Cisco Cloud Portal Software gives up too much information

According to the National Vulnerability Database Cisco Intelligent Automation for Cloud in Cisco Cloud Portal does not properly restrict the content of MyServices action URLs, which allows remote authenticated users to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history ——————————————————————————————— This vulnerability is medium, and … Read more

Extortion scheme via advertisement on Bing

Be careful on the advertisement you click on. Katie Matusik is a  Gymnast (took 3rd place in 2012 NCAA National Gymnastics) If you search for Kaite Matusik on Bing you will see the following: If someone clicks on it: then the following site comes up:   It is an extortion Scheme and is difficult to … Read more

targeted malware campaign -> to exploits in Dropbox

Malware campaign is using some old and new methods. One email claims to be from Maersk shipping line and the attachment (word doc) opens a backdoor connection to two hacker command and control servers The dropbox domain is also referenced, the links attempt to contact londonpaerl (. )co (. )uk and selombiznet(.)net (I added the … Read more

Paypal two factor authentication bypassed by testers

Duosecurity has bypassed the Two-factor authentication This is effect makes the 2FA (Two Factor Authentication) useless. this means that a password still has to be guessed(broken into) by the hackers for the account to be compromised. Essentially if you set up your PayPal account for “extra” security, unfortunately that did not pan out.  2FA is … Read more