Menu

Monthly Archives: January 2017

41% off Netgear Arlo Security System Wireless HD Camera, Indoor/Outdoor, Night Vision – Deal Alert
It’s that time of the year again: Texas school district blabs staff tax documents to phishers
Corporations at risk of malware attack via Cisco’s WebEx Chrome extension
Cisco scrambling to fix a remote code execution problem in WebEx
RoT: Ransomware of Things

Could the Internet of Things spark the Ransomware of Things? ESET’s Stephen Cobb examines how ransomware and jackware are evolving. The post RoT: Ransomware of Things appeared first on WeLiveSecurity

Twitter’s Phantom Menace: a Star Wars botnet
Charger Mobile Ransomware Removed from Google Play
Charger Android ransomware spread via the official Google Play app store
Yahoo faces SEC probe into its two record-breaking data breaches

The US Securities and Exchange Commission is looking into whether Yahoo could have been quicker to tell investors about two record-breaking data breaches. The post Yahoo faces SEC probe into its two record-breaking data breaches appeared first on WeLiveSecurity

Looking for love? Don’t get caught out by the growing number of scammers
This new ransomware ‘bluff’ trick is costing victims big, even though their files are never really i
Technology of the Year 2017: The best hardware, software, and cloud services
Identify and escape: A two-part ransomware plan
InfoWorld’s 2017 Technology of the Year Award winners
Boffins break Samsung Galaxies with one SMS carrying WAP crap

LinuxSecurity.com: Multiple vulnerabilities have been found in Oracle’s JRE and JDK software suites, the worst of which may allow execution of arbitrary code

LinuxSecurity.com: Multiple vulnerabilities have been found in X.Org X Server, the worst of which may allow authenticated attackers to read from or send information to arbitrary X11 clients.

Firefox bares teeth, attacks sites that collect personal data
Western Digital fixes remote execution bug in My Cloud Mirror
Human bot hybrid finds LinkedIn email, phone number-filching holes
Graham Cluley nominated for most entertaining security blog. Please vote!
Trump’s FBI boss, Attorney General picks reckon your encryption’s getting backdoored
Internet gang claims it caused Lloyds Bank outage via a DDoS attack
Hacker Selling 1 Billion user accounts stolen from Chinese Internet Giants
US govt can’t stop Microsoft taking its Irish email seizure fight to the Supreme Court
SpyNote RAT Now Disguised As Netflix App

LinuxSecurity.com: Security fix for console video game music emu vulnerability in the fullyoptional audacious-plugins-exotic subpackage: CVE-2016-9957, CVE-2016-9958,CVE-2016-9959, CVE-2016-9960, CVE-2016-9961

LinuxSecurity.com: Security fix for CVE-2016-2120, CVE-2016-7068, CVE-2016-7072, CVE-2016-7073,CVE-2016-7074

LinuxSecurity.com: Security fix for CVE-2016-6814

LinuxSecurity.com: Update to 0.8.0-6.git97f52c1

LinuxSecurity.com: Rebase to latest upstream gitrev 20161120

News in brief: DuckDuckGo takes off; Sundance hit by cyberattack; Oz moots biometric arrivals

LinuxSecurity.com: Update from 3.8.1 to 3.8.2. Also fixes console video game music emuvulnerability in the fully optional audacious-plugins-exotic subpackage:CVE-2016-9957, CVE-2016-9958, CVE-2016-9959, CVE-2016-9960, CVE-2016-9961

LinuxSecurity.com: Update from 3.8.1 to 3.8.2. Also fixes console video game music emuvulnerability in the fully optional audacious-plugins-exotic subpackage:CVE-2016-9957, CVE-2016-9958, CVE-2016-9959, CVE-2016-9960, CVE-2016-9961

LinuxSecurity.com: Security fix for CVE-2016-2120, CVE-2016-7068, CVE-2016-7072, CVE-2016-7073,CVE-2016-7074

LinuxSecurity.com: This update fixes a security problem with the EDE package.

LinuxSecurity.com: Fix validation logic in the base consumer The base consumer is intended to onlyderive its validation switch from the on-disk configuration if the child classdoesn’t override the validate_signatures switch. There was a bug here where thedefault value provided in the base class made it appear as if *all* childconsumers had turned *off* validation, which […]

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Android Pattern Lock ‘can be cracked in five attempts’ – here’s what to do
AG Nominee Backs Law Enforcement’s Ability to ‘Overcome’ Encryption
St. Louis Public Library Recovers from Ransomware Attack
UK courts experiencing surge in cyber-crime case load
When is a blockchain not a blockchain?
Study: 62% of security pros don’t know where their sensitive data is
Penguins force-fed root. Cruel flaw found in systemd v228
Yahoo sale to Verizon delayed, following revelation of massive security breaches
DDoSing has evolved in the vacuum left by IoT’s total absence of security
Update your Mac and iPhone – and help stop unwanted pwnage
Cisco Patches Critical Flaw in WebEx Chrome Plugin
Apple quashes bugs in iOS, MacOS, and Safari
The essential guide to anti-malware tools
Pompeo sworn in as CIA chief amid opposition from surveillance critics
Apps Carrying HummingBad Variant Booted From Google Play
As attacks rise, we ask: how secure is your Hadoop installation?
World’s most popular email server praised as ‘near-impenetrable’
I don’t care what your eyeballs tell you. Alternative fact is, we’ve locked up your files
Why Linux Installers Need to Add Security Features
Keeping Linux devices secure with rigorous long-term maintenance
Linux Is Part of the IoT Security Problem, Dev Tells Linux Conference
The evolution of (and solution to) ransomware

Contrary to popular belief, ransomware has been around for decades. The first malware program to lock up people’s files and ask for a ransom was the PC Cyborg Trojan in 1989. It was created by Harvard-trained evolutionary biologist Dr. Joseph Popp, who was working on several AIDS-related projects at the time. Dr. Popp sent a […]

LinuxSecurity.com: An update for mysql is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Firejail, the worst of which may allow privilege escalation.

HummingBad malware returns in new, more annoying variant

LinuxSecurity.com: Multiple vulnerabilities have been discovered in WebP, the worst of which could allow a remote attacker to cause a Denial of Service condition.

LinuxSecurity.com: An update for squid is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for squid34 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in LibRaw, the worst of which may allow attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in ADOdb, all of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in ICU, the worst of which could cause a Denial of Service condition.

Furby Rickroll demo: What fresh hell is this?
Kid hackers break XSS defences, find hack hole in 2 million websites
Microsoft fixes remote desktop app Mac hole
VXers gift their mates an Android bank-raiding app’s source code

LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.1, 14.2, and -current to fix security issues. [More Info…]

Apple issues security patches for… just about everything

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Western Union coughs up $586m for turning a blind eye to fraudsters
Cisco’s WebEx Chrome plugin will execute evil code, install malware via secret ‘magic URL’
What links macOS, iOS, Safari, tvOS, watchOS? They all need patching

LinuxSecurity.com: The 4.9.5 stable kernel update contains a number of important fixes across thetree.

LinuxSecurity.com: ## Version 2.2.4 – 2017-01-18 ### Security – gdImageCreate() doesn’t check foroversized images and as such is prone to DoS vulnerabilities. (CVE-2016-9317)- double-free in gdImageWebPtr() (CVE-2016-6912) – potential unsigned underflowin gd_interpolation.c – DOS vulnerability in gdImageCreateFromGd2Ctx() ###Fixed – Fix #354: Signed Integer Overflow gd_io.c – Fix #340: System frozen -Fix OOB reads of the […]

LinuxSecurity.com: The 4.9.5 stable kernel update contains a number of important fixes across thetree.

ThePirateBay.org goes down; dark web domain is up and running
Apple Patches Critical Kernel Vulnerabilities
China’s Great Firewall to crack down on unofficial VPNs – state-approved net connections only
Secure Email Service Lavabit Relaunches
WatchMojo’s official YouTube Channel Terminated Due to a Glitch (Updated)
IBM stuffs visualization tech into its bulging, uh, security portfolio
Heartbleed Persists on 200,000 Servers, Devices