Critical Git Vulnerability Allows for Remote Code Execution

The vulnerability is client-based, meaning that neither GitHub.com nor GitHub Enterprises are directly affected. Users of GitHub are advised to upgrade their clients as soon as possible to stay safe. GitHub has released updated version for itsGitHub for WindowsandGitHub for Macclients. you’ve got the option to refresh your respective clients by clicking on the respective hyperlinks. Both the updates patch the vulnerability on the client systems, including the desktop tool and the command-line counterpart....

December 20, 2014 · 1 min · 89 words · Karen Blake

Instagram purge of spam followers causes woes for most followed celebs

Instagram took up a program of culling fake Instagram accounts on 18th December. ChiragChirag78 took it rather to his heart and deleted his Instagram account. From furious to comic, the Twitterati made their anger known to Instagram through Twitter. Here are a few samples of the tweets. Akon loses 56% of his. I was a half-a-million kinda guy up ‘til today… NOW I AM NOTHING! source: www.techworm.net

December 20, 2014 · 1 min · 67 words · Michael Wall

Staples goes bare : 1.1 Million Cards Exposed in Data Breach

Upon detection of the malware, Staples claims to have taken immidiate action to eradicate the threat. To this means, it has also been working with external security experts. For more information about the report, you’re able to accessStaples report. source: www.techworm.net

December 20, 2014 · 1 min · 41 words · Ariel Taylor

Tor warns against possible attacks to disable its anonymiser network

Directory authorities is what Tor clients use to learn about the relays that constitute the entire Tor online grid. The wide range of Tor users are secure, for now. (Directory authorities help Tor clients learn the list of relays that make up the Tor internet.) Tor remains safe to use.We hope that this attack doesnt occur; Tor is used by many good people. This right is a foundation of a democratic society....

December 20, 2014 · 1 min · 85 words · Caitlyn Jones

12 million office/home routers vulnerable to ‘Misfortune Cookie’ attacks

The vulnerability has dubbed as Misfortune Cookie byCheck Point researchersand designated as CVE-2014-9222 by NVD maintained by NIST. No hacking tools required, just a simple modern net web client. The flaw has existed since 2002 in the embedded web server RomPager made by a tech firm called AllegroSoft. you’re free to view the complete list of deviceshere(PDF). Funnily cheaper and relicensed models feature prominently in the list. The researchers have stated that they do not believe it to be an intentionally included backdoor for security agencies....

December 19, 2014 · 1 min · 88 words · Shane Raymond

ISIS deploys malware to hunt down its protester and opposition groups

The sole purpose of this malware seems to be to expose the anti-ISIS groups or people and annihilate them. The message body contains a URL and tell the receiver to check about the reports of ISIS. The email being sent to the rebels is given below ? ? ? ??? ? ? ??? ? ? ???? ? ? ???? ? ? ??? ? ? ??? ? ? ???? ? ?...

December 19, 2014 · 1 min · 177 words · Heather Williamson

ISOHunt plans to swarm the internet with Pirate Bay copies by releasing The Open Bay

ISOhunt.to crew which had brought the oldpiratebay.org to users last week. has decided to swarm the internet with copies of TPB with The Open Bay initiative. We, the team that brought you Isohunt.to and oldpiratebay.org are bringing you the next step in torrent evolution. Open Pirate Bay source code, Isohunt.to says. We want to change the torrent landscape which has been frozen for 10 years. We need to push it ahead, Isohunt....

December 19, 2014 · 1 min · 75 words · Michael Cross

Newly discovered flaw could allow anyone in the world to listen in on your phone calls

Unfortunately, this vulnerability exists in protocol used by every data pipe provider across the globe. SS7 is the current iteration of the protocol in use. The flaws in question, are actually exploit the functionalities of the protocol which have been baked into SS7. There is also a probability of an attacker using these functions to carry out fraudulent activities. Thus, an attacker can access cell phone calls of an American citizen while sitting far away in China....

December 19, 2014 · 2 min · 275 words · Jose Ruiz

Online Payment Platform Payza’s Blog Hacked, Users Credentials May Have Been Compromised

Payza Payza (formerly AlertPay) is an Internet payment system similar to Paypal. It allows users to transfer money between accounts by using email addresses for a fee. Payza is particularly popular amongst its users because it allows Bitcoin transfers in addition to other world currencies. Payza has tweeted that the user details of Payza blog are not connected to the financial vertical of Payza. in reply to a tweeters query....

December 19, 2014 · 1 min · 72 words · Jason Bryan

Privilege Escalation Vulnerability in Linux #CVE-2014-9322

After notification of CVE-2014-9090, Borislav Petkov pointed out to Lutomirski some further flaws that existed even after vulnerability. Lutomirski has stated that the fix which was released for CVE-2014-9090 also patches CVE-2014-9322. If a user is a member of the wheel group, they are authorized by definition. Obviously you shouldnt give non-trusted users wheel privileges. This is a non-issue. source: www.techworm.net

December 19, 2014 · 1 min · 61 words · Angelica Ross

USBDriveby : Using $20 Teensy 3.1 USB to hijack the Mac OS X PC

Once connected, it can be used to carry out any operation on the target computer. The devices can simply begin typing and clicking. They called the attack BadUSB. The method developed was much more sophisticated compared to USBdriveby. However, they did not release thesource code until September. source: www.techworm.net

December 19, 2014 · 1 min · 49 words · Kaylee Reed

After Website, The Pirate Bay Facebook Page with Half Million Likes is Shut Down

From yesterday, the TPB Facebook page was shut down. source: www.techworm.net

December 18, 2014 · 1 min · 11 words · Jacqueline Vaughn

Banking Trojans use Pinterest as Command and Control channel for targeting South Korean Banks

However this is the first time that a Trojan has been found to use Pinterest to spread itself. TPSY_BANKER,YYSI The trojan identified in this attack is dubbed as TSPY_BANKER.YYSI. TSPY_BANKER.YYSI trojan is also targeting popular South Korean search engine visitors. Resource :TrendMicro Labs. source: www.techworm.net

December 18, 2014 · 1 min · 45 words · William Ross