Menu

Monthly Archives: January 2017

UK’s Largest Hosting firm 123-Reg ‘Pounded’ by DDoS Attack
FTC IoT privacy and security push points out D-Link router and webcam flaws

The US Federal Trade Commission has again acted on its serious concerns about data privacy and security in the Internet of Things (IoT). This time D-Link webcams and routers are the focus. Stephen Cobb puts this latest FTC move in context. The post FTC IoT privacy and security push points out D-Link router and webcam […]

Wikileaks Support Account Deletes Tweet about Making Database of Verified Accounts
Bank robber reveals identity – by using his debit card during crime
FBI let alleged pedo walk free rather than explain how they snared him
Brazil’s largest news portals UOL and Folha hacked; redirected to RedTube

security update

CIA director AOL email hacker coughs to crime
More than 10,000 exposed MongoDB databases deleted by ransomware groups
News in brief: Thai cybersecurity move; Verizon wobbles on Yahoo; Swiss rap Uber

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Symantec’s First Ever Hardware Device Protects Network and IoT Devices
CyberZeist’s claims to have hacked FBI’s website ‘are a hoax’

  FireCrypt Ransomware Builder Found in Wild Researchers have discovered a new ransomware variant that uses “.firecrypt” as its amended extension once encryption has taken place. FireCrypt is compiled using a command line builder software that allows varying inputs and outputs to be determined by the author for a unique hash, as this allows for […]

Tech security: oldies getting it in the neck again
Best company name ever! Share capital £1, name priceless…
Ransomware sleazeballs target UK schools
FBI refutes DNC claims about not investigating servers
Children in a digital world ‘need lessons in online safety’

More needs to be done to better equip children for life in a digital world, according to a new report from England’s children’s commissioner. The post Children in a digital world ‘need lessons in online safety’ appeared first on WeLiveSecurity

Telegram encrypted messaging app adds ‘Unsend’ button
Hacker Claims Breach of FBI’s Webserver; Plone CMS Calls It a Hoax
MongoDB Databases being Targeted by Cyber-criminals for Ransom
Schools hit by spate of cold call ransomware attacks
3… 2…1… and 123-Reg hit by DDoSers. Again
Dodgy dealer on Amazon lures marks towards phishing site
Man sues Verizon for $72m for not stopping him committing ID theft
D-Link sucks so much at Internet of Suckage security – US watchdog
Insane blackhats behind world’s most expensive ransomware ‘forget’ to backup crypto keys
Netgear unveils world’s easiest bug bounty

LinuxSecurity.com: This update includes the latest stable release of _Apache Subversion_, version**1.9.5**. #### Client-side bugfixes: * fix accessing non-existent paths duringreintegrate merge * fix handling of newly secured subdirectories in workingcopy * info: remove trailing whitespace in –show-item=revision ([issue4660](http://subversion.tigris.org/issues/show_bug.cgi?id=4660)) * fix recordingwrong revisions for tree conflicts * gpg-agent: improve discovery of gpg-agentsockets * gpg-agent: fix […]

LinuxSecurity.com: Update to the latest upstream release

LinuxSecurity.com: New upstream release

LinuxSecurity.com: Update to 4.5.1.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: For changes see: https://www.mozilla.org/en-US/thunderbird/45.6.0/releasenotes/

LinuxSecurity.com: **Version 5.2.21** (December 28th 2016) * Fix missed number update in versionfile – no functional changes —- **Version 5.2.20** (December 28th 2016) ***SECURITY** Critical security update for CVE-2016-10045 please update now!Thanks to [Dawid Golunski](https://legalhackers.com) and Paul Buonopane(Zenexer). —- ** Version 5.2.19** (December 26th 2016) * Minor cleanup** Version 5.2.18** (December 24th 2016) * **SECURITY** […]

KillDisk Ransomware Now Targets Linux, Prevents Boot-Up, Has Faulty Encryption
Tech Support Scammers Targeting Mac Users with DoS attacks
Smashing Security #002: ‘Invest in carrier pigeons’

security update

LinuxSecurity.com: An update for puppet-tripleo is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact [More…]

Netgear launches Bug Bounty program; offering lucrative rewards
Free 3G internet from WhatsApp? No, it’s a scam

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: CVE-2016-3189 bzip2: heap use after free in bzip2recover

LinuxSecurity.com: libpng 1.6.27 release, fixing a potential security issue. For details, seehttps://sourceforge.net/p/png-mng/mailman/message/35575076/

LinuxSecurity.com: Update to 2.46 Fixes various security issues, seehttp://www.mozilla.org/security/known-vulnerabilities/seamonkey.html for moreinfo. No more includes Chatzilla and DOM Inspector in the package — installthem yourself now (as usual other addons) from https://addons.mozilla.org

LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla Firefox and Thunderbird the worst of which could lead to the execution of arbitrary code.

News in brief: AI breaks out of the cellphone; autonomous cars ‘nowhere near’; Apple pulls NYT app in China
Spy code dormant for three years resurfaces in two new variants
Social media security is not just for kids – how safe are your profiles?
CyberZeist targets FBI, DNC claims the agency didn’t seek access to hacked servers
Ex-soldier pleads guilty to terror crime after not revealing iPhone PIN
Man sues Verizon for $72 million, says negligence allowed him to commit ID theft
KillDisk now targeting Linux: Demands $250K ransom, but can’t decrypt

ESET has discovered a Linux variant of the KillDisk component that renders Linux machines unbootable, while encrypting files and requesting a large ransom at the same time. The post KillDisk now targeting Linux: Demands $250K ransom, but can’t decrypt appeared first on WeLiveSecurity

  By now, everybody has probably heard of CryptoLocker. It makes sense that CryptoLocker would get a fair amount of media attention, since it’s been involved in several high-profile hacks, but there are a number of other players on the ransomware stage that deserve a place of distinction among the list of players. Managed service […]

Using real names online ‘leads to discrimination and harrassment’
Schools warned about cold-calling ransomware attacks
British military laser death ray cannon contract still awarded, MoD confirms
Windows exploitation in 2016

We are pleased to present our annual report Windows exploitation in 2016. In this latest version of our report, we offer a fresh look at modern security features in Windows 10. The post Windows exploitation in 2016 appeared first on WeLiveSecurity

Security expert: Ransomware took in $1 billion in 2016
Security-Oriented Kodachi 3.6 Linux OS Improves VPN and Tor Connectivity, More
LG threatens to put Wi-Fi in every appliance it releases in 2017
US government subcontractor leaks confidential military personnel data
Why companies offer a hacking bounty — and why there are challenges
Ransomware offers free decryption if you learn about cybersecurity
All that glisters is not security gold at CES in Las Vegas
Federal Trade Commission launches $25,000 IoT security competition

The Federal Trade Commission have launched a competition to encourage the public to devise a technical solution to protect IoT devices from security threats. The post Federal Trade Commission launches $25,000 IoT security competition appeared first on WeLiveSecurity

Linux 2017: With great power comes great responsibility
Ransomware Has Evolved, And Its Name Is Doxware
8 Docker security rules to live by

LinuxSecurity.com: Security Report Summary

Researchers work to save trusted computing apps from keyloggers

LinuxSecurity.com: An update for gstreamer1-plugins-bad-free is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for gstreamer1-plugins-good is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for gstreamer-plugins-good is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for gstreamer-plugins-bad-free is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

Put walls around home Things, win $25k from US government
Hacker claims FBI CMS zero day hack, dumps 155 purported logins
Ransomware scum: ‘I believe I’m a good fit. See attachments’
Florida Man sues Verizon for $72m – for letting him commit identity theft
News in brief: child bypasses iPhone security; MongoDB warning; ransom demand of time
French Businessman Spared Jail Time for Involvement in Child Porn Scheme
Warning not to spend IT security cash on the wrong things
Hot Desk? Sec-tech firm LANDESK to be forged together with HEAT

LinuxSecurity.com: upstream version 1.0.9 (BZ#1406277)

LinuxSecurity.com: – Fixes 1395311 – CVE-2016-9575 ipa: Insufficient permission check incertprofile-mod – Fixes 1370493 – CVE-2016-7030 ipa: DoS attack againstkerberized services by abusing password policy —- – Fixes 1395311 -CVE-2016-9575 ipa: Insufficient permission check in certprofile-mod – Fixes1370493 – CVE-2016-7030 ipa: DoS attack against kerberized services by abusingpassword policy

LinuxSecurity.com: upstream version 1.0.9 (BZ#1406277)

LinuxSecurity.com: An update for systemd is now available for Red Hat Enterprise Linux 7.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

The year in security: Trends 2017

In this feature, we capture some of the key ideas discussed in ESET’s latest trends paper for 2017, Security Held Ransom. The post The year in security: Trends 2017 appeared first on WeLiveSecurity

Designer launches fabric to bamboozle facial recognition
TCL targets Apple, Samsung with new BlackBerry handset
Your new year’s resolution: review your password habits
IoT devices could help authorities solve criminal cases
Travel booking systems ‘wide open’ to abuse – report