Showing posts with label Exploit. Show all posts
Showing posts with label Exploit. Show all posts

Tuesday, March 4, 2014

[infosecurity-magazine] Neutrino Exploit Kit Up For Sale

The (Russian) Neutrino exploit kit was first described by the French researcher Kafeine (Malware don't need Coffee) almost exactly one year ago. "A new exploit kit is being advertised since yesterday on underground forum : Neutrino," he announced. Now it is for sale.

Thursday, February 27, 2014

[fireeye] Amazon’s Mobile Shopping Clients and CAPTCHA

Amazon is a popular online retailer serving millions of users. Unfortunately, FireEye mobile security researchers have found security issues within Amazon’s mobile apps on both Android and iOS platforms through which attackers can crack the passwords of target Amazon accounts. Amazon confirmed our findings and hot fixed the issue. 

Saturday, February 8, 2014

[CrowdStrike] Analysis of a CVE-2013-3906 Exploit

Dec 10, 2013 | Jason Geffner, Sr. Security Researcher
Many of CrowdStrike’s customers are often targeted by email phishing campaigns and strategic web compromises (also known as watering-hole attacks). These attacks use exploits to take advantage of vulnerable unpatched software installed on the victim’s computer. If an exploit is successful, then it will run an attacker’s payload, which will typically install malware bundled with the exploit itself and/or download malware from a remote server.