Menu

Monthly Archives: December 2016

Tordow Banking Trojan – A Grave Threat for Android Users

  Credit card fraud and email scams aren’t the only thing you have to worry about this holiday season. Criminals in the UK are stepping up their game by using radio frequencies to steal cars. Ransomware Uses Credit Card Emails with Infected Attachments A new ransomware variant of Cerber is using fake credit card reports […]

Man accused of taking pics under skirt told by court to share his iPhone Passcode
Third ‘JPMorgan hacker’ arrested as he arrived at JFK
News in brief: Yahoo woes mount; Evernote backs down; ATM fraudster jailed
Banks ‘not doing enough’ to protect against bank-transfer scams
Trump’s security advisor dismisses ‘insignificant’ data-sharing fears
Remote Code Execution Bug Found in Ubuntu Quantal
Nagios Core Patches Root, RCE Vulnerabilities
Apple’s macOS file encryption easily bypassed without the latest fixes
Tales of WordPress Plugin Insecurity Overblown, Researchers Say
Backdoors ‘punish the wrong people’, EU security body warns
DDoS in 2017: Strap yourself in for a bumpy ride
Threatpost News Wrap, December 16, 2016
National Lottery whacked with £3m fine for suspect ticket win
Don’t let cybercriminals ruin Christmas: Beware these 12 threats

With spirits and internet usage at an all time high, there’s no better time for cybercriminals to lure a victim online. Here are 12 threats to be aware of. The post Don’t let cybercriminals ruin Christmas: Beware these 12 threats appeared first on WeLiveSecurity

49% off CyberPower Surge Protector 3-AC Outlet with 2 USB (2.1A) Charging Ports – Deal Alert
US voting machine certification agency probes potential hack
Microsoft to ditch Flash – sort of
5 things you should do following the Yahoo breach
9 lessons from 25 years of Linux kernel development
Trump, tech leaders avoided encryption and surveillance talk at summit
Band of Big Brothers: Meet Trump’s spy team
DNC chief Podesta led to phishing link ‘thanks to a typo’
Shadow Brokers re-emerge, with NSA’s secret exploits for sale

LinuxSecurity.com: Security Report Summary

German infosec agency urges security review after Yahoo! flensing
Ransomware scum face unified white hat army
Macbook seized or stolen? But you’ve set a FileVault password, right? Ha, it’s useless

security update

The Mirai botnet: what it is, what it has done, and how to find out if you’re part of it

LinuxSecurity.com: – update to the new upstream version (50.1.0) – fixed X Window crashes(mozbz#1271100)

LinuxSecurity.com: Update to Chromium 55. Security fix for CVE-2016-5199, CVE-2016-5200,CVE-2016-5201, CVE-2016-5202, CVE-2016-9651, CVE-2016-5208, CVE-2016-5207,CVE-2016-5206, CVE-2016-5205, CVE-2016-5204, CVE-2016-5209, CVE-2016-5203,CVE-2016-5210, CVE-2016-5212, CVE-2016-5211, CVE-2016-5213, CVE-2016-5214,CVE-2016-5216, CVE-2016-5215, CVE-2016-5217, CVE-2016-5218, CVE-2016-5219,CVE-2016-5221, CVE-2016-5220, CVE-2016-5222, CVE-2016-9650, CVE-2016-5223,CVE-2016-5226, CVE-2016-5225, CVE-2016-5224, CVE-2016-9652

LinuxSecurity.com: * Security fix for CVE-2016-9888

LinuxSecurity.com: vmncdec: Sanity-check width/height before using it —- Remove insecure nsfplugin (#1395126)

LinuxSecurity.com: Disable insecure FLX plugin (rhbz#1397441)

Dear hackers, Ubuntu’s app crash reporter will happily execute your evil code on a victim’s box
ThePirateBay and Four Other Websites to be Blocked in Australia

security update

10 Ways to Protect Your WordPress Site You Didn’t Know About

LinuxSecurity.com: – update to the new upstream version (50.1.0) – fixed X Window crashes(mozbz#1271100)

LinuxSecurity.com: Update to Chromium 55. Security fix for CVE-2016-5199, CVE-2016-5200,CVE-2016-5201, CVE-2016-5202, CVE-2016-9651, CVE-2016-5208, CVE-2016-5207,CVE-2016-5206, CVE-2016-5205, CVE-2016-5204, CVE-2016-5209, CVE-2016-5203,CVE-2016-5210, CVE-2016-5212, CVE-2016-5211, CVE-2016-5213, CVE-2016-5214,CVE-2016-5216, CVE-2016-5215, CVE-2016-5217, CVE-2016-5218, CVE-2016-5219,CVE-2016-5221, CVE-2016-5220, CVE-2016-5222, CVE-2016-9650, CVE-2016-5223,CVE-2016-5226, CVE-2016-5225, CVE-2016-5224, CVE-2016-9652

DNSChanger Exploit Kit Hijacks Routers, Not Browsers
Microsoft, Google to Block Flash by Default in Edge, Chrome

LinuxSecurity.com: This updates includes a rebase from tomcat 8.0.38 up to 8.0.39 which resolvesmultiple CVEs: * #1397493 – CVE-2016-6816 CVE-2016-6817 CVE-2016-8735 tomcat:various flaws

LinuxSecurity.com: Apport could be made to run programs as your login if it opened aspecially crafted file.

LinuxSecurity.com: This updates includes a rebase from tomcat 8.0.38 up to 8.0.39 which resolvesmultiple CVEs: * #1397493 – CVE-2016-6816 CVE-2016-6817 CVE-2016-8735 tomcat:various flaws

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: Update LXC to the latest stable version. See[here](https://linuxcontainers.org/lxc/news/) for the list of changes.

LinuxSecurity.com: **Version 1.2.3** – Searching in both contacts and groups when LDAP addressbookwith group_filters option is used – Fix vulnerability in handling of mail()’s5th argument – Fix To: header encoding in mail sent with mail() method (#5475) -Fix flickering of header topline in min-mode (#5426) – Fix bug where folderslist would scroll to top when […]

LinuxSecurity.com: Update LXC to the latest stable version. See[here](https://linuxcontainers.org/lxc/news/) for the list of changes.

Yahoo breach: I’ve closed my account because it used MD5 to hash my password
Yahoo breach: your questions answered in our Facebook Live video
This Malware converts your Computer into a Cryptocurrency Miner

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

IDG Contributor Network: Holiday shopping season and fraud: Not one without the other
Yahoo breach: why does it take so long to tell people about a hack?
News in brief: Ashley Madison fined; Pirate Bay blocked Down Under; drone delivery in 13 minutes
Bug Hunters Prefer Communication Over Compensation
Ashley Madison slammed with $1.6 million fine for devastating data breach
Code Reuse a Peril for Secure Software Development
Alleged upskirter ordered to hand over iPhone passcode by court
Evernote users threaten to quit over new privacy policy – but have already agreed to staff reading their notes
Regulators crack down on Skype and WhatsApp over privacy
StormCloud 2017 – See me speaking in London, January 2017
Yahoo breach: here’s what you need to do
ESET Trends for 2017: Holding security ransom

ESET’s Trends for 2017: Security Held Ransom report includes a review of the most important events of last year and outlines trends in cybercriminal activity and cyberthreats for 2017. The post ESET Trends for 2017: Holding security ransom appeared first on WeLiveSecurity

Yahoo breach means hackers had three years to abuse user accounts
Here’s some questions Congress should ask about the election-related hacks
Yahoo data breach: What you can do

Yahoo has announced that one billion of its user accounts has been affected by a data breach. ESET’s Mark James offers some informative security advice. The post Yahoo data breach: What you can do appeared first on WeLiveSecurity

Yahoo experiences biggest data breach in history: 1 billion affected

Yahoo has experienced the biggest data breach in history, with up to one billion user accounts thought to have been affected by a historic security incident. The post Yahoo experiences biggest data breach in history: 1 billion affected appeared first on WeLiveSecurity

Yahoo hack – a billion reasons to change your email account
Security! experts! slam! Yahoo! management! for! using! old! crypto!
Bluetooth-enabled safe lock popped after attackers win PINs
BlackEnergy power plant hackers target Ukrainian banks
Popcorn Time ransomware lets you off if you infect two other people
Yahoo Discloses Data From 1 Billion Accounts Stolen in 2013

security update

Yahoo reports massive data breach involving 1 billion accounts
Yahoo hacked; More than 1 billion user accounts impacted
Yahoo! says! hackers! stole! ONE! BEELLION! user! accounts!
Give us encrypted camera storage, please – filmmakers, journos
Bye, privacy: Evernote will let its employees read your notes

security update

LinuxSecurity.com: This updates includes a rebase from tomcat 8.0.38 up to 8.0.39 which resolvesmultiple CVEs: * #1397493 – CVE-2016-6816 CVE-2016-6817 CVE-2016-8735 tomcat:various flaws

These 26 brand new Android smartphones come with malware pre-installed
FBI Bust Indian Student for Conducting DDoS Attacks on a Chat Site

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to an information-disclosure vulnerability; fixes are available.