Menu

Monthly Archives: December 2016

When a Russian-speaking hacker cracks a US Election website…
News in brief: inflight systems ‘can be hacked’; LA seeks extradition of ‘cyberattacker’; Uber safety fears grow

LinuxSecurity.com: Several security issues were fixed in Samba.

Phishing attack on LA County computers; personal data of 756k people stolen

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low.

Risk Level: Very Low.

Hackers suspected of causing power outage in Ukraine
New Decryptor Unlocks CryptXXX v3 Files
Shadow Brokers are back with ‘stolen NSA cyberweapons’, now 99.9% off
5 technologies that will shake things up in 2017
Yahoo breach: your account is selling for pennies on the dark web
Bad news, fandroids: Mobile banking malware now encrypts files
Hacking airplane entertainment systems
Ukraine Suffers Power Outage Possibly Due to Energy Plant Hack
Christmas pump-and-dump stock spam
Fraudulent Video Ad Bot Rakes in Close to $5 Million Daily
New Linux/Rakos threat: devices and servers under SSH scan (again)

ESET’s Peter Kálnai and Michal Malik report on a new Linux/Rakos threat – devices and servers are under SSH scan again. The post New Linux/Rakos threat: devices and servers under SSH scan (again) appeared first on WeLiveSecurity

Google using Project Wycheproof to scan crypto software for security holes
In-Flight Entertainment System Flaws Put Passenger Data at Risk
How to get more from your security budget
NCSC boss asked to detail efforts to protect financial services sector against cyberattacks

The head of the UK’s NCSC has been asked to offer more detail into how the financial services sector will be protected from cyberattacks. The post NCSC boss asked to detail efforts to protect financial services sector against cyberattacks appeared first on WeLiveSecurity

This is your captain speaking… or is it?
Box won’t say if it’s giving your secrets to the government
Turkey reportedly blocks Tor network nationwide
Financial Data Worth Millions Unwittingly Exposed In Ameriprise Accounts
7 Linux predictions for 2017
Google open-sources test suite to find crypto bugs
Maybe security isn't going to get better after all

One billion-plus accounts stolen in one online heist. The U.S. presidential election messed with by another country. Corporate secrets stolen and released on the internet on a regular basis. More and more data held hostage by ransomware. Stock markets routinely manipulated by hackers. Denial-of-service attacks whacking websites all over the place. Will computer security ever […]

Lawmaker urges regulating Facebook and Google’s algorithms
756,000 individuals at risk after phish of 108 LA County employees
Evolved DNSChanger malware slings evil ads at PCs, hijacks routers

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

Sports blog jocks to crypto-cash nerds – here’s who got pwned

LinuxSecurity.com: Security Report Summary

Cops, Feds spaff $100m on Stingray cellphone snooping gear – and there’s sod all oversight
Protecting Your Online Presence with 3 Simple Tips
ShadowBrokers Dump Came from Internal Code Repository, Insider
Los Angeles to extradite bloke from Nigeria after scores of city workers fall for phish scam
You can now buy hacked NSA tools for Bitcoin 1000
Google Unveils Cryptographic Library Test Suite Wycheproof

Type: Vulnerability. Adobe Flash Player is prone to an unspecified remote code-execution vulnerability; fixes are available.

News in brief: Obama warns Putin on hacking; China to return US drone; lynda.com hacked
Stolen Yahoo Data Sold to Spammers, One Government Client
LinkedIn’s Recent Acquisition Lynda.com Suffers Massive Data Breach

LinuxSecurity.com: This update fixes CVE-2016-9580 and CVE-2016-9581.

LinuxSecurity.com: Rebase to upstream 4.4.3: http://www.freeipa.org/page/Releases/4.4.3 —- -Fixes 1395311 – CVE-2016-9575 ipa: Insufficient permission check in certprofile-mod – Fixes 1370493 – CVE-2016-7030 ipa: DoS attack against kerberized servicesby abusing password policy

LinuxSecurity.com: Security fix for CVE-2016-9957, CVE-2016-9958, CVE-2016-9959, CVE-2016-9960,CVE-2016-9961

LinuxSecurity.com: x86 CMPXCHG8B emulation fails to ignore operand size override [XSA-200,CVE-2016-9932] (#1404262) —- ARM guests may induce host asynchronous abort[XSA-201, CVE-2016-9815,

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for BZ#1401985

LinuxSecurity.com: This release fixes CVE-2016-1249 (out-of-bound read when using server-sideprepared statements) and CVE-2016-1251 vulnerability (a use after free whenusing prepared statements).

LinuxSecurity.com: Security fix for CVE-2016-9844

LinuxSecurity.com: The 4.8.14 stable kernel update contains a number of important fixes across thetree.

LinuxSecurity.com: – Security fix for CVE-2016-8670 – Security fix for CVE-2016-6911 – Security fixfor CVE-2016-7568 – For Fedora 26 disabled two tests – they are failing becauseof freetype 2.7 (https://github.com/libgd/libgd/issues/302,https://github.com/libgd/libgd/issues/217)

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for CVE-2016-9844

Risk Level: Very Low. Type: Trojan.

Insecure NAS Device Exposes 350 Ameriprise Investment Accounts
Germany threatens Facebook with €500,000 fine per fake news post
Cyber insurance brokers: If it makes you feel any better, 2016 was not our year either
US government eyes car-to-car data sharing to improve safety
Akamai buys bot-sniffing startup Cyberfend
Ransomware payouts ‘heading for $1bn a year’
Yahoo’s billion account database for sale on the black market
IoT attacks: 10 things you need to know

IoT attacks are on the rise. As the technology becomes more relevant to our lives, we take a look at what the state of play is. The post IoT attacks: 10 things you need to know appeared first on WeLiveSecurity

PayAsUGym breach exposes passwords
Review: Threat hunting turns the tables on attackers
10 biggest hacks of user data in 2016
Legion’s high-profile Twitter hacks have us looking the wrong way
Bayrob: Romanian auction fraud suspects extradited to the US
Vera for Microsoft protects Office 365 files everywhere
Netgear releases firmware updates for vulnerable routers
Tordow 2.0 Android banking trojan gains root access, mimics ransomware
LinkedIn training arm Lynda.com suffers data breach
FYI! – Your! hacked! Yahoo! account! is! worth! $0.0003!

LinuxSecurity.com: Security Report Summary

security update

LinuxSecurity.com: – update to the new upstream version (50.1.0) – fixed X Window crashes(mozbz#1271100)

LinuxSecurity.com: ARM guests may induce host asynchronous abort [XSA-201, CVE-2016-9815,CVE-2016-9816, CVE-2016-9817, CVE-2016-9818] (#1399747) qemu: Divide by zerovulnerability in cirrus_do_copy (#1399055) [CVE-2016-9921, CVE-2016-9922] Qemu:9pfs: memory leakage via proxy/handle callbacks (#1402278) qemu ioport arrayoverflow [XSA-199, CVE-2016-9637]

New Tech Lets You Use Smartphone, Tablet without Draining their Battery
SQL Injection Attack is Tied to Election Commission Breach
LinkedIn’s training arm resets 55,000 members’ passwords

security update

security update

security update

PCILeech Allows Hacking of Apple Mac Encryption Passcode in Seconds
IoT Nightmare: Wearable Health Gadgets Pose New Kind of Privacy Risks for Users
Hack attack fear scares Canadian exam board away from online tests
KickassTorrents is back as katcr.co domain under its original team
0-days hitting Fedora and Ubuntu open desktops to a world of hurt
The Coolest Hacks Of 2016
‘I told him to cut it out’ – Obama is convinced Putin’s hackers swung the election for Trump

  Who remembers the Atari 2600? Yeah, I don’t either. Just kidding. Maybe. It’s hard to think about the words tech and toys together before the 1990s. However, they were a thing. Kids of the late 70s reveled in the Atari 2600. It became a staple of pop culture—defining a generation of gaming young enthusiasts. […]

Cybersecurity skills gap: it’s big and it’s bad for security

The cybersecurity skills gap is a big problem for organizations struggling to protect rapidly expanding systems from a growing range of threats. We look at how big and what to do about it. The post Cybersecurity skills gap: it’s big and it’s bad for security appeared first on WeLiveSecurity

Houston, we have a problem: ‘App dev stole our radio station’
DDoS Attack by Phantom Squad: EA, Battlefield 1 servers go down
Don’t panic, friends, but the Chinese navy just nicked one of America’s underwater drones