Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2904775 times)

0 Members and 14 Guests are viewing this topic.

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4995 on: December 23, 2016, 01:27:33 PM »
A Malware Cocktail Shakes Up Cerber Ransomware Infections
http://www.infosecurity-magazine.com/news/a-malware-cocktail-shakes-up/
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4996 on: December 23, 2016, 11:32:38 PM »

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48595
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4997 on: December 23, 2016, 11:45:31 PM »
Alice: A Lightweight, Compact, No-Nonsense ATM Malware
http://blog.trendmicro.com/trendlabs-security-intelligence/alice-lightweight-compact-no-nonsense-atm-malware/
Now here I thought you were talking about my wife Alice and all the ATM withdrawals she's been making lately ???
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4998 on: December 23, 2016, 11:55:00 PM »
hmmm, maybe this need further investigation    ;D


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4999 on: December 24, 2016, 01:35:21 AM »
Service worker javascript code changes bringing more extensive Google snoopin'to your chrome/newtab?
Read on these recent changes: https://www.reddit.com/r/javascript/comments/3n4cyz/suspicious_service_worker_in_chrome/

Why would they do that?

Maybe we have to consider this also in the light of having to hand over your Google account credentials before entering the USA,
this is the public side of it now: http://www.politico.com/story/2016/12/foreign-travelers-social-media-232930

Soon they also will perform such checks at this side of the Atlantic too, for instance at Amsterdam Schiphol airport in the Netherlands, will be handled by American officials.

Being on social media is not that innocent, folks.
Mind the spooks....

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5000 on: December 26, 2016, 06:44:23 AM »
New DeriaLock Ransomware Active on Christmas, Includes An 'Unlock All' Command
https://www.bleepingcomputer.com/news/security/new-derialock-ransomware-active-on-christmas-includes-an-unlock-all-command/
Hope avast is ready...... ;)
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5001 on: December 26, 2016, 05:50:45 PM »
Protection against malicious Word-macro's using Windows Firewall:

https://limpidwebblog.blogspot.com/2016/10/a-shower-leads-to-powershell-puking.html

PowerShell will come to Windows 10 shortly for the command prompt interpreter.

A bash-shell in beta has also arrivedl:
http://www.howtogeek.com/249966/how-to-install-and-use-the-linux-bash-shell-on-windows-10/

Having been around for years and offering far more is cygwin, with editors, compilers, database clients, etc. You could even choose to install the X server to get an X Windows graphical user interface. In this way you can run graphical Linux: programs:https://www.cygwin.com

All for the anvanced user, but others may try as well.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5003 on: December 28, 2016, 01:50:58 PM »
Hi Pondus beaten me to it by a sec  ;)

N.B. Big zero-day hole in WordPress PHP Mailer: https://www.wordfence.com/blog/2016/12/phpmailer-vulnerability/
Critical Vulnerability in PHPMailer. Affects WP Core [1]

Millions and millions of websites vulnerable.

A critical remote code execution vulnerability in PHPMailer has been discovered by Polish researcher Dawid Golunski. The vulnerability was announced on legalhackers.com yesterday but proof of concept exploit details were not included.

Unfortunately someone posted a proof of concept to exploit-db and to github a few hours ago demonstrating how the vulnerability can be exploited in the PHPMailer library, but not targeting any web application that is in use.

We are publishing this unscheduled update to give PHP developers and our community advance warning of this issue. We expect this story to continue to evolve rapidly as more developers and malicious actors look at this code.

An issue in WP core was opened about 4 hours ago that included a patch to fix this issue. It updates WP core from using PHPMailer 5.2.14 to 5.2.19. This is just a proposed patch, not the final fix.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5004 on: December 28, 2016, 01:53:21 PM »
Evolved DNSChanger malware slings evil ads at PCs, hijacks routers

Software nasty is packed with exploits for vulnerabilities in home broadband boxes
http://www.theregister.co.uk/2016/12/20/new_dnschanger_exploit_kit_goes_after_166_types_of_router/


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5005 on: December 28, 2016, 02:01:44 PM »
Update...

Since an hour there is a patched update for WP core: https://github.com/PHPMailer/PHPMailer/blob/master/class.phpmailer.php
All are asked to update to version 5.2.19.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5007 on: January 03, 2017, 01:31:45 PM »
This man's smart television with Google TV caught some malware, and now it's bricked
http://www.androidpolice.com/2016/12/27/smart-mans-smart-television-google-tv-caught-malware-now-bricked/


Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89131
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5008 on: January 03, 2017, 03:08:19 PM »
This man's smart television with Google TV caught some malware, and now it's bricked
http://www.androidpolice.com/2016/12/27/smart-mans-smart-television-google-tv-caught-malware-now-bricked/

What I have been banging on about Smart TV for some time, pigeons coming home to roost.

I'm waiting for the IoT (Internet of Things) coming down with the same hijack/malware issues. Imagine your fridge locking you out or ordering stuff for itself, fridge light, heater and TV.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48595
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5009 on: January 03, 2017, 03:10:11 PM »
This man's smart television with Google TV caught some malware, and now it's bricked
http://www.androidpolice.com/2016/12/27/smart-mans-smart-television-google-tv-caught-malware-now-bricked/
It has already been un-bricked. :)
(Read the relies.)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet