Skip to main content

Security Blog

Filter by:

Large websites attacked by massive DDoS from Internet-enabled devices (IoT devices)

At the last weekend (21 Oct) many large websites such as Twitter, PayPal, Amazon etc. could not be accessed due to their DNS provider Dyn being attacked. From the study of security firm Flashpoint, a vast amount of vulnerable Internet-enabled, ...
Release Date: 24 Oct 2016 2178 Views

Favourite Security Reads of the Week (20 Oct 2016)

  Favourite Security Reads of the Week (20 Oct 2016) .   "Favourite Security Reads of the Week". Each week we share five news or articles that we like. We hope you will love this column and we welcome your comment via email to [email protected].   Below is the Favourite Security Reads of this Week.   多重措施保「密」 防暴力解「碼」 (Written by HKCERT on Hong Kong Economic Times, 2016-10-14, Chinese) Heightened DDoS Threat Posed by Mirai and Other Botnets (US-CERT, 2016-10...
Release Date: 20 Oct 2016 1137 Views

Several online stores in Hong Kong vulnerable to credit card fraud

HKCERT is aware that a security researcher has recently disclosed a study: 5900 online stores found skimming (read it here). The study described technique used by cybercriminals to intercept payment data on vulnerable websites. In the study, a list of about 5,900 online...
Release Date: 18 Oct 2016 1693 Views

The banking trojan – Acecard

Acecard Malware is continuously evolving. The first version of Acecard, an Android banking trojan, was detected in Feb 2014. Afterwards, its family registered more than 10 new versions of the malware, each with a far longer list of malicious functions than the previous...
Release Date: 18 Oct 2016 2140 Views

Favourite Security Reads of the Week (14 Oct 2016)

  Favourite Security Reads of the Week (14 Oct 2016) .   "Favourite Security Reads of the Week". Each week we share five news or articles that we like. We hope you will love this column and we welcome your comment via email to [email protected].   Below is the Favourite Security Reads of this Week.   正當網站掩飾 「域名屏蔽」攻擊難防 (Written by HKCERT on Hong Kong Economic Times, 2016-10-07, Chinese) NSA could put undetectable “trapdoors” in millions of crypto keys (Ars Technica...
Release Date: 14 Oct 2016 1201 Views

Favourite Security Reads of the Week (7 Oct 2016)

  Favourite Security Reads of the Week (7 Oct 2016) .   "Favourite Security Reads of the Week". Each week we share five news or articles that we like. We hope you will love this column and we welcome your comment via email to hkcert@hkcert....
Release Date: 7 Oct 2016 1037 Views

More than half of Android devices are vulnerable by BadKernel Vulnerability

In May 2015, a security bug in Google's V8 JavaScript engine was discovered and fixed. However, only in August 2016, Chinese information security researchers discovered that the V8 issue also affected a whole range of Android-related products where the older V8 engine...
Release Date: 7 Oct 2016 1539 Views

HKCERT Security Newsletter (October 2016 Issue)

  Cover Story Change your Yahoo Account password immediately Hot Topic Hong Kong Google Play Store's Apps Security Risk Report (September 2016) Upcoming Event Cyber Security Professionals Awards 2016   Want the newsletter delivered to your mailbox every month? Subscribe it...
Release Date: 3 Oct 2016 1054 Views

Favourite Security Reads of the Week (30 Sep 2016)

  Favourite Security Reads of the Week (30 Sep 2016) .   "Favourite Security Reads of the Week". Each week we share five news or articles that we like. We hope you will love this column and we welcome your comment via email to [email protected].   Below is the Favourite Security Reads of this Week.   廉價無線鍵盤不設防 私隱無保障 (Written by HKCERT on Hong Kong Economic Times, 2016-09-26, Chinese) Change your password! Yahoo confirms data breach of 500 million accounts (Sophos, 2016-...
Release Date: 30 Sep 2016 1141 Views

Change your Yahoo Account password immediately

On September 22, Yahoo confirmed their account system having 500 million user accounts stolen, among included names, email addresses, telephone numbers, dates of birth, and hashed passwords. The relevant information can be traced back since 2014. To apply the best protection of...
Release Date: 23 Sep 2016 1814 Views