Menu

Monthly Archives: February 2017

Facebook goes down; comes back with suspicious account activity alert

security update

Google Researchers Successfully Broke SHA-1 Web Security Tool

Emergency Services Lines DDoS’d in Texas Officials have sentenced a cybercriminal who manipulated a bug via the Twitter app to continuously dial 911, which spread to several hundred individuals across multiple states. By tweeting out a malicious link to his followers, anyone who clicked on it was subjected to an endless loop of dialing the […]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Latest stable upstream release, includes security fix for CVE-2017-5593

LinuxSecurity.com: WARNING: Please note that this update comes with a slightly different syntax ofsesman.ini file, so if you edited this file by hand, you may need to look at the.rpmnew file and merge any required changes by hand. This release also createsthree files in /etc/xrdp directory if they don’t already exist or are empty: -rsakeys.ini […]

LinuxSecurity.com: Latest stable upstream release, includes security fix for CVE-2017-5593

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

Mysterious Gmail account lockouts prompt hack fears
News in brief: Boeing data accidentally emailed; Russian cyber-war boost; alleged hacker arrested
Google uses AI to create troll-spotting tool to clean up comments
Threatpost News Wrap, February 24, 2017
Uber Sued by Google’s Waymo for Stealing its Self-Driving Car Technology
Cloudflare Bug Leaks Sensitive Data
Taxpayers shrug off ID fraud warnings even as attacks rise
Twitter users, do you know who’s spying on your web-surfing habits?
Debugging a kernel in QEMU/libvirt – Part II
It’s raining. It’s pouring. This fake weather app is stealing your credentials
British man arrested after 900,000 broadband routers knocked offline in Germany
Ransomware ‘customer support’ chat reveals criminals’ ruthlessness
CloudFlare Blames Internal Faults for Memory and Client Data Leakage
Facebook or Google: whose messenger AI bot has the edge?
South Korea targeted by cyberspies (again). Kim, got something to say?
Cloudbleed: Big web brands leaked crypto keys, personal secrets thanks to Cloudflare bug
Someone from China is Distributing Mirai Malware Through Windows Botnet
Policy Experts Push To Make Vulnerability Equities Process Law
I was authorized to trash my employer’s network, sysadmin tells court
US ‘security’ biz trio Sentinel Labs, Vir2us, SpyChatter accused of lying about certification

security update

BitTorrent distribution sites dropping crypto-ransomware on macOS
Google kills SHA-1 with successful collision attack
Bang! SHA-1 collides at 38762cf7­f55934b3­4d179ae6­a4c80cad­ccbb7f0a
Drones can steal data from infected PCs by spying on blinking LEDs
News in brief: San Diego plans data-gathering smart city upgrade; Amazon says no; judge says no
‘First ever’ SHA-1 hash collision calculated. All it took were five clever brains… and 6,610 years of processor time
Breaking and protecting devops tool chains
Bruce Schneier and the call for “public service technologists”
First Practical SHA-1 Collision Attack Arrives

LinuxSecurity.com: An update for python-oslo-middleware is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: This release fixes pcregrep multi-line matching with –only-matching option, acrash when JIT-compiling some patterns (CVE-2017-6004) and a possible bufferoverflow when formatting a pcregrep error message.

LinuxSecurity.com: it was found that KDE plasma does not honor the setting for prompting whenexecuting executable files on the desktop. This update resolves this issue.

LinuxSecurity.com: Security fix for CVE-2016-10132, CVE-2016-10133, CVE-2016-10141, CVE-2017-5627,CVE-2017-5628.

LinuxSecurity.com: Update to the latest version, fixes a security issue.

LinuxSecurity.com: Security fix for CVE-2016-8745

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: it was found that KDE plasma does not honor the setting for prompting whenexecuting executable files on the desktop. This update resolves this issue.

LinuxSecurity.com: Security fix for CVE-2016-10132, CVE-2016-10133, CVE-2016-10141, CVE-2017-5627,CVE-2017-5628.

LinuxSecurity.com: Update to the latest version, fixes a security issue.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

Risk Level: Very Low. Type: Trojan.

Ex-employees sued for £15m over data slurpage ordered to pay up just £2
10 Powerful But Not Yet Promoted Antivirus for PC, Mac, Android, iPhone
Barely 1% of Android users are running Nougat, as Apple shows how to update devices properly
Impact of New Linux Kernel DCCP Vulnerability Limited
Healthcare data breaches ‘mostly caused by insiders’
How much does Facebook really know about you – and is it right?
Lawmakers set to overturn broadband privacy rules, as ISPs requested
Smashing Security #009: False flags and hacker clues
Java, Python FTP Injection Attacks Bypass Firewalls
Destructive Mac ransomware spread as cracks to pirate commercial software
Publicly Disclosed Windows Vulnerabilities Await Patches
Released Android malware source code used to run a banking botnet

ESET researchers have discovered a new variant of botnet-forming Android banking malware based on source code made public a couple of months ago. The post Released Android malware source code used to run a banking botnet appeared first on WeLiveSecurity

Deutsche Telekom hack suspect arrested at London airport
Hackers spam Counter-Strike: Global Offensive to spotlight security flaws
At death’s door for years, widely used SHA1 function is now dead
Linux’s decade-old flaw: Major distros move to patch serious kernel bug
Salted Hash: RSAC 2017 Recap
How to scrub your private data from ‘people finder’ sites
‘Zombie script’ deluges Internet Explorer 11 with pop-up alerts until user closes tab
How to Install TOR on Android and iOS Devices
Microsoft catches up to Valentine’s Day Flash flaw massacre
Boffins exfiltrate data by blinking hard drives’ LEDs
Linux kernel gets patch for 11-year-old local-root-hole security bug
Firefox certificate cache leaks user information
US judge halts mass fingerprint harvesting by cops to unlock iPhones

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

New MacOS ransomware spotted in the wild
Criminals Monetizing Attacks Against Unpatched WordPress Sites
Chrome Users Beware- Do Not Fall Prey to Missing Font Malware Campaign
Netflix Stethoscope gives users a BYOD security checkup
Blundering Boeing bod blabbed spreadsheet of 36,000 coworkers’ personal details in email
BugDrop Malware Campaign Obtains Data by Compromising PC Microphones
Global spam drops by more than half – now what?
Google Upspin Secure File-Sharing Released to Open Source
Intermediate CA Caching Could Be Used to Fingerprint Firefox Users
News in brief: pushback on Pirate Bay ban; course in fake news; autonomous Ubers get passengers

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Android malware: It doesn’t hurt to know about this

Android malware is an increasing problem … but worry not – n this infographic, we highlight some of the key things you should be aware of. The post Android malware: It doesn’t hurt to know about this appeared first on WeLiveSecurity

Facebook rapped for dragging its feet on pictures stolen for ‘like-farming’
Gordon Ramsay’s father-in-law charged with hacking celebrity chef’s email
Privacy concerns over gaps in eBay crypto
Good news and bad news on the Microsoft patch front