Infosecurity News

Giant Viagra Botnet Claims 80K Devices
Researchers were able intercept payloads with details of 51 websites used by spammers to sell counterfeit drugs.

Two-Thirds of Apps Using Open Source Have Known Software Vulns
85% contain license conflicts

Mastercard's Biometric Card Promises "Apple Pay" Without the Phone
Fingerprint reader is embedded in payment card for low friction check-out

#IAPP Conference: Panel - Whose Eye is on the Five Eyes? An Intro to International Oversight Bodies
A panel of privacy commission representatives discussed the role of their organizations amid heightened public concern over state surveillance activities

Researchers Find Multiple RCE Bugs in Linksys Routers
IOActive works with manufacturer on issues with Smart Wi-Fi models

Android SMS Spyware Sees Millions of Downloads
SMSVova can steal and relay a victim's location to an attacker in real time.

Mirai-Busting Hajime Worm Could be Work of White Hat
P2P-controlled malware blocks IoT device access to suspect ports

Hundreds of Google Play Apps Infected with the BankBot Trojan
It infiltrates benign programs, hitching a ride to installation on users’ phones. Then it steals banking credentials and card details.

Bad Guys Still Rely on Marks to Click on Something
On Monday holidays, alerts dip significantly, due to a lack of employees interacting with malicious emails, attachments and links.

#CRESTCon & IISP Congress: Passive Data Sources Can Make System Mapping Great Again
There is a lot to learn from listening to our systems

Call for DHS to Abandon Demands for Travelers' Social Log-Ins
Rights groups claim plans will undermine cybersecurity for those entering US

Karmen Ransomware: User-friendly, Sandbox-averse
A dashboard shows relevant information, including the number of clients and how much money earned.

Intercontinental Hotels Suffer Major Card Breach
Franchises across the US and Puerto Rico affected

Shadow Brokers Exploits: Microsoft and Swift Play Down Impact
Only unpatched or unsupported Microsoft products affected

Critical VMware Flaw Opens Virtual Infrastructures to Attack
The flaw in its vCenter Server platform allows a remote attacker to execute arbitrary code and take control of a system.

Nintendo Offers $20K to Hack the Switch
Ostensibly, the idea is to prevent piracy. But the focus on security is also a bit of a blow to the “homebrew” community.

Cerber Takes Ransomware Crown from Locky
Cerber ransomware took over as top-dog (90% of all detections).

Australian ISP Fights DDoS Attack
Australian ISP Melbourne IT has confirmed that it was hit by “a large DDoS attack” that disrupted its web hosting

Security Training Should be Legal Requirement, Say Employees
New study claims over half haven’t been given any over past year

Philadelphia Ransomware Sets Sights on Healthcare
Philadelphia is an unsophisticated ransomware-as-a-service kit sold for a few hundred dollars to anyone who can afford it.



