ESET has spotted a new banking malware on Google Play. Disguised as a weather forecast app, it steals banking credentials and locks screens. The post Sunny with a chance of stolen credentials: Malicious weather app found on Google Play appeared first on WeLiveSecurity
This last month we have seen a new ransomware for Mac. Written in Swift, it is distributed on BitTorrent distribution site as “Patcher” for pirating popular software. The post New crypto-ransomware hits macOS appeared first on WeLiveSecurity
LinuxSecurity.com: Security Report Summary
LinuxSecurity.com: Security Report Summary
LinuxSecurity.com: Ruby Archive::Tar::Minitar is vulnerable to a directory traversal attack.
LinuxSecurity.com: Multiple vulnerabilities have been found in GPL Ghostscript, the worst of which may allow execution of arbitrary code.
LinuxSecurity.com: Several security issues were fixed in the kernel.
LinuxSecurity.com: Several security issues were fixed in the kernel.
LinuxSecurity.com: Several security issues were fixed in the kernel.
LinuxSecurity.com: Several security issues were fixed in the kernel.
LinuxSecurity.com: Several security issues were fixed in the kernel.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.
Approximately 26% of Americans have been compromised by healthcare data breaches, according to a new survey from Accenture. The post Healthcare data breaches reach a ‘sizeable number of US consumers’ appeared first on WeLiveSecurity
Today, ESET has released a white paper on RTM, a cybercrime group that has been relentlessly targeting businesses in Russia and neighboring countries. The post RTM: Stealthy group targeting remote banking system appeared first on WeLiveSecurity
One of the biggest problems with security defenses is the lack of concrete data to measure the effectiveness of mitigations against threats. In almost any other industry, the dearth of data would be embarrassing. As I’ve noted before, every organization needs to develop a data-driven security defense. Such a defense uses a company’s own threat intelligence to […]
LinuxSecurity.com: Multiple vulnerabilities have been found in tcpdump, the worst of which may allow execution of arbitrary code.
LinuxSecurity.com: Multiple vulnerabilities have been found in PHP, the worst of which could lead to arbitrary code execution or cause a Denial of Service condition.
LinuxSecurity.com: Multiple vulnerabilities have been found in Xen, the worst of which could lead to the execution of arbitrary code on the host system.
LinuxSecurity.com: Multiple vulnerabilities have been found in QEMU, the worst of which could lead to the execution of arbitrary code on the host system.
LinuxSecurity.com: Multiple vulnerabilities have been found in Nagios, the worst of which could lead to privilege escalation.
LinuxSecurity.com: Multiple vulnerabilities have been found in libass, the worst of which have unknown impacts.
LinuxSecurity.com: Multiple vulnerabilities have been found in LibVNCServer/LibVNCClient, the worst of which allows remote attackers to execute arbitrary code when connecting to a malicious server.
LinuxSecurity.com: Multiple vulnerabilities have been found in Dropbear, the worst of which allows remote attackers to execute arbitrary code.
LinuxSecurity.com: A vulnerability in Opus could cause memory corruption.
LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which may allow execution of arbitrary code.
LinuxSecurity.com: Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.
LinuxSecurity.com: A buffer overflow in TigerVNC might allow remote attackers to execute arbitrary code.
LinuxSecurity.com: Security fix for CVE-2017-3135
LinuxSecurity.com: Multiple vulnerabilities have been found in MuPDF, the worst of which allows remote attackers to execute arbitrary code.
LinuxSecurity.com: Multiple vulnerabilities have been found in the GNU C Library, the worst of which allows context-dependent attackers to execute arbitrary code.
LinuxSecurity.com: A vulnerability in NTFS-3G allows local users to gain root privileges.
LinuxSecurity.com: Security fix for CVE-2017-5595
LinuxSecurity.com: Security fix for CVE-2017-5595
LinuxSecurity.com: Update to 0.6.1
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low.
If you thought that the problem of tech support scams was disappearing, think again, says Josep Albors and David Harley. The post Support scams now reign in Spain appeared first on WeLiveSecurity
2016 saw interesting developments within the Android ransomware scene. Ransomware emerged as one of the most pressing cybersecurity issues on the mobile platform. The post Trends in Android ransomware appeared first on WeLiveSecurity
