Menu

Monthly Archives: February 2017

LinuxSecurity.com: The 4.9.9 update contains a number of important fixes across the tree

LinuxSecurity.com: Security fix for CVE-2017-2586, CVE-2017-2587 and CVE-2017-5849, —- Addlicense information file copyright_summary —- New version of netpbm isavailable (10.77.00)

LinuxSecurity.com: Rebase to latest upstream gitrev 20161120

Government focuses on young people to tackle cyberskills shortage

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Fake news: what can we all do to play our part in combating it?
Turning Tables on Nigerian Business Email Scammers
UK credit broker fined £120k for spamming folk with five million texts
Security researchers trick ‘CEO’ email scammer into giving up identity
Google Touts Progress in Android Security in 2016
‘World’s eighth-worst spammer sent more than a million emails’
Man sues Uber after privacy flaws ‘led to his divorce’
Pwnd Android conference phone exposes risk of spies in the boardroom
Proof-of-concept ransomware to poison the water supply
Kremlin-linked hackers believed to be behind Mac spyware Xagent
No Firewalls, No Problem for Google
RSA 2017: Deconstructing macOS ransomware

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

Forget quantum and AI security hype, just write bug-free code, dammit
New Chinese Cybersecurity Threats

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

Google claims ‘massive’ Stagefright Android bug had ‘sod all effect’

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

Meet LogicLocker: Boffin-built SCADA ransomware
Inside Confide, the chat app ‘secretly used by Trump aides’: OpenPGP, OpenSSL, and more
DHS Chairman Paints Bleak US Cybersecurity Picture
Schneier Brings Campaign for IoT Regulation to RSA
ASLR-security-busting JavaScript hack demo’d by university boffins
Apple: Don’t panic, but your Mac can be pwned via GarageBand .bands
PayPal users hit with “Payment Successfully Made Via Ali Express” Phishing Scam
‘We need a new Geneva Convention to protect all citizens from snoops’
Bruce Schneier: The US government is coming for YOUR code, techies
Cryptographers Dismiss AI, Quantum Computing Threats
No crypto backdoors, more immigration … says Republican head of House Committee on Homeland Security

security update

security update

security update

Roses are red, bugs make you blue, Patch Tuesday is late, because Microsoft loves you
News in brief: flying cabs for Dubai; UK hit by cyberattacks; Googlers quit after earning too much money
Someone DDoSed A University Server By Hacking Its Vending Machines
Microsoft’s president wants a Geneva Convention for cyberwar
Adobe Patches 13 Code Execution Vulnerabilities in Flash
Sage 2.0 ransomware wants to be just like Cerber when it grows up
No, you can’t get Verizon Unlimited free for 12 months
Nation States Distancing Themselves from APTs
IBM’s Watson teams up with its SIEM platform for smarter, faster event detection
65% of IT professionals feel Shadow IT is compromising cloud security
Battle of the botnets: My zombie horde’s bigger than yours
Ransomware attackers shift focus and resources to high-value sectors
Twitter stumbles on safety feature as users push back
The Rise of Fileless Malware: Over 100 Telecoms, Banks, Gov’t Orgs Under Attack
Researcher develops ransomware attack that targets water supply
CrowdStrike attempts to sue NSS Labs to prevent test release, court denies request

We’re not telling you anything new when we say that malware continues to pose a major challenge for businesses of all sizes. Polymorphism, in particular, is especially dangerous. Polymorphic executables constantly mutate without changing their original algorithm, meaning the code can change itself each time it replicates, even though its function never changes at all. […]

Worried about hacks, senators want info on Trump’s personal phone
New Android trojan mimics user clicks to download dangerous malware

Android users are exposed to a new malicious app imitating Adobe Flash Player and serving as an entrance gate for potentially any kind of dangerous malware The post New Android trojan mimics user clicks to download dangerous malware appeared first on WeLiveSecurity

Google search results are falling foul of scammers spoofing well-known sites
UK website data insecurity worries: Users in bits over car break-up emails
ILOVEYOU: The wrong kind of LoveLetter

A game with love: How the LoveLetter virus corrupted our tech by playing on our emotions. The post ILOVEYOU: The wrong kind of LoveLetter appeared first on WeLiveSecurity

Border guards force US citizen to unlock his NASA-owned work phone
Newly discovered flaw undermines HTTPS connections for almost 1,000 sites
Infrastructure under attack: The next ransomware wave
Prepare for the smart bot invasion

For most of my professional life, the term “bot” has been associated with badness. As a computer security professional, whenever I saw bots involved, they were usually committing malicious acts and harnessing hundreds or thousands of otherwise innocent devices and computers to engage in harmful deeds.But that will change as good bots become more common, […]

Android Banking Trojan Marcher Infects Devices to Steal Payment Cards
Valentine’s day: what’s your secret technology crush?
The Register’s guide to protecting your data when visiting the US
SaaS-y security outfit CrowdStrike falls out of love with test lab
Senators raise concerns over Donald Trump’s smartphone security
Roses are red, you’re over the moon, ‘cos you work in infosec, and you’re retiring soon
Explain! yourself! US! senators! yell! at! Yahoo!
Infosec pros aren’t too bothered by Trump – it’s his cabinet sidekicks you need to worry about
WTF is up with the W3C, DRM and security bods threatened – we explain
IT bosses: Get budgets for better security by rating threats on a scale of zero to Yahoo!
Smashing Security podcast: Using public Wi-Fi
Teacher Being Investigated for Exposing 7th Graders to Porn
Lazarus mob possibly behind malware attacks against Polish banks
Mozilla says Firefox Klar does not Collect User Data from iOS Devices
News in brief: Cook hits out at ‘fake news’; Trump under fire; flying cars on the runway

LinuxSecurity.com: Update to 3.20.7, fixing a serious password extraction sweep attack on thepassword manager [(#752738)](https://bugzilla.gnome.org/show_bug.cgi?id=752738)

Risk Level: Very Low. Type: Worm.

Risk Level: Very Low. Type: Trojan.

Updated Firmware Due for Serious TP-Link Router Vulnerabilities
Fancy Bear: who’s behind the group implicated in so many political hacks?
Bloke, 27, arrested, tech gear seized by cops over UK Sports Direct hack
University’s IoT devices went fishing for information – how did it happen?
Open Databases a Juicy Extortion Target
Brave VMs to destroy themselves, any malware they find on HP’s new laptop
Russia and China bombard Blighty with 188 cyberattacks in 3 months
Google to cough up $20m after Chrome rips off four malware patents
7 Best Encrypted Email Services That You Can Use
Threatpost News Wrap, February 13, 2017
‘Paranoid’ Republicans flock to app that wipes conversations
Next-gen security software: Myths and marketing

There is a view in the media of the current security market that assumes a split between first-generation and technologies using next-generation signature-less detection. The post Next-gen security software: Myths and marketing appeared first on WeLiveSecurity

Line between cyber crooks and cyber spies getting more blurry
How San Diego fights off 500,000 cyberattacks a day
Worldwide bank attack blitz linked to Sony Pictures hacking crew
Monday review – the hot 28 stories of the week
Which Windows 10 should your business install? This one