-
EFF uncovers further evidence of SSL CA bad behavior
Certificate authorities have signed over 37,000 certificates that are not specific to any organization, they contain only a hostname
-
Popular open source DHCP program open to hack attacks
The makers of the internet's most popular open source DHCP program have warned that it's vulnerable to hacks that allow attackers to remotely execute malicious code on underlying machines.
The flaw, which is present in Internet Systems Consortium's DHCP versions prior to 3.1-ESV-R1, 4.1-ESV-R2, and 4.2.1-P1, stems from the program's failure to block commands that contain certain meta-characters. The vulnerability makes it possible for rogue servers on a targeted network to remotely execute malicious code on the client, the non-profit ISC warned on Tuesday. -
MPs criticise banks on online fraud despite declining losses
A House of Commons Treasury Select Committee report has criticised banks for failing their customers in the fight against online fraud.
Members of the influential committee criticised banks as being "unprepared" to deal with internet fraud as part of a wider study into retail banking, whose main conclusions called for greater transparency on charges and steps to make it easier for consumers to switch accounts. -
SpyEye mobile banking Trojan uses same tactics as ZeuS • The Register
Cybercrooks have deployed a sophisticated man-in-the-mobile attack using the SpyEye banking Trojan toolkit.
The Trojan, which infects Windows machines, displays additional content on a targeted European bank's webpage that requests prospective marks to input their mobile phone number and the IMEI of the device. The bank customer is informed the information is needed so that a new "digital certificate" can be sent to the phone. -
Hacking: CBI identifies US, Latvia portals, gets nod to collect info
-
Anatomy of an Attack « Speaking of Security – The RSA Blog and Podcast
-
www.crif.org defaced by participants in Anonymous’ #oppalestine
-
Millions of websites hit with mass-injection cyberattack | Security - InfoWorld
Commenti