Menu

Monthly Archives: December 2016

Type: Vulnerability. Microsoft Office is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Infosec bods: This is a backdoor in Skype for Macs. Microsoft: No.
Mirai Giving DDoS-as-a-Service Industry a Boost
Google Discloses Contents of Eight National Security Letters
News in brief: Uber goes driverless in SFO; Skype on macOS; 2016’s breaches tallied; encryption call for cameras

LinuxSecurity.com: Security Report Summary

Apple Fixes 97 Vulnerabilities Across macOS, iTunes, Safari, iCloud
Flash Player Bug An Eavesdropper’s Delight
Meet “Legion Hacking Group” Hacking Bigwigs of India
Millions of websites at risk, as Joomla high level security flaw discovered. Update now
New York exhibition puts us – and our data – on display
Macs get critical updates, including patches against drive-by malware
Smart devices abandoned on the road to nowhere
Pythonic code review
Low-cost Android Smartphones Shipped with Malicious Firmware
SamB spreads the message about surveillance via rap
Ray-Bans out, Uggs in: Holiday season scam plagues social media

A new holiday season scam campaign is plaguing social media – and this time it’s pretending to sell heavily discounted Uggs, reports ESET’s Ondrej Kubovič. The post Ray-Bans out, Uggs in: Holiday season scam plagues social media appeared first on WeLiveSecurity

TalkTalk’s hacker (and blackmailer) pleads guilty
Law Enforcement Targets Users of DDoS-For-Hire Services
Google publishes national security letters for the first time
Teenager’s phone confiscated for TalkTalk cyberattack offenses

A 17-year-old who pleaded guilty to offenses relating to 2015’s TalkTalk cyberattack has had his iPhone confiscated and been sentenced to a 12-month rehabilitation order. The post Teenager’s phone confiscated for TalkTalk cyberattack offenses appeared first on WeLiveSecurity

Windows 10 Creators Update steps up your security response
Uber ‘God View’ allowed staff to spy on high-profile politicians, ex-partners and Beyoncé, court hears
Persistent ad and dialler trojans found on 28 Android phones
A single typo may have tipped US election Trump’s way
Netgear router remote control bug – what you need to know
Uber-creepy: Dial-a-ride devs accused of stalking pop diva Beyonce
Reschedule the holiday party, Patch Tuesday is here and it’s a big one
Zcash Spurs Rash of Malicious Mining Software
Pre-rolled stripped, hardened Copperhead Androids hit Oz, NZ
Snowden: Donald Trump could get pal Putin to kick me out of Russia
Beta Firmware Updates Available for Vulnerable Netgear Routers
Facebook tool helps find malicious SSL certificates
Microsoft Patches Publicly Disclosed IE, Edge Vulnerabilities
KFC’s Colonel’s Club card Scheme Hacked, 1.2million Members Impacted
Apple ships iOS 10.2, fixes “Find my iPhone hole” plus 5 lockscreen bugs
Spectacular $81m bank cyberheist ‘was not a one-off’
Adobe Patches 31 Vulnerabilities, Flash Zero-Day Under Attack
News in brief: fowl play; Google moves into Cuba; teen hacker sentenced
Leading Clinical Laboratory Services Provider Suffers Massive Data Breach
KFC Warns 1.2 Million UK Customers of Colonel’s Club Breach
The rise of TeleBots: Analyzing disruptive KillDisk attacks

ESET’s Anton Cherepanov analyzes the work of TeleBots, a malicious toolset that was used in focused cyberattacks against targets in Ukraine’s financial sector. The post The rise of TeleBots: Analyzing disruptive KillDisk attacks appeared first on WeLiveSecurity

Netgear starts patching routers affected by a critical flaw
Don’t let your former IT staff sabotage your company
DDoS-for-hire takedown! 34 arrests made by Europol, FBI, and others
Nymaim using MAC addresses to uncover virtual environments and bypass antivirus
TalkTalk hacker gets iPhone taken away by Norwich Youth Court
US-CERT warns Netgear routers can be easily exploited

It has not been a good year for the internet of things, security-wise. The latest IoT devices found vulnerable to trivial exploitation? Netgear routers. The post US-CERT warns Netgear routers can be easily exploited appeared first on WeLiveSecurity

Facebook Releases Free Certificate Transparency Monitoring Tool

  Managed service providers are tasked with serving a broad range of markets, from construction to healthcare; accounting to legal; staffing firms to manufacturing; media and advertising to technology. But the day-to-day MSP challenges, even across so many diverse verticals, remain the same. Let’s break it down: modern technology changes fast and keeps gaining momentum, […]

NWH Hacker Steals 30,000 Passport Records from Russian Consulate Website
Nearly half of all websites pose security risks
Distributed Guessing Attack can ‘compromise Visa cards in just six seconds’

A new study from Newcastle University in the UK suggests that cybercriminals can access online banking details of any Visa card through a so-called Distributed Guessing Attack. The post Distributed Guessing Attack can ‘compromise Visa cards in just six seconds’ appeared first on WeLiveSecurity

Despite costly attacks, 85% of business leaders confident in preparedness
Cybersecurity skills aren’t being taught in college
Politics bog down US response to election hacks
Op-ed: I’m throwing in the towel on PGP, and I work in security
Dozens arrested in international DDoS-for-hire crackdown
Three serious Linux kernel security holes patched
Security by design for mobile device manufacturers

ESET’s Cameron Camp takes a closer look at security by design for mobile device manufacturers, assessing where we are and where we are heading. The post Security by design for mobile device manufacturers appeared first on WeLiveSecurity

Too many contractors spoil the business

As a traveling computer security consultant for over 20 years, I’ve had the chance to visit a lot of different operations and see what works and doesn’t work. I’m always looking for common denominators for successes and failures, and I share these lessons as I learn them. But I realize I’ve unconsciously absorbed one home […]

LinuxSecurity.com: Multiple vulnerabilities have been found in Node.js, the worst of which can allow remote attackers to cause Denial of Service conditions.

LinuxSecurity.com: Multiple vulnerabilities have been found in WebKitGTK+, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Zabbix, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in WebKitGTK+, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Multiple vulnerabilities have been found in Botan, the worst of which allows remote attackers to execute arbitrary code.

P0wnographer finds remote code exec bug in McAfee enterprise

LinuxSecurity.com: Multiple vulnerabilities have been found in SQUASHFS, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: A vulnerability in Bash could potentially lead to arbitrary code execution.

LinuxSecurity.com: A buffer overflow in Pixman might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: An integer overflow in TigerVNC might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability in XStream may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in systemd, the worst of which may allow execution of arbitrary code.

Fan of KFC? Here’s some finger-licking good advice for your password: Change it now
Popcorn Time ransomware invites you to get ‘nasty’ to recover your files
SamSa ransomware devs rake in $450,000 in a year
US-CERT’s top tip: Hack your crap Netgear router before miscreants arrive

security update

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.