More than 7,000 FTP sites compromised and infected with malware

Researchers from Hold Security have discovered more than 7,000 FTP sites have been compromised by  to infect malware or to attempt to compromise connected web services. “Hackers planted PHP scripts armed with backdoors (shells) and viruses in multiple directories hoping that these directories map to Web servers of the victim companies to gain control of the […]
Share Button
Continue reading →

OSX/CoinThief a New Apple Mac Bitcoin stealing Trojan Discovered -SecureMac

CoinThief, a Bitcoin-stealing Trojan targeting Mac users, was discovered offering on several download websites such as CNET’s Download.com and MacUpdate.com. It was also available masquerading as pre compiled binaries in multiple GitHub projects. The malware variant installs a browser extensions for Safari and Google Chrome to monitor all web browsing traffic, specifically looking for login […]
Share Button
Continue reading →

US Veterans of Foreign Wars website compromised by IE Zero day Exploit (CVE-2014-0322)

Recently  a zero day vulnerability in Internet Explorer was discovered(CVE-2014-0322)). Researchers from Fireeye has identified that hackers are using this vulnerability in targeting US military personals. Furthermore they also suspect that this may be a very strategic campaign (Operation Snowman) during the President’s day weekend. FireEye researchers observed  drive-by-download attack which  alters HTML code of the […]
Share Button
Continue reading →

Careto/Mask APT cyber-espionage operations running and undetected for 7 long years

Its almost sounded unbelievable when Kaspersky research published a cyber espionage APT campaign MASK (Careto) that’s been running in the wild since 2007, undetected, targeting 31 countries.   The complexity of the tools used for MAST by the attackers are very sophisticated which makes its very special. This includes an extremely sophisticated piece of malware, a […]
Share Button
Continue reading →

IoS 7 Vulnerability Allows ‘FIND MY IPHONE’ Security Feature to be Disabled without password

Bradley Williams, a security researcher has discovered a vulnerability in iOS 7 that can allow the disabling of ” Find My iPhone” without having to enter a password. This new vulnerability  allows someone who has access to your i-phone to quickly disable  “Find My iPhone” service, which is used to track the location of all registered […]
Share Button
Continue reading →

Snapchat app is vulnerable to DDoS attack, can crash your iPhone,reacts to it very stubborn.

Jamie Sanchez, a security researcher discovered a vulnerability within Snapchat mobile app which can crash your iphone by Denial of Service attack. The vulnerability can enable a hacker to launch DoS attacks which can potentially crash a users phone or requires that the user perform a hard reset. He further says with a video that […]
Share Button
Continue reading →

Brazilian Encrypted Java Archive trojan banker spreads via Playstation phishing email – Kaspersky

Researchers from Kaspersky discovered a Brazilian Java Trojan that spreads via phishing email. Dmitry Bestuzhev explains that he never owned a Playstation but received an email with an attachment with a unusual ways of spreading Trojan bankers via .Jar files ( 14KB). It appeared to be a strange Trojan because even if  a user just clicks on a .jar […]
Share Button
Continue reading →

Syrian Electronic Army hacks Facebook’s domain wishing ‘Happy Birthday Mark!’

The Syrian Electronic Army – a hacker group supportive of Syrian President Bashar Assad – managed to hack into Facebook, on the week of 10th Anniversary. The hackers first claimed to obtain Facebook.com as published on twitter at approximately 6:30 Eastern Standard Time. WHOIS search on domain registrar indicated that the email address was tied […]
Share Button
Continue reading →

Largest Website in Sweden Aftonbladet serves Malicious Code for Internet Explorer users

Its very common lately for sites spreading malware from ads. The ad which are served from Google and Microsoft may relie on third party syndication may potentially be compromised which may lead to malware distribution.  A similar incident happened as reported by Kaspersky that the largest website of sweden was spreading scare-ware to its users. […]
Share Button
Continue reading →

Adobe released Emergency Flash Player update for critical zero day threat – CVE-2014-0497

Adobe released an emergency patch for a critical vulnerability affecting Flash Player for Windows, Linux and OS X, the exploitation of which can result in an attacker gaining remote control of the compromised systems. The security flaw exists in Adobe Flash Player 12.0.0.43 and earlier versions  Adobe thanks Alexander Polyakov and Anton Ivanov of Kaspersky Labs […]
Share Button
Continue reading →