Menu

Monthly Archives: February 2017

Want to come to the US? Be prepared to hand over your passwords if you’re on Trump’s hit list

LinuxSecurity.com: BitlBee 3.5.1 (30 Jan 2017) =========================== – purple: Fix crash onfile transfer requests from unknown contacts. This was the result of anincomplete fix in the previous release and may result in remote DoS. Read thefull security advisory at: https://bugs.bitlbee.org/ticket/1282 – After someinvestigation we decided to reclassify a crash fix from the previous release asa […]

LinuxSecurity.com: Important change: * Most of the utilities were move to the new sub-package”server-utils” Other enhancements: (see changelog) * CVE fixes, SPECfilefixes, patches revision, tests blacklist revisions * Preparation and testing ofthe Cracklib plugin to be added

Ex-NSA contractor Harold Martin indicted: He spent ‘up to 20 years stealing top-secret files’
Revealed: ‘Suicide bomber Barbie’ and other TSA quack science that cost $1.5 billion
Retail Giant Sports Direct Suffered Data Breach Affecting 30,000 Employees
Fileless Memory-Based Malware Plagues 140 Banks, Enterprises

LinuxSecurity.com: Security Report Summary

Pony credential stealer trampling users via Microsoft Publisher documents
Hackers deface thousands of website by exploiting WordPress vulnerability
Focus turns to deep learning to help social media tackle online abuse
News in brief: US might require social media passwords; BBM opens to developers; Uber rapped

LinuxSecurity.com: Update to 2.78.0. Fixes bug #1409216

Good guy Logic Supply resolves breach in days, unlike some companies
Mac malware from Iran targeting US defense industry, human rights activist

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Smashing Security podcast: Email attachment malware
Valve Patches Trivial XSS Bug in Steam
Conviction by computer is go, confirms UK Ministry of Justice
Police mine Facebook for data on inauguration protesters
Uber Debuts SSH Key Authentication Module
Beware the latest tax-season spear-phishing scam
Do you know where that open source came from?
Hacker pwns 150,000 printers to issue a security warning
Sports Direct hacked last year, and still hasn’t told its staff of data breach

Throughout 2016, many of the attacks and risks in the world of cybercrime followed “analog” crime: holding something for ransom/extortion, propaganda, theft, and identity scams. You might expect a cybersecurity vendor to see these trends as good for business, but in fact it’s the opposite. The modern world relies heavily on the internet and web […]

XSS marks the spot: Steam vuln dangles potential phishing line
Macro Malware Comes to macOS
Entrust your security secrets to a safe pair of hands

Imagine: your security is flawless. Not a single other person can access your sensitive information or accounts. And then the unthinkable happens – you’re in an accident. How will your loved ones get past your security measures to tend to your affairs? The post Entrust your security secrets to a safe pair of hands appeared […]

Ex-FireEye intern escapes prison sentence after creating and selling Dendroid malware
Why did a judge order Google to hand over emails from outside the US?
Revealed: Malware that skulks in memory, invisibly collecting sysadmins’ passwords
Open source users: It’s time for extreme vetting
Sophos to assimilate Invincea’s intelligent machine tech to fight malware
Honeypots: Free psy-ops weapons that can protect your network before defences fail
Sloppy iOS apps expose ‘encrypted’ user traffic
Smashing Security podcast: Passwords
100,000+ WordPress webpages defaced as recently patched vulnerability is exploited
Attackers Capitalizing on Unpatched WordPress Sites

LinuxSecurity.com: Minor upstream release fixing CVE-2016-8610, CVE-2017-3731, CVE-2017-3732.

LinuxSecurity.com: gnome-boxes 3.22.4 release, fixing a possible security issue with storing theexpress installation password in clear text. – Store the user password in thekeyring during an express installation. – Fix typo in debug string in vm-configurator. – Fix printf format strings in the selectiontoolbar.

LinuxSecurity.com: Update to 2.78.0. Fixes bug #1409216

Feds snooping on your email without a warrant? US lawmakers are on a war path to stop that
Popular iOS Apps Vulnerable to TLS Interception Attacks
Safer Internet Day – one thing that will make the biggest difference [VIDEO]
News in brief: more IoT devices than humans; FBI makes requests harder; rail users could pay by iris scans
Smart TV Manufacturer Vizio Fined $2.2M for Tracking Customers
St. Jude Patches Additional Cardiac Device

LinuxSecurity.com: An update for ntp is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for spice is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for spice-server is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in RTMPDump, the worst of which could lead to arbitrary code execution.

LinuxSecurity.com: Update to 3.22.6: * Fix minor memory leak[(#682723)](https://bugzilla.gnome.org/show_bug.cgi?id=682723) * Fix seriouspassword extraction sweep attack on password manager[(#752738)](https://bugzilla.gnome.org/show_bug.cgi?id=752738) * Fix adblockerblocking too much stuff, breaking Twitter[(#777714)](https://bugzilla.gnome.org/show_bug.cgi?id=777714)

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: For changes see: https://www.mozilla.org/en-US/thunderbird/45.7.0/releasenotes/

Indian hackers hack Facebook groups for posting teen, revenge porn images
Laptop-light GoCardless says customers’ personal data may have been lifted
Polish banks hit by malware seemingly spread by government website
Are you watching your TV or is your TV watching you?
Hackers take down dark web host linked with child abuse images
Phishing: Another thing we can blame on Brexit
Ransomware soars in 2016, while malware declines
76 Famous iOS Apps Vulnerable to Silent Data Interception
IRS-related phishing scams seen running rampant
AKBuilder is the latest exploit kit to target Word documents, spread malware
76 popular iPhone apps found wide open to data interception attacks
Dozens of iOS apps fail to secure users’ data, researcher says
US House approves new privacy protections for email and the cloud
Kali Linux on the Raspberry Pi: 3, 2, 1, and Zero
David Beckham calls in police over hacked emails
Fretting over fake news? It's only going to get worse

If you’re worried about fake news, you ain’t seen nothing yet. Soon we may not be able to tell the difference between a fake video and a real one, even forensically. What we are seeing today is the tip of the iceberg. Fake news has already altered the world forever. It’s always been a huge […]

FTC vs. VIZIO: Getting smart about TV data collection and sharing

Is your smart TV selling data about what you watch, without asking? As the US FTC goes after one TV maker, it may be time to check. The post FTC vs. VIZIO: Getting smart about TV data collection and sharing appeared first on WeLiveSecurity

Darkode VXer handed three years’ probation
Trump’s cybersecurity strategy kinda makes sense, so why delay?
Got an OpenBSD Web server? Better patch it

Risk Level: Very Low.

Web banking malware slurps $1.2m for crooks, now kingpin ‘fesses up
Went out boozing in SF during Dreamforce or Oracle OpenWorld? Malware may have slurped your bank card
Vizio coughs up $2.2m after its smart TVs spied on millions of families
Hacker: I made 160,000 printers spew out ASCII art around the world

security update

LinuxSecurity.com: The 4.9.7 update contains a number of important fixes across the tree

LinuxSecurity.com: Welcome to **phpMyAdmin 4.6.6**, a release containing security and bug fixes.This release includes many security fixes of various levels of severity. Werecommend all users upgrade to this release immediately. For full information onthe vulnerabilities fixed and mitigation factors for users who are unable toupgrade, refer to the ChangeLog file included with this release and […]

InterContinental Hotels Confirms Credit Card Breach

LinuxSecurity.com: The 4.9.7 update contains a number of important fixes across the tree

LinuxSecurity.com: 3.1.4

LinuxSecurity.com: Welcome to **phpMyAdmin 4.6.6**, a release containing security and bug fixes.This release includes many security fixes of various levels of severity. Werecommend all users upgrade to this release immediately. For full information onthe vulnerabilities fixed and mitigation factors for users who are unable toupgrade, refer to the ChangeLog file included with this release and […]

ICS, SCADA Security Woes Linger On
Banking chiefs ‘lack confidence to identify data breaches’

Just over one in five banks and insurers are confident in their ability to identify data breaches, according to a new global survey from Capgemini Consulting. The post Banking chiefs ‘lack confidence to identify data breaches’ appeared first on WeLiveSecurity

News in brief: ministers ‘not securing Twitter accounts’; dark web bug bounty; move on fake news in France
Anonymous shut down thousands of Dark Web sites for hosting child porn
Why does it cost 20 times as much to protect Mark Zuckerberg as Tim Cook?
Hacker hijacks thousands of publicly exposed printers to warn owners
Hacker takes over thousands of Printers; sends alerts to users
Anonymous hacker took down 10,000+ dark web sites, including child abuse content
Hacker blackmails David Beckham following email leak
RSA Conference 2017: expect to hear a lot about IoT threats, ransomware
Security Sessions: The CSO’s role in active shooter planning
Polish banks hit by malware sent through hacked financial regulator