Sophisticated WhatsApp Malware Spam uses geo location, customized filename and much more

WhatsApp is one of the widely used messaging platform in the recent days having both mobile and desktop app versions.  Its been normal to see spam voicemail messages from spammers which goes directly to spam folder. However some do escape the spam folder very easily and ends up in users hands.  The fate of the […]
Share Button
Continue reading →

Remote code-execution vulnerability on Ebay website discovered by a Pentester

A security pen tester from Germany @secalert discovered remote code execution vulnerability on ebay website. As per David Vieira-Kurtz blog , “I found a controller which was prone to remote-code-execution due to a type-cast issue in combination with complex curly syntax. ”   David exploited the RCE flaw on ebay.com website and displayed output of phpinfo() […]
Share Button
Continue reading →

Apps on Unpatched Android 4.3 can Remove Device Locks from Android Phone – Curesec Research Team – CVE-2013-6271

Recently Google introduced a remote Device locking feature  to  its Android Device Manager to unlock a stolen or lost device. This feature was exploited Researchers from Curesec Research Team from Germany discovered a vulnerability on Android 4.3 that allow a malicious app to remove device locks.leading to CVE 2013-6271. As per the blog, “ The bug […]
Share Button
Continue reading →

Digital Attack Map – New data visualization DDOS tool from Google Ideas and Arbor Networks (www.digitalattackmap.com)

Visualizing cyber attacks around the world has become easier than before and its made real by Google & Arbor Networks.  A joint collaboration between the two companies resulted in ‘Digital Attack map” tool. The usability of the tool is not still expanded but the beautiful graphical page shows various points of ho the attack takes […]
Share Button
Continue reading →

Mobile Malware Threats Q3 2013 – F-Secure

As per F-Secure labs, 259 new mobile threat families and variants of existing families were discovered in the third quarter of 2013. The growing concern in Google Play are the apps that violate privacy by over collection of data.  Screenshots from below from F-Secure reports shows the threats.                 […]
Share Button
Continue reading →

iOS 7 release causing Apple DDoS — Well kidding

iOS 7 release was a major news for Apple users. Its unbelievable to see how many users want the cool new Operating system.  This is always the fun part every year when something new comes from Apple. This time its for the new powerful Apple iOS7 release on September 18th. As reported on SANS, the […]
Share Button
Continue reading →

Internet Explorer zero-day exploit makes all versions of Internet Explorer vulnerable – Security advisory 2887505

Microsoft releases Security advisory 2887505 which infected all versions of Internet Explorer.  Currently based on Microsoft’s observation all targeted attacks directed for Internet Explorer 8 and 9. As per Microsoft “ This issue could allow remote code execution if an affected system browses to a website containing malicious content directed towards the specific browser type. […]
Share Button
Continue reading →

Android Firefox Zero day exploit up for sale by a Russian Hacker

A underground hacker from Russia with handle ‘fil9”  posted a zero day android exploit for sale. (screenshot below) This zero day exploit works on Firefox 23/24/26 as claimed by the author. Joshua from Malwarebytes spotted this advertisement on Inj3ct0r, an exploit database, where the author was selling the zero day for $460 Us dollars. As […]
Share Button
Continue reading →

How much risk is Apple’s new fingerprint authentication on the new IPhone 5s ?

We have seen fingerprint reader, face recognition authentication for a while. Smartphone manufacturers have been rumoring about this and Apple finally introduces it. Apple announced their new IPhone 5s  with fingerprint reader yesterday.  It’s a cool factor to have fingerprint instead of the password or pattern based authentication. Apple claims that fingerprint is stored local […]
Share Button
Continue reading →

L.A. Times Hit By massive Malvertising Campaign

Maladvertisers targeted L.A. Times sending its thousands of users to Blackhole exploit kit and other malicious sites. Security researcher’s from Blue Coat have discovered a set of malicious domains sending traffic to the searcherstypediscksruns dot com/.net/.org family of Blackhole sites, including adhidclick.com, ortclick.com and several other affiliated sites. These sites were registered During December 2012 […]
Share Button
Continue reading →