Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Type: Vulnerability. Microsoft Visual Studio is prone to multiple cross site scripting vulnerabilities; fixes are available.
Type: Vulnerability. Microsoft Silverlight is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft SharePoint is prone to a security-bypass vulnerability; fixes are available.
Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a security-bypass vulnerability; fixes are available.
Type: Vulnerability. Microsoft SharePoint is prone to a security-bypass vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows Remote Desktop Protocol is prone to a security-bypass vulnerability; fixes are available.
Security boundaries in the IT world are changing, porous, often imaginary lines. A security boundary is a demarcation that delineates sovereign or administrative borders that dictate who controls what. Boundary owners are supposed to protect the assets inside their domains against all other unauthorized incursions. Security boundaries are important. Nearly every war is fought over […]
The most fun I’ve had as a security guy was getting paid to penetration-test companies and websites. It’s like getting paid to be a gamer. You earn a fat paycheck to hang out with friends and hack away without fear of being arrested. Most large companies today have multiple teams of professional pen testers, often […]
It’s easier than you think to keep your computer malware and hacker free. Believe it or not, most of today’s computers are pretty safe and secure, whether you’re using Microsoft Windows, Apple OS X, Linux, BSD, or Google’s Chrome OS. Mobile devices are equally as safe, as long as you’re downloading apps from an authorized […]
My wife and I recently returned from one of the best vacations of my life, bareboating around the British Virgin Islands with another couple, when I found we were victims of credit card fraud taking place on the other side of the country. It was a lousy way to end a vacation. Worse, I had […]
I’ve said it before: The No. 1 problem with computer security is poor root-cause analysis, where security pros fail to identify and track the ways an environment was exploited, be it malware or human attack. Common root causes include social engineering, password guessing/cracking, unpatched software, misconfiguration, denial of service, and physical attacks. [ Also on […]
I came to love math later in life. In junior high, I hated it so bad I had to take pre-algebra three times and my parents celebrated if I got a D. But I fell in love with it in my first year of college and I consider the A+ I got in my three-hour […]
As much as I love public key infrastructure (PKI) and the mathematical security it can provide, it’s usually horribly implemented in the real world. If done right, like the inventors intended, it would be darn near perfect. It’s mostly broken because admins don’t deploy it right, software doesn’t enforce what needs to be enforced, and […]
It’s been a raucous few months in crypto circles. In a staid, mathematical world long accustomed to incremental changes, new developments are coming as fast as Chrome browser updates. I’m not sure what’s behind the breaks, but crypto cracking suddenly seems to have accelerated. Here’s a quick roundup of what’s been going down — and […]
The writing is on the wall. The future of computers is less application choice — in exchange for a safer overall computing experience. I’m not talking about a draconian security lockdown. I’m referring to the app stores that have emerged not only for mobile but also for desktop operating systems. OS vendors and their stores […]
Most organizations don’t do enough to educate users about computer security. The main purpose of user education programs is to decrease human-factor risk substantially. If they don’t accomplish that, the whole exercise is a waste of resources. Such programs, if they exist at all, consist of a sort of security orientation program for new employees, […]
Google has banned over 780 million so-called ‘bad ads’ in 2015 alone, explaining that these advertisements have breached the terms of their policies. The post Google bans over 780m ‘bad ads’ to protect online experience appeared first on We Live Security.
Hacking Team exploits and new security features in Google Chrome and Microsoft Edge are just a few of the highlights of ESET’s annual Windows exploitation in 2015 report. The post Windows exploitation in 2015 appeared first on We Live Security.
As Tax Identity Theft Awareness Week in the US gets underway, ESET’s Stephen Cobb offers expert advice on how to protect yourself from fraudsters. The post Tax Identity Theft Awareness Week in the US appeared first on We Live Security.
Having in place a ‘cybersecurity response plan’ is vital if hedge fund managers in London are to deal effectively with this threat. The post Hedge fund managers ‘need a cybersecurity response plan’ appeared first on We Live Security.
Highlights from the last seven days in information security include ESET’s latest trends report (In)security Everywhere and the ongoing cyberattacks against Ukraine’s electric power industry. The post The security review: ESET’s trends for 2016, more attacks in Ukraine and virtualized security appeared first on We Live Security.
For too long streaming video gamers have suffered denial-of-service attacks and raids from police SWAT teams, often assisted by Skype leaking private IP addresses. The post Skype finally hides your IP address, to protect against vengeful gamers appeared first on We Live Security.
More and more retailers are investing technology that allows them to track the movement of shoppers through their smartphone, an expert has revealed. The post Retailers ‘capable of tracking shoppers through smartphones’ appeared first on We Live Security.
It should have been a great week for the Irish Lottery, with the largest jackpot (12 million euros) for 18 months up for grabs. However, things didn’t run entirely smoothly in the run-up to the Wednesday night draw. The post Irish lottery and ticket terminals knocked offline by DDoS attack appeared first on We Live […]
Nuclear facilities across the world have little or no real security mechanisms in place to deal with cyberattacks, according to new analysis. The post Countries remain unprepared for cyberattacks on nuclear facilities appeared first on We Live Security.
ESET has discovered a new wave of cyberattacks attacks against Ukraine’s electric power industry. Interesting, the malware that was used is not BlackEnergy. The post New wave of cyberattacks against Ukrainian power industry appeared first on We Live Security.
LinuxSecurity.com: Update to 2.10.4. Major new features: * New HTTP disk cache for the NetworkProcess. * IndexedDB support. * New Web Inspector UI. * AutomaticScreenServer inhibition when playing fullscreen videos. * Initial Editor API.* Performance improvements. This update addresses the followingvulnerabilities: * CVE-2015-1122 * CVE-2015-1152 * CVE-2015-1155 *CVE-2015-3660 * CVE-2015-3730 * CVE-2015-3738 * CVE-2015-3740 *CVE-2015-3742 […]
LinuxSecurity.com: Sync with latest openssh package.
LinuxSecurity.com: Security update.
LinuxSecurity.com: PV superpage functionality missing sanity checks [XSA-167, CVE-2016-1570] VMX:intercept issue with INVLPG on non-canonical address [XSA-168, CVE-2016-1571]Qemu: pci: null pointer dereference issue CVE-2015-7549 qemu: DoS by infiniteloop in ehci_advance_state CVE-2015-8558 qemu: Heap-based buffer overrun duringVM migration CVE-2015-8666 Qemu: net: vmxnet3: incorrect l2 header validationleads to a crash via assert(2) call CVE-2015-8744 qemu: Support reading […]
LinuxSecurity.com: Patches for CVE-2016-1982,3
LinuxSecurity.com: Update to latest upstream stable release, Linux v4.3.4. Elan touchpad fixes.—- Update to 4.3.y stable series. Fixes across the tree.
LinuxSecurity.com: System administrators are aware as how important their systems security is, not just the runtime of their servers. Intruders, spammers, DDOS attack, crackers, are all out there trying to get into people’s computers, servers and everywhere they can lay hands on and interrupt the normal runtime of services.
LinuxSecurity.com: Thanks so much to Peter Smith for announcing on linuxsecurity.com the release of his Linux Network Security book available free online. “In 2005 I wrote a book on Linux security. 8 years later and the publisher has gone out of business. Now that I’m free from restrictions on reproducing material from the book, I […]
security update
security update
security update
security update
security update
security update
security update
security update
security update
security update
Risk Level: Very Low. Type: Trojan.
Type: Vulnerability. Adobe Flash Player is prone to an unspecified heap-based buffer-overflow vulnerability; fixes are available.
American consumers are more concerned about not knowing how their personal data is collected online than they are about losing their main source of income, new research has found. The post Americans ‘worry more about online privacy than losing main income” appeared first on We Live Security.
Highlights from the past seven days in information security include ESET’s annual Windows exploitation report, analysis of the Bayrob trojan and beating tax identity fraud. The post The security review: Windows exploitation 2015 and Bayrob trojan appeared first on We Live Security.
LinuxSecurity.com: AMERICAN AND BRITISH INTELLIGENCE secretly tapped into live video feeds from Israeli drones and fighter jets, monitoring military operations in Gaza, watching for a potential strike against Iran, and keeping tabs on the drone technology Israel exports around the world.
LinuxSecurity.com: Mike Mimoso talks to privacy and security veteran Jon Callas of Silent Circle about the digital footprint businesses and consumers leave, how to secure our private data, and how a new documentary sponsored by Silent Circle called “Power of Privacy” helps visualize how personal information is shared-and abused-online.
LinuxSecurity.com: It was the talk most anticipated at this year’s inaugural Usenix Enigma security conference in San Francisco and one that even the other speakers were eager to hear.
LinuxSecurity.com: The OpenSSL project has patched a problem in the cryptographic library but one that likely does not affect many popular applications. OpenSSL enables SSL (Secure Sockets Layer) or TLS (Transport Layer Security) encryption. Most websites use it, which is indicated in Web browsers with a padlock symbol.
LinuxSecurity.com: A year after Google’s Chromium Security team proposed marking all HTTP sites which are non-secure, the company is preparing to implement the policy in Chrome.
security update
security update
security update
security update
security update
