Menu

Monthly Archives: September 2016

Mozilla Wants to Drop WoSign as Trusted CA
OS X devices targeted by APT28 group with new Trojan called Komplex
Yahoo! Mail! down?! Great! timing! as! more! US! senators! dogpile! hacked! web! giant!

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: New openssl packages are available for Slackware 14.2 and -current to fix a security issue. [More Info…]

LinuxSecurity.com: Multiple vulnerabilities have been found in QEMU, the worst of which could lead to arbitrary code execution, or cause a Denial of Service condition.

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: New php packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

Risk Level: Very Low. Type: Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Signal Adds iPhone Access to Desktop App
Facebook Debuts Open Source Detection Tool for Windows
Mamba ransomware strikes at your whole disk, not just your files
New Google Tools Help Devs Improve Content Security Policy Protection
MarsJoke Ransomware Targeting Educational, Government Agencies
Girls’ fashion hangout site leaking millions of plaintext passwords
No wonder we’re being hit by Internet of Things botnets. Ever tried patching a Thing?
Security blogger Krebs says IoT DDoS attack was payback for a blog
College student arrested for allegedly hacking system to change grades
Bug that hit Firefox and Tor browsers was hard to spot-now we know why
Google pulls Krebs on Security out of the abyss
Yahoo’s claim of ‘state-sponsored’ hackers meets with skepticism
New Mac Trojan uses the Russian space program as a front
The hacker’s guide to boosting your ransomware’s brand
Krebs’ website remains online following massive DDoS attack

Brian Krebs’ website appears be to be holding up, following what has been described as “one of the biggest web attacks ever seen”. The post Krebs’ website remains online following massive DDoS attack appeared first on WeLiveSecurity.

A quick fix for stupid password reset questions

It didn’t take 500 million hacked Yahoo accounts to make me hate, hate, hate password reset questions (otherwise known as knowledge-based authentication or KBA). It didn’t help when I heard that password reset questions and answers — which are often identical, required, and reused on other websites — were compromised in that massive hack, too.  […]

152k cameras in 990Gbps record-breaking dual DDoS
Don’t let banks fool you, the blockchain really does have other uses
Google tries to cross out XSS attacks by releasing its own test tool
It’s open season for bug hunting – on Microsoft’s Azure cloud
Daesh-bag hacker gets 20 years for harvesting US military kill list

LinuxSecurity.com: Security Report Summary

Mozilla wants woeful WoSign certs off the list
Suspected Russian DNC hackers brew Mac trojan
Fax machines’ custom Linux allows dial-up hack

security update

Patch AGAIN: OpenSSL security fixes now need their own security fixes
Sofacy APT Targeting OS X Machines with Komplex Trojan
Voters’ Database of 2.9 Million State of Louisiana Natives Leaked Online
Questions Mount Around Yahoo Breach
Hancitor Downloader Abusing APIs, PowerShell Commands
Intel, Lenovo officially gone to the dogs – with FIDO fingerprint logins
Armies of hacked IoT devices launch unprecedented DDoS attacks
MarsJoke Ransomware Targets .EDU, .GOV Agencies
Don’t drill a headphone jack hole into your iPhone 7! It’s a hoax
What Pippa Middleton can teach us about iCloud security

Pippa Middleton is the latest in a long line of celebrities to have her online accounts broken into by criminals, and private photographs stolen. Have you properly secured your iCloud account? The post What Pippa Middleton can teach us about iCloud security appeared first on WeLiveSecurity.

Back to college/university? Don’t take cybercriminals with you!
Immensely Powerful iSpy Keylogger Targets Skype, Webcams and Passwords
Will quantum teleportation defeat quantum decryption?
OpenSSL Fixes Critical Bug Introduced by Latest Update
Don’t have a Yahoo email address and think you’re safe from the hack?
Here’s how Microsoft is using containerization to protect Edge users
Security man Krebs’ website DDoS was powered by hacked Internet of Things botnet
iOS 10 has vulnerability that leads to Cracking of iPhone Backups
Trump hotel chain fined over data breaches
DDoS robots for the masses: IoT security comes of age

IoT security matters more than ever, explains ESET’s Cameron Camp, as the technology, which offers us so much, is vulnerable to attack from cybercriminals. The post DDoS robots for the masses: IoT security comes of age appeared first on WeLiveSecurity.

77% of adblocker users feel guilty about it
Yelp fights court order to remove negative review of law firm
USBee: how to spy on an isolated system with a USB

USBee is a form of “air gap attack”. It uses a USB device to transmit the information the attacker wants to steal at frequencies between 240 and 480Mhz. The post USBee: how to spy on an isolated system with a USB appeared first on WeLiveSecurity.

What’s in your code? Why you need a software bill of materials
Xiny Android trojan evolves to root phones and infect system processes
Apple to crunch iOS 10 local backup password brute force hole
Dev teaches bot to talk spammers’ ears off
Google rushes in where Akamai fears to tread, shields Krebs after world’s-worst DDoS

security update

Dark Net Researcher Says Russian Hackers Attacking Big Companies in US
Armenian Hackers Leak Azerbaijani Banking and Military Data

security update

Hacker gets 20 years in prison for sharing US military data with ISIS

security update

OVH hosting suffers 1Tbps DDoS attack; largest Internet has ever seen
And! it! begins!! Yahoo! sued! over! ultra-hack! of! 500m! accounts!
Satellite Hacking: Star Wars Could be a Reality in the Near Future
Tails 2.6 – Ultra-secure Linux OS Used By Snowden Gets Updated Tor And Kernel
Matthew Garrett Explains How to Increase Security at Boot Time
Krebs on Security booted off Akamai network after DDoS attack proves pricey
IBM botched geo-block designed to save Australia’s census

security update

security update

OpenSSL Patches High-Severity OCSP Bug, Mitigates SWEET32 Attack