Menu

Monthly Archives: December 2016

Russian Malware Found in Vermont Electricity Department Laptop
Anonymous Hacks, Defaces Bilderberg Group Website Against World Crisis

security update

OurMine Group Hacks Nat Geo Photography’s Twitter Account
New Malware Poses as Android Client to Infect Wi-Fi Networks and Hijack DNS
FBI-DHS Report Links Fancy Bear Gang to Election Hacks
News in brief: US raps Russian hacking; internet clampdowns ‘cost $2.4bn’; AR move to track lost items
Pakistan automotive giant PakWheels Hacked, 700k accounts stolen
Uber, Apple Maps and location tracking: what’s really going on?
Hedge fund turns to AI to navigate through the maze
Lithuania says Russian spyware infected government computers

  Ransomware “Star” Shines on LG Smart TV As ransomware continues to steal the malware stage, its authors have widened their target audience to include smart devices, such as TVs. Since a number of smart TVs use Android® operating systems, they can be susceptible to the same Android malware that usually strikes mobile devices. Recently, […]

The 10 biggest security incidents of 2016

In 2016, companies have had their security solutions tested by increasingly sophisticated cybercriminals. We look at the year’s biggest security incidents. The post The 10 biggest security incidents of 2016 appeared first on WeLiveSecurity

In deep: the internet’s underwater weak links
What 2017 has in store for cybersecurity
The shocking failure in how the FBI warned the DNC that it had been hacked
Obama expels 35 Russian spies over election hacking
Who helped Russia “hack” the US election? It might have been you…
Beware: Facebook collects data about your offline life through data brokers

Why wait for news on the next big thing in technology, when you can get a sneak peek at the hottest, up-and-coming consumer tech and innovations at CES 2017? For the last 50 years, the yearly CES event has served as a showcase and springboard for the latest advancements in tech as they enter the […]

Anonymous Hacks Thai LA Consulate to Protest Arrests and Cyber Law

LinuxSecurity.com: A vulnerability in mod_wsgi could lead to privilege escalation.

Retailers! Avoid getting hacked during the holiday season (or any other time of the year)

Tips for cash-strapped retailers looking to avoid getting hacked, during the holiday shopping season, or any other season. The post Retailers! Avoid getting hacked during the holiday season (or any other time of the year) appeared first on WeLiveSecurity

PHPMailer, SwiftMailer Updates Resolve Critical Remote Code Execution Vulnerabilities
Microsoft May Stop Forcing You to Upgrade to Windows 10
News in brief: marijuana breach; Amazon moots airships; Firefox winds down for XP, Vista
Threatpost 2016 Year in Review
Your new year’s resolution: get ready for GDPR
Meet the Leet DDoS Botnet, Just as Powerful as Mirai
Sultry Sextortion Sisters Meet Their Match In Nigerian Oil Billionaire
Welcome to America. Now, what’s your Twitter handle?
Guest post: Whose genes are they anyway?
5 signs we’re finally getting our act together on security
5 key technologies to double down on now

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: New python packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: New samba packages are available for Slackware 14.2 and -current to fix security issues. [More Info…]

LinuxSecurity.com: Update to 2.2.4 with backport for XSS vulnerability.

LinuxSecurity.com: Update to latest jquery1 stable, with backport fix for XSS vulnerability.)

LinuxSecurity.com: This update adds security sandboxing to tracker-extract.

LinuxSecurity.com: Update to latest jquery1 stable, with backport fix for XSS vulnerability.)

LinuxSecurity.com: fix for “TLS SecurityMode.required bypass via StripTLS attack”(rhbz#1406703,1406704)

security update

LG Smart TV Screen Bricked After Android Ransomware Infection
How to Choose the Perfect Laptop for Online Study
Someone DDoSed ExtraTorrent Domain while ThePirateBay suffered downtime

LinuxSecurity.com: * Mon Dec 12 2016 Norvald H. Ryeng – 5.7.17-1 -Update to MySQL 5.7.17, for various fixes described athttps://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-17.html – Add newplugin: connnection_control.so – Add MySQL Group Replication:group_replication.so – Add numactl-devel to buildreq and enable NUMA support (ifavailable) – Simplify boost path – Build compat-openssl10 in rawhide for now -Reqs. in -devel packages was […]

LinuxSecurity.com: Updated to 2.1.4

LinuxSecurity.com: This update contains a **SECURITY** fix for an issue with potentially seriousconsequences but very limited scope. If an administrator of a wiki you talked tousing python-wikitcms were malicious, they could cause arbitrary code executionas the user running wikitcms. No-one besides a wiki administrator could do this,as it requires crafting the wiki’s response to an […]

LinuxSecurity.com: Updated to 2.1.4

LinuxSecurity.com: This update contains a **SECURITY** fix for an issue with potentially seriousconsequences but very limited scope. If an administrator of a wiki you talked tousing python-wikitcms were malicious, they could cause arbitrary code executionas the user running wikitcms. No-one besides a wiki administrator could do this,as it requires crafting the wiki’s response to an […]

LinuxSecurity.com: Update to 2.2.4 with backport for XSS vulnerability.

LinuxSecurity.com: Security fix for CVE-2016-4330, CVE-2016-4331, CVE-2016-4332, CVE-2016-4333

LinuxSecurity.com: two security flaws (#1406840) x86 PV guests may be able to mask interrupts[XSA-202, CVE-2016-10024] x86: missing NULL pointer check in VMFUNC emulation[XSA-203, CVE-2016-10025] x86: Mishandling of SYSCALL singlestep duringemulation [XSA-204, CVE-2016-10013] (#1406260)

LinuxSecurity.com: * Mon Dec 12 2016 Norvald H. Ryeng – 5.7.17-1 -Update to MySQL 5.7.17, for various fixes described athttps://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-17.html – Add newplugin: connnection_control.so – Add MySQL Group Replication:group_replication.so – Add numactl-devel to buildreq and enable NUMA support (ifavailable) – Simplify boost path – Build compat-openssl10 in rawhide for now -Reqs. in -devel packages was […]

LinuxSecurity.com: – fix floating point buffer overflow issues (CVE-2016-9586)

News in brief: Amazon asked for Echo data; Facebook in new fake news row; airline systems ‘insecure’
Three Chinese Hackers Made Millions by Hacking American Law Firms
Mixing biology with technology: what could possibly go wrong?
‘Meltdown’ over international cybersecurity agreement
Leaked info confirms in-house hacking capabilities of Israeli firm Cellebrite
Thai Police Arrest 9 Suspects Behind Cyber Attacks on Gov’t Sites
US Immigration asking foreign travelers for their social media account details
Four New Normals for 2017
Weekly review – the hot 28 stories of the past week
Trio charged with $4m insider trading by hacking merger lawyers
How Microsoft will drive enterprise IT in 2017
Encryption in 2016: Small victories add up
Android Trojan Switcher Infects Routers via DNS Hijacking
What is encryption and how does it work?

It has become one of the most topical and discussed topics in information security in recent times. In this video we outline some of the key aspects of encryption. The post What is encryption and how does it work? appeared first on WeLiveSecurity

security update

PHPMailer Bug Leaves Millions of Websites Open to Attack

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for CVE-2016-8743, CVE-2016-2161, CVE-2016-0736

LinuxSecurity.com: Security fix for CVE-2016-8743, CVE-2016-2161, CVE-2016-0736

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: New expat packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: New openssh packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: Multiple vulnerabilities have been found in Samba, the worst of which may allow execution of arbitrary code with root privileges.

LinuxSecurity.com: Multiple vulnerabilities have been found in Xerces-C++, the worst of which may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities were found in Tor, the worst of which could allow remote attackers to cause a Denial of Service condition.

The real reason we can't secure the internet

Last week I speculated that the current horrible state of internet security may well be as good as we’re ever going to get. I focused on the technical and historical reasons why I believe that to be true. Today, I’ll tell you why I’m convinced that, even if we were able to solve the technical […]

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Firejail, the worst of which may allow bypassing of sandbox protection.

15% off Nest Cam Indoor Security Camera – Deal Alert
A year in infosec: Bears, botnets, breaches … and elections

security update

Man Jailed for uploading UK’s Top 40 singles on The Pirate Bay and KickAssTorrents

security update

security update

Tumblr Attackers Now threatening to Ruin Christmas for Xbox Users with DDoS Attacks
Cerber Ransomware Infecting Devices by Exploiting Flaws in Web Browsers

security update

Android-compatible Google Daydream VR Controller Hacked to Run on iOS
Clever Facebook Hack Reveals Private Email Address of Any User
Exim gives Linux admins a security fix for Christmas
Steam and Origin Servers Down? Phantom Squad and PoodleCorp Claim Responsibility

LinuxSecurity.com: ### Botan 1.10.14 ### * NOTE WELL: Botan 1.10.x is supported for securitypatches only until 2017-12-31 * Fix integer overflow during BER decoding, foundby Falko Strenzke. This bug is not thought to be directly exploitable butupgrading ASAP is advised. (CVE-2016-9132) * Fix two cases where (in errorsituations) an exception would be thrown from a […]

LinuxSecurity.com: gdk-pixbuf 2.36.2 release. * Remove the pixdata loader (#776004) * Fixinteger overflows in the jpeg loader (#775218) * Add an external thumbnailerfor images * Fix a NULL pointer dereference (#776026) * Fix a memory leak(#776020) * Support bmp headers with bitmask (#766890) * Add tests for scaling(#80925) * Handle compressed pixdata in resources (#776105) […]