Menu

Monthly Archives: February 2017

Security firms need to stop exaggerating hacker’s abilities to hype their products
Google ordered by U.S. court to produce emails stored abroad

The benefits of adopting the managed service provider (MSP) business model are compelling. After all, predictable, recurring revenue; deeper engagement with clients; and a trusted advisor relationship that generates further business opportunities all sound like everything a successful services business could want. However, for some, it still means braving uncharted territory. Important Considerations IT solutions […]

The best security solutions of the year
Microsoft’s DRM can expose Windows-on-Tor users’ IP address
Hello? Police? My darknet drug market was just hacked by criminals
“This is you?” message is the latest scam to be distributed via Facebook

Risk Level: Very Low. Type: Trojan.

Slammer worm slithers back online to attack ancient SQL servers
Why You Should Use These 5 VPN Services
Twitter Users Hit with Blue Badge Verification Phishing Scam
Hacker Dumps Hacking Tools Allegedly Stolen from Cellebrite
Privacy-Focused Tails 2.10 Linux Includes Security Updates, New Tools
Linux: The 10 best privacy and security distributions
AI isn’t for the good guys alone anymore
Thought your data was safe outside America after the Microsoft ruling? Think again
New SMB bug: How to crash Windows system with a ‘link of death’
Hacking the 2016 election: A timeline

Hotel Doors Locked By Ransomware A prestigious hotel in Austria was the target of a ransomware attack that left their electronic door locking systems inoperable for several hours. The hack only stopped hotel personnel from activating new keycards due to system is capabilities allowing the functionality without power. Unfortunately, the hotel did pay a ransom […]

PayPal Users Hit with Account Limited Phishing Scam
Honeywell SCADA Controllers Exposed Passwords in Clear Text
Locky Ransomware, Kovter Click-Fraud Malware Spreading in Same Campaigns
Critical WordPress update fixes zero-day flaw unnoticed

LinuxSecurity.com: This release turns on HTTPS encyption all over the publishing plugins. Usersusing Tumblr and Yandex.Fotki publishing are strongly advised to change theirpasswords and reauthenticate Shotwell to those services after upgrade. Users ofPicasa and Youtube publishing are strongly advised to reauthenticate (Log outand back in) Shotwell to those services after upgrade. Changes in shotwell0.24.5 release: […]

LinuxSecurity.com: This release turns on HTTPS encyption all over the publishing plugins. Usersusing Tumblr and Yandex.Fotki publishing are strongly advised to change theirpasswords and reauthenticate Shotwell to those services after upgrade. Users ofPicasa and Youtube publishing are strongly advised to reauthenticate (Log outand back in) Shotwell to those services after upgrade. Changes in shotwell0.24.5 release: […]

LinuxSecurity.com: This update should make OpenLDAP up to date with latest NSS, notably: – fixolcTLSProtocolMin handling – fix TLS_CIPHER_SUITE parsing – update a list ofciphers to fit latest NSS development – make use of NSS global settings for`DEFAULTS’ TLS_CIPHER_SUITE keyword Additionaly, slapd should start correctlyafter network is online, now.

LinuxSecurity.com: Update wavpack to 5.1.0

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for rabbitmq-server is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…]

Google will use Gmail to nudge you into updating your browser
News in brief: Pentagon risks cyberattacks; government rapped on security; Russia warned on meddling

Risk Level: Very Low. Type: Trojan.

Palestinian Engineer Jailed for Hacking Israeli CCTVs & Drones
Scammers target firms with W-2 phishing/CEO fraud blend
Sophos update borks systems at London NHS trust
Threatpost News Wrap, February 3, 2017
0-Day Security Flaw Could Lead Windows Devices to BSOD
Cisco Patches Authentication Bypass in Cisco Prime Home
Chinese hackers switch tactics for spying on Russian jet makers
Critical Cisco security hole could lead to hackers seizing control of thousands of home routers
Microsoft Waits for Patch Tuesday to Fix SMB Zero Day
How AI is stopping criminal hacking in real time
Vulnerability in Microsoft SMBv3 protocol crashes Windows PCs
UK defence secretary: Russian hacks are destabilising Western democracy
Pacemaker data used to help indict alleged arsonist
UK.gov slammed by Parliamentary types for ‘dysfunctional’ infosec
GCHQ cyber-chief slams security outfits peddling ‘medieval witchcraft’

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: The system could be made to crash if it received specially craftednetwork traffic.

Popular hacker warkit Metasploit now hacks hardware and cars

LinuxSecurity.com: The system could be made to crash if it received specially craftednetwork traffic.

LinuxSecurity.com: Several security issues were fixed in the kernel.

Particle accelerator hacked: Boffins’ hashed passwords beamed up
Smashing Security podcast #006: ‘A romantic ransomware hotel break’
Buggy Pentagon systems a dream come true to attackers, says researcher

Risk Level: Very Low. Type: Trojan.

Careless Licking gets a nasty infection: County stiffed by ransomware

security update

Two Arrested in UK for Hacking DC CCTV Cameras Before Trump Inauguration
WordPress Silently Fixed Privilege Escalation Vulnerability in 4.72 Update
Printing and Marketing Firm Leaks High-Profile Customers’ Data
‘Webroot made my PCs s*** the bed’ – AV update borks biz machines hard
Is your office printer vulnerable to being attacked?
News in brief: Czech minister’s emails attacked; Dutch fear election hacking; Facebook extends connections
Google Adds Security Key Enforcement to G Suite Apps, Hosted S/MIME to Gmail
Another Schneider vuln: Plaintext passwords on client-side RAM resolved
What’s the actual cost to a business of a data breach?
Strategic cybersecurity will stymie ‘expanding threat landscape’

Strategic cybersecurity the key to keeping the threat of cyberattacks at bay, a new report states. The post Strategic cybersecurity will stymie ‘expanding threat landscape’ appeared first on WeLiveSecurity

Gamers lose suit over retention of biometric faceprints
Lego builds social network that should be safe for kids
Wardriving: A digital census of Wi-Fi networks?

Are you au fait with wardriving? ESET’S Lucas Paus explains the best ways to survey wireless networks while you’re on the move. Hint: avoid free Wi-Fi networks! The post Wardriving: A digital census of Wi-Fi networks? appeared first on WeLiveSecurity

Why 2017 will be the worst year ever for security
HPE acquires security startup Niara to boost its ClearPass portfolio
Hackers are seeking out company insiders on the black market
Protest against Trump’s US travel ban leaves ‪PasswordsCon‬ in limbo
Ignorance is bliss? An enormous WordPress zero-day has been secretly fixed
Shopping for W2s, Tax Data on the Dark Web
Security flaws in Pentagon systems “easily” exploited by hackers
The essential guide to MongoDB security
How to predict the next major hack
Netherlands reverts to hand-counted votes to quell security fears
Wanna protect your data center? Take tips from the US Secret Service
Bring out your dead! Firm wants to pay big bucks for old bugs
WordPress fixed god-mode zero day without disclosing the problem

Twitter is buzzing with chatter about the RSA Conference 2017 (RSAC). Attendees, vendors, and speakers alike are anxiously awaiting the opportunity to discuss information security and the latest technology at the largest security conference in the world. Attending RSAC? Here’s what you should know about Webroot. What’s new with Webroot in 2017 Today, we announced […]

Home-pwners: Cisco’s Prime Home lets hackers hijack people’s routers, no questions asked
WordPress Websites Exposed to Severe Content Injection Vulnerability

security update

security update

Fear not, Europe’s Privacy Shield is Trump-proof – ex-FTC bigwig
HTTPS Hits 50 Percent Traffic Milestone
New security flaws can turn Netgear Routers into army of botnets
Latest Ubuntu Update Includes OpenSSL Fixes

Type: Vulnerability. Microsoft SQL Server is prone to a privilege-escalation vulnerability; fixes are available.

GitLab database goes out after spam attack
Google upgrades G Suite with tools for IT pros
Easing of security checks at remote Scottish airports ‘a risk’

LinuxSecurity.com: Security Report Summary