Get FREE threat intelligence on hackers and exploits with the Recorded Future Cyber Daily

Get trending info on hackers, exploits, and vulnerabilities every day for FREE with the Recorded Future Cyber Daily [Sponsor]

Graham Cluley Security News is sponsored this week by the folks at Recorded Future. Thanks to the great team there for their support!

Recorded Future provides deep, detailed insight into emerging threats by automatically collecting, analyzing, and organizing billions of data points from the Web.

And now, with its FREE Cyber Daily email all IT security professionals can access information about the top trending threat indicators – helping you use threat intelligence to help make better decisions quickly and easily.

Which means that you will be able to benefit from a daily update of the following:

  • Information Security Headlines: Top trending news stories.
  • Top Targeted Industries: Companies targeted by cyber attacks, grouped by their industries.
  • Top Hackers: Organizations and people recognized as hackers by Recorded Future.
  • Top Exploited Vulnerabilities: Identified vulnerabilities with language indicating malcode activity. These language indicators range from security research (“reverse engineering,” “proof of concept”) to malicious exploitation (“exploited in the wild,” “weaponized”).
  • Top Vulnerabilities: Identified vulnerabilities that generated significant amounts of event reporting, useful for general vulnerability management.

Infosec professionals agree that the Cyber Daily is an essential tool:

“I look forward to the Cyber Daily update email every morning to start my day. It’s timely and exact, with a quick overview of emerging threats and vulnerabilities. For organizations looking to strengthen their security program with threat intelligence, Recorded Future’s Cyber Daily is the perfect first step that helps to prioritize security actions.” – Tom Doyle, CIO at EBI Consulting.

So, what are you waiting for?

Sign up for the Cyber Daily today, and starting tomorrow you’ll receive the top trending threat indicators.


If you’re interested in exclusively sponsoring my site for a week, and reaching an IT-savvy audience that cares about computer security, you can find more information here.

Continue reading Get FREE threat intelligence on hackers and exploits with the Recorded Future Cyber Daily→

Happy ending for Pornhub after vulnerability researchers gain access to entire user database

The Register reports:

A trio of hackers have gained remote code execution powers on servers used by adult entertainment outlet Pornhub, using a complex hack that revealed twin zero day flaws in PHP.

Google sofware intern and security boffin Ruslan Habalov (@evonide) detailed the Return Orientated Programming hack in detailed debriefing explaining how he and fellow hackers @_cutz and Dario Weißer @haxonaut gained access to the entire Pornhub database including sensitive user information.

Regular readers will recall that earlier this year Pornhub announced its bug bounty program, asking vulnerability researchers to help harden its security.

The researcher threesome rose to the challenge, and earned themselves a tasty US $20,000 from Pornhub for their efforts. The Internet Bug Bounty threw an extra US $2,000 into the mix for the discovery of the PHP zero-day vulnerabilities.

In the wrong hands, vulnerabilities like these could have caused enormous damage to the x-rated website and its many clandestine users, as well as potentially other sites too.

So, a happy ending all round.

Continue reading Happy ending for Pornhub after vulnerability researchers gain access to entire user database→

Police 3D print murder victim’s finger to unlock his phone

Fusion reports:

A man was murdered, and the police think there might be clues to who murdered him stored in his phone. But they can’t get access to the phone without his fingerprint or passcode. So instead of asking the company that made the phone to grant them access, they’re going another route: having the Jain lab create a 3D printed replica of the victim’s fingers. With them, they hope to unlock the phone.

The numerous media reports I’ve read about this case don’t mention what type of smartphone the police are trying to break into, but my hunch is that it’s an Android.

There are some big differences between how iOS and Android devices implement fingerprint authentication, and some of the design decisions Apple made make the scenario described above highly unlikely.

For instance, an iPhone or iPad will time out the fingerprint sensor every time the device is restarted or after 48 hours of inactivity, requiring you to enter your passcode instead.

However, on Android 4.4 – 5.1.1 the fingerprint unlock *never* expires. Even with Android 6.0 Marshmallow, which adds an official fingerprint authentication API for the first time, I don’t believe there are any set requirements for when the fingerprint unlock should expire.

It seems to me that fingerprint security has been pretty sloppy generally on Android, with some smartphones even storing unencrypted images of users’ fingerprints in a non-protected folder.

Continue reading Police 3D print murder victim’s finger to unlock his phone→

Edward Snowden’s new case design detects if your iPhone is broadcasting its location

NSA whistleblower Edward Snowden has teamed up with hardware hacker Andrew “Bunnie” Huang to design an iPhone accessory that could help protect journalists working in dangerous parts of the world.
Read more in my article on the Hot for Security blog.
Continue reading Edward Snowden’s new case design detects if your iPhone is broadcasting its location→

When the people selling you IT security solutions hack into their rival’s database…

The Register reports:
Five men working at UK-based IT security reseller Quadsys confessed today to hacking into a rival’s database.
Owner Paul Streeter, managing director Paul Cox, director Alistair Barnard, account manager Steve Davies and security co… Continue reading When the people selling you IT security solutions hack into their rival’s database…→

Turns out that you can’t trust ‘Trump free Wifi’ at the Republican National Congress

The cheeky japesters at Avast created a series of fake Wi-Fi networks at various locations around the Republican National Congress in Cleveland, as Silicon Angle reports:

Avast’s team set up several networks, using names such as “Trump free Wifi” or “Google Starbucks,” which were designed to look as though they were set up for convention attendees. Upon connecting, trusting a random and unprotected network they found in a public setting, the users unwittingly gave Avast access to spy on their devices.

Over the course of a day, Avast found over a thousand attendees that were completely negligent in their device’s security. Over 60 percent of the users who connected had their identity completely exposed, and slightly less than half of them checked their email or used messenger apps.

By the way, whether the SSID “Trump free Wifi” is supposed to represent a Wi-Fi that is “free of Trump”, or “free on behalf of Trump” is unclear to this writer. Your preference may vary.

Apparently some RNC attendees also used the fake Wi-Fi hotspots to access their umm.. Tinder and Grindr accounts. Oh, and about 5.1% of people who accessed the phony free Wi-Fi used it to play Pokémon Go.

I guess they wanted to mix the serious business of choosing a US presidential candidate with a little fun. Who can blame them?

You should always take care about what Wi-Fi hotspots you connect to, and use a VPN to help keep their sensitive information out of the hands of snoopers.

You can learn more about Avast’s findings in its press release.

Continue reading Turns out that you can’t trust ‘Trump free Wifi’ at the Republican National Congress→

Drupalgeddon hits Warframe – nearly 800,000 gamers’ account details being sold on the net

Are you a fan of Warframe?
Is so, Digital Extremes, the company behind the popular online game has some bad news for you.
Read more in my article on the Tripwire State of Security blog.
Continue reading Drupalgeddon hits Warframe – nearly 800,000 gamers’ account details being sold on the net→