ScoreSports.com hacked and compromised for 3 months, customer payment data stolen

This was announced by the owners of ScoreSports.com, SCORE. SCORE has been founded in 1975 and it is a family owned and operated business. It distributes youth and adult athletic apparel and equipment for soccer, basketball and baseball at factory direct prices. It is based in Anaheim Street in Wilmington, California U.S.A. Leaked data includes name, payment card account number, expiration date, and SCORE account number. SCORE also doesnt know how many of its customers data was actually compromised....

October 24, 2014 · 1 min · 145 words · Mark Hansen

Warsaw Stock Exchange hacked by ISIS cyber criminals?

The Website was officially unavailable for the brokers and investors between 2 pm and 4 pm Warsaw time. Its just a beginning of the FIGHT against those whore bombing our Homeland! A Polish websiteniebezpiecznik.plstated that the Warsaw Stock Exchange had confirmed the hack in a email to them. ISIS cyber criminals behind the attack? The paste as stated above says that the WSE was as a revenge against those whore bombing our Homeland!...

October 24, 2014 · 2 min · 235 words · Brenda Schmidt

Yahoo, AOL visitors impacted by Malware in Ads, Ransomware in Action

the Malware in action CryptoWall 2.0 ransomware impacted the visitors running a vulnerable/ unpatched version of Adobe Flash player. Using Adobe Flash, the malvertisements silently pull in malicious exploits from the FlashPack Exploit Kit. The exploits attack a vulnerability in the end-users web app and install CryptoWall 2.0 on end-users computers. List of domains which were affected along with their global Alexa rankings as given on proofpoint blog. These dynamic ads in turn were serving the CryptoWall to the the victims....

October 24, 2014 · 1 min · 83 words · Richard Powers

Google’s security key through USB takes 2-factor authentication to a whole new level

What is this Security Key ? With the new security key users wont face such kind of problem. Mobile users are suggested not to opt to this service. How do I get a Security Key? the devices are available for saleonline. Disadvantages of opting for the USB based Security Key. This issue has not been discussed at all. source: www.techworm.net

October 23, 2014 · 1 min · 60 words · Dawn Page

All Windows versions except Windows 2003 vulnerable to a new Sandworm exploit

US-CERT recommends users and administrators review theMicrosoft Security Advisoryand apply the recommended workarounds. Meanwhile in a separate report,McAfeehas said that this zero-day exploit is a part of theSandworm. The Operation Sandworm was discovered by iSIGHT Partners and allocated CVE-2014-4114. However, Microsoft apparently botched up the patch released for the original Operation Sandworm zero-day exploit, the CVE-2014-4114. The botch up revealed another zero-day which is now identified as CVE-2014-6352. In other words, attackers might still be able to exploit the vulnerability even after the patch is applied....

October 22, 2014 · 1 min · 112 words · Nicole Woods

Apple issues security fix for its iCloud users amidst reports of MitM hacking in China

Chinese censorship monitoring group, GreatFire tweeted the following, post the release of fix by Apple. Apple changedhttps://t.co/ntNAO3GHrsDNS in China to avoid MITM. The attacked 23.59.94.46 is no longer used. But will GFW attack new IP? GreatFire.org (@GreatFireChina)October 21, 2014 Chinese Government behind the hack ? Chinese Foreign Ministry spokeswoman Hua Chunying said that China is resolutely opposed to hacking. Why iCloud has been buzzing around the media. source: www.techworm.net

October 22, 2014 · 1 min · 69 words · Melissa Jones

iCloud Hacks leaks victim Madison Louch gets the blackmailing, hacker arrested

Later that day she got a call from a self claiming hacker who bragged he hacked her account. He told her he was notorious for hacking into the accounts of celebs and posting their NSFW photos online. The iCloud Hacks first surfaced on 31st August on the 4Chan image boarding site and later on Reddit forum. Madison panicked at the thought of her images being leaked. Realising that she may be swindled, she called up Los Angeles Police Department (LAPD)....

October 22, 2014 · 1 min · 170 words · Kimberly Bullock

Koler worm, the new variant is a Android devices Ransomware

The emergence of this worm was detected by AdaptiveMobile on on 19th Oct, 2014. This punch in of malware was first spotted in May this year blackmailing victims on Android devices. In July new reports suggested a new version that can also target PCs. Bitly is a URL shortening service which sends shortened links to user for the URLs. It has been used earlier for this kind of phishing attacks because of its innocuous looking link....

October 22, 2014 · 1 min · 156 words · Dustin Mckinney

PHP Bug allows Integer overflow in unserialize() PHP, Patch Released

Warning: Class __PHP_Incomplete_Class has no unserializer in /home/user/Desktop/poc.php on line 2 Program received signal SIGSEGV, Segmentation fault. source: www.techworm.net

October 22, 2014 · 1 min · 19 words · David Farmer

Be forewarned : Snappening Files may infect your device with Malwares

Some of the links contain sinister malware which can harm the victims computer and steal personal information. Computers been going nuts all day, one of the redditor said. source: www.techworm.net

October 21, 2014 · 1 min · 30 words · Chase Hudson

Researcher creates worm for Network-attached-storage (NAS) devices

He selected popular devices from 10 manufacturers and found that they were all were susceptible to root compromise. To his further indignation, he found that exploiting half of them did not require any authentication. What is a connection-attached-storage unit? It can serve a company, institution or even government. To prove his point, he has created a proof-of-concept worm that can infect devices from three different manufacturers. It then downloads and runs a binary copy of itself and begins scanning from the new rig....

October 21, 2014 · 1 min · 119 words · Mary Frye

Virginia Police Have Been Secretively Stockpiling Private Phone Records

All other information in the telephone calls database comes from mobile phones seized from any suspect during an arrest. The database of the calls records is also maintained in the city of Hampton. It is also said to contain the the contents of mobile devices seized during raids and arrests. The US law requires a special warrant signed and approved by the Foreign Intelligence Surveillance Court (FISC). Further there is a time limit for such kind of data to be saved....

October 21, 2014 · 1 min · 100 words · Chad Crawford

AngeCryption, a tool that can deliver Malware through Image or PDF file on Android

AngeCryption The researchers have named the creation as AngeCryption as it was conceived and created by Ange. AngeCryption has been made available as a Python script and you could visitGoogle Code. Demonstration AngeCryption was presented to the audience during the recently held BlackHat Europe in Amsterdam last week. The researchers said that 3DES can also be employed with the same success. However only packing the malware into image wont work as per the researchers....

October 20, 2014 · 1 min · 152 words · Elizabeth Anderson