Artwork

Treść dostarczona przez Paul Torgersen. Cała zawartość podcastów, w tym odcinki, grafika i opisy podcastów, jest przesyłana i udostępniana bezpośrednio przez Paul Torgersen lub jego partnera na platformie podcastów. Jeśli uważasz, że ktoś wykorzystuje Twoje dzieło chronione prawem autorskim bez Twojej zgody, możesz postępować zgodnie z procedurą opisaną tutaj https://pl.player.fm/legal.
Player FM - aplikacja do podcastów
Przejdź do trybu offline z Player FM !

Linux Root Malware, Gallium’s PingPull RAT, Guzzle Drupal Patch, and more.

2:46
 
Udostępnij
 

Archiwalne serie ("Kanał nieaktywny" status)

When? This feed was archived on May 25, 2023 16:09 (11M ago). Last successful fetch was on July 29, 2022 18:35 (1+ y ago)

Why? Kanał nieaktywny status. Nasze serwery nie otrzymały odpowiedzi od kanału przez zbyt długi czas.

What now? You might be able to find a more up-to-date version using the search function. This series will no longer be checked for updates. If you believe this to be in error, please check if the publisher's feed link below is valid and contact support to request the feed be restored or if you have any other concerns about this.

Manage episode 331612045 series 2478053
Treść dostarczona przez Paul Torgersen. Cała zawartość podcastów, w tym odcinki, grafika i opisy podcastów, jest przesyłana i udostępniana bezpośrednio przez Paul Torgersen lub jego partnera na platformie podcastów. Jeśli uważasz, że ktoś wykorzystuje Twoje dzieło chronione prawem autorskim bez Twojej zgody, możesz postępować zgodnie z procedurą opisaną tutaj https://pl.player.fm/legal.
A daily look at the relevant information security news from overnight - 14 June, 2022
Episode 244 - 14 June 2022
Linux Root Malware- https://www.bleepingcomputer.com/news/security/new-syslogk-linux-rootkit-uses-magic-packets-to-trigger-backdoor/
Gallium’s PingPull RAT -
https://www.theregister.com/2022/06/14/gallium-pingpull-rat/
Metasploit Upgrades- https://www.bleepingcomputer.com/news/security/metasploit-620-improves-credential-theft-smb-support-features-more/
Reach Out and GhostTouch Someone -
https://portswigger.net/daily-swig/ghosttouch-hackers-can-reach-your-phones-touchscreen-without-even-touching-it
Guzzle Drupal Patch -
https://threatpost.com/bluetooth-signals-track-smartphones/179937/
Hi, I’m Paul Torgersen. It’s Tuesday June 14th, 2022, and this is a look at the information security news from overnight.
From BleepingComputer.com
A new Linux rootkit malware named ‘Syslogk’ can force-load its modules into the Linux kernel, and hide directories and network traffic. It also loads a backdoor called Rekoobe, which lays dormant until specially crafted "magic packets" are used to wake it up. The malware is currently under heavy development.
From TheRegister.com:
The Gallium group, believed to be a Chinese state-sponsored team, has begun using an upgraded remote access trojan called PingPull, that is very difficult to detect. The group is also broadening its scope, adding financial service firms and government agencies to the telecoms companies it usually targets. Their geographic focus continues to be Asia, Southeast Asia, Europe and Africa,
From BleepingComputer.com:
​Metasploit 6.2.0 has been released with 138 new modules, 148 new improvements or features, and 156 bug fixes since version 6.1.0 was released almost a year ago. Great for the pen teasters. Unfortunately, also great for the threat actors that use it as well. Details in the article.
From PortSwigger.net:
Attacks on smartphones require physical access to the device and interactions with the touchscreen. Or at least they used to. According to new research an attack can execute taps and swipes on the phone’s screen from a distance of up to 40 millimeters. The attack, called GhostTouch, uses electromagnetic interference to manipulate the touchscreen and can initiate calls or even download malware.
And last today, from SecurityWeek.com
The Drupal team has released a moderately critical advisory for serious vulnerabilities in the third-party library Guzzle that handles HTTP requests and responses to external services, and can be exploited to remotely hijack Drupal-powered websites. The vulnerabilities do not affect Drupal core, but may affect some contributed projects or custom code on Drupal sites. Details and a link to the advisory in the article.
That’s all for me today. Have a great rest of your day. Like and subscribe, and until tomorrow, be safe out there.
  continue reading

221 odcinków

Artwork
iconUdostępnij
 

Archiwalne serie ("Kanał nieaktywny" status)

When? This feed was archived on May 25, 2023 16:09 (11M ago). Last successful fetch was on July 29, 2022 18:35 (1+ y ago)

Why? Kanał nieaktywny status. Nasze serwery nie otrzymały odpowiedzi od kanału przez zbyt długi czas.

What now? You might be able to find a more up-to-date version using the search function. This series will no longer be checked for updates. If you believe this to be in error, please check if the publisher's feed link below is valid and contact support to request the feed be restored or if you have any other concerns about this.

Manage episode 331612045 series 2478053
Treść dostarczona przez Paul Torgersen. Cała zawartość podcastów, w tym odcinki, grafika i opisy podcastów, jest przesyłana i udostępniana bezpośrednio przez Paul Torgersen lub jego partnera na platformie podcastów. Jeśli uważasz, że ktoś wykorzystuje Twoje dzieło chronione prawem autorskim bez Twojej zgody, możesz postępować zgodnie z procedurą opisaną tutaj https://pl.player.fm/legal.
A daily look at the relevant information security news from overnight - 14 June, 2022
Episode 244 - 14 June 2022
Linux Root Malware- https://www.bleepingcomputer.com/news/security/new-syslogk-linux-rootkit-uses-magic-packets-to-trigger-backdoor/
Gallium’s PingPull RAT -
https://www.theregister.com/2022/06/14/gallium-pingpull-rat/
Metasploit Upgrades- https://www.bleepingcomputer.com/news/security/metasploit-620-improves-credential-theft-smb-support-features-more/
Reach Out and GhostTouch Someone -
https://portswigger.net/daily-swig/ghosttouch-hackers-can-reach-your-phones-touchscreen-without-even-touching-it
Guzzle Drupal Patch -
https://threatpost.com/bluetooth-signals-track-smartphones/179937/
Hi, I’m Paul Torgersen. It’s Tuesday June 14th, 2022, and this is a look at the information security news from overnight.
From BleepingComputer.com
A new Linux rootkit malware named ‘Syslogk’ can force-load its modules into the Linux kernel, and hide directories and network traffic. It also loads a backdoor called Rekoobe, which lays dormant until specially crafted "magic packets" are used to wake it up. The malware is currently under heavy development.
From TheRegister.com:
The Gallium group, believed to be a Chinese state-sponsored team, has begun using an upgraded remote access trojan called PingPull, that is very difficult to detect. The group is also broadening its scope, adding financial service firms and government agencies to the telecoms companies it usually targets. Their geographic focus continues to be Asia, Southeast Asia, Europe and Africa,
From BleepingComputer.com:
​Metasploit 6.2.0 has been released with 138 new modules, 148 new improvements or features, and 156 bug fixes since version 6.1.0 was released almost a year ago. Great for the pen teasters. Unfortunately, also great for the threat actors that use it as well. Details in the article.
From PortSwigger.net:
Attacks on smartphones require physical access to the device and interactions with the touchscreen. Or at least they used to. According to new research an attack can execute taps and swipes on the phone’s screen from a distance of up to 40 millimeters. The attack, called GhostTouch, uses electromagnetic interference to manipulate the touchscreen and can initiate calls or even download malware.
And last today, from SecurityWeek.com
The Drupal team has released a moderately critical advisory for serious vulnerabilities in the third-party library Guzzle that handles HTTP requests and responses to external services, and can be exploited to remotely hijack Drupal-powered websites. The vulnerabilities do not affect Drupal core, but may affect some contributed projects or custom code on Drupal sites. Details and a link to the advisory in the article.
That’s all for me today. Have a great rest of your day. Like and subscribe, and until tomorrow, be safe out there.
  continue reading

221 odcinków

כל הפרקים

×
 
Loading …

Zapraszamy w Player FM

Odtwarzacz FM skanuje sieć w poszukiwaniu wysokiej jakości podcastów, abyś mógł się nią cieszyć już teraz. To najlepsza aplikacja do podcastów, działająca na Androidzie, iPhonie i Internecie. Zarejestruj się, aby zsynchronizować subskrypcje na różnych urządzeniach.

 

Skrócona instrukcja obsługi