Menu

Monthly Archives: March 2017

Apple Fixes 223 Vulnerabilities Across macOS, iOS, Safari

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

News in brief: Hong Kong voters’ data lost; Rudd faces pushback; Google Home lands in Britain

Risk Level: Very Low. Type: Trojan.

LastPass is scrambling to fix another serious vulnerability
Laptops With More than 3.7 Million Hong Kong Voters’ Data Stolen
Man loses appeal over Facebook threat to kill Obama
RIP: Antivirus veteran Raimund Genes, 54
eBay to ‘downgrade’ verification by switching to SMS
Necurs: Mass mailing botnet returns with new wave of spam campaigns
Unexplained three-month absence resulted in a seven-fold decrease in rate of emails containing malware. Read More

Ransomware authors are pivoting their attacks from individuals to government entities and health care institutions, causing a threat to public safety. Traditionally, crypto ransomware targeted individuals and encrypted their personal data and files as a form of extortion for hundreds of dollars. Ransomware has evolved to target businesses and government agencies for much larger financial […]

Apple squashes cert-handling bug affecting macOS and iOS
‘Siri, please dial 999 and save Mummy’s life’
India extends ‘Orwellian’ ID card scheme as critics warn of risks
Close to 1.4 billion data records compromised in 2016

Over a billion data records were compromised globally in 2016, according to Gemalto’s latest Breach Level Index. The post Close to 1.4 billion data records compromised in 2016 appeared first on WeLiveSecurity

API flaws said to have left Symantec SSL certificates vulnerable to compromise
How to respond to device and software backdoors inserted or left by vendors
World+dog had 1.4 BEEEELLION of its data records exposed last year
Why government plans to spy on WhatsApp will fail
Free public certificate authorities: Nice idea, big flaw

Readers often ask me how I feel about the latest free, public certificate authorities (CAs). I always tell them the same thing: It’s difficult for a free CA to actually provide any security assurance. There is no free lunch.I was reminded of this maxim when I read a recent article from HashedOut revealing that the […]

“Unique and Highly Sophisticated” Vulnerability Found in LastPass Manager
As of today, iThings are even harder for police to probe
CompSci boffins propose scheme to protect privacy in database searches

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

LinuxSecurity.com: A vulnerability in Xen’s bundled QEMU version might allow privilege escalation.

LinuxSecurity.com: A vulnerability in Deluge might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability in Libtasn1 allows remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: A coding error has been found in cURL, causing the TLS Certificate Status Request extension check to always return true.

FYI Docs.com users: You may have leaked passwords, personal info – thousands have
New Clues Surface on Shamoon 2’s Destructive Behavior
APT29 Used Domain Fronting, Tor to Execute Backdoor
LastPass scrambles to fix another major flaw – once again spotted by Google’s bugfinders
News in brief: Facebook rolls out location-sharing; Uber pulls tests after crash; NASA thanks schoolboy
Here’s What a Samsung Galaxy S7 Hacked with Ransomware Looks Like
Politicians call – again – for backdoors into encrypted messages
Ex-military and security firms oppose Home Sec in WhatsApp crypto row
Fileless UAC Bypass Uses Windows Backup and Restore Utility
US to make social media checks compulsory for some visas
Microsoft’s Docs.com is sharing dangerously sensitive personal files, information
Encrypted Email Service Tutanota Celebrates 2 Million Users
LastPass steps up quickly to fix vulnerabilities spotted by researchers
Why it’s a good idea to clear your browser history and cookies
Man indicted for sending seizure-causing GIF as a ‘deadly weapon’
iPhone-havers think they’re safe. But they’re not
How to configure WinDbg for kernel debugging

In this post, Matías Porolli looks at how to configure an environment with WinDbg and virtual machines in order to debug drivers or code running in Windows kernel space. The post How to configure WinDbg for kernel debugging appeared first on WeLiveSecurity

DoubleAgent ‘vulnerability’ – just how bad is it?
Encryption is a good thing
Critical flaw alert! Stop using JSON encryption
87 fake Minecraft mods exposed Android users to scammy websites, aggressive ads
USA can afford golf for Trump. Can’t afford .com for FBI infosec service

Risk Level: Very Low. Type: Trojan.

Dishwasher has directory traversal bug
World’s largest artificial Sun switched on for the very first time
25 vBulletin Forums Hacked; Millions of Accounts Being Sold on Dark Web

security update

Google Play faces cat and mouse game with sneaky Android malware
Online stores under attack; a new fraudster bot spotted in the wild

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Experts Doubt Hackers’ Claim Of Millions Of Breached Apple Credentials
Google proposes sending Symantec to TLS sin bin
FBI director floats international framework on access to encrypted data
Ever visited a land now under Islamic State rule? And you want to see America? Hand over that Facebook, Twitter, pal
CIA, WikiLeaks and Doctor Who?
WikiLeaks: CIA hacking tools infiltrate iPhones, MacBooks – Apple: It’s an old story
Apple: Macs and iPhones are safe from newly revealed CIA exploits
GiftGhostBot scares up victims’ gift-card cash with brute-force attacks
Privacy Advocates Vow to Fight Rollback of Broadband Privacy Rules
Instagram Adds Two-Factor Authentication
Prosecutors access data from locked phones of 100 Trump protesters
News in brief: Pyongyang role in heist probed; EU to discuss laptops ban; social media rapped on terrorism

Risk Level: Very Low. Type: Trojan.

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. Hackers Threaten to Lock 200M+ iCloud Accounts Hackers are threatening to remotely lock down over 200 million […]

Google to Symantec: We don’t trust you anymore
Latest WikiLeaks dump shows CIA targeting Apple earlier than others
Apple underwhelmed by latest CIA exploits revealed by WikiLeaks

WikiLeaks’s revelations about security vulnerabilities in Apple products appear to be a damp squib. The post Apple underwhelmed by latest CIA exploits revealed by WikiLeaks appeared first on WeLiveSecurity

Threatpost News Wrap, March 27, 2017
Bitcoin rise fuels social media scams
Still running Windows Vista? Here’s a wake-up call for you
UK.gov confirms it won’t be buying V-22 Ospreys for new aircraft carriers
16 years of Mac OS X: Secure but not invincible to malware

Mac OS X is still secure 16 years after its creation, but increasingly being targeted by cybercriminals. No operating system is 100% malware-proof. The post 16 years of Mac OS X: Secure but not invincible to malware appeared first on WeLiveSecurity