Menu

Monthly Archives: November 2016

Every move you make, every click you take, we’ll be watching you
Telegram API ransomware wrecked three weeks after launch
It’s time: Patch Network Time Protocol before it loses track of time
Signal security revealed: A triple-Diffie-Hellman with a double ratchet

LinuxSecurity.com: An update for memcached is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for memcached is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

Credit cards ripped from Madison Square Garden venues in year-long op
Snail mail thieves feed international identity theft rings say Oz cops
FYI: The FBI is being awfully evasive about its fresh cyber-spy powers
WordPress auto-update server had flaw allowing anyone to add anything to websites worldwide

Risk Level: Very Low. Type: Worm.

$55 surveillance camera hacked by Mirai botnet within 98 seconds
Users Reporting Electronic Arts and PlayStation Servers are Down

security update

security update

Hospital info thief malware puts itself into a coma to avoid IT bods
Despite DDoS attack, Dyn Clinches Acquisition Deal with Oracle
Microsoft Cutting Off SHA-1 Support in February for Edge, IE 11
Black Friday: What to watch out for when you hit the stores

LinuxSecurity.com: New ntp packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

Michigan State University experiences data breach

Michigan State University has experienced a data breach, which it said took place on November 13th. The post Michigan State University experiences data breach appeared first on WeLiveSecurity.

Exploit Code Released for NTP Vulnerability
Scammers Using Images on Facebook Messenger to Drop Locky Ransomware
WordPress Plugins Leave Black Friday Shoppers Vulnerable
Hack the Army: US military begs white hats to sweep it for bugs
DoD Publishes Vulnerability Disclosure Policy
Get Safe Online warns of Amazon email scam

Amazon customers are the latest victims of an email scam, warns Get Safe Online. The post Get Safe Online warns of Amazon email scam appeared first on WeLiveSecurity.

178 arrested in pan-European money mule crackdown
Merkel calls for balanced approach to data protection
Is encrypted e-mail a must in the Trump presidential era?
Your car will be recalled in 2017 thanks to poor open-source security
Siemens-branded CCTV cameras vulnerable to hacking, require urgent firmware patch
Time’s almost out for websites to abandon SHA-1
Moment of truth: Web browsers and the SHA-1 switch

The long-awaited SHA-1 deprecation deadline of Jan. 1, 2017, is almost here. At that point, we’ll all be expected to use SHA-2 instead. So the question is: What is your browser going to do when it encounters a SHA-1 signed digital certificate? We’ll delve into the answers in a minute. But first, let’s review what […]

Siemens-branded CCTV webcams require urgent firmware patch

Your business’s CCTV camera could be coughing up your admin passwords. Patch now, or regret later. The post Siemens-branded CCTV webcams require urgent firmware patch appeared first on WeLiveSecurity.

Irish eyes are crying: Tens of thousands of broadband modems wide open to hijacking

LinuxSecurity.com: A buffer overflow in TestDisk might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A path traversal attack in Tar may lead to the remote execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: A buffer overflow in RPCBind might allow remote attackers to cause a Denial of Service.

LinuxSecurity.com: Multiple vulnerabilities have been found in the Chromium web browser, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Poppler, the worst of which allows remote attackers to execute arbitrary code.

IETF plants privacy test inside DNS
Boffins bake Crysis ransomware’s keys into handy decryptor
Free ‘cyber hugs’ for all is the plan at New Zealand’s first CERT
Office Depot halts PC Health Checks amid bogus infection claims
Surprise! Another insecure web-connected CCTV cam needs fixing
Ask Toolbar Update Feature Hacked to Drop Malware
Microsoft plans St Valentine’s Day massacre for SHA‑1
Even big data devs make big data security gaffes
Backdoor Found in Firmware of Some Android Devices
Office 365 Vulnerability Identified Bogus Microsoft.com Email as Valid
Alternative social network Ello in plaintext password glitch
Anti-virus away! Android banking trojan blocks security apps to evade detection

LinuxSecurity.com: Multiple vulnerabilities have been discovered in MIT Kerberos 5, the worst of which may allow remote attackers to cause Denial of Service.

LinuxSecurity.com: A vulnerability in MongoDB can lead to a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in imlib2, the worst of which allows for the remote execution of arbitrary code.

LinuxSecurity.com: – update to new upstream (50.0)

LinuxSecurity.com: The 4.8.8 stable update contains a number of important fixes across the tree.

LinuxSecurity.com: – update to new upstream (50.0)

LinuxSecurity.com: 3.1.3

LinuxSecurity.com: The 4.8.7 stable kernel update contains a number of important fixes across thetree.

LinuxSecurity.com: Security fix for CVE-2016-6170 —- Security fix for CVE-2016-8864

LinuxSecurity.com: Rebase to 1.5.3 to fix CVE-2016-9243

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Credentials Accessible in Siemens-Branded CCTV Cameras
Privacy boost for iOS users as Mozilla launches Firefox Focus
Nemucod Infections Spreading Over Facebook
AdultFriendFinder waits a week before warning users of security breach
Were your grandparents hacking in 1963?
Time for a fresh look at IAM?
Campaigners bid to delay Rule 41 ‘legal hacking’ bill
Monday review – the hot 16 stories of the week
Symantec doubles down on consumer security by buying LifeLock
The odd, 8-year legacy of the Conficker worm

The Conficker worm was huge news when it emerged towards the end of 2008, exploiting millions of Windows devices. Today, it remains one of the most pervasive malware families around the globe. The post The odd, 8-year legacy of the Conficker worm appeared first on WeLiveSecurity.

LinuxSecurity.com: An update for ipsilon is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

Hackers electrocute selves in quest to turn secure doors inside out
Qualcomm now offering US$15k for security bugs

LinuxSecurity.com: Security Report Summary

Hacker dishes advanced phishing kit to hook clever staff in 10 mins

security update

More Androids carry phone-home firmware
More details emerge regarding the Three data breach

LinuxSecurity.com: Several security issues were fixed in OpenJDK 7.

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

Microsoft’s Color Binoculars App Lets Colorblind People See The Normal Way
Canadian Army Recruitment Site Hacked; Redirected to Chinese Govt Webpage
Surveillance camera compromised in 98 seconds

Alarming Number of Sites Still Using SHA-1 Certificates The January deadline for switching over to SHA-2 rapidly approaching. For the vendors that are still lagging behind, they will begin to see browser warnings to their customers stating the site is untrustworthy for processing sensitive information. Surprisingly, 1/3 of all worldwide sites are still using the […]

security update

security update

Why your password is still important – even if you use multi-factor authentication
Drupal Fixes ‘Moderately Critical’ Vulnerabilities in Core Engine
Gorilla Glue finds itself in sticky situation after hackers steal data
Qualcomm and HackerOne Partner on Bounty Program