Menu

Monthly Archives: May 2017

Trump Signs Cybersecurity Executive Order
Vanilla Forums Open Source Software Vulnerable to RCE, Host Header Injection Vulnerability
Microsoft’s New Security Update Guides Get Mixed Reviews
Google won’t fix Android ‘contentjacking’ flaw for months

Risk Level: Very Low. Type: Trojan.

Fake Google Chrome Android App Infecting Users with Malicious Payload
News in brief: laptop ban could be extended; DDoS hits news sites; Taiwan might block Google DNS
Keylogger Found in Audio Drivers on Some HP Machines
Would you like a side of facial recognition with your pizza?
Hackers who stole information from law firms and made millions by insider trading, fined $9 million

Law firms, PR agencies, newswires, accountants… all manner of firms need to ensure that they are working hard to secure the information entrusted to them by their corporate clients, and keep it out of unauthorised hands. The post Hackers who stole information from law firms and made millions by insider trading, fined $9 million appeared […]

ASUS Patches RT Router Vulnerabilities
Reports claim US will ban laptops in all cabins of flights from Europe
Unhappy 39th birthday, spam, and many unhappy returns
Anti-trust, EU complaints and the anti-malware industry

ESET’s Tony Anscombe takes a closer look at the anti-malware industry. The post Anti-trust, EU complaints and the anti-malware industry appeared first on WeLiveSecurity

4 Best Practices for Web Browser Security on Your Linux Workstation
A bot is flooding the FCC’s website with fake anti-net neutrality comments
The hijacking flaw that lurked in Intel chips is worse than anyone thought
One more way to get busted on the Dark Web
Persirai IoT botnet threatens to hijack over 120,000 IP cameras
Face recognition system at US airports may target citizens

security update

Session Hijacking, Cookie-Stealing WordPress Malware Spotted
Android Permissions Flaw Will Linger Until O Release
News in brief: Game of Thrones tells cast to use 2FA; Cisco flaw patched; Windows 10 on 500m devices
Microsoft Makes it Official, Cuts off SHA-1 Support in IE, Edge
Minority Report in Chicago as police aim to stop crime before it happens
FCC confirms DDoS attacks

The Federal Communications Commission in the US has confirmed that it experienced multiple distributed denial-of-service attacks (DDoS) over the weekend. The post FCC confirms DDoS attacks appeared first on WeLiveSecurity

Microsoft finally bans SHA-1 certificates in Internet Explorer, Edge
How to hack a Jeep Cherokee – but don’t try this at home, kids
New Persirai Malware infects tons of IP cameras
Holidaymakers warned against increased threat from online fraudsters

An increasing number of holidaymakers are finding themselves targeted by online fraudsters, according to a new study. The post Holidaymakers warned against increased threat from online fraudsters appeared first on WeLiveSecurity

French electoral system hacked by Russia, NSA claims
Cisco Patches IOS XE Vulnerability Leaked in Vault 7 Dump
Gizmodo security test proves everyone (even Donald Trump’s team) can get phished
The Google Play apps that say they don’t collect your data – and then do
Latest Intelligence for April 2017
Number of web attacks blocked by Symantec rises to more than 1 million per day and Longhorn cyber espionage group linked to malware detailed in Vault 7 [...]
IDC: 1 in 4 companies have no clue GDPR is coming their way

A quarter of European companies admit they were not aware of GDPR, with more than half unsure of the impact it will have, according to a new survey. The post IDC: 1 in 4 companies have no clue GDPR is coming their way appeared first on WeLiveSecurity

Gmail fake Docs attack: Now Google tightens OAuth rules to block phishing
Hackers Leverage Flaws in SS7 to Drain Victims’ Bank Accounts
Backdoors: When Good Intentions Go Bad
Military ‘revenge porn’ investigation leads to 21 felony cases
DDoS or bust! Angry gamers come for IT

LinuxSecurity.com: An update for java-1.6.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary and Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary and Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com:

LinuxSecurity.com:

LinuxSecurity.com:

LinuxSecurity.com:

LinuxSecurity.com:

LinuxSecurity.com:

LinuxSecurity.com:

security update

LinuxSecurity.com:

Microsoft Plugs Three Zero Day Holes as Part of May Patch Tuesday
Google’s OSS-Fuzz Finds 1,000 Open Source Bugs

security update

LinuxSecurity.com:

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com:

LinuxSecurity.com:

LinuxSecurity.com:

Sednit adds two zero-day exploits using ‘Trump’s attack on Syria’ as a decoy

Sednit is back – this time with two more zero-day exploits embedded in a phishing email titled Trump’s_Attack_on_Syria_English.docx. The post Sednit adds two zero-day exploits using ‘Trump’s attack on Syria’ as a decoy appeared first on WeLiveSecurity

Mac video app HandBrake – now with free spyware
News in brief: Google teases Fuschia OS; Microsoft patches ‘crazy bad’ flaw; Vienna raps Facebook
John Oliver unleashes his net neutrality flying monkeys on the FCC
Adobe Patches Seven Critical Vulnerabilities in Flash, AEM
Lawyers demand answers after artist forced to unlock his phone
Game of Thrones actress reveals cast forced to embrace two-step verification, and so should you
Downloading Chrome for Android? Be careful – we’ve found an evil twin
Here’s how to check if your PC got Microsoft’s fix for Windows Defender bug
Elementary vulnerability exposed sensitive medical records on healthcare data website
Emergency Update Patches Zero Day in Microsoft Malware Protection Engine
Jackware hits the big screen in #Fast8: Fate of the Furious

ESET’s Stephen Cobb examines how close we are to the kind of jackware technology shown in the latest Fast and Furious film franchise, Fate of the Furious. The post Jackware hits the big screen in #Fast8: Fate of the Furious appeared first on WeLiveSecurity

Dating site users spammed with smut after ‘third-party’ data leak
What it takes to be a security architect
False positives can be more costly than a malware infection

Poor business decisions can be very costly, especially in cybersecurity, where so-called false positives can have very damaging consequences. The post False positives can be more costly than a malware infection appeared first on WeLiveSecurity

Microsoft rushes emergency fix for critical antivirus bug
Google Docs Phishing Scam a Game Changer
Hackers are reusing free online tools as part of their cyberespionage campaigns
How the Macron campaign slowed cyberattackers
Why your security appliance will be hacked

I’m no world-class hacker/penetration tester, but I’ve been able to break into any organization I’ve been (legally) hired to do so in an hour or less, except for one place that took me three hours. That was on my second engagement with the customer after it had implemented many of the protections I had recommended […]

Emergency patch released for critical security hole in Microsoft’s malware scanner

LinuxSecurity.com: An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

security update

Type: Vulnerability. Microsoft Windows is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.