Menu

Monthly Archives: December 2016

LinuxSecurity.com: xen : various security flaws (#1397383) x86 null segments not always treated asunusable [XSA-191, CVE-2016-9386] x86 task switch to VM86 mode mis-handled[XSA-192, CVE-2016-9382] x86 segment base write emulation lacking canonicaladdress checks [XSA-193, CVE-2016-9385] guest 32-bit ELF symbol table loadleaking host data [XSA-194, CVE-2016-9384] x86 64-bit bit test instructionemulation broken [XSA-195, CVE-2016-9383] x86 software interrupt […]

LinuxSecurity.com: Libvirt is vulnerable to directory traversal when using Access Control Lists (ACL).

LinuxSecurity.com: Multiple vulnerabilities have been found in GD, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability in LinuxCIFS utils’ “cifscreds” PAM module might allow remote attackers to have an unspecified impact via unknown vectors.

DarkWeb Website Asking for Funds to Assassinate Donald Trump and Mike Pence
Putin moves to step up Russia’s cyberdefenses
App developers not ready for iOS transport security requirements
Sony Closes Backdoors in IP-Enabled Cameras
Daily Motion video sharing service named in breach claim of 80M accounts
‘Rich irony’ as Facebook blocks extension to highlight fake news
Lock suspect in stolen car to bust him? There’s an app for that…
Dailymotion hacked, millions of user accounts exposed
Hackers actively stealing Wi-Fi keys from vulnerable routers
Rogue admin jailed after taking down former employer’s network
Hacking is legal again finally (sometimes)

Go ahead and hack your car, that’s fine now. Go ahead and hack the Department of Defense, that’s okay too under new policies. It wasn’t always this way. The post Hacking is legal again finally (sometimes) appeared first on WeLiveSecurity.

4 top disaster recovery packages compared
Are you human or a bot? Google’s invisible reCAPTCHA will decide
Obama’s cybersecurity plan faces uncertainty with Trump
Own goal for Scottish Football Association as fans sent phishy emails
Sony kills off secret backdoor in 80 internet-connected CCTV models
The cloud storage security gap — and how to close it
Why it’s so hard to prosecute cyber criminals
<div>Why it's so hard to prosecute cyber criminals</div>

We live in a world where internet crime is rampant. Cyber criminals steal hundreds of millions of dollars each year with near impunity. For every 1 that gets caught, 10,000 go free — maybe more. For every 1 successfully prosecuted in a court of law, 100 get off scot-free or with a warning. Why is […]

The UK’s Investigatory Powers Act allows the State to tell lies in court
Facebook, Microsoft, Twitter and YouTube team to ID terror content
In the three years since IETF said pervasive monitoring is an attack, what’s changed?
Standards body warned SMS 2FA is insecure and nobody listened
Printer security is so bad HP Inc will sell you services to fix it
Arista CloudVision Portal bug revealed, plus evidence it’s been used
1.4bn records from HaveIBeenPwned offered for your analytical pleasure
Video-sharing Website Dailymotion Hacked; 87 Million Accounts Leaked
CloudFlare warns of another massive botnet, er, flaring up
Credit Cards can be Hacked in Just 6 Seconds—Reveals New Study
Dirty Cow Vulnerability Patched in Android Security Bulletin
Google Debuts Continuous Fuzzer for Open Source Software
Distributed Guessing Attack Reels in Payment Card Data
Toyota dealer sued for stealing intimate photo off couple’s smartphone
New Large-Scale DDoS Attacks Follow Schedule
How to guess credit card security codes
News in brief: porn database hacked; Obama call to Trump; MPs move on Snooper’s Charter
Chrome bug triggered errors on websites using Symantec SSL certificates
Facebook reportedly looking at curating news (again)
Be Prepared for Jail Time if You Post Fake News on Social Media in Saudi Arabia
Amazon Launches AWS Shield DDoS Protection Service
Saudi Arabian Central Bank Systems Targeted with Shamoon Malware
Website leaves 43,000 sensitive medical records exposed
Yorkshire cyber security biz ECSC Group to debut on AIM exchange
EFF Blasts DEA in Ongoing Secret ‘Super Search Engine’ Lawsuit
Five new malware programs are discovered every second
How to survive the death of Flash
Apple set to deploy drones to boost Maps accuracy
Take care copy-and-pasting that code from Stack Overflow
Android ransomware spreads further, with new methods in its toolbox

ESET lifts the lid on Android ransomware – the picture doesn’t look good. It’s on the increase and extremely sophisticated. The post Android ransomware spreads further, with new methods in its toolbox appeared first on WeLiveSecurity.

Child safety: An unexpected radio interview

David Harley, talking about child safety and security in (and yet not in) the South Atlantic. The post Child safety: An unexpected radio interview appeared first on WeLiveSecurity.

Guessing valid credit card numbers in six seconds? Priceless
IoT camera crew Titathink tells Reg it’ll patch GET bug in a week
U.K. Police don’t pay to unlock iPhones, they mug you while phone is unlocked
Vendor claims to sell millions of Experian and Whois accounts on Dark Web
Hackers steal $31 million from Russia’s central bank, as FSB warns of foreign plot
New anti-Facial Recognition Glasses Protect Users’ Privacy From CCTV Cameras

LinuxSecurity.com: A vulnerability in DavFS2 allows local users to gain root privileges.

LinuxSecurity.com: Due to a design flaw, the output of GnuPG’s Random Number Generator (RNG) is predictable.

LinuxSecurity.com: Security fix for CVE-2016-7504, CVE-2016-7505, CVE-2016-7506, CVE-2016-9017,CVE-2016-9108, CVE-2016-9109, CVE-2016-9294

LinuxSecurity.com: Security fix for CVE-2016-7504, CVE-2016-7505, CVE-2016-7506, CVE-2016-9017,CVE-2016-9108, CVE-2016-9109, CVE-2016-9294

LinuxSecurity.com: Update to 1.9.9 (bugfix release for CVE-2016-7146, CVE-2016-7148)

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: A security update that fixes Calamares bug CAL-405:https://calamares.io/bugs/browse/CAL-405 When installing with a LUKS-encrypted`/` partition, Calamares was always creating a keyfile to decode `/` and storingit in the initramfs. It did that even with an unencrypted separate `/boot`partition. As a result, the keyfile would be stored in cleartext on the `/boot`partition, and it was possible […]

LinuxSecurity.com: Update to 1.9.9 (bugfix release for CVE-2016-7146, CVE-2016-7148)

LinuxSecurity.com: A security update that fixes Calamares bug CAL-405:https://calamares.io/bugs/browse/CAL-405 When installing with a LUKS-encrypted`/` partition, Calamares was always creating a keyfile to decode `/` and storingit in the initramfs. It did that even with an unencrypted separate `/boot`partition. As a result, the keyfile would be stored in cleartext on the `/boot`partition, and it was possible […]

LinuxSecurity.com: Security fix for CVE-2016-9299

LinuxSecurity.com: Security fix for CVE-2016-9299

LinuxSecurity.com: Update to 1.9.9 (bugfix release for CVE-2016-7146, CVE-2016-7148)

Gone: Russian Central Bank hacked; $31 million stolen
Beware of These Cyber Threats in 2017
Israeli News Channels’ Telecast Hacked; replaced with Muslims’ call to prayer
Tor Browser Impacted by Firefox’s Zero-day Vulnerability
Fry all the things! USB Kill zaps tons of computing devices
iPhone security is so good that police had to ‘mug’ a suspect to get his data
‘Toyota dealer stole my wife’s saucy snaps from phone, emailed them to a swingers website’
‘Avalanche’ botnet takes a tumble after Europol cyber-bust
New iOS lockscreen bypass renders Activation Lock useless

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Avalanche takedown: Check if you are safe

Earlier this week coordinated law enforcement action took down the Avalanche fast-flux network. ESET has been assisting in the cleanup. The post Avalanche takedown: Check if you are safe appeared first on WeLiveSecurity.

Google Fixes 12 High-Severity Flaws In Chrome Browser
News in brief: meals on robot wheels; Mirai blamed for new attacks; police bypass iPhone encryption
Russia accuses hostile foreign powers of plot to undermine its banks
Highly Sensitive Data of Explosives-Handling Company Leaked Online

  Between a handful of high profile network hacks and the steady stream of ransomware attacks, the last week of November didn’t pull any punches in the constant sparring match that is cybersecurity. In the wake of headlines about a US Navy breach, large scale network outages across Germany, and more, internet users across the […]

Gooligan Malware Breaches 1 Million Google Accounts
Dorkbot: Life after disruption

A year ago on 2nd December 2015, a collaboration between major cybersecurity firms, law enforcement and software providers – including ESET and Microsoft – successfully managed to disrupt Dorkbot, a malware family that had been infiltrating systems worldwide for over four years. Since its detection in April 2011, Dorkbot had caused numerous problems for businesses […]

Sh… IoT just got real: Mirai botnet attacks targeting multiple ISPs
Would Facebook or Twitter dare to ban Trump? [Poll]
How Windows 10 data collection trades privacy for security
7 security predictions for 2017
TalkTalk and Post Office customers lose internet access as routers hijacked
Microsoft’s ‘Samaritan’ refuses help to hackers doing Win 10 recon
Hackers waste Xbox One, PS4, MacBook, Pixel, with USB zapper
Shamoon malware returns to again wipe Saudi-owned computers

Risk Level: Very Low. Type: Trojan.

Online criminals iced as cops bury malware-spewing Avalanche