Menu

Monthly Archives: January 2017

Conflicting Reports Suggest Phineas Fisher (HackBack) Arrested in Spain
Trump stresses cybersecurity but postpones executive order
Trump hits control-Z on cybersecurity order: No reason given for delay

LinuxSecurity.com: Multiple vulnerabilities have been found in PCSC-Lite, the worst of which could lead to privilege escalation.

Flaws Found in Popular Printer Models
Human memory, or the lack of it, is the biggest security bug on the ‘net
Password-stealing security hole discovered in many Netgear routers

LinuxSecurity.com: flatpak 0.8.2 release, fixing a security issue that could lead to sandboxescaping. For details, see https://github.com/flatpak/flatpak/releases/tag/0.8.2

LinuxSecurity.com: The 4.9.6 stable kernel update contains a number of important fixes across thetree.

LinuxSecurity.com: This is an security update fixing CVE-2017-5193, CVE-2017-5194, CVE-2017-5195,CVE-2017-5196, CVE-2017-5356.

LinuxSecurity.com: A heap-buffer overflow vulnerability was discovered in pycrypto leading toarbitrary code execution. All users of pycrypto’s AES module that allow the modeof operation to be specified by an attacker, check for ECB explicitly and createthe objects without specifying an IV are vulnerable to this issue. This isCVE-2013-7459.

LinuxSecurity.com: The 4.9.6 stable kernel update contains a number of important fixes across thetree.

LinuxSecurity.com: This is an security update fixing CVE-2017-5193, CVE-2017-5194, CVE-2017-5195,CVE-2017-5196, CVE-2017-5356.

Ugly Password Gaffe Plagues Cryptkeeper Encryption App
Cocker Hill’s PD held to ransom by hackers; crucial digital evidence lost
Facebook steps up security by allowing physical keys for log-in
News in brief: Witcher user details stolen; email chain generated 500m messages; Russians face treason charges
Trump to sign cybersecurity order calling for government-wide review
Suffered a breach? Expect to lose cash, opportunities, and customers – report
Austrian hotel experiences ‘ransomware of things attack’

Only one month into the new year, it appears that we may well have our first example jackware in 2017 with a ransomware of things attack on an Austrian hotel. The post Austrian hotel experiences ‘ransomware of things attack’ appeared first on WeLiveSecurity

Security professionals shortage in UK ‘increasing competition among companies for talent’

IT security professionals are at the forefront of the demand from companies across the UK, many of whom have placed greater demand on tech skills. The post Security professionals shortage in UK ‘increasing competition among companies for talent’ appeared first on WeLiveSecurity

Security execs voice concern over Trump travel ban
Telemarketing firm leaks 17,000 recorded calls, many containing credit card details
Nicolas Brulez on Malware Reverse Engineering Tips and Tricks
Another Radio Station Transmission hacked with F*** Donald Trump Songs
‘I’m not a robot’ verification test beaten by … a robot
Privacy worries are on the rise, new U.S. poll shows
Cybersecurity: 5 basic lessons for everyone

A new way of looking at cybersecurity, no longer viewing it as a goal in itself, but instead something that is directly connected to business needs. The post Cybersecurity: 5 basic lessons for everyone appeared first on WeLiveSecurity

Facebook, GitHub teams up to make password resets more secure
NATO Members Targeted by Unique Macro Malware
We see you, ransomware flingers, testing out your baddest stuff on… Germany?
Do I have to hand over bank and social media details at the US border?
MongoDB ransom attacks continue to plague administrators
Better security through obscurity? Think again

When attackers look for vulnerabilities, they target popular software. Why bother chasing flaws in applications that few people use? That’s why one of my best friends runs a third-party application instead of Adobe Acrobat Reader to open and read PDF documents. Another friend runs the Maxthon browser to stay out of the way of exploits […]

Ransomware: Key insights from infosec experts

Ransomware is not going anywhere. Here, we’ve rounded up vital tips and advice from three ESET experts: Lysa Myers, Stephen Cobb and David Harley. The post Ransomware: Key insights from infosec experts appeared first on WeLiveSecurity

Want to bring down that pesky drone? Try the power of sound

LinuxSecurity.com: Multiple vulnerabilities have been found in HarfBuzz, the worst of which could allow remote attackers to cause a Denial of Service condition.

We don’t want to alarm you, but PostScript makes your printer an attack vector
Google’s Chrome is about to get rather in-your-face about HTTPS
VMware’s enterprise mobility management tool can p0wn itself
OpenSSL pushes trio of DoS-busting patches
Apple kills activation lock check, possible dirty stolen device hack
Infosec industry to drive machine learning spend surge says analyst
You’re taking the p… Linux encryption app Cryptkeeper has universal password: ‘p’
WTF is your problem, Netgear? Another hijack hole found in its routers

LinuxSecurity.com: An update for nagios is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for nagios is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for nagios is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for nagios is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

With net neutrality pretty much dead in the US, your privacy is next

security update

Forgot your GitHub password? Facebook cooks up spec to reset logins via social network
Hundreds of Thousands of Netgear Routers Vulnerable to Password Bypass

LinuxSecurity.com: Security Report Summary

Fake Netflix, WhatsApp, Facebook Android Apps Contain SpyNote RAT
Facebook Tackles Account Recovery with Delegated Recovery Protocol

security update

Telemarketing Firm Leaks 400,000 Recorded Calls
Ransomware avalanche at Alpine hotel puts room keycards on ice
News in brief: DC cameras hacked; Trump ‘unprepared’ for Russian cyberattacks; fake news probed
Ransomware attack impacted 70% of Washington DC police surveillance cameras

LinuxSecurity.com: Update to 6.2.4

LinuxSecurity.com: Update to Firefox 51.0.1. —- – new upstream version (51.0.1)

LinuxSecurity.com: Security fix for CVE-2016-10164

LinuxSecurity.com: This is a security update for these CVEs: *[CVE-2016-9601](https://bugzilla.redhat.com/show_bug.cgi?id=1410021) – *Heap-buffer overflow in jbig2_image_new function* This update also solves possiblelicensing issues with ghostscritpt’s source code.

LinuxSecurity.com: Update to 7.0.4

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: A null pointer dereference in libpng might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in SQUASHFS, the worst of which may allow execution of arbitrary code

LinuxSecurity.com: An integer overflow in libXpm might allow remote attackers to execute arbitrary code or cause a Denial of Service Condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in FFmpeg, the worst of which may allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: A vulnerability in Firewalld allows firewall configurations to be modified by unauthenticated users.

GDPR is just over a year away – and many firms are nowhere near ready
Ransomware disrupts Washington DC’s CCTV system
Many Android VPN Apps Breaking Privacy Promises
Sex club for women exposes members’ private photographs
70% of DC Police CCTV cameras were hacked before presidential inauguration
How a single SMS can break your Samsung Galaxy Android phone
Hackers Infect Hotel Door Lock System with Ransomware
Barclays warns customers of the risks of business email compromise
Has President Trump’s executive order on ‘Public Safety’ killed off Privacy Shield?
Questions to ask your recovery vendor before you buy
How most hackers get into systems
Managing risk by understanding attack surfaces
Trump’s immigration move sparks fears for Privacy Shield protections
Some examples of vulnerable code and how to find them

“When looking for vulnerabilities in open-source code, it is advisable to check portions of code that is prone to errors”: Useful tips from one of ESET’s malware analysts, Matías Porolli, on how to spot vulnerable code. The post Some examples of vulnerable code and how to find them appeared first on WeLiveSecurity

UK Cybersecurity: Permanent job salaries growing faster than contractor pay rises
Man logs into Facebook account of the woman using his stolen laptop
Google moves into the Certificate Authority business
Big Blue’s BigInsights has big-ish bugs
Marketing company leaks 17,000 recorded phone calls, many with credit card numbers
Hotel guests locked in their rooms by ransomware? It doesn’t make sense
Ransomware killed 70% of Washington DC CCTV ahead of inauguration
WordPress slips out three quick patches
Cisco TelePresence control software had remote-exploitable bug
Linux devices with standard settings infected by Linux.Proxy.10 malware

LinuxSecurity.com: Multiple vulnerabilities have been found in Perl, the worst of which could allow remote attackers to execute arbitrary code.

security update

security update

38% of Android VPN Apps on Google Play Store Plagued with Malware