Menu

Monthly Archives: February 2016

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Type: Vulnerability. Microsoft Visual Studio is prone to multiple cross site scripting vulnerabilities; fixes are available.

Type: Vulnerability. Microsoft Silverlight is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Remote Desktop Protocol is prone to a security-bypass vulnerability; fixes are available.

27% of all malware variants in history were created in 2015
Harvard study refutes 'going dark' argument against encryption
Cisco's CTO charts a new direction
Data destruction 101: There's more to it than wiping your drive
Cisco patches authentication, denial-of-service, NTP flaws in many products
Over 113 million health records breached in 2015 — up 10-fold from 2014
Dumb passwords: The 2016 Oscars Edition
U.S. Congress to federal agencies: You have two weeks to tally your backdoored Juniper kit
8 tips for recruiting cyber security talent
Critical vulnerabilities patched in Magento e-commerce platform
Thousands of gamers' passwords easily cracked in 3 minutes
LinuxSecurity.com: Every year SplashData releases a list of the world’s worst passwords, and for the last five years that list hasn’t changed [...]
Magento update fixes critical XSS flaws
LinuxSecurity.com: Magento has released new security patches designed to plug a number of critical XSS vulnerabilities.
NMAP PING and UDP Scanning
NMAP PING and UDP Scanning When using NMAP, there are basic scans which are used to find specific information. These scans are the most used by NMAP and [...]
Understanding OpenSSL
OpenSSL (https://www.openssl.org/) is a cryptography library that provides various security tools such as the Transport Layer Security (TLS), Datagram [...]
NMAP Installation and Basics
NMAP Installation and Basics Many System Administrators (Admins) need a way to find security issues on the network and close them. If a security issue is [...]
Creating a Self-Signed Certificate With Python
Writing a web application in Python is easily frustrating, but what’s more troublesome is requiring a self-signed certificate for HTTPS. If [...]
Metasploit: Android Session
Metasploit: Android Session In previous articles, I have covered how to access a Windows system as well as a Linux system. What if you wanted to gain [...]
Metasploit: Linux Session
Metasploit: Linux Session If you have been reading the previous articles, you may be wondering how to access a system and gain control of it. In this [...]
Metasploit: Windows Session
Metasploit: Windows Session If you have been reading the previous articles, you may be wondering how to access a system and gain control of it. In this [...]
Metasploit: Port Use
Metasploit: Port Use Now that we have a better understanding of discovering hosts on the network, finding NetBIOS names and even open ports, we have a [...]
Metasploit: Advanced Discovery
Metasploit: Advanced Discovery Now that we have a basic understanding of discovering hosts on the network, we can look a little deeper into finding more [...]
Metasploit: Basic Discovery
Metasploit: Basic Discovery Discovering the information of computer systems can be a very important aspect of finding vulnerabilities. Keeping systems safe [...]
Why identity is the new security

Security boundaries in the IT world are changing, porous, often imaginary lines. A security boundary is a demarcation that delineates sovereign or administrative borders that dictate who controls what. Boundary owners are supposed to protect the assets inside their domains against all other unauthorized incursions. Security boundaries are important. Nearly every war is fought over […]

Attention, 'red team' hackers: Stay on target

The most fun I’ve had as a security guy was getting paid to penetration-test companies and websites. It’s like getting paid to be a gamer. You earn a fat paycheck to hang out with friends and hack away without fear of being arrested. Most large companies today have multiple teams of professional pen testers, often […]

4 do's and don'ts for safer holiday computing

It’s easier than you think to keep your computer malware and hacker free. Believe it or not, most of today’s computers are pretty safe and secure, whether you’re using Microsoft Windows, Apple OS X, Linux, BSD, or Google’s Chrome OS. Mobile devices are equally as safe, as long as you’re downloading apps from an authorized […]

To catch a thief: Cyber sleuth edition

My wife and I recently returned from one of the best vacations of my life, bareboating around the British Virgin Islands with another couple, when I found we were victims of credit card fraud taking place on the other side of the country. It was a lousy way to end a vacation. Worse, I had […]

7 keys to better risk assessment

I’ve said it before: The No. 1 problem with computer security is poor root-cause analysis, where security pros fail to identify and track the ways an environment was exploited, be it malware or human attack. Common root causes include social engineering, password guessing/cracking, unpatched software, misconfiguration, denial of service, and physical attacks. [ Also on […]

Math to the rescue! Try this novel hacking defense

I came to love math later in life. In junior high, I hated it so bad I had to take pre-algebra three times and my parents celebrated if I got a D. But I fell in love with it in my first year of college and I consider the A+ I got in my three-hour […]

The sorry state of certificate revocation

As much as I love public key infrastructure (PKI) and the mathematical security it can provide, it’s usually horribly implemented in the real world. If done right, like the inventors intended, it would be darn near perfect. It’s mostly broken because admins don’t deploy it right, software doesn’t enforce what needs to be enforced, and […]

Encryption is under siege. Move to SHA-2 now!

It’s been a raucous few months in crypto circles. In a staid, mathematical world long accustomed to incremental changes, new developments are coming as fast as Chrome browser updates. I’m not sure what’s behind the breaks, but crypto cracking suddenly seems to have accelerated. Here’s a quick roundup of what’s been going down — and […]

Freedom or security? Most users have chosen

The writing is on the wall. The future of computers is less application choice — in exchange for a safer overall computing experience. I’m not talking about a draconian security lockdown. I’m referring to the app stores that have emerged not only for mobile but also for desktop operating systems. OS vendors and their stores […]

The most important security question to ask users

Most organizations don’t do enough to educate users about computer security. The main purpose of user education programs is to decrease human-factor risk substantially. If they don’t accomplish that, the whole exercise is a waste of resources. Such programs, if they exist at all, consist of a sort of security orientation program for new employees, […]

Google bans over 780m ‘bad ads’ to protect online experience

Google has banned over 780 million so-called ‘bad ads’ in 2015 alone, explaining that these advertisements have breached the terms of their policies. The post Google bans over 780m ‘bad ads’ to protect online experience appeared first on We Live Security.

Windows exploitation in 2015

Hacking Team exploits and new security features in Google Chrome and Microsoft Edge are just a few of the highlights of ESET’s annual Windows exploitation in 2015 report. The post Windows exploitation in 2015 appeared first on We Live Security.

Tax Identity Theft Awareness Week in the US

As Tax Identity Theft Awareness Week in the US gets underway, ESET’s Stephen Cobb offers expert advice on how to protect yourself from fraudsters. The post Tax Identity Theft Awareness Week in the US appeared first on We Live Security.

Hedge fund managers ‘need a cybersecurity response plan’

Having in place a ‘cybersecurity response plan’ is vital if hedge fund managers in London are to deal effectively with this threat. The post Hedge fund managers ‘need a cybersecurity response plan’ appeared first on We Live Security.

The security review: ESET’s trends for 2016, more attacks in Ukraine and virtualized security

Highlights from the last seven days in information security include ESET’s latest trends report (In)security Everywhere and the ongoing cyberattacks against Ukraine’s electric power industry. The post The security review: ESET’s trends for 2016, more attacks in Ukraine and virtualized security appeared first on We Live Security.

Skype finally hides your IP address, to protect against vengeful gamers

For too long streaming video gamers have suffered denial-of-service attacks and raids from police SWAT teams, often assisted by Skype leaking private IP addresses. The post Skype finally hides your IP address, to protect against vengeful gamers appeared first on We Live Security.

Retailers ‘capable of tracking shoppers through smartphones’

More and more retailers are investing technology that allows them to track the movement of shoppers through their smartphone, an expert has revealed. The post Retailers ‘capable of tracking shoppers through smartphones’ appeared first on We Live Security.

Irish lottery and ticket terminals knocked offline by DDoS attack

It should have been a great week for the Irish Lottery, with the largest jackpot (12 million euros) for 18 months up for grabs. However, things didn’t run entirely smoothly in the run-up to the Wednesday night draw. The post Irish lottery and ticket terminals knocked offline by DDoS attack appeared first on We Live […]

Countries remain unprepared for cyberattacks on nuclear facilities

Nuclear facilities across the world have little or no real security mechanisms in place to deal with cyberattacks, according to new analysis. The post Countries remain unprepared for cyberattacks on nuclear facilities appeared first on We Live Security.

New wave of cyberattacks against Ukrainian power industry

ESET has discovered a new wave of cyberattacks attacks against Ukraine’s electric power industry. Interesting, the malware that was used is not BlackEnergy. The post New wave of cyberattacks against Ukrainian power industry appeared first on We Live Security.

Business email compromise campaigns continue targeting C-level employees despite warnings
So-called “whaling” scams attempt to trick high-ranking financial employees into making large wire transfer payments.Read More
Terror-alert spam targets the Middle East, Canada to spread malware
Cybercriminals spoof law enforcement officials in Dubai, Bahrain, Turkey, and Canada to send terror-alert spear-phishing emails containing [...]
Japanese corporations targeted with active malware spam campaign
Fake emails posing as order confirmations from local Japanese suppliers of printers and components are spreading Infostealer.Shifu. Be aware and be [...]
Scammers quick to capitalize on Ashley Madison breach
Symantec telemetry shows surge in spam messages mentioning Ashley Madison megabreach.Read More
Australians beware: Scammers are impersonating the Australian Taxation Office
Australian tax payers are receiving malicious emails that infect computers with Downloader.Upatre and Infostealer.Dyre. Read More

LinuxSecurity.com: Update to 2.10.4. Major new features: * New HTTP disk cache for the NetworkProcess. * IndexedDB support. * New Web Inspector UI. * AutomaticScreenServer inhibition when playing fullscreen videos. * Initial Editor API.* Performance improvements. This update addresses the followingvulnerabilities: * CVE-2015-1122 * CVE-2015-1152 * CVE-2015-1155 *CVE-2015-3660 * CVE-2015-3730 * CVE-2015-3738 * CVE-2015-3740 *CVE-2015-3742 […]

LinuxSecurity.com: Sync with latest openssh package.

LinuxSecurity.com: Security update.

LinuxSecurity.com: PV superpage functionality missing sanity checks [XSA-167, CVE-2016-1570] VMX:intercept issue with INVLPG on non-canonical address [XSA-168, CVE-2016-1571]Qemu: pci: null pointer dereference issue CVE-2015-7549 qemu: DoS by infiniteloop in ehci_advance_state CVE-2015-8558 qemu: Heap-based buffer overrun duringVM migration CVE-2015-8666 Qemu: net: vmxnet3: incorrect l2 header validationleads to a crash via assert(2) call CVE-2015-8744 qemu: Support reading […]

LinuxSecurity.com: Patches for CVE-2016-1982,3

LinuxSecurity.com: Update to latest upstream stable release, Linux v4.3.4. Elan touchpad fixes.—- Update to 4.3.y stable series. Fixes across the tree.

LinuxSecurity.com: System administrators are aware as how important their systems security is, not just the runtime of their servers. Intruders, spammers, DDOS attack, crackers, are all out there trying to get into people’s computers, servers and everywhere they can lay hands on and interrupt the normal runtime of services.

LinuxSecurity.com: Thanks so much to Peter Smith for announcing on linuxsecurity.com the release of his Linux Network Security book available free online. “In 2005 I wrote a book on Linux security. 8 years later and the publisher has gone out of business. Now that I’m free from restrictions on reproducing material from the book, I […]

security update

security update

security update

security update

security update

security update

security update

security update

security update

security update

The secrets of malware success in the Google Play Store
Never fear, home IT heroes – Sophos has a security solution for you

Risk Level: Very Low. Type: Trojan.

Type: Vulnerability. Adobe Flash Player is prone to an unspecified heap-based buffer-overflow vulnerability; fixes are available.

Americans ‘worry more about online privacy than losing main income”

American consumers are more concerned about not knowing how their personal data is collected online than they are about losing their main source of income, new research has found. The post Americans ‘worry more about online privacy than losing main income” appeared first on We Live Security.

The security review: Windows exploitation 2015 and Bayrob trojan

Highlights from the past seven days in information security include ESET’s annual Windows exploitation report, analysis of the Bayrob trojan and beating tax identity fraud. The post The security review: Windows exploitation 2015 and Bayrob trojan appeared first on We Live Security.

LinuxSecurity.com: AMERICAN AND BRITISH INTELLIGENCE secretly tapped into live video feeds from Israeli drones and fighter jets, monitoring military operations in Gaza, watching for a potential strike against Iran, and keeping tabs on the drone technology Israel exports around the world.

LinuxSecurity.com: Mike Mimoso talks to privacy and security veteran Jon Callas of Silent Circle about the digital footprint businesses and consumers leave, how to secure our private data, and how a new documentary sponsored by Silent Circle called “Power of Privacy” helps visualize how personal information is shared-and abused-online.

LinuxSecurity.com: It was the talk most anticipated at this year’s inaugural Usenix Enigma security conference in San Francisco and one that even the other speakers were eager to hear.

LinuxSecurity.com: The OpenSSL project has patched a problem in the cryptographic library but one that likely does not affect many popular applications. OpenSSL enables SSL (Secure Sockets Layer) or TLS (Transport Layer Security) encryption. Most websites use it, which is indicated in Web browsers with a padlock symbol.

LinuxSecurity.com: A year after Google’s Chromium Security team proposed marking all HTTP sites which are non-secure, the company is preparing to implement the policy in Chrome.

security update

security update

security update

security update

security update

Adblocker blockers move to a whole new level