Ethereum fixes serious “eclipse” flaw that could be exploited by any kid

Enlarge (credit: Armin Kübelbeck) Developers of Ethereum, the world’s No. 2 digital currency by market capitalization, have closed a serious security hole that allowed virtually anyone with an Internet connection to manipulate individual users’ access to the publicly accessible ledger. So-called eclipse attacks work by preventing a cryptocurrency user from connecting to honest peers. Attacker-controlled […]

An Adobe Flash 0day is being actively exploited in the wild

Enlarge / A screenshot of the malicious Excel document spreading a Flash zeroday. (credit: Talos) An increasingly sophisticated hacking group is exploiting a zero-day vulnerability in Adobe’s Flash Player that lets them take full control of infected machines, researchers said Friday. The critical, use-after-free vulnerability, which is indexed as CVE-2018-4877, resides in the latest version […]

Windows 0-day is exploited to install creepy Finspy malware (again)

Enlarge / The WSDL parser, where the zero-day was located. (credit: FireEye) On Tuesday, Microsoft patched a previously unknown vulnerability that researchers say was actively exploited by an undisclosed nation to install surveillance malware on one or more vulnerable computers. The exploit, according to a blog post published Tuesday by security firm FireEye, was embedded […]

US Open 2017: Rafael Nadal found the weakness in Del Potro's game and exploited it

Nadal secured a place in the US Open final and is on the brink of a 16th Grand Slam after going for Del Potro’s backhand like there was no tomorrow. Nadal came through after losing the first set and ended up winning 4-6 6-0 6-3 6-2 in two and a half hours. And Del Potro […]

Microsoft Word 0-day was actively exploited by strange bedfellows

Enlarge / An identical artifact in two exploits, one installing Finspy and the other Latenbot. (credit: FireEye) A critical Microsoft Word zero-day that was actively exploited for months connected two strange bedfellows, including government-sponsored hackers spying on Russian targets and financially motivated crooks pushing crimeware. That assessment, made Wednesday with “moderate confidence” from researchers at […]

Ransomware scammers exploited Safari bug to extort porn-viewing iOS users

(credit: Lookout) Ransomware scammers have been exploiting a flaw in Apple’s Mobile Safari browser in a campaign to extort fees from uninformed users. The scammers particularly target those who viewed porn or other controversial content. Apple patched the vulnerability on Monday with the release of iOS version 10.3. The flaw involved the way that Safari […]