Remove 04
Remove 2019 Remove Data Remove Information Security Remove Security
article thumbnail

Zero-day vulnerability in Android OS yet to be patched

Security Affairs

” reads the security advisory published by ZDI. ” The vulnerability resides in the way the Video for Linux (V4L2) driver handles input data, it could be exploited by an attacker to elevate permissions to kernel level. The post Zero-day vulnerability in Android OS yet to be patched appeared first on Security Affairs.

Access 77
article thumbnail

Hackers target zero-day flaws in enterprise Draytek network devices

Security Affairs

Since December 2019, researchers from Qihoo 360 observed two different attack groups that are employing two zero-days exploits to take over DrayTek enterprise routers to eavesdrop on FTP and email traffic inside corporate networks. The attacker is snooping on port 21,25,143,110 (1/2) — 360 Netlab (@360Netlab) December 25, 2019. #0-day

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Lampion malware origin servers geolocated in Turkey

Security Affairs

From December 2019 it had spread, impersonating and using template emails from the Portuguese Government Finance & Tax (Portal das Finanças – ATA) , Energias de Portugal (EDP) , and most recently DPD firm – an international parcel delivery service. Nome do Servidor: Linux portaldasfinancas 4.4.0-116-generic Pierluigi Paganini.

article thumbnail

Fraudulent purchases of digitals certificates through executive impersonation

Security Affairs

Since GDPR legislation came into effect, most EU domain registrars have agreed that WHOIS records are considered private and personally identifiable information. “ 2019-04-30 07:07:59 – The first signed malicious file appears in the wild. Pierluigi Paganini. SecurityAffairs – digital certificates, hacking).

article thumbnail

Grandoreiro Malware implements new features in Q2 2020

Security Affairs

23-04-2020] Malware #portugal #trojan #evasion new sample [link] –c2– hxxp://192.236.147.]100:51224/$rdgate?ACTION=x Figure 2: Grandoreiro variant VT sample submitted on 2020-04-24 during this investigation. Figure 1: Grandoreiro email template Q2 2020 (Portugal). 100:51224/$rdgate?ACTION=x ACTION=x 192.236.147.]100:1950/zflipbgi.iso

article thumbnail

South Korean and US payment card details worth nearly $2M up for sale in the underground

Security Affairs

Singapore, 24/04/2020 – Group-IB , a Singapore-based cybersecurity company, has detected a dump containing details for nearly 400,000 payment card records uploaded to a popular darknet cardshop on April 9. The provenance of this data remains unknown. 2 – Sale of South Korean-issued card dumps in the underground.

Sales 101
article thumbnail

Lazarus BTC Changer. Back in action with JS sniffers redesigned to steal crypto

Security Affairs

The simple nature of such attacks combined with the use of malicious JavaScript code for intercepting payment data attract more and more cybercriminals, and JS-sniffers became one of the most prominent sources of stolen bank cards on underground markets. If you want to receive the weekly Security Affairs Newsletter for free subscribe here.