
Pirates of old were on the hunt for gold, silver, and rum. Modern pirates just want WiFi — and they want it free.
The post Here come the free WiFi Pirates of the Adriatic appeared first on Avira Blog.

Pirates of old were on the hunt for gold, silver, and rum. Modern pirates just want WiFi — and they want it free.
The post Here come the free WiFi Pirates of the Adriatic appeared first on Avira Blog.
Posted by redrain root on Sep 12
Airmail is a popular email client on iOS and OS X.
I found a vulnerability in airmail of the latest version which could cause
a file:// xss and arbitrary file read.
Author: redrain, yu.hong () chaitin com
Date: 2016-08-15
Version: 3.0.2 and earlier
Platform: OS X and iOS
Site: http://airmailapp.com/
Vendor: http://airmailapp.com/
Vendor Notified: 2016-08-15
Vulnerability:
There is a file:// xss in airmail version 3.0.2 and earlier.
The app can…
Posted by Justa Person on Sep 12
Samsung has zero interest in fixing this and I’m tired of trying to report
it to them. Enjoy.
Posted by Dawid Golunski on Sep 12
Vulnerability: MySQL Remote Root Code Execution / Privilege Escalation 0day
CVE: CVE-2016-6662
Severity: Critical
Affected MySQL versions (including the latest):
<= 5.7.15
<= 5.6.33
<= 5.5.52
Discovered by:
Dawid Golunski
http://legalhackers.com
An independent research has revealed multiple severe MySQL vulnerabilities.
This advisory focuses on a critical vulnerability with a CVEID of CVE-2016-6662.
The vulnerability affects MySQL…
Posted by Julien Ahrens on Sep 12
RCE Security Advisory
https://www.rcesecurity.com
1. ADVISORY INFORMATION
=======================
Product: XenForo ToggleME plugin
Vendor URL: https://xenforo.com/community/resources/toggleme.137/
Type: Cross-Site Scripting [CWE-79]
Date found: 2016-09-06
Date published: 2016-09-11
CVSSv3 Score: 5.5 (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N)
CVE: –
2. CREDITS
==========
This vulnerability was discovered…
Posted by Sysdream Labs on Sep 12
# Cross-site scripting vulnerability found on www.google.fr
We were able to identify a cross-site scripting (XSS) vulnerability in the main domain of Google: www.google.fr.
### Description
Cross-site scripting is a kind of vulnerability that allows an attacker to send malicious code, usually in the form of
Javascript, to another user. Exploiting an XSS may lead to private information compromise, cookie theft or even browser
take over….
A researcher has disclosed some details and a limited proof-of-concept for a critical MySQL vulnerability. The flaw has been patched in MariaDB and PerconaDB.

![]()

Though it may seem trivial, it is not: the security of your company and of your customers depends largely on the passwords that your employees use. In fact, should any of them make such a serious error as, for example, reusing their login credentials across different services, the consequences could be catastrophic, as Dropbox has recently learned.
Just a few days ago, the cloud storage company acknowledged that passwords of more than 68 million accounts had been leaked, with a security issue jeopardizing the information of its more tan 500 million users. All the problems started with a simple lapse on the part of one of the company’s employees
The incident occurred in 2012, when some Dropbox users began to complain: email accounts that they had used exclusively to register for the service had started to receive a lot of spam messages. The key to the mystery lay in the theft of passwords from a Dropbox employee: cyber-crooks had got hold of the employee’s LinkedIn password, which was the same as the one used for the cloud storage account. And in the Dropbox account, the employee had a document with a list of user’s email accounts. The perfect gift for spammers.
Some of the passwords that have now been leaked correspond to those accounts included in the previous theft some years before. In fact, a few days before its acknowledgement of this latest leak, Dropbox asked users that had not changed their passwords for some years to do so as soon as possible: “We’re reaching out to let you know that if you haven’t updated your password since mid-2012, you’ll be prompted to update it the next time you sign in. This is purely a preventative measure and we’re sorry for the inconvenience”, read the email.
Some of the passwords filtered correspond to hacked accounts years ago (…) Dropbox asked users that has not changed their passwords for 4 years ago to do so as soon as possible.
In short, poor password practice by employees in company email or service accounts can put the whole company at risk. In fact, Dropbox has already taken measures to enable employees to comply with corporate security rules, including among other things, not reusing passwords. You can also do the same. Panda’s security solutions include a password manager to facilitate the use of different passwords for different services, without having to memorize each one.
The post Companies that are making the same mistake as Dropbox appeared first on Panda Security Mediacenter.
Hello, Being an internet player, you must be aware of the fact that eCommerce industry will sooner replace traditional shopping methods. The ones with the best online store will be eventually among the ones that can ripe the fruit of this flourishing industry. This side Abhinav Kumar Singh<http://www.magentocommerce.com/certification/directory/dev/2000581>, India's foremost Magento Certified Developer and Solution Specialist with an expertise of 7+ years in this domain. Currently, I'm leading a team of 100+ Magento Certified Developers and Solution Specialists to offer professional services for Magento Store redesigning, development and integration. Click here<http://www.magentocommerce.com/certification/directory/dev/2000581> to check my Magento Certification over the official website of Magento Inc. or you can also copy-paste the given URL in your browser: http://www.magentocommerce.com/certification/directory/dev/2000581 Our Organization: Since the early days of Magento, our professionals have accomplished 1000+ projects related to Magento Store designing, development, and advanced feature integration. It is just our professional approach and on-time delivery of the projects that a huge part of our business is based on the repeated service requests. Our Magento Certified professionals always ensure to keep a vigil eye towards the crucial points and customer-centric approach so that more and more visitors can be easily fetched to the eCommerce Store. Apart from a dedicated team of Magento Certified developers and solution specialists, our organization is also backed by an experienced team of graphic designers, web developers, application developers and SEO specialists. We always ensure to provide our clients the services at our fingertips that they crave for. Click here<https://drive.google.com/open?id=0B6oIxFB5yr2PdE5FekxPWHdqczA> to know how we transform ideas into real-time business or simply copy-paste the given URL in your browser: https://drive.google.com/open?id=0B6oIxFB5yr2PdE5FekxPWHdqczA Our Services: Some of our Offered Magento-based Services are: * Magento Store Designing from scratch. * Magento Store Development from scratch. * Re-Designing of Existing Magento Store. * Advanced features Integration in Existing Magento Store. * Migration of existing eCommerce Store (Yahoo/Abacco/Shopify/Joomla/WooCommerce) to Magento. * Magento Store upgrading to Magento 2.0. * SEO Testing of existing Magento store as per Google Guidelines to gain higher visibility in search engines. Kindly reply me if you are interested in any of our offered services. Based on your response, I will reply you back with my official email id regarding the detailed communication for the project. Looking forward to your positive response. NOTE: * We would love to showcase you the best of our projects. Please reply us back if you want to see our portfolio of the amazing work related to your business domain. * If you are a web development firm looking forward to outsourcing your Magento-based projects, kindly contact us by replying to this email. We have an assorted range of partnership models available for a mutual win-win situation. * Since we have an in-house team of Magento Certified developers and solution specialists along with graphic designers and web developers, we do not have anything called overhead expense. Be assured to get the best quotation for your Magento projects. Warm Regards, Abhinav Kumar Singh Senior Magento Developer and Solution Specialist