Menu

Monthly Archives: April 2017

LinuxSecurity.com: An update for nss is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for nss-util is now available for Red Hat Enterprise Linux 6.2 Advanced Update Support, Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, Red Hat Enterprise Linux 6.5 Telco Extended Update Support, Red Hat Enterprise [More…]

LinuxSecurity.com: An update for nss and nss-util is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com:

News in brief: Google Home gets smarter; Hackers target South Korean missiles; Harry Huskey dies
Multiple security holes discovered in Linksys routers

Risk Level: Very Low. Type: Trojan.

Young cybercriminals ‘more motivated by peer respect than financial gain’

A new report suggests young cybercriminals are often motivated by the possibility of notoriety, rather than financial gain. The post Young cybercriminals ‘more motivated by peer respect than financial gain’ appeared first on WeLiveSecurity

Threatpost News Wrap, April 21, 2017
Want to watch HSBC’s security awareness videos? You’d best have Flash installed…
Google Pleads for Better Cross-Border Exchange of Digital Evidence
Donald Trump’s review of America’s cybersecurity misses its deadline

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. Neiman Marcus Breach Bigger than Initially Believed Following the 2015 Neiman Marcus breach, the company only […]

UK government reports on business breaches and it’s not pretty
Mirai and Hajime Locked Into IoT Botnet Battle
Google Won’t Trust Symantec and Neither Should You
Network Firewalls: How to Protect Your Network from Unauthorized Access
Navy and Marines crack down on nude photo sharing
What it takes to be a security consultant

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Buggy open source components still dog dev teams
Credit card stealing malware: 1200 InterContinental hotels breached
Google Fixes Unicode Phishing Vulnerability in Chrome 58, Firefox Standing Pat
Flaws let attackers hijack multiple Linksys router models
Bose Headphones allegedly spying on users – Lawsuit Filed
News in brief: Google ‘plans native adblocker’; Facebook seeks fake news lead; near miss for Earth
20 Linksys Router Models Vulnerable To Attack
Stuxnet LNK Exploits Still Widely Circulated
Nearly half of UK businesses experienced a cybersecurity incident in the last 12 months

Nearly half of all UK businesses have experienced a cybersecurity incident over the last 12 months, according to a new government paper. The post Nearly half of UK businesses experienced a cybersecurity incident in the last 12 months appeared first on WeLiveSecurity

Locked out of your accounts? Facebook wants to hold the key
Fake Android system update *really* wants to know your location
Drupal Closes Access Bypass Vulnerability in Core Engine
Google is building an ad-blocker into Google Chrome, report claims
The IoT malware that plays cat and mouse with Mirai
AI could be better than your doctor at predicting a heart attack
Don’t get bit by zombie cloud data
Smashing Security #017: Data breaches, zero day exploits, and toenail clippings

security update

Microsoft Touts New Phone-Based Login Mechanism
Tons of Apps on Google Play Store Infected with BankBot Malware
Phishing with ‘punycode’ – when foreign letters spell English words
News in brief: Bose ‘spying’ on users via app; Samsung annoys users over Bixby; Microsoft raps gag orders
Patched Flaw in Bosch Diagnostic Dongle Allowed Researchers to Shut Off Engine
Cybercriminals prefer to chat over Skype
InterContinental Hotels Group reveals ‘how it minimized recent malware attack’

The InterContinental Hotels Group says the implementation of its SPS system helped to minimize the damage caused by a recent data breach. The post InterContinental Hotels Group reveals ‘how it minimized recent malware attack’ appeared first on WeLiveSecurity

Never can say goodbye: face scans for departing US visitors fast-tracked
Beware; Sophisticated Phishing Attacks Using Unicode Characters
The Hajime IoT worm fights the Mirai botnet for control of your devices
How tech support scammers have made millions of dollars
Join us at Red Hat Summit 2017
Oracle fixes Struts and Shadow Brokers exploits in huge patch release
Turn the light on and give me your passwords!

ESET researchers have discovered another banking trojan on Google Play targeting Android users – this time disguised as a Flashlight widget. The post Turn the light on and give me your passwords! appeared first on WeLiveSecurity

Cybersecurity startups to watch
Record Oracle Patch Update Addresses ShadowBrokers, Struts 2 Vulnerabilities
Been to one of these 1170 hotels? Your credit card details may have been stolen by malware
Trump’s cybersecurity mystery: 90 days in, where’s the plan?
Watch out for fraudsters attacking Amazon Marketplace accounts
Shadow Brokers lessons: First, don’t panic
Foodie social network Allrecipes warns that someone stole users’ email addresses and passwords
Strong customer authentication and risk analysis under PSD2: how to comply? Download VASCO’s white paper

security update

At $175, this ransomware service is a boon to cybercriminals
Are Drones an invasion of privacy?
IHG Confirms Second Credit Card Breach Impacting 1,000-Plus Hotels

LinuxSecurity.com:

LinuxSecurity.com:

Facebook Delegated Account Recovery SDKs Published for Java, Ruby Apps
News in brief: Facebook introspects; Magento RCE; RIP Robert Taylor
Google: “Google Hire” Won’t Share Browsing History with Employers
Internet routing weakness could cost Bitcoin users
Fact or fiction? The truth about the Windows and Office hacks
Beware bogus emails from LinkedIn asking for your CV!
Researchers develop synthetic skeleton keys for fingerprint sensors
Tracking pixels can conduct surveillance for targeted attacks
Anonymous India Claims Snapchat Hack, Leaking Details of 1.7 Million users
Burger King triggers Google Home devices with TV ad
Sneaky Exploit Allows Phishing Attacks From Sites That Look Secure
Encryption: Usage grows again, but only at snail’s pace

LinuxSecurity.com:

LinuxSecurity.com:

LinuxSecurity.com:

Low-Cost Ransomware Service Discovered
When PR and reality collide: The truth about machine learning in cybersecurity

Machine learning (ML) is routinely cited by post-truth vendors as their biggest selling point, their main advantage. But ML – if it’s done properly – comes with problems and limitations. The post When PR and reality collide: The truth about machine learning in cybersecurity appeared first on WeLiveSecurity

A computer security tip for those campaigning in the UK general election
Lessons to learn as McAfee’s LinkedIn page is hijacked
Capsule8 Building Container-Aware Security Platform for Linux
Tor Security for Android and Desktop Linux
Big Linux bug, low security concerns
SSHGuard 2.0
Tuesday review – the hot 22 stories of the week
9 superheroes for crack security teams

As a traveling enterprise security consultant, I get to see security teams at their best and their worst. Under stress, some teams work like a well-oiled machines, while others devolve into inefficient, finger-pointing bureaucracies.Every great computer security team has a synergistic collection of skilled professionals who work well together to meet common goals. The team […]

Chrome, Firefox, and Opera users vulnerable to Unicode domain phishing attacks
BankBot Android banking malware targets hundreds of apps on Google Play

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for libreoffice is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 9.0 (Mitaka). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]