Menu

Monthly Archives: January 2017

Girls targeted by GCHQ for cybersecurity careers
Justine Bone on St. Jude Vulnerabilities and Medical Device Security
China clamps down on app stores in bid to curb malware
Adobe Acrobat auto-installed a vulnerable Chrome extension on Windows PCs
Trump inauguration DDoS protest is ‘illegal’, warn securobods
How to Keep Hackers out of Your Linux Machine Part 1: Top Two Security Tips
Google Infrastructure Security Design Overview
Oracle to Java devs: Stop signing JAR files with MD5
ProtonMail launches Tor hidden service to dodge totalitarian censorship
What’s the biggest danger to the power grid? Hackers? Terrorists? Er, squirrels
Chrome dev explains how modern browsers make secure UI just about impossible
Insecure Hadoop installs next in ‘net scum crosshairs
Adobe’s naughty Chrome telemetry code had XSS problem

security update

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low.

Silence is golden: How Google hunts Android malware in the wild
Hacker Exploits Remote Code Execution Bug to Breach Facebook Security
Carbanak Using Google Services for Command and Control
Skills gap could hold back blockchain, AI, IoT advancements in 2017
College fires IT admin, loses access to Google email, successfully sues IT admin for $250,000
Docker Patches Container Escape Vulnerability
News in brief: Assange ducks promise; CIA papers go online; G+ adds Facebook-like features
Oracle Patches 270 Vulnerabilities in Year’s First Critical Patch Update

“Highest average score for ease of use, quality of support, and […] requirements in endpoint protection.” That’s how Marty Duffy, Director of Research at G2 Crowd, describes Webroot after seeing the results of this year’s G2 Crowd survey on Best Software for IT Teams 2017. We’d be lying if we said we weren’t over the […]

Student keylogger creator faces jail after pleading guilty

LinuxSecurity.com: **Version 5.2.22** (January 5th 2017) * **SECURITY** Fix[CVE-2017-5223](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-5223),local file disclosure vulnerability if content passed to `msgHTML()` is sourcedfrom unfiltered user input. Reported by Yongxiang Li of Asiasecurity. The fixfor this means that calls to `msgHTML()` without a `$basedir` will not importimages with relative URLs, and relative URLs containing `..` will be ignored. *Add simple […]

LinuxSecurity.com: This new point release fixes a security vulnerability in wrestool. For furtherdetails see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850017

LinuxSecurity.com: Security fix for CVE-2016-9888

LinuxSecurity.com: This new point release fixes a security vulnerability in wrestool. For furtherdetails see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850017

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise MRG 2.5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

UK’s ICO releases new guidelines for becoming GDPR ready

The UK’s ICO has released a new set of guidelines aimed at ensuring companies are adequately prepared for the introduction of the GDPR. The post UK’s ICO releases new guidelines for becoming GDPR ready appeared first on WeLiveSecurity

Cyber Criminals Held Cancer Services Computers for Ransom
Stuxnet general pardoned by Obama – but deeper questions remain

Risk Level: Very Low. Type: Trojan.

Remote code execution vulnerability affecting Facebook’s servers earns researcher $40,000
Oracle patches raft of vulnerabilities in business applications
Artificial intelligence can be used to predict your death – but is it secure?
‘Ancient’ Mac backdoor discovered that targets medical research firms
The return of the cyber squirrel wars
Clash of Clans’ Developer “Supercell” Hacked; 1.1 Million Accounts Stolen
Not lovin’ it! Researcher finds way to steal McDonald’s users’ passwords
Hacker claims our private cell number on Facebook may not be so private
Drone pilot facing jail after knocking out a woman at Pride
How—and why—you should use a VPN any time you hop on the internet
If you’re going to use Windows, it makes security sense to use Windows 10
Passwords: A long goodbye
Ooooh, that’s NASty. Security-watchers warn over man-in-the-middle risk
Rogue developer used ‘backdoor’ web access to fuel cybercrime spree
Flashback Wednesday: Pakistani Brain

This month’s Flashback Wednesday takes us back to the beginning. Pakistani Brain, discovered on January 19th, is considered to be the first-ever PC virus. The post Flashback Wednesday: Pakistani Brain appeared first on WeLiveSecurity

WikiLeaks’ Assange confident of winning ‘any fair trial’ in the US
Can a DDoS attack on Whitehouse.gov be a valid protest?
Spora Ransomware Offers Victims Unique Payment Options
Understanding The Basics Of Two-Factor Authentication
Advances in SSL: 5 Strategies For Secure, High-Performance Load Balancers
Hacker cracks Facebook with remote code execution bug
Ransomware scum infect cancer non-profit
SOHOpeless routers offer hard-coded credentials and command injection bugs

LinuxSecurity.com: An update for runc is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for docker is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for docker-latest is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact [More…]

Kill it with fire: US-CERT urges admins to firewall off Windows SMB
Thanks to Obama: Chelsea Manning will be out in May 2017
New RCE Flaws Found in Samsung Smartcam
Gmail Phishing Scam Stealing Credentials Through Infected Attachment
Vulnerabilities Leave iTunes, App Store Open to Script Injection
Sensitive access tokens and keys found in hundreds of Android apps

LinuxSecurity.com: NVIDIA graphics drivers could be made to crash under certain conditions.

News in brief: flying cars take off; terrible passwords; Facebook picks Paris incubator campus
The unseemly world of Darkweb marketplaces

LinuxSecurity.com: Multiple vulnerabilities have been found in libxml2, the worst of which could lead to the execution of arbitrary code.

LinuxSecurity.com: Security fix for CVE-2016-9131, CVE-2016-9147, CVE-2016-9444

LinuxSecurity.com: Security fix for CVE-2016-9131, CVE-2016-9147, CVE-2016-9444

LinuxSecurity.com: This update avoids a malicious repository writing to files outside the localstorage root.

LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for bind97 is now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

Terrorists are winning the digital arms race
Router Vulnerabilities Disclosed in July Remain Unpatched
Italian pair arrested over alleged hack of cardinals and masons
Credential-stuffers enjoy up to 2% attack success rate – report
Mega UK hospitals trust Barts says IT borkage was due to trojan – not ransomware
SHA-1 End Times Have Arrived
Advice for Trump: think about your security infrastructure
Why WhatsApp’s ‘Backdoor’ Isn’t a Backdoor
WhatApp scams spread widely thanks to trust between friends
It makes good security sense to change Alexa’s name – here’s how
BBC launches probe into leak of Russian-dubbed Sherlock finale
Andrew Macpherson on Intelligence Gathering with Maltego
Facebook took two weeks to remove video of 12-year-old girl that livestreamed her suicide
Ransomware: Should you pay up?

ESET’s Cameron Camp provides valuable insight into what you should do if you’re a victim of ransomware. The post Ransomware: Should you pay up? appeared first on WeLiveSecurity

The war for cybersecurity talent hits the Hill
Ransomware brutes smacked 1 in 3 NHS trusts last year
Google ventures into public key encryption
Got microservices? You'd better secure them

One of the toughest parts of being a computer security pro is trying to figure out what to hang your career on every two to five years. Which new buzzwords will stick to become a new paradigms, and which will disappear into the ether? Keeping up with the latest and greatest enterprise tech is part […]

Is your IP security camera making you less secure?
Advice to Donald Trump: think before you tweet
Devs reverse-engineer 16,000 Android apps, find secrets and keys to AWS accounts