The goal of this project is to make virtual world a safer and better place without child pornography, major computer crime and RIAA.
Login As
You can log in if you are registered at one of these services:
Security Bulletins
Latest Malware Updates

Infostealer.Posteal

02/26/2015

Downloader.Busadom

02/26/2015

Trojan.Ladocosm

02/26/2015

SONAR.SuspDocRun

02/25/2015

SONAR.SuspHelpRun

02/25/2015

A Windows zero-day might be exploited to conduct industrial espionage

A Windows zero-day might be exploited to conduct industrial espionage

Sophos experts have informed that a European aeronautical supplier's website is infected with virus that leverages CVE-2012-1889 vulnerability. This flaw was reported by Microsoft in the course of the June Patch Tuesday as a zero-day.

All operation systems supported by Microsoft, including Windows 7 are vulnerable to this flaw. CVE-2012-1889 can be exploited with a specially crafted web-page or a file, opened by Microsoft Office 2003 or Microsoft Office 2007 and allows hacker gain the same privilege on the system as the local user has. Vendor has not issued a patch for this vulnerability yet, but temporary workaround is accessible on the Microsoft Technet website.

Graham Cluley links this vulnerability with recent Google’s warnings about state-sponsored attacks. He considers that hackers could have embedded malicious file to the aeronautical supplier’s web-site to compromise computer systems of arms manufacturers or defense ministries who visit the resource.

“We know that a hacker who manages to plant malicious code on the website of, say, a company which supplies aeronautical parts may reasonably predict that staff at a larger organisation - such as an arms manufacturer or defence ministry - might have reason to access the site” Ц Cluley said

Graham Cluley’s post is accessible here.

(c) Naked Security


Security Advisories Database

Remote Code Execution Vulnerability in Microsoft OpenType Font Driver

A remote attacker can execute arbitrary code on the target system.

07/21/2015

SQL Injection Vulnerability in Piwigo

SQL inection vulnerability has been discovered in Piwigo.

02/05/2015

Cross-site Scripting Vulnerability in DotNetNuke

A cross-site scripting (XSS) vulnerability has been discovered in DotNetNuke.

02/05/2015

Cross-site Scripting Vulnerability in Hitachi Command Suite

A cross-site scripting vulnerability was found in Hitachi Command Suite.

02/02/2015

Denial of service vulnerability in FreeBSD SCTP RE_CONFIG Chunk Handling

An attacker can perform a denial of service attack.

01/30/2015

Denial of service vulnerability in Apache Traffic Server HTTP TRACE Max-Forwards

An attacker can perform a denial of service attack.

01/30/2015

Denial of service vulnerability in MalwareBytes Anti-Exploit "mbae.sys"

An attacker can perform a denial of service attack.

01/30/2015

Denial of service vulnerability in Linux Kernel splice

An attacker can perform a denial of service attack.

01/29/2015

Denial of service vulnerability in Python Pillow Module PNG Text Chunks Decompression

An attacker can perform a denial of service attack.

01/20/2015