware

The malware aims to commit click fraud, where there are visited all kinds of pages that contain advertisements via a hidden browser window. The criminals are paid for every ad displayed. One problem for victims of Poweliks is that the ads displayed itself may be malicious. Poweliks infected with a computer can therefore become infected with a variety of other threats, including ransomware.

According to anti-virus company Symantec , a report ( pdf ) published on the malware, there are many cases in which there was downloaded ransomware through the ads displayed. Remarkably, the malware is active mainly in the United States. Of the 198,500 infected computers showed that 99.5% were in the US. However, that does not mean that users in other countries are not at risk. The virus fighter says that Poweliks shows what future threats may do, with cyber criminals are even more determined to make money from their creations.

Monday, 23 March 2015

Emergency Patches Firefox Remedy Pwn2Own Leak


Mozilla has released in a short time two emergency patches for Firefox that fix critical vulnerabilities that an attacker in the worst case, the computer could take over completely. It involves two vulnerabilities that were demonstrated during the Pwn2Own contest in Vancouver.

During the event, researchers can win cash prizes by showing vulnerabilities in popular browsers and browser plug-ins. In Firefox three vulnerabilities were demonstrated, where it earned two responsible investigators $ 45,000 together. A day after the demonstration had already updated to Mozilla Firefox 36.0.3 done that fixed the first two leaks. A few hours later by Firefox 36.0.4 for the third vulnerability.

Updating to Firefox 36.0.4 possible via the automatic update feature of the browser or Mozilla.org . Besides Firefox succeeded researchers during the event also to Internet Explorer 11 , Safari and Google Chrome hack. In IE11 most vulnerabilities were discovered, namely four. On the same day as Mozilla also came with a Google update for Chrome, but the description is not mentioned in it or this version vulnerabilities have been patched.

Tuesday, 27 January 2015

Apple: "Thunderbolt Attack In OS X Patch"


Apple will soon release an update for Mac OS X Yosemite discovered next three vulnerabilities revealed by Google and also the last year demonstrated Thunderbolt attack will remedy. Let sources with access to the beta version of Mac OS X 10.10.2 opposite iMore know.

In late December showed researcher Trammell Hudson during the CCC hacker conference in Hamburg how he bootkit can install on an Apple Macbook that reinstalling the operating system and replace the hard drive can survive through the Thunderbolt port. Once the bootkit is running that can spread virally by infecting other Thunderbolt devices.

To install the bootkit is need physical access to the computer. To adjust Mac computers to protect against the attack Apple had not only the code that prevents the boot ROM is replaced, but that a rollback to a previous state which prevented the attack still works.

Further, Mac OS X, 10.10.2 Yosemite also three vulnerabilities remedy that Google recently revealed in the OS.Researchers from the search giant had vulnerabilities discovered last year and reported to Apple. Since they are not within the Apple patched the details were automatically made ​​public time limits provided by Google. Something happened earlier vulnerabilities in Microsoft.