Menu

Monthly Archives: October 2016

LinuxSecurity.com: Security Report Summary

Personal info on more than 58 million people spills onto the web from data slurp biz
Google Handles Record Number of Government Requests for Data
Enjoy taking selfies? That plays right into the hands of this identity-stealing malware…
Clinton campaign official’s Twitter account hijacked: “I’ve switched teams”
Facebook Bug Bounty Program Pays Out $5 Million in Five Years
Popular Bitcoin site hit by DNS attack, loses control of own website
Cisco Patches Critical Bug In Video Conferencing Server Hardware
Clinton campaign chief tweets “Vote Trump”, after his account is hacked
New GCHQ unit: Psst, breached biz bods. We won’t rat you out to the ICO
Beware of the student loan forgiveness scam spam
Trojan.Ascesso has been observed trying to send out thousands of student loan forgiveness scam emails. Read More
Hacker grabs over 58 million customer records from data storage firm
How CSOs can better manage third-party risks
Old SSH Vulnerability at Center of Credential-Stuffing Attacks
Breach exposes at least 58 million accounts, includes names, jobs, and more
US-CERT Cautions Against Phishing Scams In Aftermath Of Hurricane Matthew
Odinaff trojan targets SWIFT users, financial organisations
Why You Should Seriously Care About SSH User Keys
Amazon resets customer passwords, while LeakedSource discloses massive update
A SSHowDowN in security: IoT devices enslaved through 12 year old flaw
Signal, the Cypherpunk App of Choice, Adds Disappearing Messages
US government: Russia behind hacking campaign to disrupt US elections
Facebook, Twitter, Instagram cut off surveillance tool used to track protesters
Vera Bradley alerts customers to data breach

Vera Bradley has notified its customers of a data breach, explaining that it had launched an investigation last month into a “payment card incident”. The post Vera Bradley alerts customers to data breach appeared first on WeLiveSecurity.

Putin denies any Russian interest in alleged US election hacking
Lizard Squad, PoodleCorp members arrested in DDoS-for-hire bust
Time to crack down on sales of dragon’s gold – securobods
Email security: We CAN fix the tech, but what about the humans?
Hackers pop 6000 sites on active 18-month carding bonanza
Carders bag stylish sack shop Vera Bradley
Surge of email attacks using malicious WSF attachments
Ransomware attack groups among the most frequent users of new tactic. Read More

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Vera Bradley Retail Chain Breached
Unsecured MongoDB Database: 58M Business Firm Accounts Leaked

LinuxSecurity.com: Multiple vulnerabilities have been found in BIND, the worst of which could cause a Denial of Service condition.

Disappearing Messages Added to Signal App
Twitter bot baits bullies into meaningless and futile arguments
Gary McGraw on BSIMM7 and Secure Software Development
Phisher arrested for stealing Bitcoins from dark web users
CCTV that lets the crooks watch you, not the other way around…
SAP fixes gaping authentication bypass flaw after 3 YEARS
Enterprises outsmarting themselves with security, while attackers easily use common techniques
Europe loves to pay by bonk* – survey
Yahoo accused of deliberately making it hard to close your account
Online safety tips for social media and IM fans

Since October is European Cyber Security Month, it is a good time to recap on social media and IM security. These online safety tips will do you well. The post Online safety tips for social media and IM fans appeared first on WeLiveSecurity.

Leaky IoT devices help hackers attack e-commerce sites
Decrypt THIS! Ransomware dev taunts security researchers in support forum
12 hardware and software vulnerabilities you should address now
Snowden investigator slams leaker-detector background checks
Singapore slings millions into ASEAN infosec
Adobe on patch parade to march out 83 bugs
Oz infosec spooks: ease back on the “cybers”, this is serious
Hungarian bug-hunters spot 130,000 vulnerable Avtech vid systems on Shodan

security update

Nuclear Power Plant Disrupted by Cyber Attack
Like it or not, here are ALL your October Microsoft patches

security update

Microsoft Patches Five Zero Days Under Attack
Second hacking group targets SWIFT-connected banks
Adobe Fixes 81 Vulnerabilities in Acrobat, Reader, Flash

LinuxSecurity.com: An update for tomcat is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for tomcat6 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: Security Report Summary

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Amazon finds cache of reused passwords: change yours now!
Encrypted communications could have an undetectable backdoor
IoT Botnet Uses HTTP Traffic to DDoS Targets
NHS increasingly being targeted by ransomware attacks

NHS hospitals in England are increasingly being targeted with ransomware attacks, according to an investigation by the i newspaper The post NHS increasingly being targeted by ransomware attacks appeared first on WeLiveSecurity.

$15 million fake IRS call center busted by police
WinRar and TrueCrypt Installer Dropping Malware on Users’ PCs
The EU’s latest idea to secure the Internet of Things? Sticky labels
Yahoo won’t let you forward your emails to another service – but why?
NSA could put undetectable “trapdoors” in millions of crypto keys
Systemd vulnerability crashes Linux systems
Even a Fake Clinton Foundation Hack Can Do Serious Damage
Yahoo wants to spy on you through advertising billboards
WikiLeaks dumps another trove of email, allegedly from Clinton aide
10 decisions you’ll face when deploying a honeypot
Group policies, meet EMM: New and old Windows 10 management unite
<div>10 decisions you'll face when deploying a honeypot</div>

Honeypots provide the best way I know of to detect attackers or unauthorized snoopers inside or outside your organization. For decades I’ve wondered why honeypots weren’t taking off, but they finally seem to be reaching critical mass. I help a growing number of companies implement their first serious honeypots — and the number of vendors […]

LinuxSecurity.com: Multiple vulnerabilities have been found in MySQL and MariaDB, the worst of which could allow remote attackers to cause a Denial of Service condition or obtain sensitive information.

LinuxSecurity.com: Multiple vulnerabilities have been found in Subversion and Serf, the worst of which could lead to execution of arbitrary code.

One-quarter of UK police websites lack a secure connection
Nuke plant has been hacked, says Atomic Energy Agency director

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

Type: Vulnerability. Microsoft Internet Explorer is prone to multiple information-disclosure vulnerabilities; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to an information disclosure vulnerability; fixes are available.