Menu

Monthly Archives: January 2017

GDPR: what does the new EU data protection law mean for small businesses?
Exposed MongoDB installs being erased, held for ransom
FTC sets $25,000 prize for automatic IoT patching
Obama’s Russian Hacking Retaliation Is Biggest “Since the Cold War”
White Hat Hacker Launches Public Support Site
Hackers could explode horribly insecure smart meters, pwn home IoT

LinuxSecurity.com: An update for ghostscript is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for ghostscript is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

Boffins bag side-channel bugs before they bite
Kaspersky fixing serious certificate slip
Web-exposed MongoDB installs wiped by bitcoin ransoming script scum
Lone Hacker Defaces Google Brazil Domain
Washington Post backtracks on frenzied reporting of Russian hack attack against power grid
Latest WhatsApp Scam Infects Users with Banking Malware
Box.com Plugs Account Data Leakage Flaw
Vermont Grid ‘Hack’ Latest Tumble Down Attribution Rabbit Hole
Pentagon Subcontractor Inadvertently Leaks 11 Gigs of Sensitive Data
Review: Microsoft Windows Defender comes up short
News in brief: fears over electronic voting; TV hit with ransomware; Telsa’s mileage data store

LinuxSecurity.com: CVE-2016-3189 bzip2: heap use after free in bzip2recover

LinuxSecurity.com: Update to 2.46 Fixes various security issues, seehttp://www.mozilla.org/security/known-vulnerabilities/seamonkey.html for moreinfo. No more includes Chatzilla and DOM Inspector in the package — installthem yourself now (as usual other addons) from https://addons.mozilla.org

LinuxSecurity.com: – Fixed crash in auth process when auth-policy was configured and authenticationwas aborted/failed without a username set. – director: If two users haddifferent tags but the same hash, the users may have been redirected to thewrong tag’s hosts. – Index files may have been thought incorrectly lost, causing”Missing middle file seq=..” to be logged […]

LinuxSecurity.com: An integer overflow in LZO might allow remote attackers to execute arbitrary code or cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in HDF5 which could lead to the arbitrary execution of code.

LinuxSecurity.com: Multiple vulnerabilities have been found in memcached which could lead to the remote execution of arbitrary code.

LinuxSecurity.com: An integer overflow in musl might allow an attacker to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in libotr and Pidgin OTR, allowing remote attackers to execute arbitrary code.

LinuxSecurity.com: An update for ipa is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: This update fixes CVE-2016-9580 and CVE-2016-9581. —- This update adds apatch to fix CVE-2016-9573 and CVE-2016-9572.

LinuxSecurity.com: This update fixes CVE-2016-9580 and CVE-2016-9581.

Police mull gathering crime evidence from smart home devices
PHPMailer could put your website at risk: here’s what you need to know

Risk Level: Very Low. Type: Trojan.

If you’re anything like me, you probably make a bunch of lofty resolutions every year that you probably won’t, or even can’t, achieve. (For instance, I’ve been promising to hit the gym a little harder for about 6 years now.) But enough is enough. Here are 5 completely achievable resolutions to help keep you and […]

CNN Report Shows Fallout 4 Screenshots to Explain Russian Hacking Scheme
New Android-infecting malware brew hijacks devices. Why, you ask? Your router
How to remove ransomware from your LG Smart TV
Apple sued over fatal FaceTime car crash
Deprecation of Insecure Algorithms and Protocols in RHEL 6.9
Data breaches through wearables put target squarely on IoT in 2017
Claims that Russia hacked the US election and power grid are ‘overblown’
Weekly review – the hot 13 stories of the week
How to tell if your Snapchat has been hacked, and how to get it back
Army social media psyops bods struggling to attract fresh blood
Better authentication: Go get 'em, FIDO

Only a handful of industry associations accomplish what they set out to do. In the security realm, I’ve always been a huge fan of the Trusted Computing Group. It’s one of the few vendor organizations that truly makes computers more secure in a holistic manner. The Fast Identity Online (FIDO) Alliance is another group with lots […]

LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla Firefox, SeaMonkey, and Thunderbird the worst of which could lead to the execution of arbitrary code.

Programmer finds way to liberate ransomware’d Google Smart TVs
Libpng library gets fix for truly ancient bug
Hate ‘contact us’ forms? This PHPmailer zero day will drop shell in sender
Android tops 2016 vuln list, with 523 bugs
Russian ‘grid attack’ turns out to be a damp squib
Top Secret -cleared SOCOM staff in 11GB Govt contractor breach

security update

5 Premium VPN Services To Access HULU Outside The US
Philippine Military Website Hacked and Defaced
Latest iMessage Hack Crashes iPhone within Minutes
A lesson from network outages: Redundancy matters
Cyber-savvy New Year’s resolutions you’ll want to keep

Put cyber security at the top of your New Year’s resolution list for 2017, implementing a digital detox and improving your online behaviors. The post Cyber-savvy New Year’s resolutions you’ll want to keep appeared first on WeLiveSecurity