Stories by Lucian Constantin

Anonymous publishes Israeli SCADA log-in details

A member of the Anonymous hacktivist collective has published a list of Internet-facing Israeli SCADA (supervisory control and data acquisition) systems and alleged log-in details.

Written by Lucian Constantin13 Jan. 12 04:14

Hash collision DoS vulnerability fixed in PHP 5.3.9

The PHP development team <a href="http://www.php.net/archive/2012.php#id2012-01-11-1">has released</a> version 5.3.9 of the popular Web development platform in order to address a recently disclosed denial-of-service (DoS) vulnerability, as well as other security issues and bugs.

Written by Lucian Constantin13 Jan. 12 01:26

Lawsuit claims Symantec sells scareware-like products

Symantec has been accused in a lawsuit of California's unfair competition laws and fraudulent inducement by using scareware-like tactics to trick users into buying licenses for its PC utility-type products.

Written by Lucian Constantin12 Jan. 12 05:29

Carrier IQ detection tool converted to premium SMS Trojan

Android malware writers are taking advantage of the controversy surrounding Carrier IQ's smartphone tracking software in order to distribute a premium SMS Trojan, security researchers from Symantec warn.

Written by Lucian Constantin12 Jan. 12 02:46

Attack code published for serious ASP.NET DoS vulnerability

Exploit code for a recently patched denial-of-service (DoS) vulnerability that affects Microsoft's ASP.NET Web development platform has been published online, therefore increasing the risk of potential attacks.

Written by Lucian Constantin11 Jan. 12 03:41

Industrial espionage gang sends malicious emails in security vendor's name

A cybercrime gang that primarily targets companies from the chemical industry has launched a new series of attacks that involve malware-laden emails purporting to be from Symantec, the security vendor responsible for exposing its operation earlier this year.

Written by Lucian Constantin14 Dec. 11 08:25

Two zero-day vulnerabilities found in Flash Player

Two newly discovered vulnerabilities in Adobe's Flash Player can be exploited to execute arbitrary code remotely, according to <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4694">advisories</a> from the U.S. Computer Emergency Readiness Team (US-CERT) and various security research companies.

Written by Lucian Constantin10 Dec. 11 04:05

Second-hand USB drives riddled with malware, Sophos finds

An analysis of USB memory sticks lost on trains in Sydney revealed that two thirds of them were infected with one or more strains of malware and none was secured with an encryption solution.

Written by Lucian Constantin08 Dec. 11 11:15

WikiLeaks: Security worries impede new submission system

WikiLeaks has postponed the launch of its new secure submission system due to recent security compromises that seriously affected the credibility of the SSL infrastructure.

Written by Lucian Constantin29 Nov. 11 23:55
[]