2018年4月30日 星期一

TrendLabs: XTRAT and DUNIHI Backdoors Bundled with Adwind in Spam Mails

Figure 1. Adwind detections between January 1 and April 17, 2018
Figure 1. Adwind detections between January 1 and April 17, 2018
REF: https://blog.trendmicro.com/trendlabs-security-intelligence/xtrat-and-dunihi-backdoors-bundled-with-adwind-in-spam-mails/

2018年4月29日 星期日

Google GDPR policy

---------- Forwarded message ----------
From: Google
Subject: Important updates about the General Data Protection Regulation (GDPR)

In August last year, we announced our commitment to comply with Europe’s new General Data Protection Regulation (GDPR). Last month, we shared more about our GDPR policy, contract and product changes and today, we wanted to share new Help Center articles for DFP/AdX, AdMob, AdSense which provide more information on these changes. The articles cover:
  • Controller responsibilities
  • Consent support
  • Choice and control over ads personalisation
If you have any questions about this update, please don't hesitate to reach out to your account team or contact us through the Help Center.
Thanks,
The Google Team

TrendLabs: Not Only Botnets: Hacking Group in Brazil Targets IoT Devices With Malware

Figure 6. List of proxy addresses
Figure 6. List of proxy addresses
REF: https://blog.trendmicro.com/trendlabs-security-intelligence/not-only-botnets-hacking-group-in-brazil-targets-iot-devices-with-malware/

RememBear Official Launch

RememBear Official Launch
If you’ve never used a password manager, RememBear will happily walk you through setting your account up with straightforward instructions and animations.

REF: https://www.remembear.com/blog/remembear-official-launch/

TrendLabs: Necurs Evolves to Evade Spam Detection via Internet Shortcut File

Figure 1.  A diagram of a previous version of the Necurs malware.
Figure 1.  A diagram of a previous version of the Necurs malware.
REF: https://blog.trendmicro.com/trendlabs-security-intelligence/necurs-evolves-to-evade-spam-detection-via-internet-shortcut-file/

2018年4月25日 星期三

[USN-3632-1] Linux kernel (Azure) vulnerabilities

It was discovered that the KVM implementation in the Linux kernel allowed
passthrough of the diagnostic I/O port 0x80. An attacker in a guest VM
could use this to cause a denial of service (system crash) in the host OS.
(CVE-2017-1000407)

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
  https://usn.ubuntu.com/usn/usn-3632-1
  CVE-2017-0861, CVE-2017-1000407, CVE-2017-15129, CVE-2017-16994,
  CVE-2017-17448, CVE-2017-17450, CVE-2017-17741, CVE-2017-17805,
  CVE-2017-17806, CVE-2017-17807, CVE-2018-1000026, CVE-2018-5332,
  CVE-2018-5333, CVE-2018-5344, CVE-2018-8043

2018年4月24日 星期二

[USN-3629-1] MySQL vulnerabilities

In addition to security fixes, the updated packages contain bug fixes, new
features, and possibly incompatible changes.

Please see the following for more information:
http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-60.html
http://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-22.html
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html

References:
  https://usn.ubuntu.com/usn/usn-3629-1
  CVE-2018-2755, CVE-2018-2758, CVE-2018-2759, CVE-2018-2761,
  CVE-2018-2762, CVE-2018-2766, CVE-2018-2769, CVE-2018-2771,
  CVE-2018-2773, CVE-2018-2775, CVE-2018-2776, CVE-2018-2777,
  CVE-2018-2778, CVE-2018-2779, CVE-2018-2780, CVE-2018-2781,
  CVE-2018-2782, CVE-2018-2784, CVE-2018-2786, CVE-2018-2787,
  CVE-2018-2810, CVE-2018-2812, CVE-2018-2813, CVE-2018-2816,
  CVE-2018-2817, CVE-2018-2818, CVE-2018-2819, CVE-2018-2839,
  CVE-2018-2846