PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

DNS-Hijacking Malware Targeting iOS, Android and Desktop Users Worldwide

lundi 21 mai 2018 à 16:57
Widespread routers' DNS hijacking malware that recently found targeting Android devices has now been upgraded its capabilities to target iOS devices as well as desktop users. Dubbed Roaming Mantis, the malware was initially found hijacking Internet routers last month to distribute Android banking malware designed to steal users' login credentials and the secret code for two-factor

Nethammer—Exploiting DRAM Rowhammer Bug Through Network Requests

jeudi 17 mai 2018 à 11:54
Last week, we reported about the first network-based remote Rowhammer attack, dubbed Throwhammer, which involves the exploitation a known vulnerability in DRAM through network cards using remote direct memory access (RDMA) channels. However, a separate team of security researchers has now demonstrated a second network-based remote Rowhammer technique that can be used to attack systems using

Another severe flaw in Signal desktop app lets hackers steal your chats in plaintext

mercredi 16 mai 2018 à 16:14
For the second time in less than a week, users of the popular end-to-end encrypted Signal messaging app have to update their desktop applications once again to patch another severe code injection vulnerability. Discovered yesterday by the same team of security researchers, the newly discovered vulnerability poses the same threat as the previous one, allowing remote attackers to inject

Red Hat Linux DHCP Client Found Vulnerable to Command Injection Attacks

mardi 15 mai 2018 à 22:31
A Google security researcher has discovered a critical remote command injection vulnerability in the DHCP client implementation of Red Hat Linux and its derivatives like Fedora operating system. The vulnerability, tracked as CVE-2018-1111, could allow attackers to execute arbitrary commands with root privileges on targeted systems. Whenever your system joins a network, it’s the DHCP client

Hackers Reveal How Code Injection Attack Works in Signal Messaging App

lundi 14 mai 2018 à 23:37
After the revelation of the eFail attack details, it's time to reveal how the recently reported code injection vulnerability in the popular end-to-end encrypted Signal messaging app works. As we reported last weekend, Signal has patched its messaging app for Windows and Linux that suffered a code injection vulnerability discovered and reported by a team of white-hat hackers from Argentina. <!