Geïnfecteerde advertenties op nu.nl

Fox-IT houdt voor haar klanten de netwerkbeveiliging in de gaten. Hierbij zijn op 5 juni tussen 10:42 en 15:34 besmettingen geconstateerd van klanten die nu.nl bezochten. Er zijn waarschijnlijk meer Nederlanders besmet na een bezoek aan nu.nl. De infectie werd verspreid via advertenties. De oorzaak is een advertentieserver die op nu.nl adverteerde. De software om … Continue reading Geïnfecteerde advertenties op nu.nl

Security advisory: Unencrypted storage of confidential information in Keeper® Password & Data Vault v5.3 for iOS

Summary Paul Pols of Fox-IT's penetration testing team discovered a critical vulnerability in version 5.3 of the "Keeper® Password & Data Vault" app for iPhones, iPods touch and iPads. An update was released today that is said to resolve the issues that we identified. We urge all users of this application to install this update … Continue reading Security advisory: Unencrypted storage of confidential information in Keeper® Password & Data Vault v5.3 for iOS

Writeup on nbc.com distributing Citadel malware

Every now and then, an incident occurs in the SOC (Security Operation Center) that really captures everyone involved's imagination. NBC's websites getting hacked, is just one case, in point.  At 16:43 CET, this afternoon we noticed that the NBC.com website links to the redkit exploit kit that is spreading Citadel malware, targeting US financials institutions. This version of … Continue reading Writeup on nbc.com distributing Citadel malware

Oracle getting serious about Java

Recently, Oracle released new a version of Java with a difference. Java/1.7.0_13 is the latest version. Its increased the default security from ‘Medium’ to ‘High’, which restricts execution of unsigned applets. It also introduced a new warning to people executing Java code which checks if Java is using the latest version. You might notice the … Continue reading Oracle getting serious about Java

Cyber Security in Nederland op de agenda!

Volgende week, op 6 december, gaat de vaste Kamercommissie voor Veiligheid en Justitie weer vergaderen over de voortgang van onze nationale Cyber Security strategie. Op de agenda staan 8 onderwerpen die in 3 uur behandeld moeten worden. Dat is weinig tijd voor stuk voor stuk belangrijke onderwerpen. Om de discussies efficiënt te laten lopen, leek … Continue reading Cyber Security in Nederland op de agenda!

Fox-IT discovers security bugs in Oracle Software

In its latest quarterly Critical Patch Update, Oracle has acknowledged and repaired two security bugs identified by Sjoerd Resink, Senior IT Security Expert at Fox-IT. The bugs were discovered during one of Fox-IT's penetration testing assignments in version 10.1.4.3 of Oracle Application Server's Single Sign-On component. The first security issue, numbered CVE-2012-3175 by the Common … Continue reading Fox-IT discovers security bugs in Oracle Software

Observations on the recent Java 0-day exploits in the wild

Recently the Internet has been abuzz with news of an unpatched (0-day) exploit for the latest version of Java. The vulnerability is critical because it can exploit a fully patched version of Windows, Linux or Mac OS X. Also, it can do all this without users knowledge or consent. All that is needed is have … Continue reading Observations on the recent Java 0-day exploits in the wild