Menu

Monthly Archives: December 2016

Get $20k in cash prize if you can exploit Nintendo 3DS system
If you’ve got a Sony IP camera, update its firmware now
New Call to Regulate IoT Security By Design
Kids’ privacy-endangering internet-connected toys should be banned, says EPIC
Turkish Hackers Offering Hacking Tools as Prizes for DDosing Political Websites
OpenVPN will be audited for security flaws
Making calls on the plane? Spies may have your number
Old Linux Kernel Code Execution Bug Patched
US commission whistles to FIDO: Help end ID-based hacks by 2021
Solar Power Firm Patches Meters Vulnerable to Command Injection Attacks
Man who hacked 130 celebrities jailed for five years
Mirai variant turns TalkTalk routers into zombie botnet agents
The cybercrime business model and its value chain

The security landscape has evolved to a point where most IT threats occur with the intention of generating financial gain for their creators and financiers. The post The cybercrime business model and its value chain appeared first on WeLiveSecurity

Fighting ransomware: A fresh look at Windows Server approaches
Patch your Sony security cameras against backdoor attacks!
Where Cybercriminals Go To Buy Your Stolen Data
Augmented reality start-up brings facial recognition to phones
Get Safe Online: Watch out for banking scammers

Get Safe Online has issued a warning to consumers to be aware of banking scammers, as cybercriminals are finding more sophisticated ways to access their account details. The post Get Safe Online: Watch out for banking scammers appeared first on WeLiveSecurity

Can ISPs step up and solve the DDoS problem?

LinuxSecurity.com: Multiple vulnerabilities have been found in OpenJPEG, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: A vulnerability in CrackLib could lead to the execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities were found in Binutils, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in socat, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: A vulnerability in Coreutils could lead to the execution of arbitrary code or a Denial of Service condition.

Playtime’s over: Internet-connected kids toys ‘fail miserably’ at privacy

LinuxSecurity.com: Multiple vulnerabilities were found in SQLite, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: A buffer overflow in jq might allow remote attackers to execute arbitrary code.

Stealing, scamming, bluffing: El Reg rides along with pen-testing ‘red team hackers’
Silver screen script hacker and dox douche gets 5 years in US cooler
Need Xmas ideas? Try CVE-2015-7645, a Flash gift that keeps on giving
Masterful malvertisers pwn Channel 9, Sky, MSN in stealth attacks
Santa says you’ve been nice kids: OpenVPN to get security audit
Body cams too fragile for Canadian Mounties – so they won’t be used

  Corny title aside, ‘tis officially the season for online shopping, and that means a drastic increase in phishing scams. In order to obtain sensitive information from specific organizations and people, these threats have become increasingly sophisticated and are carefully crafted. According to the latest Webroot Quarterly Threat Update, 84 percent of phishing sites exist […]

Sigh… ‘Hundreds of thousands’ of… sigh, web CCTV cams still at risk of… sigh, hijacking
When it comes to security, TalkTalk is all talk talk…
3 Reasons why cyberattacks force competitors to share information
Could this be you? Really Offensive Security Engineer sought by Facebook

LinuxSecurity.com: Security fix for CVE-2016-7433, CVE-2016-7426, CVE-2016-7429, CVE-2016-9310,CVE-2016-9311

LinuxSecurity.com: Update to the latest upstream release, which fixes CVE-2016-8704, CVE-2016-8705,CVE-2016-8706.

LinuxSecurity.com: php-gettext 1.0.12 ================== * Security fix for potential codeinjection bug (LP#1515334) * Do not assume mbstring functions are alwaysthere, pass text through if they aren’t (LP#734494)

LinuxSecurity.com: phpMyAdmin 4.6.5.1 (2016-11-26) =============================== A patch-levelrelease fixing two small issues: * an issue affecting a small number of usersusing $cfg[‘Servers’][$i][‘hide_db’] or $cfg[‘Servers’][$i][‘only_db’]. * anissue affecting the create table dialog where the partition selection tool wasoverzealous and made it difficult to create a new table. There are also minorimprovements to the Czech language file. phpMyAdmin […]

LinuxSecurity.com: Security fix for CVE-2016-7433, CVE-2016-7426, CVE-2016-7429, CVE-2016-9310,CVE-2016-9311

IDG Contributor Network: Ubuntu Core has the keys to IoT security
You can Download Music, Videos, Webpages and View them Offline with Chrome 55 for Android
Don’t have a Dirty COW, man: Android gets full kernel hijack patch
Zeus Variant ‘Floki Bot’ Targets PoS Data
Buffer Overflow in BSD libc Library Patched
Crims turn to phishing-as-a-service to slash costs and max profits
Flash Player remains target of choice for exploit kits
Here’s how the Windows 10 Creators Update helps enterprises

LinuxSecurity.com: An update for sudo is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: The 4.8.11 stable kernel update contains a number of important fixes across thetree.

LinuxSecurity.com: Add fix for gstreamer FLIC decoder vulnerability

LinuxSecurity.com: Fix Integer overflow when allocating render buffer in vmnc decoder

LinuxSecurity.com: New upstream vesion, 1.17.27 . Security fix for CVE-2015-0860

LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 6.2 Advanced Update Support, Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, Red Hat Enterprise Linux 6.5 Telco Extended Update Support, Red Hat Enterprise [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in ARJ, the worst of which may allow attackers to execute arbitrary code.

Adobe Flash responsible for six of the top 10 bugs used by exploit kits in 2016
McDonald’s Drive-Thru Intercom Wireless Frequency System Hacked

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

How to secure your Wi-Fi network – the basic version
Charities hit with fines for sharing donors’ data without consent
Nearly 80 Sony IP Camera Models Plagued with Backdoor Accounts
Critical Vulnerability Patched in Roundcube Webmail
Flaw spotted in North Korea’s Red Star operating system
New Botnet is Attacking the US West Coast with Huge DDoS Attacks
Nintendo targets 3DS vulnerabilities in new bug bounty
Hackers Gamify DDoS Attacks With Collaborative Platform
Malicious online ads expose millions to possible hack
Crims using anti-virus exclusion lists to send malware to where it can do most damage
Uber is watching your smartphone’s battery charge

LinuxSecurity.com: Multiple vulnerabilities have been found in Mercurial, the worst of which could lead to the remote execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in OpenSSH, the worst of which allows remote attackers to cause Denial of Service.

LinuxSecurity.com: A buffer overflow in PECL HTTP might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in OpenSSL, the worst of which allows attackers to conduct a time based side-channel attack.

Android, Qualcomm move on insecure GPS almanac downloads
Open source Roundcube webmail can be attacked … by sending it an e-mail

Risk Level: Very Low. Type: Trojan.

After IoTs, it is the IMDs that are Most Vulnerable to Hacking
IBM Watson steps into real-world cybersecurity

LinuxSecurity.com: New upstream version 2.50. – Fixes serious DLL hijacking attack:https://sourceforge.net/p/nsis/bugs/1125/

Flash Exploit Found in Seven Exploit Kits
DailyMotion Hack Leaks Emails, Passwords of 87M Users
News in brief: smart toys ‘threaten kids’ security’; Samsung battery teardown; HP turns off Telnet

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Nghttp2 is vulnerable to a Denial of Service attack.

LinuxSecurity.com: Patch is vulnerable to a locally generated Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in the Chromium web browser, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Security fix for CVE-2016-9296

LinuxSecurity.com: phpMyAdmin 4.6.5.1 (2016-11-26) =============================== A patch-levelrelease fixing two small issues: * an issue affecting a small number of usersusing $cfg[‘Servers’][$i][‘hide_db’] or $cfg[‘Servers’][$i][‘only_db’]. * anissue affecting the create table dialog where the partition selection tool wasoverzealous and made it difficult to create a new table. There are also minorimprovements to the Czech language file. phpMyAdmin […]

LinuxSecurity.com: Update to 1.10.1

LinuxSecurity.com: Add fix for gstreamer FLIC decoder vulnerability