Menu

Monthly Archives: May 2017

Keybase Extension Brings End-to-End Encrypted Chat To Twitter, Reddit, GitHub
Revised Active Defense Bill Allows Victims to Recover or Destroy Stolen Data

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available. An update that fixes 9 vulnerabilities is now available. An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: MiniUPnP could be made to crash or run programs if it received specially crafted network traffic.

News in brief: Twitter pays $7,500 bounty; China gets ‘tweaked’ Windows; how to hide passwords
WannaCry Ransom Note Written by Chinese, English Speaking Authors
Put down the popcorn and patch your media player
Samba Patches Wormable Bug Exploitable With One Line Of Code
Google debuts a new way to follow your footsteps around the web
Russian Postal Service Hit by WannaCry Ransomware Attack
ICO urges businesses to focus on becoming GDPR compliant

The ICO says businesses should stop focussing on the consequences of non-compliance and instead be motivated by the advantages of getting GDPR right. The post ICO urges businesses to focus on becoming GDPR compliant appeared first on WeLiveSecurity

4 Reasons the Vulnerability Disclosure Process Stalls
YouTube, Twitter and Facebook face curbs on hate speech videos

LinuxSecurity.com: Firefox was updated to a new version.

Yup, the Android app store is full of useless, unwanted anti-WannaCry apps
Smashing Security #022: Walk this way… to defeat biometrics
Password Breaches Fueling Booming Credential Stuffing Business
Samsung Galaxy S8’ iris scanner hacked using contact lens and photo

LinuxSecurity.com: New samba packages are available for Slackware 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: Samba could be made to run programs as an administrator.

Hackers have found a way to hijack your system through subtitles
Android Overlay and Accessibility Features Leave Millions at Risk
Europol busts 27 burglars for Black box-based ATM logic attacks
EU security body calls for a security trust mark for IoT devices
News in brief: drones could be hobbled; cost of ransomware counted; Target agrees $18.5m deal
Twitter Flaw Could Have Allowed Attacker to Tweet From Any Account
Police swoop on gang that planted banking Trojan on 1m phones
WannaCryptor, aka WannaCry interview with Stephen Cobb and Marc Saltzman

Stephen Cobb, a senior security researcher at ESET, talks about one of the biggest cyberattacks of 2017 – WannaCryptor, aka WannaCry with radio and TV personality Marc Saltzman. The post WannaCryptor, aka WannaCry interview with Stephen Cobb and Marc Saltzman appeared first on WeLiveSecurity

386 WannaCry Ransomware and 26 EternalRocks Samples Discovered
Malware Network Communication Provides Better Early Warning Signal
LastPass’s new cloud backup option – sunny skies or a brewing storm?
Hacked Twitter account spits out poison – make sure yours isn’t next
Sn1per – Penetration Testing Automation Scanner
Hackers Unlock Samsung Galaxy S8 With Fake Iris

LinuxSecurity.com: MiniUPnP could be made to crash or run programs if it received specially crafted network traffic.

LinuxSecurity.com: Several security issues were fixed in jbig2dec.

LinuxSecurity.com: Samba could be made to run programs as an administrator.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update for samba3x is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for samba is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for samba4 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: Jakub Jirasek of Secunia Research discovered that libtasn1, a library used to handle Abstract Syntax Notation One structures, did not properly validate its input. This would allow an attacker to cause a crash by denial-of-service, or potentially execute arbitrary code, by

LinuxSecurity.com: steelo discovered a remote code execution vulnerability in Samba, a SMB/CIFS file, print, and login server for Unix. A malicious client with access to a writable share, can take advantage of this flaw by uploading a shared library and then cause the server to load and execute it.

LinuxSecurity.com: This updates fixes a security bug in the route manager, to prevent it from overwriting arbitrary files (CVE-2017-8921)

security update

security update

Risk Level: Very Low. Type: Worm.

Subtitle Hack Leaves 200 Million Vulnerable to Remote Code Execution
Google Elevates Security in Android O
Yahoo Retires ImageMagick After Bugs Leak Server Memory
Indian hacker pwned Air India, SpiceJet & Cleartrip; booked free flights
News in brief: Dubai launches its first robocops; Samsung woes over iris recognition; IoT security criticised
Hackers Claim Leaking Thousands of Spotify Login Credentials
Apple Receives First National Security Letter, Reports Spike in Requests for Data
XData ransomware making rounds amid global WannaCryptor scare

A week after the global outbreak of WannaCryptor, also known as WannaCry, another ransomware, known as XData, has been making rounds. The post XData ransomware making rounds amid global WannaCryptor scare appeared first on WeLiveSecurity

Digital watermark leads police straight to Bollywood pirates
Man jailed for stealing images and details from more than 50 women
Top 3 Chrome VPN Extensions for Maximum Online Privacy
Is the world ready for GDPR? Privacy and cybersecurity impacts are far-reaching

Enforcement of GDPR, the General Data Protection Regulation, begins in May of 2018, imposing data privacy and security requirements on many organizations in the US and other countries. Are you impacted? The post Is the world ready for GDPR? Privacy and cybersecurity impacts are far-reaching appeared first on WeLiveSecurity

Yahoo retires ImageMagick library after 18-byte exploit leaks user email content
Ashley Madison claims to be gaining 500,000 new members each month
Warning after WannaCry sets off fake BT phishing attack
How to remove all your cookies, cached data, and browsing history from Safari

LinuxSecurity.com: An update for rpcbind is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for libtirpc is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

US politicians think companies should be allowed to ‘hack back’ after WannaCry

LinuxSecurity.com: Update to chromium 58. Move chrome-remote-desktop to user systemd service. Security fixes for CVE-2017-5068, CVE-2017-5057, CVE-2017-5058, CVE-2017-5059, CVE-2017-5060, CVE-2017-5061, CVE-2017-5062, CVE-2017-5063, CVE-2017-5064, CVE-2017-5065, CVE-2017-5066, CVE-2017-5067, CVE-2017-5069

LinuxSecurity.com: Update to chromium 58. Move chrome-remote-desktop to user systemd service. Security fixes for CVE-2017-5068, CVE-2017-5057, CVE-2017-5058, CVE-2017-5059, CVE-2017-5060, CVE-2017-5061, CVE-2017-5062, CVE-2017-5063, CVE-2017-5064, CVE-2017-5065, CVE-2017-5066, CVE-2017-5067, CVE-2017-5069

LinuxSecurity.com: The 4.10.16 stable kernel update contains a number of important fixes across the tree.

LinuxSecurity.com: The 4.10.16 stable kernel update contains a number of important fixes across the tree.

Trump’s Cybersecurity Boss Talks Priorities

LinuxSecurity.com: Update to chromium 58. Move chrome-remote-desktop to user systemd service. Security fixes for CVE-2017-5068, CVE-2017-5057, CVE-2017-5058, CVE-2017-5059, CVE-2017-5060, CVE-2017-5061, CVE-2017-5062, CVE-2017-5063, CVE-2017-5064, CVE-2017-5065, CVE-2017-5066, CVE-2017-5067, CVE-2017-5069

LinuxSecurity.com: Update to chromium 58. Move chrome-remote-desktop to user systemd service. Security fixes for CVE-2017-5068, CVE-2017-5057, CVE-2017-5058, CVE-2017-5059, CVE-2017-5060, CVE-2017-5061, CVE-2017-5062, CVE-2017-5063, CVE-2017-5064, CVE-2017-5065, CVE-2017-5066, CVE-2017-5067, CVE-2017-5069

LinuxSecurity.com: The 4.10.16 stable kernel update contains a number of important fixes across the tree.

LinuxSecurity.com: The 4.10.16 stable kernel update contains a number of important fixes across the tree.

Verizon Patches XSS Issues in its Messaging Client
Facebook guidelines give discomforting insight into moderation policy

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

News in brief: Bitcoin price bubbles up; Uber uses AI to boost its take; WannaCry ‘hero’ censures tabloids

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

IDG Contributor Network: What’s all the chatter about chatbots
EternalRocks Worm Spreads Seven NSA SMB Exploits
Yes, Geek Squad can search your files and hand you over to the police
Zomato working with ‘ethical hacker’ to improve security

Zomato has confirmed that it has been communicating with the hacker responsible for stealing the data of around 17 million of its customers. The post Zomato working with ‘ethical hacker’ to improve security appeared first on WeLiveSecurity

Hackers trying to bring back WannaCry attacks by DDoSing its KillSwitch
After WannaCry, EternalRocks digs deeper into the NSA’s exploit toolbox
Judge demands cellphone passwords from social media star
North Korea denies link to WannaCry ransomware attack
GDPR is just a year away: here’s what you need to know
EternalRocks Worm Uses Same SMB Flaw in Windows like WannaCry
Jaya Baloo on WannaCry and Defending Against Advanced Attacks
What does Twitter think you’re interested in? Now you can find out
Keys for Crysis released, as decryption efforts of WannaCryptor files continue

ESET have prepared a new Crysis decrypting tool. Victims who still have their encrypted files can now download the decryptor from its utilities page. The post Keys for Crysis released, as decryption efforts of WannaCryptor files continue appeared first on WeLiveSecurity