Menu

Monthly Archives: February 2016

UK police force hire ‘Britain’s greatest fraudster’ to help tackle cybercrime

Once described as ‘Britain’s greatest online fraudster’, reformed Tony Sales has been hired by West Midlands Police in the UK to help tackle ongoing cybercrime. The post UK police force hire ‘Britain’s greatest fraudster’ to help tackle cybercrime appeared first on We Live Security.

Gozi trojan coder free after being sentenced to time served

Deniss Calovskis, one of the men found to be responsible for the Gozi trojan, is free to return home to Latvia after being sentenced to time served. The post Gozi trojan coder free after being sentenced to time served appeared first on We Live Security.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low.

Risk Level: Very Low. Type: Trojan.

Type: Vulnerability. Microsoft VBScript is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Oracle Java SE is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Adobe Flash Player is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. GNU Bash is prone to remote code execution vulnerability; fixes are available.

Type: Vulnerability. Adobe Flash Player is prone to an unspecified remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

7 easy steps to Internet street smarts

Whether or not you were born in a big city, you quickly learn the rules of walking in congested public areas, full of people who want your money. You learn what areas and which people to avoid. You learn to walk like you know where you’re going and to ignore strangers trying to get your […]

Waste of time or wise investment? Two sides of user security training

I often get in arguments with computer security experts who declare such-and-such computer defense is worthless because it isn’t perfect. No topic exemplifies these types of debates better than the value of user education. On one side, you have people who believe that user education is a crucial part of any computer security defense. The […]

Evil conspiracy? Nope, everyday cyber insecurity

Last Wednesday, the world’s largest stock exchange went down for half a day, the world’s fifth-largest airline grounded its planes for a few hours, and The Wall Street Journal’s home page went missing, all within a few hours of each other. No wonder speculation was rife that a large-scale cyber attack was under way. But […]

In the security world, the good guys aren't always good

Reading about the widespread bribery and corruption of public officials supposedly hired to catch Columbian drug lord Pablo Escobar reminds me of the current state of computer crime. In both instances you have criminal interests making hundreds of millions of dollars while the very entities that could easily bring them down only watch or, even […]

4 fatal problems with PKI

I’m a huge PKI (public key infrastructure) fan. I love the beauty of the mathematics and cryptography. I love its myriad uses and scenarios. I’ve been installing PKIs for private and public companies for over two decades. That’s always been a big part of my job, and lately, it seems like that’s all I’ve been […]

Employees face penalties for ‘misinterpreting security policies’

Corporations will take a much tougher approach to insider security threats by penalizing employees who “invite a data breach”, according to a new survey. The post Employees face penalties for ‘misinterpreting security policies’ appeared first on We Live Security.

Global operation against DD4BC results in arrests

European countries have joined the fight against DD4BC, as part of a global response against the cybercriminal organization, resulting in arrests. The post Global operation against DD4BC results in arrests appeared first on We Live Security.

Security holes found in Windows, Office, Internet Explorer, Adobe… Start patching now!

Critical security patches have been released for Microsoft and Adobe products. Have you installed them yet? The post Security holes found in Windows, Office, Internet Explorer, Adobe… Start patching now! appeared first on We Live Security.

Operational technology ‘susceptible to remote attacks’

Reid Wightman, a security researcher, has discovered that internet-connected operational technology can ‘easily’ be attacked and damaged. The post Operational technology ‘susceptible to remote attacks’ appeared first on We Live Security.

Data thieves ‘need to be handed tougher sentences’

Data thieves need to receive tougher sentences, says Christopher Graham, the UK’s information commissioner, as this will be a more effective deterrent. The post Data thieves ‘need to be handed tougher sentences’ appeared first on We Live Security.

What does Fitbit hacking mean for wearables and IoT?

Wearable activity tracking devices like those made by Fitbit were one of the hottest gifts this past holiday season and it appears criminal hackers were paying attention, ESET’s Stephen Cobb reports. The post What does Fitbit hacking mean for wearables and IoT? appeared first on We Live Security.

Microsoft ends support for old Internet Explorer versions

With more of a whimper than a bang, Microsoft has followed up on its August 2014 promise to end support for older versions of Internet Explorer. As of today (January 12th, 2016), Microsoft will end support and security updates for several versions of Internet Explorer running on various versions of Windows. The post Microsoft ends […]

Your smartwatch may be revealing your card’s PIN code

Wearable devices bring us a whole world of technological innovation, yet at the same time it appears as though they also bring with them a serious security risk. The post Your smartwatch may be revealing your card’s PIN code appeared first on We Live Security.

CES 2016: Day 3 – the drones are back (but with augmented reality)

The final instalment in Cameron Camp’s security-focused coverage of CES 2016, looks at the future of drones. It’s all about augmented reality. The post CES 2016: Day 3 – the drones are back (but with augmented reality) appeared first on We Live Security.

BlackEnergy and the Ukrainian power outage: What we really know

Robert Lipovsky, a senior malware researcher at ESET, offers his expert insight into the recent discovery of BlackEnergy malware in Ukrainian energy distribution companies. The post BlackEnergy and the Ukrainian power outage: What we really know appeared first on We Live Security.

security update

security update

7 signs your network is being hacked
Amazon eases Web encryption with AWS Certificate Manager
Now raging: The 3 cloud battles that matter most
2015's biggest data breaches: Were you a victim?

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low.

Risk Level: Very Low. Type: Trojan.

Risk Level: Low. Type: Worm.

Risk Level: Very Low. Type: Virus, Worm.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft DirectShow is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Know your threats before you deploy defenses

Only in the computer security world would I get taken to task for saying the defenses you apply should be directly related to the threats you face. That’s exactly what happened after I posted “The No. 1 problem with computer security” last week. Several readers wrote to tell me how stupid I was for not […]

The No. 1 problem with computer security

I’ve been in the computer security field for nearly three decades. During that time, I’ve watched it go from bad to worse to ugly. Today, the average computer security defense is so bad, we had to invent a new paradigm a few years ago called “assume breach.” This phrase admits that our security controls are […]

American ingenuity: Why the U.S. has the best hackers

Be scared! The Russians are attacking us. If it’s not the Russians, it’s the Chinese — or maybe the North Koreans. Yes, foreign governments are attacking us. But we’re also attacking them. It’s spycraft as usual. The U.S. government and the media’s continued warnings about who is hacking us reminds me of a womanizing cheat […]

Catch attackers even when they don't use malware

A big paradigm shift is under way in the malware world. Less malware is being used in the biggest, most sophisticated attacks. Instead, malicious intruders are using the legitimate tools built into various operating systems to do their dirty work. Legitimate tools, including remote management tools and scripting engines, are far harder to detect than […]

How to stop your DNS server from being hijacked

It seems like ancient history now, but in the early decades of the Internet we had huge problem: Our email servers were too friendly. In a nutshell, most email servers allowed anyone to connect to them and send email to anyone else. You didn’t have to be a user of that email server, though sometimes […]

Bulletproof admin boxes beat the toughest hackers

Persistent hackers have a common means of taking over company networks: They compromise one or more enterprise users using social engineering. Either they’ve already compromised a website the user visits or they send a phishing email, which asks for enterprise credentials. If the user visits a compromised website, usually a malicious script will probe the […]

9 steps to make you completely anonymous online

I’m still in shock over the Ashley Madison hack, which exposed more than 37 million users. No, my name and email address are not on the list. No, I’m not morally outraged over the number of people who were either lying to a significant other or hoping to have a liaison with someone lying to […]

10 years on: 5 big changes to computer security

This post marks my 10th year writing for InfoWorld magazine. I became a regular writer for InfoWorld by being, shall we say, persistent — I wasn’t a big fan of InfoWorld’s security coverage at the time and suggested I could do better. Eventually, InfoWorld’s editors agreed, and I’ve been posting here ever since. Frequent readers of […]

Make stolen data worthless

APTs (advanced persistent threats) are tough to detect and stop. Typically, APT attackers break in, survey all the servers on the network, and take what they’ve come for long before they get noticed … if ever. If only there was a way to prevent that stolen data from being used when it left your network. […]

Bug-free code: Another computer security lie

Behavioral psychiatrists say that virtually all people lie. Most are little white lies to protect the feelings of others. Some lies are acts of commission — a deliberate statement of untruth — whereas others are lies of omission. In the latter case, someone tells an absolutely true fact, but leaves out a very important related […]

Metasploit Installation
Metasploit Installation Metasploit is a penetration tool used to test vulnerabilities on systems in a network. Weak areas on the network are found so you [...]
Cryptographic Algorithms
In the field of cryptography, there are many types of cryptographic algorithms, each with their advantages, disadvantages, and uses. Cryptographic [...]
Hacking WEP WiFi
WEP is a common WiFi security algorithm that has been found to have many security flaws. This security algorithm is so weak that it can be hacked in about [...]
Intro to Cryptography
Cryptography is an important topic in computing and network security. Cryptography is the study of secure communication. Cryptography covers many topics [...]
Suricata: The Snort Replacer (Part 3: Rules)
In the previous installment, we configured Suricata and successfully tested it via a simple rule that alerts on ICMP/ping packets being detected. In this [...]
Phony web traffic to cost advertisers $7.2 billion in 2016

Fraudsters are set to hit online advertisers hard this year, costing them $7.2 billion globally as a result of phony web traffic generated by bots, new research has found. The post Phony web traffic to cost advertisers $7.2 billion in 2016 appeared first on We Live Security.

ESET Trends for 2016: Threats keep evolving as security becomes part of our lives

ESET’s Trends for 2016: (In)Security Everywhere report includes a review of the most important events of last year and outlines trends in cybercriminal activity and cyberthreats for 2016. The post ESET Trends for 2016: Threats keep evolving as security becomes part of our lives appeared first on We Live Security.

Managing security in virtualized environments – agent-based or agentless?

Before you jump into the virtualization migration process, there are a few things to consider, like security, explains ESET’s Miguel Angel Mendoza. The post Managing security in virtualized environments – agent-based or agentless? appeared first on We Live Security.

Weak passwords continue to pose huge security threat

People’s choice of passwords continues to be a huge security risk, according to new research. SplashData’s annual Worst Passwords List finds ‘123456’ and ‘password’ continue to be the most common choice. The post Weak passwords continue to pose huge security threat appeared first on We Live Security.

‘Context’ shapes American attitudes towards privacy

A new survey has revealed that when it comes to making a decision on information sharing and privacy, context plays an important part for many Americans. The post ‘Context’ shapes American attitudes towards privacy appeared first on We Live Security.

Twitter goes offline across the globe

Twitter users across the globe have experienced problems with the social network, which was unavailable for between one to two hours. The post Twitter goes offline across the globe appeared first on We Live Security.

Phishing scams spike leads to social engineering campaign

Get Safe Online has launched a major new campaign in the UK to help raise awareness of the dangers of social engineering, as figures suggest more needs to be done to inform the public about this growing nuisance. The post Phishing scams spike leads to social engineering campaign appeared first on We Live Security.

The security review: BlackEnergy, Internet Explorer and Fitbit

Highlights from the past seven days in information security include an analysis of the BlackEnergy trojan and Microsoft’s decision to end support for older versions of Internet Explorer. The post The security review: BlackEnergy, Internet Explorer and Fitbit appeared first on We Live Security.

Legal firms ‘risk compromising data over poor login security’

Firms in the legal sector are at risk of compromising information confidentiality because of poor data practices, according to new research by IS Decisions. The post Legal firms ‘risk compromising data over poor login security’ appeared first on We Live Security.

Online predator busted after being intercepted by tech-savvy mom

An attentive and tech-savvy mom, based in Colonie in New York, has been lauded by the police for helping uncover and bring an online predator to justice. The post Online predator busted after being intercepted by tech-savvy mom appeared first on We Live Security.

security update

security update

security update

security update

security update

security update

security update

security update

security update

security update

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.