Menu

Monthly Archives: November 2016

Three mobile network experiences data breach

UK mobile company Three has fallen victim to a major data breach, with up to six million customers reported to have been affected. The post Three mobile network experiences data breach appeared first on WeLiveSecurity.

FS.to pirate website shut down after Ukraine’s National Police Raid

Risk Level: Very Low. Type: Trojan.

Mobile phone company 3 in “upgrade intercept scam” data breach
IBM opens ‘cyber-range’ to practice security battles
Office Depot allegedly running in-store tech support scams
Threatpost News Wrap, November 18, 2016
Android banking malware remains active when infected devices sleep to save power
US lawmakers introduce bill to delay enhanced government hacking powers
Without tech industry guidance, U.S. may resort to weakening encryption
iPhones vulnerable to yet another lockscreen bypass
Three to appear in court over TalkTalk hack
NIST shifts focus of security guidance to ‘engineering’
Data breach at Three, millions of customer details potentially exposed
Hackers’ modular worm builder hoses popular team web chat apps
Three Mobile, two alleged hackers, one big customer database heist

test The post test appeared first on Webroot Threat Blog.

The encryption conundrum: Should tech compromise or double down?

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

The solution to security breaches? Kill the human middleware
Google Removing SHA-1 Support in Chrome 56

security update

iOS 10 Passcode Bypass Can Access Photos, Contacts
This $5 hacking tool lets attackers bypass security on locked computers
iPhone Call History Synced to iCloud Without User Consent, Knowledge
WhatsApp to offer encrypted video calling

WhatsApp is to add encrypted video calling to its service on Monday, as it continues to bolsters security on the app. The post WhatsApp to offer encrypted video calling appeared first on WeLiveSecurity.

LinuxSecurity.com: Security Report Summary

BlackNurse revisited: what you need to know
How a $5 Raspberry Pi Zero can hack your locked laptop
Emergency services 4G by 2020? And monkeys could fly out of my butt
Gang Up on the Problem, Not Each Other
Once again, Siri helps attackers bypass your iPhone’s passcode
WindTalker Attack Leaks User Data Using Smartphone’s WiFi Signals
PlayStation users: “Our accounts are being hacked”; Sony denies foul play
Mark Zuckerberg has his Pinterest account hacked (again)
Surveillance cameras most dangerous IoT devices in enterprise
Chinese Android Smartphones Sending Data to China through Secret Software
Barclays mulls letting customers check balances via Facebook
New airline scam promises free Emirates flight tickets

A new airline scam is promising people free Emirates flight tickets if they take part in a “fast survey”, ESET’s Denise Giusto Bilić reports. The post New airline scam promises free Emirates flight tickets appeared first on WeLiveSecurity.

IBM sets up test range to practice fighting cybersecurity battles
America’s Top Spy Talks Snowden Leaks and Our Ominous Future
How To ‘PoisonTap’ A Locked Computer Using A $5 Raspberry Pi
Despite Trump Fears, Snowden Sees a Hopeful Future
Wickedly Clever USB Stick Installs a Backdoor on Locked PCs
How to seek and destroy advanced persistent threats

LinuxSecurity.com: An update for openssl is now available for Red Hat Enterprise Linux 6.2 Advanced Update Support, Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, Red Hat Enterprise Linux 6.5 Telco Extended Update Support, Red Hat Enterprise [More…]

Holding down the Enter key can smash through Linux’s defenses
Hacker’s Mac pwning expedition: ‘Help, I’ve got too many shells!’
PoisonTap fools your PC into thinking the whole internet lives in an rPi

LinuxSecurity.com: A vulnerability in libuv could lead to privilege escalation.

Antivirus tools are a useless box-ticking exercise says Google security chap
Experts to Congress: You must act on IoT security. Congress: Encourage industry to develop best practices, you say?
IBM Opens Attack Simulation Test Center
Mozilla Patches 29 Vulnerabilities, Prevents MIME Confusion Attacks, in Firefox 50

LinuxSecurity.com: – update to new upstream (50.0)

LinuxSecurity.com: The 4.8.7 stable update contains a number of important fixes across the tree.

LinuxSecurity.com: Allow zone size limit (CVE-2016-6170) —- Security fix for CVE-2016-8864

security update

security update

security update

Get root on Linux: learn the secret password

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for 389-ds-base is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for openshift-ansible and ansible is now available for OpenShift Container Platform 3.2 and 3.3. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for atomic-openshift is now available for Red Hat OpenShift Container Platform 3.3. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for rh-php56, rh-php56-php, and rh-php56-php-pear is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for rh-mysql56-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in Xen, the worst of which allows gaining of privileges on the host system.

LinuxSecurity.com: Multiple vulnerabilities have been found in libpng, the worst of which may allow remote attackers to cause Denial of Service.

Regulation May Be Best Answer to IoT Insecurity
PoisonTap Steals Cookies, Drops Backdoors on Password-Protected Computers
WhatsApp tightens user privacy with encrypted video calls
US lawmakers balk at call for IoT security regulations
Concern and confusion over privacy and security of AR technology
Ransoc Desktop Locker Ransomware Scans Social Media Profiles for Exploitation
Evolution of the SSL and TLS protocols
New Ransoc extortionists hunt for actual child abuse material
Shazam for Mac keeps listening, even after you’ve switched it off
Shanghai surprise as cheap Android devices ‘phone home’ to China
Backdoor in some Android phones caught secretly sending data to China
Akamai warns: Look for IoT devices to attack during Thanksgiving, Christmas
Teenager admits to TalkTalk cyberattack

A teenager has admitted being behind last year’s TalkTalk cyberattack, explaining he compromised the company’s website to “show off” to his friends. The post Teenager admits to TalkTalk cyberattack appeared first on WeLiveSecurity.

Analysts apply Occam’s razor to Tesco Bank breach
Gone in 70 seconds: Linux can be owned by holding Enter key
If you can chdir you can hack CA’s Unified Infrastructure Manager

LinuxSecurity.com: An update for nss and nss-util is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.