Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2888954 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3945 on: July 25, 2015, 12:15:43 PM »
Cybercriminal's favorite exploit kit by far is named Angler:
Angler dominated with an 82% of the exploit kit market share - https://blogs.sophos.com/2015/07/21/a-closer-look-at-the-angler-exploit-kit/  link article author = Fraser Howard.   
Qualities of this malware: http://blogs.cisco.com/security/talos/angler-domain-shadowing
Link article author is Nick Biasini and edited by Joel Esler.

posted here by polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3946 on: July 27, 2015, 01:35:54 PM »
Security Researchers wary of Wassenaar Treaty. Discriminating export restrictions could severely hamper international digital security. Lobbyists and none-technical political forces could have clipped the wings of security researchers and could have hampered security for the global community and especially outside the "Wassenaar Global Empire" with the proposals as they are now for CFAA.
What does it bring  if you have a computer with a Tb of memory and you cannot work it because of the slow Celeron processor it has inside, you'd better have a swift processor on a computer with an external hard disk?

Or what if you run privacy risks in parts of the world because of encryption export restrictions, even worse if by technical incompetence the encryption is served the wrong end up.

It is like old Rome revisited, the Romans were producing cheese with the use of rennet and germanic/slavonic tribes outside the limes (bounderies) of the empire they made their "ost"/"ser" passing milk through nets made of the Galium plant, also known as catchweed or goosegrass, later they adopted to the new Roman ways of life and produced real cheese (word taken from Latin caseus), with Wassenaar rules "caseus" would never have been exported. Now we even produce kosher and halal cheese.

Read here: https://threatpost.com/security-researchers-wary-of-proposed-wassenaar-rules/112937  Article author = Michael Mimoso.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline SpeedyPC

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3398
  • Avast shall conquer the whole world
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3947 on: July 28, 2015, 06:08:53 AM »
Leaked files from state-sponsored hackers reveal which protection their trojans can’t get past

Data breaches on international surveillance firms can teach us a lot about which antivirus programs are actually working.

Recent high-profile leaks show that malware from surveillance firms Hacking Team and FinFisher can't be detected by more than 80% of antivirus programs!

http://blog.emsisoft.com/2015/07/27/leaked-files-from-state-sponsored-hackers-reveal-which-protection-their-trojans-cant-get-past/?ref=ticker150727&utm_source=newsletter&utm_medium=newsletter&utm_content=blog&utm_campaign=ticker150727

Quote
Hacking Team’s trojan detected by 5 out of 34 antivirus vendors
http://ht.transparencytoolkit.org/KnowledgeBase/-%20AV%20Test%20Summary%20-%20%5DHT%5B%20%3A%3A%20KnowledgeBase%20Product.html
Gigabyte 670 LGA1200 Full ATX MB | Intel Core i9-13900 CPU/LGA 1700 | GeForce Nvidia RTX-4070/12GB | 32GB DDR4 | 2 x 1TB Samsung SSD | W11 Home 64bit | Avast Premium v24.3.6108 | Avast SecureLine VPN | Avast Secure Browser | Avast Driver Updater | Avast BreachGuard | Firefox 64bit | MalwareBytes Premium | Adguard Premium | CCleaner Portable | Macrium Reflect | 7-Zip

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3948 on: July 28, 2015, 12:51:36 PM »
Hi dear avast users,

10 million potential victims of malverting leading to Angler exploit infections.
Read: http://www.cyphort.com/malvertising-spike/  link article author = Nick Bilogorskiy.
Malvertising via -ads.us.e-planning.net is being blocked for me by uBlock Origin.
Users should always have protection via a decent adblocker.
Understand that using adblockers is a vital part of your protection.
"Do not surf without being protected, else you will surely get infected".  ;D

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3949 on: July 28, 2015, 12:56:37 PM »
The Home Office warns against TorrentLocker-ransomware with an additional advice to use HTTPS only: https://www.gov.uk/government/news/home-office-fraudulent-email-warning

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3950 on: July 28, 2015, 03:25:55 PM »
Quantserve trackers and adware pusher use soup. It is a soup which taste I do not like and why I have an adblocker like uBlock Origin to keep such destinations blocked. See what Visitor related info is gathered via soup
Code: [Select]
Results from scanning URL: httc://edge.quantserve.com/quant.js
[code]
window.SOUP_test_ab = "";
Quote
Visitor related
Login status of the user - all following flags apply to a logged in visitor (= Soup user) only
Blog privacy - the privacy status the visitor configured for their blog
NSFW toggle - this pertains to an upcoming release that let's the visitor toggle if they want to see NSFW material in /everyone, /friends etc.
Exports - tells us which exports the visitor has configured (currently this can only be facebook)
Reported someone - did the visitor report posts for anything, like spam. This may pertain to the visitors engagement level.
Email - did the visitor supply an email with their registration?
Which imports did the visitor configure?
Did the visitor connect their account to facebook, either via export or signup?
How long has the visitor had his account with Soup, in days
Which pool does the visitor belong to? Currently there is only A, which are all members of @testkitchen, and B, which is the default for everyone. We may use this to do split-testing in the future.
Is the visitor using an adblocker?
How many feeds is the visitor importing to their blog?
How many original (non-imported) posts does the visitor have on their blog?
Days since the last original post of the visitor
Number of groups the visitor is member of

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5616
  • Spartan Warrior
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3951 on: July 28, 2015, 07:10:35 PM »
The Home Office warns against TorrentLocker-ransomware with an additional advice to use HTTPS only: https://www.gov.uk/government/news/home-office-fraudulent-email-warning

polonus
Timely warning notification there.  I'm sure avast will have protection soon.
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5616
  • Spartan Warrior
« Last Edit: July 28, 2015, 08:55:04 PM by mchain »
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3955 on: July 30, 2015, 06:20:05 PM »
How your privacy has been thrown out of the window on Google Android:
http://arstechnica.com/gadgets/2013/10/googles-iron-grip-on-android-controlling-open-source-by-any-means-necessary/
That was written in 2013 and the situation has only grown worse with adblockers taken from Google Shop etc. etc.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3956 on: July 30, 2015, 10:13:21 PM »
BIND users should immediately upgrade - there is no circumventing this vulnerability can be easily attacked by exploitkits.
Read: https://www.isc.org/blogs/about-cve-2015-5477-an-error-in-handling-tkey-queries-can-cause-named-to-exit-with-a-require-assertion-failure/  posted by Michael McNally
This general bug could mean a big problem when not patched.

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3959 on: August 03, 2015, 09:36:00 PM »
Cybercriminals planning future atatcks preying on existing vulnerabilities:
http://www.net-security.org/secworld.php?id=18691
For instance: https://isc.sans.edu/forums/diary/Worm+Backdoors+and+Secures+QNAP+Network+Storage+Devices/19061
Shellshock or Bashdoor: https://en.wikipedia.org/wiki/Shellshock_(software_bug)
Reconnaissance attack tools: http://www.sans.org/reading-room/whitepapers/tools/tools-tools-tools-406
(P.S. Use of such tools could be offensive, restricted  and under circumstances illegal - )

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!