Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2886046 times)

0 Members and 5 Guests are viewing this topic.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89033
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4950 on: December 01, 2016, 12:22:57 AM »
Hi DavidR & Eddy,

Regular firefox and the tor browser has been updated to patch that hole.
Tor browser goes to version 6.0.7 and Firefox to version 50.0.2.

More info on Tor can be had here: https://blog.torproject.org/blog/tor-browser-607-released

polonus

Yes, just updating to 50.0.2 now.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4951 on: December 01, 2016, 07:16:08 AM »
Firefox SVG Animation Remote Code Execution (FF/FF ESR/TB)
https://www.mozilla.org/en-US/security/advisories/mfsa2016-92/
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4953 on: December 03, 2016, 12:32:00 PM »
6700 webshops infested with Magento mage.jpg malware:
https://gwillem.gitlab.io/2016/12/01/visbot-malware-on-6691-stores-analysis/

Re: http://www.snapfast.com/blog/magento-mage-jpg-hack/
Infested webshops use Magento and have not installed a vital security update: https://www.security.nl/posting/448375/Magento%3A+gehackte+websites+hebben+update+niet+ge%C3%AFnstalleerd

More on visbot: https://www.bleepingcomputer.com/news/security/visbot-malware-found-on-6-691-magento-online-stores/

A creditcard with rotating CVV code seems the best protection scheme against such hard to detect malware.
High time for high tech cards to be rolled out.

polonus

P.S. Magento shop owners can scan here: https://www.magereport.com/
(info cedits go out to Willem de Groot)
« Last Edit: December 03, 2016, 01:10:38 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
« Last Edit: December 04, 2016, 01:48:06 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4955 on: December 04, 2016, 03:11:53 AM »
Sh... IoT just got real: Mirai botnet attacks targeting multiple ISPs
http://www.theregister.co.uk/2016/12/02/broadband_mirai_takedown_analysis/

Shamoon malware returns to again wipe Saudi-owned computers
http://www.theregister.co.uk/2016/12/02/accused_iranian_disk_wiper_returns_to_destroy_saudi_orgs_agencies/
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4956 on: December 04, 2016, 06:08:28 PM »
Avast Releases Four Free Ransomware Decryptors
https://blog.avast.com/avast-releases-four-free-ransomware-decryptors



Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4957 on: December 06, 2016, 01:20:00 PM »
Google's Invisible CAPTCHA coming to a site near you!

: https://www.google.com/recaptcha/intro/comingsoon/invisible.html

More security through obscurity or meant as an advanced surveillance threat for the anonymous tor-user?
Hiding the captcha vault in plain sight, how long will it last before they have to think of something new?

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48552
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4958 on: December 06, 2016, 01:39:32 PM »
Google's Invisible CAPTCHA coming to a site near you!

: https://www.google.com/recaptcha/intro/comingsoon/invisible.html

More security through obscurity or meant as an advanced surveillance threat for the anonymous tor-user?
Hiding the captcha vault in plain sight, how long will it last before they have to think of something new?

polonus
Is there something wrong with making it easier for the average user while making it harder on the bad guys ???
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4959 on: December 06, 2016, 02:11:58 PM »
Not all users of the tor browser are bad guys, there are some very legit reasons to be using tor
(foreign journalists use it, you may use it when you do not want your insurance know about your searches
that will set your hospital bills unreasonably high).

To-day the mere reason that people use tor makes them suspect of doing something bad. To-day often one is guilty until one has proven oneself to be innocent. Strange Napoleontic interpretation of the law where one was innocent until proven guilty (tax laws exempt).

Funny is that it is always the not so bright tor-user that comes caught. The ones that do not follow the no javascript enable rule, that will use extensions to better set them out through their browser fingerprint. So the not so bright baddies are caught and rigthfully so.
You always should use tor within the frameworks of the law. I do not use it, but if I used it only as a law-abiding citizen and for legit reasons.

But I can imagine situations where people want some extra anonimity with tor.

polonus
« Last Edit: December 06, 2016, 05:25:52 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4960 on: December 07, 2016, 03:33:19 AM »
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4961 on: December 07, 2016, 03:35:50 AM »
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4962 on: December 08, 2016, 12:34:20 AM »
IoT dolls spy on children or feed them with ad messages:
http://www.forbrukerradet.no/siste-nytt/connected-toys-violate-consumer-laws

You do not want to have your children being exposed to this,
and these invaders of your child's privacy should at least be punished for turning children into products.

What kind of parents allow their children to have such toys?

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4963 on: December 08, 2016, 09:27:22 AM »
Dailymotion admits hack exposed millions of accounts
http://www.zdnet.com/article/dailymotion-hack-exposes-millions-of-accounts/
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89033
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4964 on: December 08, 2016, 11:17:48 AM »
Dailymotion admits hack exposed millions of accounts
http://www.zdnet.com/article/dailymotion-hack-exposes-millions-of-accounts/

The only time that these companies are going to take responsibility for securing their systems (and customer data), is when they start getting heavy fines/punitive damages.

Currently there is no incentive for them to spend money securing their systems.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security