Infosecurity News

Pirate Bay Dredged from the Deep with Clone Site
The file-sharing site that was known for living up to its name has been replicated.

Banking Statement Phish Carries Nasty PowerShell Payload
Claiming to be a financial document, this attack's attachment uses a three-pronged execution path.

SANS Warns of Shellshock Attacks on NAS Kit
Unpatched QNAP devices are at high risk, says training institute

DNS Attacks Ravage Three-Quarters of US/UK Firms
Cloudmark study claims critical business and customer data at risk

OphionLocker Uses Advanced Crypto and Tor for Bitcoin Payment
Latest ransomware spotted by researchers uses Elliptic Curve Cryptography

Hundreds of Thousands of Wordpress Sites Serving SoakSoak
A vulnerability in the RevSlider plug-in opens the door to complete website compromise.

Malwarebytes Flaw Found in Upgrade Mechanisms
Users of the consumer version of the Malwarebytes Anti-Malware and Anti-Exploit should upgrade to the latest version of the security software as soon as possible.

Hackers Offer ‘100% Guarantees’ on Dark Web Goods
Dell SecureWorks report finds increased competition is forcing better customer service

GCHQ Launches Android Crypto App for Kids
Cryptoy is designed to get more children interested in cybersecurity

Feds Warn US Firms of Iranian Cyber Campaign
Flash report comes just days after Operation Cleaver revelations

Pirated Assassins Creed Spreads Malware
The malware intercepts text messages and harvests information from the phone.

Dyreza Banking Threat Back to Target North America
Microsoft said that the busy Dyreza RAT has a fresh attack vector using a wire transfer phish.

Cameron Calls in the Spies to Deal With Child Abuse Online
GCHQ and NCA to co-operate, but critics say it’s simply electioneering

China Responsible for 85% of Global Phishing Domains – APWG
Cyber-criminals targeting victims inside Great Firewall are blamed for malicious domain registrations

ICS-CERT: BlackEnergy Attacks on Critical Infrastructure Target Known Vulnerabilities
In a new wrinkle in an ongoing attack, the BlackEnergy malware is targeting internet-connected human-machine interfaces (HMIs).

Charge Anywhere Admits Breach May Have Given Hackers Access for Five Years
Mobile payments processor only partially encrypted data travelling across its network

Ukraine Attacks Rained Down on Cyber Monday – Report
Imperva spots attackers using shopping period as cover to steal data and break systems

Serious Flaw Found in Alibaba's English e-Commerce Site
An attacker could alter product prices, delete goods or close a merchant’s shop on the site.

RedOctober Rises Again with Cloud Atlas APT
Cloud Atlas uses an unusual set of tactics that are not very common in the APT world, including using cloud accounts for C&C communications.

Advanced Inception APT Malware Likely State-Sponsored
The highly sophisticated malware targets wireless and PC users in high-value positions.



