17 August 2025
250817 insider info Critical SharePoint Zero-Day Exploit CVE-2025-53770
27 December 2021
211227 SwedBank Pay gives free Christmas Presents
Reference:
https://zenosloim.blogspot.com/2021/09/210930-swedbank-pay-security-flaw.html
It seems that SwedBank is very generous giving to anyone for free, Christmas presents.
Similar security flaw in the SwedBank Pay paying system, makes possible to order/buy anything and paying via SwedBank Pay (PayEx) payment system.
You'll never be invoiced.
The SwedBank Pay (PayEx) was informed about the new security flaw.
17 November 2021
211117 use chemical solvents as antihacking tool
Use chemical solvents as antihacking tool.
Guaranteed for any Apple, Android, BlackBerry, Windows Phone, Java, Linux, or any other platform using password for log in to access the device or using tokens for OAuth to banking services.
Background:
Using a password implies using a physical keyboard (ex. BlackBerry) or a virtual keyboard generated on the screen.
Every person has a particular way of making the input of password: timing between individual keystrokes, pressure of individual keystrokes, physiological health - amount of perspiration and fat substances on fingers, resulting in particular amounts of chemical traces left on surface of keyboard (physical or virtual).
Up to day there is no device with virtual keyboard which aleatory generates the geometry (disposal) of the individual tastes (buttons).
UV-analyzers used by enforcement agencies for taking fingerprints can map exactly the areas with specific amount of human perspiration and fat on surface. This identifies exactly which symbols were used in password.
Spectrometers can measure exactly the amount of rests, hence the older of each individual trace. This identifies the succession of the symbols.
So your password is revealed.
More: most token based OAuth for banking services are using only digits, making easier to reveal the password.
How many persons use to use a chemical solvent to wipe the keyboard of their device after use?
So, use a chemical solvent to wipe your keyboard or DO NOT USE A PASSWORD, only fingerprint or iris-recognition for login and banking services.
30 September 2021
210930 SwedBank Pay security flaw
210930 SwedBank Pay (PayEx) security flaw - Bugg i betalssystemet PayEx från SwedBank
A security flaw was discovered in SwedBank Pay (PayEx) payment system, allowing to buy anything from a customer using the above payment system, without paying in practice, because you will never be invoiced or debted by the bank.
The SwedBank Pay (PayEx) was informed via secured communication about the security flaw, detailed description and how to remedy the security flaw.
Buggfel har upptäckts i betalningssystemet PayEx tillhörande SwedBank, som tillåter att beställa via faktura tjänster och varor från företag som använder SwedBank Pay (PayEx).
Företaget för betalt från SwedBank Pay (köpet blir godkänt via faktura), men själva kunden som handlat blir ej debiterad, utan SwedBank får betala.
SwedBank Pay (PayEx) har informerats via säkrade kanaler om buggen, hur den uppstår och hur kan den korrigeras, med detaljerad information.
05 July 2021
210705 Kaseya or Application Specialist urgently needed
Recent Kaseya events just remind me of my comment on Solar Winds affair:
https://zenosloim.blogspot.com/2020/12/201222-from-solar-winds-hack-to.html
Well, same story happens again: blind and dumb trust in well-known US software company.
Or what happens when you cut costs by outsourcing at any price and not using own application specialists.
In Sweden we have full fun: major companies are completely blocked or partially blocked: Coop, SJ...
I remember when working as Application Specialist at SAAB, I provoked rumour when I said that I discovered hidden malware on a CD received from the renowned German company Rohde & Schwarz.
Impossible, absurd...but I was right in my assessment.
Nowadays, being an Application Specialist, is no longer important, who cares to test and reverse engineer/repack updates from Microsoft, Adobe, ... Kaseya, Solar Winds...?
Consequences? Russian hackers become rich on criminal activities and dumb arrogance of chiefs obsessed by cutting costs at any price.
We need Application Specialists in Windows softwares among others, only Linux techies are not enough...:), because advanced filtering firewalls from Israel Check Point are too expensive to be affordable.
Also not anyone is using multi- layered security solutions for email servers and intranet.
03 June 2021
210603 Google Play payment mechanism security issue - any paid app can be downloaded
210603 Google Play payment mechanism security issue - any paid app can be downloaded
I just discovered a security issue in Google Play payment system, which makes possible for an unauthorized person to download any paid app without payment.
Google was contacted for reporting and correction of the security issue.
19 March 2021
210319 after more than 4 years, Swedish State Authorities react in good direction
References:
https://zenosloim.blogspot.com/2016/02/it-services-outsourcing-between-cutting.html
https://zenosloim.blogspot.com/2017/07/transportstyrelsen-skandalen.html
Background:
During past years, keyword Outsourcing was the magic key for many Swedish responsibles from both government agencies, state authorities and big private companies.
Cutting costs without long term planning and analysis, became almost a catastrophic way of thinking and a 100% sure way to IT-security incidents and disasters.
Now it seems that many rational analysers have made their point listened and the result is here:
https://sverigesradio.se/artikel/regeringen-lagger-fram-ny-sakerhetslag
"Skärpt säkerhetslag ska skydda känslig information
Publicerat idag kl 10.30
Regeringen föreslår nu ändringar i säkerhetsskyddslagen som ska granskas av lagrådet.
Syftet är att hindra att känslig information kommer på avvägar. Till exempel måste myndigheter eller privata företag i vissa fall samråda med Säpo om IT-system ska läggas ut på entreprenad. Det kan gälla verksamhet med kopplingar till förvaret, energiförsörjning, eller telefon- och datanätverk.
Struntar de i samrådet kan de straffas med en avgift på upp till 50 miljoner kronor."
At last...
Sådana chefer som lägger allt inkl. känslig IT-drift på entreprenad, utan att tänka på konsekvenser, borde också lägga deras eget tjänst på entreprenad, så att någon mer kompetent ersätter dem.
06 March 2021
210306 Microsoft Outlook.com latest massive hack
About 2 weeks ago something strange happened.
A mail sent apparently from Microsoft Outlook servers invited me to click on a link to reconfirm my Google account designed as recovery account for my Microsoft account.
Why strange?
1. In case of account suspicious activity or hacking, there are well defined rules of alert.
2. Having more accounts on Microsoft and Google, respective suspicious email came only on certain accounts: those used for corporate purpose which were associated with interesting list of Contacts.
3. Analysis of email's header revealed only real internal ip addresses from Microsoft Outlook.
Same for the clickable link sent to click on in order to reverify your data.
4. Despite message said if you do not reverify, you can no longer use the account, checking the account from a different ip and device, all was ok, and more, the pretended email did not even existed, alike so-called flash-sms.
My Good Sense told me do ignore the email and for sure something happened inside Microsoft.
Today, the world news showed I was right.
Massive internal attack on Microsoft Outlook servers and Cloud- based email services.
I can only imagine how many US and world companies and authorities using Microsoft Outlook.com services are now in big trouble.
Such a sofisticated attack and hack could only be done by a state actor: China or Russia.
Israel is not in discussion, being an US ally.
In any case, the whole trouble was kept totally secret for at least 10 days.
22 December 2020
201222 From Solar Winds hack to Symantec hack, McAffee hack, F-Secure hack, Avecto hack and...SAAB
201222 From Solar Winds hack to Symantec hack, McAfee hack, F-Secure hack, Avecto hack and...SAAB
Latest Solar Winds hack could have been discovered long time ago, and avoid so much dammage as it is partially recognized today.
Main cause: many companies and state authorities have a blind belief in an already established trusted software company, especially if it is located in USA or UK.
Responsible with IT Security Management, Repacks and Application Specialists trust blindly any version and update if it is "signed" with a "verified" digital signature.
They get for granted above and do not trust if any would reverse-engineer a certain software for backdoors discovering.
How about if a certain famous software company have backdoors in their intranet or update servers and unauthorized strangers get access to their intranet and signing tools and certs or special access cookies which can emulate authorized external access?
This was the case few years ago with all famous names: Symantec, McAfee, Avecto, F-Secure.
All above, reputated security software companies from USA, UK, Finland-Sweden, actively used in many global companies and state/military/sigint authorities.
Imagine a high-security encrypted laptop being left completely open.
Imagine a cloned RSA Security USB-stick for unauthorised access.
Imagine an intranet antivirus server "cooked" with modded virus-definitions updates.
Imagine a "poisoned" Access Server, with modded records if unauthorized access records installed.
Imagine a user getting hidden local/global admin rights, after "getting unauthorized access" to Active Directory records of others.
Unfortunately, the practice described above (trust blindly and refuse to accept "unpleasant" discoveries) is well spread mostly among Corporate CEOs and high-rank officers and responsibles.
If someone discovers "the incredible", it's like whistling in the church and gets punished instead of using precious info with critical timing.
Few years ago I worked as IT-Security Administrator SAAB Global Network.
After discovering similar issues, SAAB leading thought I whistled in the church.
What is more serious is that a lot of hacking info discovered by me was found via my direct hacking of certain servers located in Russia.
I'm sure if any IT Security responsible in any affected country/company/authority affected by Solar Winds hack, would not have trusted blindly any software (update) and digcert, the situation today would have been completely different.
Zeno Sloim
IT-Security Specialist, MSC in Computer Sciences
ex. SAAB Global Network IT-Security Administrator
14 December 2020
13 September 2020
200913 När bankernas drömmar väcks av realiteten
Stefan.Ingves@riksbanken.se
registratorn@riksbank.se
registrator.riksdagsforvaltningen@riksdagen.se
finansdepartementet.registrator@regeringskansliet.se
Referenser:
https://www.fplus.se/ingves-vi-behover-fysiska-kontanter-om-nagot-hander/a/0KEQ6o
https://omniekonomi.se/ingves-vi-behover-fysiska-kontanter-om-nagot-hander/a/x3RgkV
https://www.bloomberg.com/news/articles/2020-09-12/sweden-s-cashless-future-reveals-a-whole-world-of-hidden-risks
https://zenosloim.blogspot.com/2018/11/181107-swedish-digital-bank-id-hacked.html
https://zenosloim.blogspot.com/2019/09/190912-latest-attack-vector-on-digital.html
https://zenosloim.blogspot.com/2020/01/200105-swedish-people-lose-swedish.html
Det verkar som att varken Linux eller Python, Java och C++ kan ersätta elström och fungerande internet, för att garantera ett fungerande ekonomi och normal handel för Sveriges befolkning.
För en tid sedan och fortfarande, fanns det gott om "snillar" inom Linux, Java och Python, som påstod att kontanter ska försvinna och digitaliseringen ska ersätta allt.
Idéen var mest omtyckt av bankernas direktörer samt om de flesta affärsägare som påstod att kostnaderna för kontanthantering och rånriskerna blivit alldelles för höga.
Stackars Securitas personal, riskerade massarbetslöshet.
Men tack vare en allt mer aggressivt Ryssland och Kina, insåg de ansvariga på Riksbanken att internationella politiska konflikter och cyberattacker kan göra ännu mera skador och ingen snille i världen eller Sverige kan använda Linux eller Java och Python för att ersätta elström och fungerande internet.
Men som bankdirektörerna drömt, total digitalisering kan fortfarande bli sambo med en kompromiss lösning.
Man kan fortfarande eliminera kontanterna.
Hur?
Enkelt.
Förse alla affärsinnehavare med pappersregister som på 1900 och som fortfarande finns i Afrika eller Mellanöstern.
Ifall om elström eller internet är borta pga krig, kriser, cyberattacker...och dylikt, alla transaktioner registreras med penna på papper i pappersregistret.
När allt blir normalt igen, alla pappersregistrar lämnas in till bankerna, och bankernas personal kan skanna in och uppdatera alla konton och transaktioner.
Behövs ej längre någon Securitas, eftersom ingen vore intresserad att stjäla pappersregistrarna.
Så, vi ej längre behöver kontanter.
Bara pappersregistrar.
Smart?
Hälsningar till alla "snillar" i Linux, Java och Python, oavsett om de arbetar på Riksbanken, Finansdepartementet, FRA eller MUST.
Mvh
Zeno Sloim
05 January 2020
200105 Swedish people lose, Swedish Banks profits, when 'naive technocrats' try to eliminate Swedish Krona as bank-notes and coins
The past years "fight" of "naive technocrats" to totally eliminate Swedish Krona on bank-notes and coins, has just received their first cold shower when Swedish Government decided to adopt the law that imposes all Swedish banks to assure normal Swedish Krona bank-notes for all people of Sweden.
The frenezy with digital e-krona and elimination of Cash has received a serious blow.
The Swedish Government also recognized the huge risks associated with elimination of normal bank-notes and coins, in case of international conflicts and natural disasters.
My previous warning articles addressed to the Swedish State, have been read and understood.
See:
190912 Latest attack vector on digital payment systems
https://zenosloim.blogspot.com/2019/09/190912-latest-attack-vector-on-digital.html
181107 - Swedish Digital Bank-ID hacked again - How secure is e-krona - open letter to the Swedish State
https://zenosloim.blogspot.com/2018/11/181107-swedish-digital-bank-id-hacked.html
But recent decision of Swedish Government comes a bit too late, after enough damage already done on the international credibility of Swedish Krona.
The result of the inconsistent policy regarding future of Swedish Krona has dropped the credibility for the Swedish Krona internationally, more exactly,
most foreign banks from non-euro area, no longer accept the Swedish Krona.
Swedish people travelling abroad in non-euro countries, are losing in average about 30% of their money, when exchanging swedish crowns to national valuta of respective country, at all Swedish banks and exchange companies like Forex.
Concrete example: Romania, non-euro European country.
Exchanging to Romanian valuta in Sweden at Swedish banks or Forx, you lose about 30%, compared to exchanging Swedish crowns directly to Romanian valuta, in Romania.
Same situation is valid for all other world countries non-using euro.
In Romania, 3 years ago, all major banks (at least 8) accepted and exchanged directly Swedish crowns.
Nowadays, no bank longer, accepts Swedish crowns, due to fear that Swedish crown will disappear, as a result of the inconsistent and naive policy for eliminating of paper/coin money.
Who is the major loser: all swedish people travelling abroad, many foreign tourists visiting Sweden, all Swedish merchants selling in open markets, not every one affords having a wireless portable payment terminal.
Who profits: Swedish banks and Forex.
Hope only that recent decision of Swedish government will repair and reestablish the lost international credibility for Swedish Krona.
01 November 2019
191101 WhatsApp installs new rootkit - part2 of the story
https://zenosloim.blogspot.com/2019/07/190704-whatsapp-installs-new-rootkit.html
Part 2 of the story continues here:
https://www.theguardian.com/technology/2019/oct/29/whatsapp-sues-israeli-firm-accusing-it-of-hacking-activists-phones
https://www.reuters.com/article/us-facebook-cyber-whatsapp-nsogroup/facebook-sues-israels-nso-group-over-alleged-whatsapp-hack-idUSKBN1X82BE
Kaspersky has done its job.
12 September 2019
190912 Latest attack vector on digital payment systems
Sweden's top military and intelligence community considers Russia as main and closest military and national threat.
The contemporan history of Russian submarines "visit" to Sweden's waters is well-known.
As well as Sweden's preoccupation for Russian military presence in Baltic Sea.
If all above elements were not enough, Russia's latest Orlan drones included in the Leer-3 electronic warfare complex, should be a nightmare.
Why?
Leer-3 electronic warfare system can:
- jam cell phone base stations and act as their substitute.
- can monitor all incoming and outgoing traffic of cell phone stations.
- can remotely plug-in into the base stations and intercept their data flow.
Concrete implications:
- total disruption of Sweden's digital payment systems: almost all payment terminals are using the mobile network and cell-phone base stations
- total disruption of all Bankomat stations, hence no one in Sweden will be able to access own banking account and dispose of own money/cash
- localization and neutralization of any person in Sweden owing a mobile phone, even if phone is closed
In the light of these news, just wonder once again if Riksbanken plans for a so-called "e-krona" is realistic or just "inconscience".
At least, no one yet in Sweden tries or plans to drop the physical Swedish National ID-Card (ID-card, or Driving licence, or Company ID-Card) and replace it with a "mobile phone + Swedish Digital bank-ID".
However, many software developers still "dream" of e-kronan, unhackable and functionally even during military conflicts.
Still a dream imho, because even in near future, no economically sustainable mobile device can be bought by ordinary people.
Actual military communication systems are far too expensive to be accessible in portable form to ordinary citizens.
Forget any crypto system working on a mobile network.
previous reference:
181107 - Swedish Digital Bank-ID hacked again - How secure is e-krona - open letter to the Swedish State:
https://zenosloim.blogspot.com/2018/11/181107-swedish-digital-bank-id-hacked.html
Just "Google" for Orlan Leer-3, and you wil find why.
That is why the physical Swedish National ID-Card will exist for many years ahead.
And hope also for the Swedish "sedel + mynt" krona.
E-krona is a just a nice and naive dream, but in a world full of greed, aggresivity and non-humanism. A "Jungle of animals".
A dream which can easy transform in a nightmare for Swedish people and economy.
29 August 2019
190829 GDPR, Outsourcing and Microsoft Office 365 banned in German schools
04 July 2019
190704 WhatsApp installs new rootkit
09 March 2019
Booz Allen Hamilton Software Reverse Engineering Analyst
07 November 2018
181107 - Swedish Digital Bank-ID hacked again - How secure is e-krona - open letter to the Swedish State
Stefan.Ingves@riksbanken.se
registratorn@riksbank.se
registrator.riksdagsforvaltningen@riksdagen.se
finansdepartementet.registrator@regeringskansliet.se
Reference:
Swedish Digital Bank-ID hacked again:
https://zenosloim.blogspot.com/2018/10/swedish-digital-bank-id-hacked-again.html
Swedish Digital Identification System BankID from Finansiell ID-Teknik BID AB byepassed on Android:
https://zenosloim.blogspot.com/2017/06/170607-swedish-digital-identification.html
In theory Swedish Digital Bank-ID should be unique, impossible to copy or restore on another device (smartphone, tablet, etc.)
In practice, despite permanent updates and higher security requirements, it is still hackable even on latest versions of Android and ... unrooted phones!
Hence the legitimate question: How secure is a non-cash payment system?
Risk factors: international conflicts, cyberwarfare, dependency of foreign powers, all affecting Sweden national independence as a sovereign state.
Above 2 reference articles just want to expose how vulnerable is a non-cash payment system based on Internet traffic, foreign powers and naive trust in completely digitally solutions.
Björn Eriksson already showed the danger of nedmonteringen av kontantsystemet in sk Kontant Uppröret.
All digital payment systems are based on US companies and Swedish private banks totally controlled by big foreign actors.
The duty of Sveriges Riksbank is to protect the interest of Swedish people and Swedish National Interests.
What happens in case of a military conflict or natural disaster which cuts the digital communication lines?
How can Swedbank or Nordea then guarantee a sustainable paying system for all swedish citizens?
How can VISA or Master Card guarantee a working payment system?
How can e-krona exist if communications are disrupted?
How can e-krona be used in foreign countries?
Unpleasant questions.
They all say today cash paying is too expensive! Really? Or todays banks greed is too big and the banking system has become an Overstate inside the State?
The actual banking system is not yet capable of having a 100% secure paying system and 100% secure digital identification system!
Yet the banking system is working fully for a total dependence of The National State versus Banking System!
This is no longer Democracy but a return to early stage of 1800 Capitalism.
It is the duty of Sveriges Riksbank and Swedish Government to guarantee a working all-situations payment system, totally independent from Private Banking System and Foreign powers. Only the existence of cash-payment system can guarantee the same freedom to all swedish ciitzens, independent of external conflicts, cyberwar, greedy foreign actors and states.
It is total madness and inconscience to believe in a cashless paying system, which is totally vulnerable and can make a country to lose its national independence.
Nathan Rothschild: "Give me control of a nation's money and I care not who makes its laws" is more actual than ever.
Zeno Sloim
IT Security Expert
LinkedIn: https://www.linkedin.com/in/zeno-sloim-6121a6136
IT Security Blog: https://zenosloim.blogspot.com/
Twitter: https://twitter.com/ZenoSloim
Email: zeno.sloim@gmail.com
10 October 2018
Swedish digital Bank-ID "hacked" again
Platform was Android 4.x Samsung Note 4 rooted.
Titanium Backup was used for hacking.
I cooperated with the Swedish company Finansiell Bank-ID AB, the developer and maintainer of the product.
The backdoor was corrected by eliminating Android 4.x as accepted OS, demanding at least Android 5.x and using TPM.
Well, it was sufficient for almost 1 year, until now.
Test platform was Android 6.x Samsung Note 4 rooted and Android 8.x Motorola G6 Plus rooted.
Swedbank latest version Android app and Finansiell Bank-ID latest version Android app.
Test was done today 2018-10-10, against Finansiell Bank-ID auth server.
A special modified TWRP recovery was the "tool".
Conclusion:
It seems that new security demands must be asked and following the actual trend:
- SuperSU sold to bogus "chinese" company in USA and abandoned developing
- SuperSU totally eliminated from Google Play
- Huawei no-longer giving bootloader unlocking codes
It seems that it will be a harsh race between Rooting a device and using that device for banking operations or digital authentication.
