SECURITY WARNINGS & Notices - Please post them here

Attackers gain access to Ubisoft customer data
http://www.h-online.com/security/news/item/Attackers-gain-access-to-Ubisoft-customer-data-1910357.html
http://blog.ubi.com/security-update-for-all-ubisoft-account-holders/

Majority of windows computers infested through java: https://www.csis.dk/en/csis/news/3981/ link article author = Peter Kruse

84.3 % of all virus infections can be traced back to the drive-by attacks from malicious or compromised websites

polonus

Microsoft Security Bulletin Advance Notification for July 2013
http://technet.microsoft.com/en-us/security/bulletin/ms13-jul

Wasn’t sure where to post this.

http://miami.cbslocal.com/2013/07/07/growing-problem-of-tech-support-scams/

Exploit for Android signing hole published
http://www.h-online.com/security/news/item/Exploit-for-Android-signing-hole-published-1914228.html

New backdoor in HP server products
http://www.h-online.com/security/news/item/New-backdoor-in-HP-server-products-1916506.html

Telstra storing data on behalf of US government
http://www.theage.com.au/it-pro/security-it/telstra-storing-data-on-behalf-of-us-government-20130712-hv0w4.html

Microsoft gave NSA’s PRISM access to Skype, Outlook.com and SkyDrive
http://www.h-online.com/security/news/item/Microsoft-gave-NSA-s-PRISM-access-to-Skype-Outlook-com-and-SkyDrive-1916730.html
http://www.guardian.co.uk/world/2013/jul/11/microsoft-nsa-collaboration-user-data

FBI-themed ransomware now affecting OS X users

http://cdn.slashgear.com/wp-content/uploads/2013/07/ransomware1-580x394.png

Critical vulnerabilities in numerous ASUS routers
http://www.h-online.com/security/news/item/Critical-vulnerabilities-in-numerous-ASUS-routers-1918469.html

10 year old API vulnerability, issue 69, troubles java 7: http://archives.neohapsis.com/archives/fulldisclosure/2013-07/0172.html
article author Adam Gowdiak
If you can do without java uninstall it,

polonus

PS Let us make it a two-in-one java alert: http://www.securityweek.com/multiple-java-instances-keep-enterprise-systems-vulnerable-attack-report
link source Security Week’s Fahmida Y. Rashid

it would be really nice if Oracle joined the MS security initiative …
since Adobe and some others joined it, it really helped to decrease the amount of critical vulnerabilities …
anyway the whole Java 7 story is real tragedy (i can understand Java 6 was old code and under massive amount of attacks)
thanks a lot for posting this ;( the details about go totally around the Java sandbox is nasty

Chinese Hackers discovered second Android master key vulnerability
http://thehackernews.com/2013/07/chinese-hackers-discovered-second.html

Windows Media Player 12 Plugin: Arbitrary File Read Vulnerability
http://www.rawsec.net/wmp-vulnerability.html

Ubuntu Forums got hacked
http://ubuntuforums.org/announce.html

Hi forum friends,

During my automated security scannings
I have found that an enormous amount of websites
are still vulnerable to configuration insecurities.

These insecurities are grossly underestimated
by webmasters and sloppy IT staff alike,
opening up a goldmine of unintended information for malicious attackers.
At least security through obscurity should be a priority.

Important insecurities found:

  1. excessive headers
    (info can be used to pinpoint security flaws to attackers).

  2. clickjacking (X-frame option header not returned),
    malcontent can be embedded in a frame.

ASP netsites can be scanned here at: https://asafaweb.com/Scan?Url=
Other sites can be scanned at: safersite.de

polonus

Urausy Lockscreen: Your computer will remain locked for 3 days, 11 hours and 20 minutes!

https://blog.avast.com/wp-content/uploads/2013/07/00-urausy_mainlogo.png

The good thing for us is that it’s detected by avast!. :slight_smile:

Who do you trust ???
Virus total scan results:
https://www.virustotal.com/en/file/7d01bd6c9fef5b1cdddee4de1d5a03edce07c2b706fc566753949992775fcf67/analysis/1372871468/

or avast!:

http://www.screencast-o-matic.com/screenshots/u/Lh/1374664221488-2273.png

Link received from a “friend” first analyzed and reported clean.
Thanks avast! for always having my back!

Use different passwords for different sites.

Hello,

You are receiving this message because you have an account registered with this address on ubuntuforums.org.

The Ubuntu forums software was compromised by an external attacker. As a result, the attacker has gained access to read your username, email address and an encrypted copy of your password from the forum database.

If you have used this password and email address to authenticate at any other website, you are urged to reset the password on those accounts immediately as the attacker may be able to use the compromised personal information to access these other accounts. It is important to have a distinct password for different accounts.

The ubuntuforums.org website is currently offline and we are working to restore this service. Please take the time to change your ubuntuforums.org account password when service is restored.

We apologize for any inconvenience to the Ubuntu community, thank you for your understanding.

The Canonical Sysadmins.

Multisystem Trojan Janicab attacks Windows and MacOSX via scripts

Analysis Report in the Avast Blog:http://blog.avast.com/2013/07/22/multisystem-trojan-janicab-attacks-windows-and-macosx-via-scripts/

There are also many JS: Detections added with Database version 130724-0

http://www.avast.com/de-de/virus-update-history