Menu

Monthly Archives: December 2016

Type: Vulnerability. Microsoft Internet Explorer is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to an information-disclosure vulnerability; fixes are available.

Risk Level: Very Low. Type: Trojan.

Europol and US authorities bust 34 DDoS attackers and 101 suspects
CIA: Russia hacked election. Trump: I don’t believe it! FAKE NEWS!
Apple Fixes 12 Vulnerabilities in iOS 10.2
Scammers spreading celebrity nude PDFs on Facebook, pushing malware installation
Netgear Routers Remain Exposed to Critical Flaw
Kentucky pried chicken: Fried grease chain’s loyalty club hacked
Alpha Version of Sandboxed Tor Browser Released
Facebook Technical Glitch Making Old Pictures Reappear on Timeline

LinuxSecurity.com: Security fix for CVE-2016-6318

LinuxSecurity.com: This updates adds a patch to fix CVE-2016-9573 and CVE-2016-9572.

LinuxSecurity.com: update

Risk Level: Very Low. Type: Trojan.

Netgear routers have gaping remote access hole
News in brief: Trump scorns ‘meddling’ claims; outdated OS use ‘widespread’; teen ‘hackers’ arrested
DDoS tool encourages users to compete against each other for points
Botched Microsoft update knocks Windows 8, 10 PCs offline – regardless of ISP
German Industrial Giant Victim of Cyber Espionage
An unpatched vulnerability exposes Netgear routers to hacking
Like Jessica Alba? Don’t click Facebook links promising nude photos of her – or anyone else
Security Sessions: Ransomware as a service on the rise
Ransomware with a deal: Infect other computers, get your decryption key
Scammers can trick Microsoft Edge into displaying fake security warnings
Why combining technology with standards could combat fraud

ESET’s Miguel Ángel Mendoza looks at why combining technology with standards could combat fraud. The post Why combining technology with standards could combat fraud appeared first on WeLiveSecurity

DDoS script kiddies are also… actual kiddies, Europol arrests reveal
5 enterprise-related things you can do with blockchain technology today
Trump, tech executives may try to untangle relationship
Give the gift of a social engineering demo this Christmas
Modern attacks on Russian financial institutions

ESET’s Anton Cherepanov Jean-Ian Boutin discuss their paper, titled Modern Attacks on Russian Financial Institutions, which was published earlier this year. The post Modern attacks on Russian financial institutions appeared first on WeLiveSecurity

Finally! A minimum standard for certificate authorities
Spring 2017 sponsorships available
How to secure your Wi-Fi network – the more advanced version
Top tech company’s IP was looted by China, so it plans to hack back
Microsoft Edge’s malware alerts can be faked, researcher says
Melbourne hacker adds padding oracle to free popular hacker course
Germany warns Moscow will splash cash on pre-election propaganda and misinformation spree

Risk Level: Very Low. Type: Trojan.

Ransomware scum offer free decryption if you infect two mates

LinuxSecurity.com: Multiple heap overflows in SoX may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability in Docker could lead to the escalation of privileges.

LinuxSecurity.com: Multiple vulnerabilities have been found in VirtualBox, the worst of which allows local users to escalate privileges.

LinuxSecurity.com: Two vulnerabilities have been found in exFAT allowing remote attackers to execute arbitrary code or cause Denial of Service.

Adult Toys Manufacturer Facing Lawsuit for Collecting “Users Personal Data”

LinuxSecurity.com: Multiple heap overflows in SoX may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A heap-based buffer overflow vulnerability in libmms might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: update

LinuxSecurity.com: A vulnerability in Docker could lead to the escalation of privileges.

LinuxSecurity.com: Multiple vulnerabilities have been found in VirtualBox, the worst of which allows local users to escalate privileges.

security update

security update

Child Pornography Case: 73-year old Pedophile gets 300 years sentence
Inherent Vulnerability making Netgear’s Routers Exploitable by Hackers

LinuxSecurity.com: An update for python-XStatic-jquery-ui is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for python-XStatic-jquery-ui is now available for Red Hat OpenStack Platform 9.0 (Mitaka). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security fix for CVE-2016-8740

LinuxSecurity.com: An update for rh-mariadb100-mariadb is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for rh-mariadb101-mariadb is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…]

Fatal flaw found in PricewaterhouseCoopers SAP security software
Russian hackers got Trump elected? Yeah, let’s take a close look at that, says Obama
Ex-Expedia IT worker hacked firm to commit insider trading after he left
‘I found a bug that let anyone read anyone’s Yahoo! Mail and all I got was this $10k check’
After Spying Webcams, Welcome the Spy Toys “My Friend Cayla and I-Que”
How one man could have set loose a Yahoo Mail virus
Obama orders review of election hacks as Trump doubts Russia’s role
News in brief: Mounties drop bodycam plans; vibrator firm to settle lawsuit; Samsung to brick Note 7s
Ransomware attacks against businesses increased threefold in 2016
Admin spied on Expedia executive emails to make share killing
Ransomware Gives Free Decryption Keys to Victims Who Infect Others

Risk Level: Very Low. Type: Trojan.

Attackers use hacked home routers to hit Russia’s 5 largest banks

  Personal computers and devices aren’t the only targets for ransomware authors. Their methods have evolved to target government offices and profitable organizations, forcing them to rethink their cybersecurity mitigation plans.   Blackheart Records Data Left Exposed Online Recently, it has been discovered that a large, unsecured database containing sensitive information on several prominent recording […]

Windows XP ‘still widespread’ among healthcare providers
Making in-flight cellphone calls? GCHQ, NSA have been listening
NYU Students Apply Blockchain Solution to Electronic Voting Security
Fancy that! Google was keen on ‘draining the swamp’ in 2013
Bahamian Hacker Gets 5 Years Jail Time for Hacking, Leaking Celebrities Photos
Threatpost News Wrap, December 8, 2016
‘Professional’ hackers steal industrial secrets from ThyssenKrupp
The IoT: Gateway for enterprise hackers
Yahoo Mail XSS Bug Worth Another $10K to Researcher
Yahoo flaw, now fixed, allowed hackers to access any user’s email
Ugh! Is that your security budget? *Sucks teeth and shakes head*
10 essential PowerShell security scripts for Windows administrators
Did Russia hack the US election? Democrats want an investigation
UK.gov state of the nation report: Infosec’s very important, mmmkay
Expedia support tech raided his CFO to rack up insider trades
Hacker who stole celebrity emails, sex videos, movie scripts gets five years in prison
Yahoo patches critical vulnerability that allowed hackers to read any email

Risk Level: Very Low. Type: Trojan.

Goldeneye ransomware: the resumé that scrambles your computer twice
Japanese hosting company Kagoya hacked; credit card data stolen

security update

Real deal: Hackers steal steelmaker trade secrets
Trend Micro AV nukes innocent Sharepoint code, admins despair
Researchers Question Security in AMD’s Upcoming Zen Chips
News in brief: fake news move; ‘massive’ data breach; spook welcomes Snooper’s charter
OpenVPN to Undergo Cryptographic Audit