Menu

Monthly Archives: October 2016

Cisco Patches Critical Vulnerability in Facility Events Response System

LinuxSecurity.com: New version of jasper is available (jasper-1.900.13). Security fix forCVE-2016-8690, CVE-2016-8691, CVE-2016-8692, CVE-2016-8693.

Datto launches backup and disaster recovery technology to combat ransomware

LinuxSecurity.com: Fixes CVE-2016-7969, CVE-2016-7970 and CVE-2016-7972 —- Update to 0.13.3.Contains various bugfixes.

Microsoft Extends Malicious Macro Protection to Office 2013
DDoS Attack on Dyn: Largest of Its Kind Involving 100,000 Mirai Botnets
Dyn DDoS Could Have Topped 1 Tbps
Keen Lab Takes Down iPhone 6S, Nexus 6P at Mobile Pwn2Own

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Locky Ransomware in Action: Real-World Attack Description
Phishing fraudsters pose as UK bank social media types
Windows Atom Tables Can Be Abused for Code Injection Attacks
Belgian court fines Skype for failing to intercept criminals’ calls in 2012
Sweden bans cameras on drones, deeming it illegal surveillance
How to fight macro malware in Office 2016 and 2013
Facebook hoax: “Live” videos of space walk? Not quite!
Schneider Electric plugs gaping hole in industrial control kit
Conspiracy or cockup? Google hid ProtonMail’s encrypted email service from search results
How Google’s Project Zero made Apple refactor its kernel
PayPal patches bone-headed two factor authentication bypass
Good luck securing ‘things’ when users assume ‘stuff just works’
Hacker’s Icarus machine steals drones midflight
Internet of S**t things claims another scalp: DNS DDoS smashes StarHub
Three LibTIFF bugs found, only two patched
How many Internet of S**t devices knocked out Dyn? Fewer than you may expect
Joomla! squashes critical privileged account creation holes

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Patch Flash NOW
Blue screen of death with a support number? Beware the malware scam

security update

security update

end-of-life

Adobe emits emergency patch for Flash hole malware is exploiting right this minute
Cybercriminals in the health sector put under the microscope
Joomla Update Fixes Two Critical Issues, 2FA Error

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for XXE SVG issue.

LinuxSecurity.com: Security Report Summary

Arrested LinkedIn Hacker Accused of Hacking DropBox, Stealing Bitcoins
Remote Code Execution Vulnerabilities Plague LibTIFF Library
Password1? You’re so random. By which we mean not random at all – UK.gov
Two-factor authentication (2FA) and why we do or don’t use it
Fake Blue Screen of Death faux-freezes your system like the real McCoy
Adobe Patches Flash Zero Day Under Attack
Lawmakers Asking What ISPs Can Do About DDoS Attacks
Election hacking FAQ: 2016 US presidential election edition

Stephen Cobb, senior security researcher at ESET answers the 10 most frequently asked questions on election hacking. The post Election hacking FAQ: 2016 US presidential election edition appeared first on WeLiveSecurity.

AT&T Spies on Customer; Sells Data to the Government: Report
Webcam security: Understanding this modern day threat

Who would have thought that webcams could be exploited? Well, they can, and so serious is the issue, that it has the likes of Mark Zuckerberg covering them with up with tape. The post Webcam security: Understanding this modern day threat appeared first on WeLiveSecurity.

Rise of the IoT machines
Accountant jailed after falling for Nigerian email scammer sexpot
Major Vulnerability Found In Schneider Electric Unity Pro
IoT chickens come home to roost

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

The Hive Mind: When IoT devices go rogue

IoT devices, while extremely useful for simplifying various mundane aspects of everyday life, also offer criminals a new attack platform: your appliances. The post The Hive Mind: When IoT devices go rogue appeared first on WeLiveSecurity.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise MRG 2.5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

Got Ancient exploit but nowhere to use it? Try the horrid GRX network
No, the Jester didn’t hack the Russian Foreign Ministry website
VXer turns to ancient freemium model to flog keylogger, malware tools
This is not a drill: Hackers pop stock Nexus 6P in five minutes
Microsoft Security Essentials Installer Leads to Support Scam Malware
Asterisk users need to patch DoS bug

security update

LinuxSecurity.com: Security fix for XXE SVG issue.

Hacker Selling Hacked IoT Botnet for DDoS Attacks up to 1Tbps
Dyn DDoS Work of Script Kiddies, Not Politically Motivated Hackers
ARM builds up security in the tiniest IoT chips
Every step your phone tracker takes I’ll be watching you
Following Lull, New Campaigns Pushing Retooled ‘Pumpkin’ Locky
Apple Patches iOS Flaw Exploitable by Malicious JPEG

From: Apple Product SecurityReply to list APPLE-SA-2016-10-24-5 watchOS 3.1 watchOS 3.1 is now available and addresses the following: CoreGraphics Available for: All Apple Watch models Impact: Viewing a maliciously crafted JPEG file may lead to arbitrary code execution Description: A memory corruption issue was addressed through improved […]

From: Apple Product SecurityReply to list APPLE-SA-2016-10-24-4 tvOS 10.0.1 tvOS 10.0.1 is now available and addresses the following: CFNetwork Proxies Available for: Apple TV (4th generation) Impact: An attacker in a privileged network position may be able to leak sensitive user information […]

From: Apple Product SecurityReply to list APPLE-SA-2016-10-24-3 Safari 10.0.1 Safari 10.0.1 is now available and addresses the following: WebKit Available for: OS X Yosemite v10.10.5, OS X El Capitan v10.11.6, and macOS Sierra 10.12 Impact: Processing maliciously crafted web content may lead to arbitrary code execution […]

From: Apple Product SecurityReply to list APPLE-SA-2016-10-24-2 macOS Sierra 10.12.1 macOS Sierra 10.12.1 is now available and addresses the following: AppleGraphicsControl Available for: OS X Yosemite v10.10.5 and OS X El Capitan v10.11.6 Impact: An application may be able to execute arbitrary code with kernel privileges […]

From: Apple Product SecurityReply to list APPLE-SA-2016-10-24-1 iOS 10.1 iOS 10.1 is now available and addresses the following: CFNetwork Proxies Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch 6th generation and later Impact: An attacker in a privileged network position may be able to […]

DirtyCOW Linux hole works on Android too – “root at will”
Apple iOS users taste Android anxiety with nasty CoreGraphics image flaw
Millions of Android Devices Vulnerable to DRAMMER Attack
Paging 1994: Crap encryption still rife in devices
Election Leaks Failed to Move Needle on Polls
Find Your Keys, Lose Your Privacy

LinuxSecurity.com: The OpenSSL Project is a collaborative effort to develop a robust, commercial-grade, full-featured Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) protocols as well as a full-strength general purpose cryptography library.

LinuxSecurity.com: New upstream release

LinuxSecurity.com: Security fix for CVE-2016-2774

LinuxSecurity.com: Security fix for CVE-2016-3102. Update to 1.651.1. Fix dangling symlink(rhbz#1330472)

LinuxSecurity.com: Security fix for CVE-2016-3102. Update to 1.651.1. Fix dangling symlink(rhbz#1330472)

LinuxSecurity.com: Security fix for CVE-2016-3102. Update to 1.651.1. Fix dangling symlink(rhbz#1330472)

LinuxSecurity.com: Security fix for CVE-2016-3102. Update to 1.651.1. Fix dangling symlink(rhbz#1330472)

LinuxSecurity.com: phpMyAdmin 4.6.4 (2016-08-16) ============================= This releaseincludes many security fixes of various levels of severity. Upstream recommendsall users upgrade to this release immediately. For full information on thevulnerabilities fixed and mitigation factors for users who are unable toupgrade, refer to the ChangeLog file included with this release and the securityannouncements at https://www.phpmyadmin.net/security/ Aside from the […]

LinuxSecurity.com: Security fix for CVE-2016-3102. Update to 1.651.1. Fix dangling symlink(rhbz#1330472)

LinuxSecurity.com: Security fix for CVE-2016-4855 (#1373374)

LinuxSecurity.com: Security fix for CVE-2016-3102. Update to 1.651.1. Fix dangling symlink(rhbz#1330472)

LinuxSecurity.com: Security fix for CVE-2016-3102. Update to 1.651.1. Fix dangling symlink(rhbz#1330472)

Surveillance by consent: Commissioner launches UK-wide CCTV strategy
Lifting the lid on Sednit: A closer look at the software it uses

ESET’s threat analysts have taken a closer look at the software used by Sednit to spy on its targets and steal confidential information. The post Lifting the lid on Sednit: A closer look at the software it uses appeared first on WeLiveSecurity.

How hackers broke into John Podesta, DNC Gmail accounts