For well over a decade our focus at ionCube has been on PHP security but recently with the release of ionCube24 we have been looking into different kinds of vulnerabilities. This post has a few of the interesting issues we have found this week.
A selection of this week’s more interesting vulnerbility disclosures and cyber security news.
General
- Security firm sued for filing woefully inadequate forensics report (ArsTechnica)
- Shop online at Asda? Website vuln created account hijack risk (The Register)
- Spamming Someone from PayPal (Schneier blog)
- Trend Micro password manager had remote command execution holes and dumped data to anyone: Project Zero (ZDNet)
- Trustwave failed to spot casino hackers right under its nose lawsuit (The Register)
- Ukraine energy utilities attacked again with open source Trojan backdoor (The Register)
- Google confirms new Linux hole not a big deal for Android (ZDNet)
- How to fix the latest Linux and Android zero day flaw (ZDNet)
- Linux Kernel Flaw Puts Millions of Devices at Risk
- Samsung sued over ‘lackadaisical’ Android security updates (The Register)
- Zero-Day Flaw Found in Linux (InfoRiskToday)
Malware
Weekly Cyber Security News 22/01/2016