Menu

Monthly Archives: February 2017

LinuxSecurity.com: An update for openssl is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

Connected car in the second-hand lot? Don’t buy it if you’re not hack-savvy
Google goes public about unpatched Windows vulnerability
German parents urged to destroy data-collecting toy doll
Google bellows bug news after Microsoft sails past fix deadline

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Goodbye Spy Toy: Germany Bans My Friend Cayla Doll
Charging Smartphone in Public Ports Leads to Data Hack — So Let’s Stop

LinuxSecurity.com: Backport upstream fix to force limit and offset to be numeric

LinuxSecurity.com: Backport upstream fix to force limit and offset to be numeric

LinuxSecurity.com: USN-3199-1 introduced a regression in the Python Cryptography Toolkit whichcaused programs which relied on the original behavior to fail.

LinuxSecurity.com: Multiple vulnerabilities have been found in ImageMagick, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Programs using the Python Cryptography Toolkit could be made to crash or runprograms if they receive specially crafted network traffic or other input.

LinuxSecurity.com: Security Report Summary

Apple May Introduce Facial Recognition Instead of Touch ID in iPhone 8
Florida Man jailed for 4 years after raking in a million bucks from spam
Hackers Selling Undetectable Proton Malware for macOS in 40 BTC
RSA – day 3: Security for those who don’t know what that means

Here at RSA, an increasing amount of security purchases are made by those who got the task dumped in their laps, but who have little or no formal or practical training. The post RSA – day 3: Security for those who don’t know what that means appeared first on WeLiveSecurity

Paper factory fired its sysadmin. He returned via VPN and caused $1m in damage. Now jailed
RSA demo: TruStar anonymizes incident data to improve information exchange
Why cyber-robotics is key to cybersecurity’s future
Probe President Trump and his crappy Samsung Twitter-o-phone, demand angry congressfolk

security update

Smash up your kid’s Bluetooth-connected Cayla ‘surveillance’ doll, Germany urges parents
IDF targeted by sophisticated cyber espionage through Android devices
Gmail now blocks all JavaScript email attachments
News in brief: Oculus demos closed; smart doll ‘should be destroyed’; Europe warned over elections
Squirrels, Not Hackers, Pose Biggest Threat to Electric Grid

Risk Level: Very Low. Type: Trojan.

Couple can’t store data from camera pointed at next door’s garden
US account holders more likely to switch banks following fraud
Your computer is a cookie that you can’t delete
SMTP Strict Transport Security Coming Soon to Gmail, Other Webmail Providers
Cris Thomas on Cyberwar Rhetoric
To Spy or Not to Spy; Congress to Decide

Outerwear Online Retailer Hit with Cyber Attack Columbia Sportswear announced that they were in the midst of investigating a cyberattack on one of its subsidiary retail sites, prAna, a brand that was acquired by Columbia in 2014. While officials still haven’t confirmed the type of attack, they have stated that it shouldn’t affect any of […]

8 things you should know about spyware

WeLiveSecurity takes a look at what you need to know about spyware – the malware secretly prying on your online activities. The post 8 things you should know about spyware appeared first on WeLiveSecurity

Mystery deepens over Android spyware targeting Israeli soldiers
Tips for negotiating with cyber extortionists
Experts at RSA give their best cybersecurity advice
New Royal Navy Wildcat helicopters can’t transmit vital data
Xen Project asks to limit security vulnerability advisories
How Google reinvented security and eliminated the need for firewalls
Signal app gets video calling overhaul and a warning for iOS users
RSA 2017 hit parade: All the cool new security tools
RSA 2017 – day 2: Attacking yourself

Want to find holes in your security perimeter? What better way than to attempt to attack yourself, and here at RSA there are plenty of tools to help. The post RSA 2017 – day 2: Attacking yourself appeared first on WeLiveSecurity

Graham Cluley named most entertaining security blog

Successful companies stand on the shoulders of great customer service. At Webroot, we aim to consistently be the best, and to do so, we rely heavily on our highly skilled, globally-based technical support team to delight our customers at every turn. At Webroot, we utilize a follow-the-sun approach with customer service support staff in Australia, […]

US visitors must hand over Twitter, Facebook handles by law – newbie Rep starts ball rolling
Don’t panic over cyber-terrorism: Daesh-bags still at script kiddie level

security update

Corpse of US anti-spying law unearthed, reanimated, pushed blinking into the sunlight
Bangkok Police Arrests Ukrainian Hacker Planning ATM Malware Attack
Divide Between Work, Personal Data on Android Breached

LinuxSecurity.com: Applications using libgc could be made to crash or run programs asyour login.

News in brief: cookie breach alert for Yahoo users; text spammer fined; Churchill’s search for alien life
Smashing Security podcast #008: ‘I’ll give you my Android when you pry it from my cold, dead paws’
Microsoft calls for ‘Digital Geneva Convention’ to rein in cyberwarfare
Magento stores targeted by self-healing malware that steals credit card details
Haven’t deleted your Yahoo account yet? Reminder: Hackers forged login cookies
Another Yahoo Hack: Company Issues Security Notice to Users
Researchers develop battery that could run for more than a decade
Retailers push back against plans to boost security of online shopping
Security fixes delayed as Microsoft postpones Patch Tuesday
Fallen for a fake Twitter account? Here’s how to spot them
Should security pros get special H-1B visa consideration?
F-Secure buys industrial control security firm
RSA 2017: Microsoft Word Intruders step outside Office for the first time
A.I. faces hype, skepticism at RSA cybersecurity show
Former NSA techies raise $8m for their data governance startup
Yahoo warns users of account breaches related to recent attacks
New ASLR-busting JavaScript is about to make drive-by exploits much nastier
A Chip Flaw Strips Away Hacking Protections for Millions of Devices
At RSA, doubts abound over US action on cybersecurity
Demystifying targeted malware used against Polish banks

The purpose of this blog is to deliver technical details of an as-yet minimally documented malware that has made headlines in Poland. The post Demystifying targeted malware used against Polish banks appeared first on WeLiveSecurity

Researchers Discover Yet Another Malware Designed to Compromise Mac Devices
More Yahoo users warned of malicious account access via forged cookies
RSA 2017: The year the little guys get swallowed up

RSA feels like a mashup of giant tech Titans steadily swallowing up the little guys to make one massive, unholy tech monster. But how does that really work for small businesses as customers, and the rest of us? The post RSA 2017: The year the little guys get swallowed up appeared first on WeLiveSecurity

Gmail starts blocking JavaScript attachments: Alternative infector vectors to be expected?

Gmail rolls out a new policy to block JavaScript attachments, increasing security restrictions as ransomware attacks increase. The post Gmail starts blocking JavaScript attachments: Alternative infector vectors to be expected? appeared first on WeLiveSecurity

What is Cyber Deception?
Revealed: Web servers used by disk-nuking Shamoon cyberweapon
Organizations ‘concerned by cybersecurity skills gap’

The ongoing cybersecurity skills gap is dealing a significant blow to the confidence of organizations looking to defend themselves against potential attacks. The post Organizations ‘concerned by cybersecurity skills gap’ appeared first on WeLiveSecurity

Crypto-curious? Wickr’s opened its kimono for code review
ITU ponders whether blockchain belongs in its security standards
As Microsoft touts Windows Insider for biz, let’s take a look at W10’s broken 2FA logins
Setting Expectations Between States on Cyberwar
Republicans send anti-Signal signal to US EPA
OK, it’s time to talk mass spying again: America’s Section 702 powers are up for renewal
Cerber ransomware takes special care not to encrypt security product files
World’s Sturdiest Phone Nokia 3310 To Be Relaunched this Year
Rasputin whips out large intimidating tool, penetrates uni, city, govt databases – new claim
Verizon! surprisingly! OK! with! Yahoo! despite! mega-hack!

The City of San Diego is the 8th largest city in the US and has over 12,000 employees, numerous vendor partnerships, as well as a vast array of diverse systems and devices to protect. In addition to more traditional endpoints and data centers, the City must protect each new piece of smart technology it implements. These […]

News in brief: Nokia to reboot iconic phone; AI assistants set to do voice calls; Yahoo, Verizon ‘agree price’

LinuxSecurity.com: Qemu: net: mcf_fec: infinite loop while receiving data in mcf_fec_receive[CVE-2016-9776] Qemu: audio: memory leakage in ac97 [CVE-2017-5525] Qemu: audio:memory leakage in es1370 device [CVE-2017-5526] oob access in cirrus bitblt copy[XSA-208, CVE-2017-2615]

LinuxSecurity.com: – update to the latest upstream pre-release (fixes CVE-2016-9179)

LinuxSecurity.com: The newest upstream commit, fixing CVE-2017-5953 vim: Tree length values notvalidated properly when handling a spell file

LinuxSecurity.com: Security fix for CVE-2016-7922, CVE-2016-7923, CVE-2016-7924, CVE-2016-7925,CVE-2016-7926, CVE-2016-7927, CVE-2016-7928, CVE-2016-7929, CVE-2016-7930,CVE-2016-7931, CVE-2016-7932, CVE-2016-7933, CVE-2016-7934, CVE-2016-7935,CVE-2016-7936, CVE-2016-7937, CVE-2016-7938, CVE-2016-7939, CVE-2016-7940,CVE-2016-7973, CVE-2016-7974, CVE-2016-7975, CVE-2016-7983, CVE-2016-7984,CVE-2016-7985, CVE-2016-7986, CVE-2016-7992, CVE-2016-7993, CVE-2016-8574,CVE-2016-8575, CVE-2017-5202, CVE-2017-5203, CVE-2017-5204, CVE-2017-5205,CVE-2017-5341, CVE-2017-5342, CVE-2017-5482, CVE-2017-5483, CVE-2017-5484,CVE-2017-5485, CVE-2017-5486

LinuxSecurity.com: Security fix for CVE-2017-3135