Times of India website vulnerable to Cross Site Scripting (XSS) attacks

Times of India which operates a website called indiatimes.com is a top news website in India and elsewhere. This ranks the Times of India as the top English daily in India by readership. It can be used by attackers to bypass access controls such as the same origin policy (SOP). He has found that the vulnerability occurs at Indiatimess URL links. Indiatimes only party filters the filenames in its website....

December 1, 2014 · 1 min · 105 words · Shawn Wilson

Updated: Honda’s verified Twitter Account hacked by Skeletor

The description of Skeletor is given by the hacker as follows : It is I, Skeletor! Master of the Universe, Internet, and now Hondas Twitter Account! Prepare to experience my evil in 140 characters or less!! Proof that Honda owned the internet yesterday. This was the tweet that Honda made after revealing that it was a promo campaign And were back! source: www.techworm.net

December 1, 2014 · 1 min · 63 words · Kristen Montgomery

Creator of Facebook, Mark Zuckerberg is unblockable

The blocking system is overloaded just wait a few minutes and loop back and try. This error isnt specific to any one account. Its generated when a person has been blocked a certain large number of times. The purpose of this system is to protect the experience for people targeted by these campaigns. Were constantly working to improve our systems and are taking a closer look at this one. source: www....

November 30, 2014 · 1 min · 71 words · Jessica Ward

AnonGhost to use Remote Code Execution malware in future hack attacks : Zsclaler Research

However this may not hold true in not so distant future according to the security experts from Zscaler. .This flaw is already being exploited by a cyber criminal group calledAPT3 aka UPS. Zscaler notes that AnonGhost may use this very flaw with Dokta Chef Exploit Kit. obfuscated data found by Zscaler in recent AnonGhost hacks This can cause remote code execution if the victim visits a specially crafted webpage using Internet Explorer....

November 28, 2014 · 1 min · 83 words · Karen Kennedy

Black Friday : Android Tablets selling on Walmart, elsewhere shipping with major security flaws

What seemed like great bargains turned out to be big security concerns. Maybe a case of bottomline coming before the buyers security! ! source: www.techworm.net

November 28, 2014 · 1 min · 25 words · Caitlin Griffith

Globe Website Hacked, Poor internet service is not worth what is paid, Hacker Says

4 of its subdomains were defaced by Filipino hackers using the online handle BloodSec International. Do something or expect the consequence. This is just the beginning. the message on the deface page read followed with All your Data Belongs to Us Now. Globe later confirmed that mybusiness.globe.com.ph, payroll.globe-csme.com, duointernational.globe-csme.com, and update.globe-csme.com, were defaced. all hosted by a third party hosting provider. said Globe Chief Information Security Officer Anton Bonifacio. source: www....

November 28, 2014 · 1 min · 71 words · Bradley Barnett

Uber’s Android app caught reporting data back without permission

Gods View Tool at work, Ubers Android app caught reporting data back without permission. All this is being done when Uber doesnt have yourexplicit permission to do so. GironSec has illustrated how Uber is reporting all this user confidential data back to the base. GironSec has torn apart the Uber Android App but he has not published much about Ubers iPhone App. Gods View Tool eh? source: www.techworm.net

November 28, 2014 · 1 min · 68 words · Phillip Hicks DDS

DareDevil PoS Malware, Infects Ticket Machines and Electronic Kiosks

Veiled Threat The malware has been disguised as a legitimate process, making it difficult to track. The malware hasnt been kept limited to POS systems. It is also attacking mass transit systems as well as ATM machines. The attackers might have believed that they can stay on for longer in these systems. Another use, experts believe, is to allow itself to add more features to itself in the future. Research in hindsight of the discovery of daredevil has busted this myth....

November 27, 2014 · 1 min · 83 words · Karen Garner

Syrian Electronic Army hacks several websites, Forbes, Ferrari, Independent, Daily Telegraph and many other websites hijacked

The Syrian pro-Assad hacktivist group today hacked and downed many media website mostly from United Kingdom. The hack came at wee hours of Thursday but was well coordinated attack one. A part of our website run by a third-party was compromised earlier today. We’ve removed the component. No Telegraph user data was affected. Gigiya It seems like the SEA struck popular social login service Gigya. Gigiya is a popular customer identity management platform provider for many of the websites hacked by SEA....

November 27, 2014 · 2 min · 220 words · Joan Gray

BT and Sky blocking private torrent sites, without a court order

PTorrents and Torrentday are significant targets because they are private torrents. IPTorrents though is still accessible via its alternate .ru and .me domains. VPNs and proxy servers are also ways to reach the site for BTs users. source: www.techworm.net

November 26, 2014 · 1 min · 39 words · Jonathan Burnett

Developers turn to crimeware and release DroidJack RAT after their Android App failed

But the App apparently did not catch the fancy of Android users and faded into obscurity. The ad, redirected the user to the app on the Play Store. However, SandroRAT is far from dead and buried. Sandroid in its original avatar on Google Play DroidJack is sold on its own website for $210, the cost of a lifetime package. Capabilities DroidJack has similar features to other Android RATs, such as AndroRAT and Dendroid....

November 26, 2014 · 1 min · 145 words · Christine Smith

Google releases Devices and Activity App for enhanced security and frees Zix Encryption

Customers can utilize the wizard to provide account recovery information, and review permissions and activity on the account. Security key Security Key is a security mechanism released by Google in the month of October. A Redditor,makebaconpancakesseems to have noticed it 15 days ago. In fact, a redditor commented that he had paid $16000.00 for Zix just a week ago. BMOD provides transparent encryption among all ZixCorp customers as well as two different keyless delivery methods for other recipients....

November 26, 2014 · 1 min · 90 words · Rebecca Jackson

Regin – the ‘New Stuxnet’ state sponsored espionage tool

Its design makes it highly suited for persistent, long term surveillance operations against targets, the researchers wrote. Regins talented authors encrypted data blobs after the stage one vector. There are also seperate version for 32 bit and 64bit machines. A driver with an innocuous name of pciclass.sys seemed to be causing the crashes. One of those layers gives attackers the means to penetrate and monitor GSM base station controllers. Kaspersky researchers have noticed that Regin had targeted GSM networks also....

November 25, 2014 · 1 min · 111 words · Nathan Santana