Menu

Monthly Archives: June 2017

WannaCry Ransomware Hits Traffic Cameras in Australia
Coming soon (maybe) to toyshops – AI doll that can read kids’ emotions
Botnets – malware that makes you part of the problem [Security SOS Week]
Honeypots and the Internet of Things
WannaCry ransomware infects Australian traffic cameras, human error blamed
‘No decision’ on Raytheon GPS landing system aboard Brit aircraft carriers
Deep Root: what can we learn from the GOP’s data leak?

LinuxSecurity.com: Disable executable stack for aarch64 builds.

NSA-Backed OpenC2.org Aims to Defend Systems at Machine Speed

LinuxSecurity.com: CVE-2017-1000381: c-ares NAPTR parser out of bounds access

LinuxSecurity.com: This update addresses CVE-2017-1000366, a vulnerability in the dynamic linker allowing local privilege escalation.

LinuxSecurity.com: Update to .104. Fix mp3 playback. Security fix for CVE-2017-5087, CVE-2017-5088, CVE-2017-5089

LinuxSecurity.com: Rebuild for new luajit

Smashing Security #030: GDPR – The good and the bad

LinuxSecurity.com: Alvaro Munoz and Christian Schneider discovered that jython, an implementation of the Python language seamlessly integrated with Java, is prone to arbitrary code execution triggered when sending a serialized function to the deserializer.

LinuxSecurity.com: Aniket Nandkishor Kulkarni discovered that in tomcat7, a servlet and JSP engine, static error pages used the original request’s HTTP method to serve content, instead of systematically using the GET method. This could under certain conditions result in undesirable results,

LinuxSecurity.com: Aniket Nandkishor Kulkarni discovered that in tomcat8, a servlet and JSP engine, static error pages used the original request’s HTTP method to serve content, instead of systematically using the GET method. This could under certain conditions result in undesirable results,

LinuxSecurity.com: Several security issues were fixed in the kernel.

Researcher calls the fuzz on OpenVPN, uncovers crashy vulns
Homeland Security: Putin’s hackers tried to crack electoral networks in 21 US states

security update

security update

security update

US Judge falls for email scam; loses $1 million
Microsoft Extends Edge Bug Bounty Program Indefinitely
Trump’s Cybersecurity Executive Order Under Fire

LinuxSecurity.com: Multiple vulnerabilities have been found in the Chromium web browser, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in the GNU C Library, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in mbed TLS, the worst of which could lead to the remote execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Kodi, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A header injection vulnerability in GNU Wget might allow remote attackers to inject arbitrary HTTP headers.

LinuxSecurity.com: An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

News in brief: WannaCry knocks out Honda plant; Skype hit by global outage; NSA shares tools on GitHub
Honda Shut Down Plant Impacted by WannaCry
Commercial spyware unleashed against Mexican political activists
ProtonMail Launches Free ProtonVPN to Fight Online Censorship
GDPR: how to avoid the data protection cowboys
Honda hit by WannaCry ransomware attack; shuts down plant
OpenVPN Patches Critical Remote Code Execution Vulnerability
New malware uses old trick – and is a reminder to disable UPnP
Netflix’ Orange Is the New Black Season was Stolen Using Windows Flaw
Avaya Patches Remote Code Execution Flaw in Aura
Ztorg malware hid in Google Play to send premium-rate SMS texts, delete incoming SMS messages
Supreme Court: sex offenders can’t be banned from social media
When does security turn into snooping? [Security SOS Week]
WannaCryptor attack ‘may have come from Lazarus group’

Experts in the UK and the US have reportedly claimed that the recent global WannaCryptor ransomware attack was initiated by the North Korean Lazarus Group. The post WannaCryptor attack ‘may have come from Lazarus group’ appeared first on WeLiveSecurity

Stack Clash vulnerabilities smash Linux defenses in the quest for root access
pyrasite – Inject Code Into Running Python Processes
NSA failed to implement security measures, says damning report

LinuxSecurity.com: An update that solves four vulnerabilities and has 35 fixes An update that solves four vulnerabilities and has 35 fixes An update that solves four vulnerabilities and has 35 fixes is now available. is now available.

LinuxSecurity.com: An update that solves 10 vulnerabilities and has one errata An update that solves 10 vulnerabilities and has one errata An update that solves 10 vulnerabilities and has one errata is now available. is now available.

LinuxSecurity.com: For changes see https://www.mozilla.org/en-US/thunderbird/52.2.0/releasenotes/

LinuxSecurity.com: Fixes CVE-2017-9502 (Windows builds only)

LinuxSecurity.com: An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

security update

security update

security update

security update

TP-Link Fixes Code Execution Vulnerability in End-of-Life Routers
Internet-Enabled Drill Demonstrates IoT Security Done Right
URL Padding: Facebook Mobile Users Hit by Phishing Scam
University College London Ransomware Linked to AdGholas Malvertising Group

LinuxSecurity.com: An update that solves one vulnerability and has four fixes An update that solves one vulnerability and has four fixes An update that solves one vulnerability and has four fixes is now available. is now available.

News in brief: Canada warns on election threats; ‘Record’ $1m ransom paid; Hawking urges return to moon
ProtonMail Launches Free VPN Service
Stack Clash Linux vulnerability: you need to patch now
Erebus Ransomware: Hosting Firm Pays Hackers $1m Ransom
How social media companies are using AI to fight terrorist content
Man arrested for uploading Deadpool on Facebook may face 3 years in jail
Many companies have been ‘hacked’, but please don’t make it THIS easy
Google Removes Two Ztorg Trojans from Play Marketplace
Say Goodbye to SMBv1 in Windows Fall Creators Update

These days, it seems like you can’t turn on the TV or open a news site without reading some terrifying headline related to cybersecurity. And the numbers keep escalating. Yahoo’s breaches impacted 1 billion user accounts. Chipotle’s security incident affected more than 2,500 stores in 48 states. We know what cybercriminals are doing; they’re stealing […]

Europol campaign fights the online sexual extortion of children
Machine learning by ESET: The road to Augur

Machine learning (ML) in eight blogposts!? In our last post, let’s take a peek under the hood of ESET’s cybersecurity engine and its ML gears. The post Machine learning by ESET: The road to Augur appeared first on WeLiveSecurity

PanicGuard panic alarm app leaks your personal information, including location
Phishing – how this troublesome crime is evolving [Security SOS Week]
200 Million US Citizens Got Their Personal Data Exposed
WikiLeaks emits CIA’s Wi-Fi pwnage tool docs
Security-Oriented Alpine Linux 3.6.2 OS Adds Linux Kernel 4.9.32 and Tor 0.3.0.8
Ubuntu 17.10 to Improve Secure Boot for Booting Windows from GRUB, Enable PIE
How to install Linux on a Chromebook (and why you should)
Web-hosting firm agrees to pay over $1 million to ransomware extortionists
FIN10 Extorting Canadian Mining Companies, Casinos

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has one An update that solves three vulnerabilities and has one An update that solves three vulnerabilities and has one errata is now available. errata is now available.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Anatomy of a scam: how phone frauds harvest millions from us
Your anti-virus may remove this malware but it will still remain active