Menu

Monthly Archives: March 2017

HackerOne offers bug bounty service for free to open-source projects
The Border Patrol can take your password. Now what?
4 strategies to root out your security risks

You’ll never reduce your security risk if you can’t identify and mitigate the root causes of those vulnerabilities. It isn’t enough to have a list of malware programs that your antimalware has detected. You need to to determine how viruses and hackers have penetrated your environment in the past. In the vast majority of organizations, […]

LinuxSecurity.com: Security fix for CVE-2017-6060 CVE-2017-5896 —- Add comment with explanationof disabled debuginfo

LinuxSecurity.com: – Update to 1.0.4 Release notes: http://www.cacti.net/release_notes_1_0_0.phphttp://www.cacti.net/release_notes_1_0_1.phphttp://www.cacti.net/release_notes_1_0_2.phphttp://www.cacti.net/release_notes_1_0_3.phphttp://www.cacti.net/release_notes_1_0_4.php

Boffins show Intel’s SGX can leak crypto keys
That big scary 1.4bn leak was basically nothing but email addresses
Shamoon malware spawns even nastier ‘StoneDrill’
Put down the coffee, stop slacking your app chaps or whatever – and patch WordPress
Wow, did you see what happened to Veracode? Oh no, no, it’s not dead. It’s been bought by CA
Don’t worry, slowpoke Microsoft, we patched Windows bug for you, brags security biz

Risk Level: Very Low. Type: Worm.

Western Australia’s Web votes have security worries, say ‘white hat’ mathematicians
US Marines seek a few supposedly good men … who leaked naked pics of a few good women
DOJ Dismisses Playpen Case to Keep Tor Hack Private

security update

Spammer’s Leaky Backup Exposes Massive Empire

LinuxSecurity.com: Security fix in CA certificate chain verification (better check untrusted CAcertificates from peer, more strict error handling).

Destructive StoneDrill Wiper Malware On The Loose
Meet StoneDrill Malware Destroying Everything on Infected Computers

Talks of integration are often met with audible sighs of displeasure. It’s a lot of work. You have to combine various platforms, software, and the list goes on. At Webroot, we decided to take some of the pain out of this process by partnering with Kaseya to deliver a fully integrated endpoint security solution for […]

‘Dozens’ of police departments maintain private DNA databases

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for CVE-2017-3135 (unaffected), fixes regression made byCVE-2016-8864

LinuxSecurity.com: Security fix for CVE-2017-2626

LinuxSecurity.com: Security fix for CVE-2017-2625

LinuxSecurity.com: Security fix for CVE-2017-5884, CVE-2017-5885

LinuxSecurity.com: Security fix for CVE-2016-9299

LinuxSecurity.com: Security fix for CVE-2016-9299

LinuxSecurity.com: Security fix for CVE-2017-6410

LinuxSecurity.com: Security fix for CVE-2017-6410

LinuxSecurity.com: Security fix for CVE-2017-3135 (unaffected), fixes regression made byCVE-2016-8864

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: new upstream release 2.5.3, fixing leaks

News in brief: Facebook tags ‘disputed’ news; products to be judged on security; smart meters snafu
Hackers could bypass protective measures to gain access to locked Twitter accounts
Uber under fire for ‘Greyball’ program used to dodge enforcement officials
Microsoft Bug Bounty Program: Report Vulnerabilities, Get up to $30,000
Bruce Schneier on IoT Regulation
Third party patch released for Microsoft zero-day that Google made public
10 ways to ruin a cybercriminal’s day

Technology is affecting our relationships and changing our lives, but are we taking the necessary measures to protect ourselves online? Here’s how to outsmart cybercriminals. The post 10 ways to ruin a cybercriminal’s day appeared first on WeLiveSecurity

Ex penetrated us almost 700 times through secret backdoor, biz alleges
Realistic crisis simulations are the backbone of cyber preparedness – ENISA plays a role in EU cyber preparedness
Google, Microsoft bump bug bounties
1.37bn records from somewhere to leak on Monday
Is Obama planning a coup? Yes, says Google Home
1 Million Decrypted Gmail and Yahoo Accounts Being Sold on Dark Web
Hackers Using Unmonitored System Tools, Protocols for Malicious Goals
Telegram lets scammers connect directly with potential victims by way of stored contacts
Someone hacked this billboard in Mexico and defaced with porn video

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Worm.

IoT of toys stranger than fiction: cybersecurity and data privacy update

The Internet of Stranger Things came to life in the recent case of a cuddly connected toy, raising wider and deeper questions about cybersecurity, privacy, and the future of digital technology. The post IoT of toys stranger than fiction: cybersecurity and data privacy update appeared first on WeLiveSecurity

South Korean Retail Giant Lotte’s Website Hacked After US Military Deal
New Fileless Attack Using DNS Queries to Carry Out PowerShell Commands

security update

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Robots can be hacked, exploit to kill people, spy on military secrets: Researchers
Pence v Clinton: Both used private email for work, one hacked, one accused of hypocrisy
News in brief: Virginia greenlights delivery bots; Line to launch AI assistant; Uber seeks licence

LinuxSecurity.com: An update for python-oslo-middleware is now available for Red Hat OpenStack Platform 9.0 (Mitaka). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for ipa is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

HackerOne Offers Open Source Projects Free Access to Platform
Amazon mega-outage caused by single command line error
Google to Protect Mac Chrome Users with Additional “Safe Browsing” Alerts
Secrets of the Filecode ransomware revealed
Cybersecurity rules toughened up for NY financial firms

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. Boeing Informs Workers of Data Breach Am I surprised there’s another data breach in the news […]

Apple pushing two-factor authentication for iOS 10.3 users
Threatpost News Wrap, March 3, 2017
Slack quick to whack account hijack crack
Yahoo CEO forgoes annual bonus, worth millions, over security breaches

Yahoo’s Marissa Mayer has missed out on $2m from her annual bonus due to her management of security breaches affecting billions of users. The post Yahoo CEO forgoes annual bonus, worth millions, over security breaches appeared first on WeLiveSecurity

Researcher uses Google’s speech tools to skewer Google reCAPTCHA
Mike Pence used personal AOL account for government business as Indiana governor
RAF pilot awaits sentence for digicam-induced airliner dive
Bletchley Park: Training the next the generation of cybersecurity codebreakers

Bletchley Park, considered to be the birthplace of modern computing, is to train the generation of cybersecurity codebreakers. The post Bletchley Park: Training the next the generation of cybersecurity codebreakers appeared first on WeLiveSecurity

A Minor Typo Brought the Entire Internet Network of Amazon Down
UK’s first Investigatory Powers Commissioner: Lord Justice Fulford
Howard Schmidt’s Legacy of Service Remembered
MWC: These might be the droids you are looking for
Awkward. Investigatory Powers Act could prove hurdle to UK-EU Privacy Shield following Brexit
Pence used private mail for state work as governor, and account was hacked
Free decryption tools now available for Dharma ransomware
Howard A Schmidt remembered as a ‘humble’ industry giant
Nearly 1m Coachella user details potentially accessed in breach
This old ransomware variant is back – with sneaky new tricks
Three Years after Heartbleed, How Vulnerable Are You?
9 secrets to cyberattack survival
132 Android apps found in the Google Play Store exploiting malicious iFrames

Locky (.osiris) O Locky, Locky! Wherefore art thou, Locky? Alas, could Locky be no more? At the beginning of 2017, data from the field suggested potential Locky infections had decreased dramatically, so we were hoping it was on its way out. Unfortunately, Locky returned with a vengeance, though it had changed its methods somewhat. Upon […]

SHA-1 crack just got real: System Center uses it to talk to Linux

Don’t Let Tax Season Scammers Steal Your Refund! This time of year, most of us are probably still dreading the moment we have to quit procrastinating, buckle down, and file our income taxes. Coincidentally, it’s also a time that cybercriminals are working overtime to scam home users into giving over their financial data, and even […]

LinuxSecurity.com: Security fix for CVE-2017-2625

LinuxSecurity.com: The 4.9.13 update contains a number of important fixes across the tree