Hacking Facebook user “Access Token” using Man in the Middle Attack

Facebook had a long list of vulnerabilities and their Security team is incapable in dealing with the real world security. Unfortunately their mission of making the world open also aligns with Security principles as well. This is just the opinion and may not be the reality. This vulnerability still exists and the author says in […]
Share Button
Continue reading →

Facebook Advertising “Suggested Posts” delivers Android Malware

Researchers have identified a tricky Android malware spreading via facebook advertising. When Facebook is accessed from an Android device, users may see messages under Facebook adverting under “Suggested Post”. Some of the identified ads read as “WhatsApp tips like: “Want to know how to see your contacts’ chats on WhatsApp?” “Want to hide your WhatsApp […]
Share Button
Continue reading →

More than 360 million newly stolen credentials sold on black market

Researchers from Hold Security LLC,have identified more than 360 million credentials in the underground market. The details of the data is not yet publicized nor any company name is identified as per the reports. Alex Holden, CISO of Hold Security LLC, said in an interview that the data was obtained over the past three weeks. […]
Share Button
Continue reading →

Yahoo vulnerability could have allowed Hacker to delete more than 1.5 million records

Ibrahim Raafat ( @RaafatSEC ) , a Egyptian security researcher identified an vulnerability which could have potentially deleted more than 1.5 million records form its database. He further demonstrated ‘Insecure Direct Object Reference Vulnerability’ on his blog which appeared to have been fixed by Yahoo. He performed the demo with his account. The vulnerability escalated the users privilege to delete the […]
Share Button
Continue reading →

EC-Council, Security Certification Group website hacked and defaced

“Although EC-Council has been respected by corporations and governments, many in the in the security community don’t agree the way they certify and considered it as useless certification ”  Analysts predict that Passports of more than 60,000 US military and government IT professionals at risk Hacker went by the name of Eugene Belford, claims to […]
Share Button
Continue reading →

First TOR-Based Android Malware Spotted by Kaspersky !

Researchers from Kaspersky have spotted Tor-based Andorid Malware in the wild. Hackers have started creating Android based Trojans in mass scale. A new mrthod of Windows Trojan malware is implemented under Android has been spreading lately. The Android based Trojan, who as a C & C uses the domain of pseudo-zone- Onion. The Trojan uses the anonymous […]
Share Button
Continue reading →

Youtube serving Malwar- Caphaw Banking Trojan

Monetizing by  serving ads has been the business model lately by most know sites like facebook, twitter, google, msn.com and various other websites. However there is a dark ecosystem in which these ads are either hijacked or compromise user accounts to server malware.  A similar issue was seen by  Bromium Labs  and has been reported […]
Share Button
Continue reading →

Syrian Electronic Army hacks Forbes, steals user information

This time Syrian Electronic Army has targeted Forbes for the big hack day. SEA published the hack on Friday, showing several screenshots of the WordPress admin panel backend of the Forbes.com website.                       SEA  said in a tweet that more than one million user e-mails and passwords […]
Share Button
Continue reading →

Mass Exploitation of Linksys routers – E1000 & E1200 by “TheMoon”

Johannes B, a security researcher from the SANS has posted a warning for useres about  a self-replicating malware named “The Moon”has been exploiting authentication bypass and code-execution vulnerabilities on Linksys routers – E1000 & E1200 wireless routers. How does it work ? The malware remotely calls Home Network Administration Protocol (HNAP), allows identification, configuration and management of networking devices.  Malware […]
Share Button
Continue reading →

More than 2000 TESCO customers account hacked and posted online

              TESCO has been targeted by hackers this time and account information of more than 2000 customers have been posted online on pastebin. Tesco.com internet shopping accounts, personal details and Tesco club card details  were  posted last Thursday online by the hackers. As a result ,  Tesco was forced […]
Share Button
Continue reading →