Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2905188 times)

0 Members and 7 Guests are viewing this topic.

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5666
  • Spartan Warrior
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2850 on: January 17, 2014, 03:22:01 AM »
NSA secret and covert pathways into foreign air-gapped computers
http://www.nytimes.com/2014/01/15/us/nsa-effort-pries-open-computers-not-connected-to-internet.html?hp&_r=1

Other devices than PC's/workstations affected as well.
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2851 on: January 17, 2014, 05:02:42 PM »
Why experts again advise to uninstall Java altogether, see: http://www.kb.cert.org/vuls/id/625617
Some kernel components should be completely rewritten according to Bitdefender's Bogdan Botezatu on Twitter Bogdan Botezatu
ATbbotezatu.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2852 on: January 18, 2014, 06:30:56 PM »
Adware vendors buy Chrome Extensions to send ad- and malware-filled updates
http://arstechnica.com/security/2014/01/malware-vendors-buy-chrome-extensions-to-send-adware-filled-updates/
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2853 on: January 21, 2014, 03:58:26 PM »
Vietman Governmental Attackers use poisoned Word documents to attack critical bloggers-> https://www.virustotal.com/nl/file/351813270729b78fb2fe33be9c57fcd6f3828576171c7f404ed53af77cd91206/analysis/
-> https://www.virustotal.com/nl/file/351813270729b78fb2fe33be9c57fcd6f3828576171c7f404ed53af77cd91206/analysis/
The malicious part is https://threatcenter.crdf.fr/?More&ID=83663&D=CRDF.Virus.Virus.MSWord.Sattelite987105478
and has been around since 2012 and is being used in the latest versions also: https://malwr.com/analysis/NWM5NDU4NmM4NWNlNDJiYzhiYmM4ODhkNGQzNWFkMTY/
Only 1 of 49 av vendors detect the attack code heuristically,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37549
  • Not a avast user

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37549
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2855 on: January 21, 2014, 07:59:19 PM »
EE BrightBox routers can be hacked 'by simple copy/paste operation'
http://www.theregister.co.uk/2014/01/20/brightbox_routers_vuln/



Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Cast

  • Sr. Member
  • ****
  • Posts: 302
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2857 on: January 22, 2014, 10:51:49 PM »
Chrome Bugs Allow Sites to Listen to Your Private Conversations
http://talater.com/chrome-is-listening/

I wonder if this affects chromium based browsers as well since Chrome is based of it.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37549
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2858 on: January 23, 2014, 09:06:00 PM »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2859 on: January 31, 2014, 12:23:28 PM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2860 on: January 31, 2014, 03:03:11 PM »
Data snooping revelations, what can developers do to better protect users? (They let it slip  :(  )
Read: http://stackoverflow.com/questions/21389844/with-the-nsa-data-snooping-revelations-what-can-app-developers-do-to-prevent-th

The angry-bird app developers did not even provide a blocking mechanism - all so-called "sitting data" could be snooped upon, slurped and exploited for BB surveillance purposes!

polonus

P.S. Note - On a side-line.
We had some interesting thread here on blocking/uninstalling geo-location from various software. Why this was I do not know but somehow we have both lost  thread and user  ::) In hindsight from the revelations of grand scale data exploitation/abuse he had a lot of prophetic insight there and then...
I know you cannot blame the surveillance institutions simply on geo-location data proliferation sec, but it has been and still is an importing facilitating factor where user snooping and user profiling  is concerned.  :-[
Read: http://www.ghacks.net/2010/05/10/how-to-disable-geolocation-in-google-chrome/
link author = Martin Brinkman

D
« Last Edit: January 31, 2014, 03:31:43 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37549
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2861 on: January 31, 2014, 03:11:08 PM »
Malware infections “staying the same” say security experts
http://blogs.norman.com/2014/for-consumption/malware-infections-staying-the-same-say-security-experts


Quote
A new survey of computer security professionals has revealed that the amount of malware threats reaching users has stayed the same over the past year, and that users are more likely to be infected by surfing the internet than downloading attachments to emails.


Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37549
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2862 on: January 31, 2014, 03:14:10 PM »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2863 on: February 01, 2014, 03:59:47 PM »
168 domains seized in grand counterfeit goods action: http://www.ice.gov/news/releases/1401/140130newyork.htm

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2864 on: February 04, 2014, 03:31:34 PM »
About the danger of downloading ENC files and banking trojans: http://garwarner.blogspot.co.uk/2014/02/gameover-zeus-now-uses-encryption-to.html
article author = Gary Warner
Go over your logs and check!

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!