Investigation of regular high load on unused machines every 7 hours
https://blog.avast.com/investigation-of-regular-high-load-on-unused-machines-every-7-hours

iOS WebView auto dialer bug
https://www.mulliner.org/blog/blosxom.cgi/security/ios_webview_auto_dialer.html

Google Pixel pwned in 60 seconds - Chinese teams kill Safari, laugh at four-second Flash hack
http://www.theregister.co.uk/2016/11/11/google_pixel_pwned_in_60_seconds

Live HTTP Headers (and other Chrome extensions) distributing adware
https://cwhite.me/live-http-headers-is-now-an-adware-distributor/

CVE-2016-4484: Cryptsetup Initrd root Shell
http://hmarco.org/bugs/CVE-2016-4484/CVE-2016-4484_cryptsetup_initrd_shell.html

Ransoc Desktop Locking Ransomware Ransacks Local Files and Social Media Profiles
https://www.proofpoint.com/us/threat-insight/post/ransoc-desktop-locking-ransomware-ransacks-local-files-social-media-profiles

Your Android could be sending messages to China
https://blog.avast.com/your-android-could-be-sending-messages-to-china

Strangely enough, I have always been wary of Chinese products and that only strengthened after the Lenovo issue. I did however take a punt on the Huawei Nexus 6P by a “Chinese telecommunications company that has been manufacturing mobile phones since 1997.”

Nice to see that avast has this covered.

iPhone User? Your Calls Go to iCloud
https://blog.elcomsoft.com/2016/11/iphone-user-your-calls-go-to-icloud/

[0day] [PoC] Risky design decisions in Google Chrome and Fedora desktop enable drive-by downloads
https://scarybeastsecurity.blogspot.com/2016/11/0day-poc-risky-design-decisions-in.html

3 million Android phones vulnerable due to pre-installed rootkit
https://blog.avast.com/3-million-android-phones-vulnerable-due-to-pre-installed-rootkit
http://blog.anubisnetworks.com/blog/ragentek-android-ota-update-mechanism-vulnerable-to-mitm-attack

Locky Ransomware now using the Aesir Extension for Encrypted Files
http://www.bleepingcomputer.com/news/security/locky-ransomware-now-using-the-aesir-extension-for-encrypted-files/

Nemucod downloader spreading via Facebook
https://bartblaze.blogspot.com/2016/11/nemucod-downloader-spreading-via.html

Android Banking Malware Masquerading as Email App Targets German Banks
https://blog.fortinet.com/2016/11/18/android-banking-malware-masquerading-as-email-app-targets-german-banks

What I would give to get my hands on the creators of Locky! Many lost nights restoring customers from backups.

BTW - Love the Avatar of Mr. Incredible

You’re not alone pal. :wink:

You Can Now Rent a Mirai Botnet of 400,000 Bots
http://www.bleepingcomputer.com/news/security/you-can-now-rent-a-mirai-botnet-of-400-000-bots/

Here’s a secret: ɢoogle.com is not google.com
http://www.analyticsedge.com/2016/11/heres-a-secret-ɢoogle-com-is-not-google-com/
http://help.analyticsedge.com/spam-filter/definitive-guide-to-removing-google-analytics-spam/

Google warns journalists and professors: Your account is under attack
http://arstechnica.com/security/2016/11/google-warns-journalists-and-professors-your-account-is-under-attack/

Locky Ransomware putting us to sleep with the ZZZZZ Extension
http://www.bleepingcomputer.com/news/security/locky-ransomware-putting-us-to-sleep-with-the-zzzzz-extension/