Menu

Monthly Archives: January 2017

Amazon Echo and the Alexa dollhouses: Security tips and takeaways

Tips on securing the Alexa service on Amazon Echo devices, notably voice purchasing, a topic brought into focus by the recent “San Diego dollhouse TV story”. The post Amazon Echo and the Alexa dollhouses: Security tips and takeaways appeared first on WeLiveSecurity

Anonymous hacks Thai Gov’t job portal; leaks a trove of data
Netflix Phishing Campaign Targeted User Information, Credit Card Data

LinuxSecurity.com: Multiple vulnerabilities have been found in libTIFF, the worst of which may allow execution of arbitrary code.

The Spy, sorry, The Fridge Who Loved Me
Adobe Patches Code Execution Flaws in Flash, Reader, Acrobat
Cybercriminals ‘should be punished with Wi-Fi jammers’

A senior UK police officer has suggested that offenders of cybercrime should be penalized by being made to wear Wi-Fi jammers rather than being sent to prison. The post Cybercriminals ‘should be punished with Wi-Fi jammers’ appeared first on WeLiveSecurity

US college pays $28,000 to get files back after ransomware attack
Disk-wiping malware Shamoon targets virtual desktop infrastructure
News in brief: cookie monster slain; FBI disclosure on shooter’s iPhone; Mayer to step down
Lawmakers Reintroduce Popular Email Privacy Act
Two New Edge Exploits Integrated into Sundown Exploit Kit
How could social media legalese be made more friendly?
Security scare over hackable heart implants

A US government probe into claims that certain heart implants are vulnerable to hacking attacks, has resulted in emergency security patches being issued for devices that cardiac patients have in their homes. The post Security scare over hackable heart implants appeared first on WeLiveSecurity

EU tosses Europe’s cookies… popups
UK Parliament suddenly remembers it wants to bone up cyber security *cough* Russia *cough*
New privacy rules at risk as Trump prepares to take office
Someone stole $3.6M from a Miami bank; officials oblivious for 6 months
Google Patches Android Custom Boot Mode Vulnerability
Threatpost News Wrap, January 6, 2017
Experts Warn of Novel PDF-Based Phishing Scam
FTC: D-Link Failed to Secure Routers, IP Cameras
Attacks On MongoDB Rise As Hijackings Continue
Ransomware extorts Los Angeles school to the tune of $28,000
Uber offers an olive branch to city planners with new tool
Dangerous assumptions that put enterprises at risk
Former DHS head urges Trump to see economic dangers from cyberattacks
Privacy legislation reintroduced for mail older than 180 days
Because I’m bad, I’m bad, Shamoon: PC wiper tried to shut down Saudi snapshot defences
Stolen details of 3.3m Hello Kitty fans – including kids – published online
What do you call a firm that leaves customer financials unencrypted on a hard drive? RSA
MongoDB ransacked: Now 27,000 databases hit in mass ransom attacks
GitHub secret key finder released to public
Trump Plans To Build Anti-Hacking Team
Hacker: Lol, I pwned FBI.gov! Web devs: Nuh-uh, no you didn’t
Git Hound, Truffle Hog root out GitHub leaks
Q&A: RSA crypto pioneer Adleman keeps pushing the limits

I recently had the pleasure of interviewing Dr. Leonard Adleman — the “A” in the very popular public cryptographic algorithm RSA — as part of the Association for Computing Machinery’s 50th anniversary celebration of the Turing Award. In 2002, Adleman himself won the Turing Award, often referred to at the Nobel Prize of the computing […]

Rethink on bank cybersecurity rules might only follow major bank breach, says expert

LinuxSecurity.com: Multiple vulnerabilities have been found in Python, the worst of which could lead to arbitrary code execution.

LinuxSecurity.com: Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.

Like stealing data from a kid: LA school pays web scum US$28,000 ransom
Autocomplete a novel phishing hole for Chrome, Safari crims
St Jude patching Merlin@home heart kit
Two years on, thousands of unpatched Magento shops still being carded
Onion Browser goes free for privacy-conscious iOS users, citing ‘recent events’

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows LSASS is prone to a local privilege-escalation vulnerability; fixes are available.

Bank leaks 60,000 account details in three character email slip-up
27,000 MongoDB servers have their data wiped, receive ransom demand for its safe return
MongoDB Attacks Jump From Hundreds to 28,000 In Just Days
St. Jude Medical Patches Vulnerable Cardiac Devices
iCloud Glitch? Woman buys iPhone, finds contact details of top celebs
Hello Kitty Database of 3.3 Million Breached Credentials Surfaces
Following Extortion Attempt, Gaming Network ESEA Breached, 1.5M Profiles Leaked
Prison librarian swaps books for bars after dark-web gun buy caper
‘Fear factor pushing up cyber-insurance premiums’

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: MinGW cross compiled libpng 1.6.27 release, fixing a potential security issue.For details, see https://sourceforge.net/p/png-mng/mailman/message/35575076/

LinuxSecurity.com: This update fixes an old NULL pointer dereference bug in png_set_text_2()discovered and patched by Patrick Keshishian (CVE-2016-10087). The potential”NULL dereference” bug has existed in libpng since version 0.71 of June 26,1995. To be vulnerable, an application has to load a text chunk into the pngstructure, then delete all text, then add another text chunk […]

LinuxSecurity.com: Update —- Update to 0.11 —- Update —- Update. **WARNING:** if youare using your own config file, add “` include /etc/sway/config.d/* “` Atthe end of it, otherwise nothing will work on Wayland

LinuxSecurity.com: MinGW cross compiled libpng 1.6.27 release, fixing a potential security issue.For details, see https://sourceforge.net/p/png-mng/mailman/message/35575076/

LinuxSecurity.com: This update fixes an old NULL pointer dereference bug in png_set_text_2()discovered and patched by Patrick Keshishian (CVE-2016-10087). The potential”NULL dereference” bug has existed in libpng since version 0.71 of June 26,1995. To be vulnerable, an application has to load a text chunk into the pngstructure, then delete all text, then add another text chunk […]

Hackers Leak 1.5 Million ESEA Player Records after Demanding $50k as Ransom
Man pleads guilty to role in harassment scheme against senior US government officials

Justin Liverman, a student from North Carolina, has admitted collaborating in a harassment scheme targeting US officials and their families. The post Man pleads guilty to role in harassment scheme against senior US government officials appeared first on WeLiveSecurity

US Voting Systems Deemed Critical Infrastructure
News in brief: Moscow freezes out LinkedIn; teen crooks ‘should have Wi-Fi blocked’; 123-reg hit by DDoS
FTC sues D-Link for ‘insecure’ routers and IP cameras
This tool can help weed out hard-coded keys from software projects
FTC will pay you to build an IoT security checker
Top cop: Strap Wi-Fi jammers to teen web crims as punishment
Drug Trade on Dark Web Lands Two Men into Jail
Connected car hacking: Who’s to blame?

ESET’s Cameron Camp just about recovered from the sensory overload that is CES to gather his thoughts on what was another fascinating event. The post Connected car hacking: Who’s to blame? appeared first on WeLiveSecurity

How to recover your system from a Ransomware attack
What a Locky Ransomware attack looks like
The Impact of British IP Bill on Technological Awareness and the Dark Web
MongoDB ransomware attacks sign criminals are going after servers, applications
Obama’s social media posts published as searchable archive
Open source server simplifies HTTPS, security certificates
Hacker publishes GitHub secret key hunter
Google caps punch-yourself-in-the-face malicious charger hack
VNC server library gets security fix
MongoDB ransom attacks soar, body count hits 27,000 in hours

security update

Risk Level: Very Low. Type: Trojan.

Twitter suspends ‘Pharma bro’ Martin Shkreli’ account for harassment
TV News anchor says ‘Alexa, buy me a dollhouse’ with predictable results…

LinuxSecurity.com: Security Report Summary

How to respond to a ransomware infection

LinuxSecurity.com: Update to Samba 4.4.9 —- Security fix for CVE-2016-2125, CVE-2016-2126

LinuxSecurity.com: For changes see: https://www.mozilla.org/en-US/thunderbird/45.6.0/releasenotes/

LinuxSecurity.com: **Version 5.4.5** (2016-12-29) * SECURITY FIX: fixed CVE-2016-10074 bydisallowing potentially unsafe shell characters Prior to 5.4.5, the mailtransport (Swift_Transport_MailTransport) was vulnerable to passing arbitraryshell arguments if the “From”, “ReturnPath” or “Sender” header came from anon-trusted source, potentially allowing Remote Code Execution * deprecatedthe mail transport

Super Mario Run for Android? No, it’s malware

LinuxSecurity.com: **Version 5.4.5** (2016-12-29) * SECURITY FIX: fixed CVE-2016-10074 bydisallowing potentially unsafe shell characters Prior to 5.4.5, the mailtransport (Swift_Transport_MailTransport) was vulnerable to passing arbitraryshell arguments if the “From”, “ReturnPath” or “Sender” header came from anon-trusted source, potentially allowing Remote Code Execution * deprecatedthe mail transport

Unprotected MongoDB: Medical Data of Veterans affected by sleep disorders leaked

security update

security update

How to use “Find my iPhone” app to locate your smartphone
Now hiring: 1 million cybersecurity job openings in 2017