Menu

Monthly Archives: June 2017

Popular third-party chat platforms like Slack, Discord, and Telegram are just a few of the many new productivity applications that are being hijacked by cybercriminals to create command-and-control (C&C) communications infrastructures for their malware campaigns. As corporate security teams become more aware of traditional malware threats and deploy new security solutions to defend against them, […]

Mexican Journalists, Lawyers Focus of Government Spyware

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Irssi, a terminal based IRC client. The Common Vulnerabilities and Exposures project identifies the following problems:

LinuxSecurity.com: Update to a bugfix release of yara.

LinuxSecurity.com: Update to a bugfix release of yara.

LinuxSecurity.com: Upstream 3.2.8 —- Upstream 3.2.7 (important security fix) —- Security fix for CVE-2013-7458

LinuxSecurity.com: Mostly a bugfix update, but includes an update of the keyboard/mouse hwdb and various small fixes and a minor security issue and a boot issue on virtualized systems with no VGA console. No need to reboot or log out.

LinuxSecurity.com: Security fix for CVE-2017-9433

LinuxSecurity.com: – new upstream update (54.0)

LinuxSecurity.com: **Rebase to 10.1.24** Plugin oqgraph enabled Plugin jemalloc enabled Sphinx engine enabled Build dependecies Bison and Libarchive added, others corrected Disabling Mroonga engine for i686 architecture, as it is not supported by MariaDB **Removed patches: (fixed by upstream)** Patch5: %{pkgnamepatch}-file-contents.patch Patch14: %{pkgnamepatch}-example-config-

LinuxSecurity.com: * Bump to 1.7.6 * Security fix for CVE-2017-8932

LinuxSecurity.com: This release fixes a possible setting arbitrary mode on an arbitrary file in rmtree() and remove_tree() calls known as CVE-2017-6512.

LinuxSecurity.com: Rebuild with new bochs version

Republican Data Broker Exposes 198M Voter Records
News in brief: Girl Scouts get cybersecurity badges; 1m hit by university data theft; India criticised
Stack Clash Vulnerability in Linux, BSD Systems Enables Root Access
EU throws a spanner in London’s encryption backdoor works
4 School Districts in Florida Attacked By Moroccan Hackers
Why gathering genetic data could mean a whole world of pain
Universal Plug ‘n’ Pwn! Pinkslipbot malware exploits UPnP to help it steal credentials
IoT Malware Activity Already More Than Doubled 2016 Numbers
Pervert arrested for taking candid photos of women, posting on Twitter
Amazon plans to check up on your price checks

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

Industroyer: ICS were developed decades ago with no security in mind

Senior ESET malware researcher Robert Lipovsky discusses Industroyer, the biggest threat to Industrial Control Systems (ICS) since Stuxnet. The post Industroyer: ICS were developed decades ago with no security in mind appeared first on WeLiveSecurity

Industroyer poses the highest risk for critical infratstructure since Stuxnet

ESET researchers have been analyzing samples of dangerous malware – detected by ESET as Win32/Industroyer, and named Industroyer – which is capable of performing an attack on power supply infrastructure. Robert Lipovsky, a researcher at ESET, tells us more. The post Industroyer poses the highest risk for critical infratstructure since Stuxnet appeared first on WeLiveSecurity

Risk Level: Very Low. Type: Trojan.

security update

security update

Google is having a hard time getting rid of malicious Android apps
Disruptive Ransomware Group ‘FIN10’ Hacked Casinos, Mining Firms
Erebus Ransomware Targets Linux Servers
Enhancing the security of the OS with cryptography changes in Red Hat Enterprise Linux 7.4
Hackers can exploit E-Cigarettes to hack computers

security update

security update

Wikileaks Alleges Years of CIA D-Link and Linksys Router Hacking Via ‘Cherry Blossom’ Program
Security SOS Week – learn from our top experts for free

LinuxSecurity.com: It was discovered that RT::Authen::ExternalAuth, an external authentication module for Request Tracker, is vulnerable to timing side-channel attacks for user passwords. Only ExternalAuth in DBI (database) mode is vulnerable.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system. The Common Vulnerabilities and Exposures project identifies the following problems:

LinuxSecurity.com: An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

LinuxSecurity.com: libmwaw could be made to crash or run programs as your login if it opened a specially crafted file.

LinuxSecurity.com: zziplib could be made to crash or run programs as your login if it opened a specially crafted file.

News in brief: Facebook moderators revealed to terrorists; WikiLeaks release Cherry Blossom; language-translating earpiece
Someone Failed to Contain WannaCry
Hundreds of Malicious Android Apps Masked as Anti-virus Software
Uber in the privacy spotlight again

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. New Mobile Phishing Attacks are Using URL Padding In an attempt to trick mobile browsing users […]

What’s worse than getting phished? Getting phished *and* sending a selfie of your Photo ID and credit card
Threatpost News Wrap, June 16, 2017
Hackers Using Chinese Malware to Rob ATMs Using Outdated Windows XP
The Google Play adware apps that just won’t die
Seven years after Stuxnet: Industrial systems security once again in the spotlight

Seven years after Stuxnet first came to light, industrial systems security once again in the spotlight, reports ESET’s Robert Lipovsky. The post Seven years after Stuxnet: Industrial systems security once again in the spotlight appeared first on WeLiveSecurity

Erosion of ISP Privacy Rules Sparks New Anti-Snooping Efforts
Would you trust your smartphone with your life?

Smartphone security is, of course, essential these days, but how confident are you in your device’s ability to help keep you safe and secure? The post Would you trust your smartphone with your life? appeared first on WeLiveSecurity

Facebook staff had their identities exposed to suspected terrorists due to security lapse
Brit hacker admits he siphoned info from US military satellite network
CIA has been hacking into Wi-Fi routers for years, leaked documents show
Cybersecurity labor crunch to hit 3.5 million unfilled jobs by 2021
Buggy devices and lazy operators make VoLTE a security nightmare
Parrot Security OS Devs Mock systemd: It’s an Immature Init System for GNU/Linux
British hacker admits stealing satellite data from US Department of Defense
Your mouse knows when you are lying
The 2 cloud security myths that must die

LinuxSecurity.com: – new upstream update (54.0)

LinuxSecurity.com: Update to version 1.8.2. The upstream release notes: https://mail.gnome.org/archives/ftp-release-list/2017-June/msg00015.html

LinuxSecurity.com: **Rebase to 10.1.24** Plugin oqgraph enabled Plugin jemalloc enabled Sphinx engine enabled Build dependecies Bison and Libarchive added, others corrected Disabling Mroonga engine for i686 architecture, as it is not supported by MariaDB **Removed patches: (fixed by upstream)** Patch5: %{pkgnamepatch}-file-contents.patch Patch14: %{pkgnamepatch}-example-config-

6 months for abuser caught in FBI’s Playpen snare
Ransomware attack against University College London blamed on poisoned website
Cherry Blossom: WikiLeaks’ Latest Dump Exposes CIA Wireless Hacking Tools
News in brief: Samsung customers exposed; emergency service drones; potatoes on the Moon?

security update

US-CERT issues North Korean cyberattack patch warning
Nigerian BEC Scams Hit 500 Companies in 50 Countries
Ransomware Attack Hobbles Prestigious University College London
Airbnb – the heartache of fake holiday scams
University College London hit by a major ransomware attack

Webroot SecureAnywhere® Business solutions will now give admins more ease of control within the Global Site Manager (GSM). From web overrides to Mac- and PC-specific enhancements, we’re delivering new features you asked for to ensure the best multi-vector protection possible. Webroot protects endpoints against myriad threats at multiple attack stages spanning a variety of attack […]

Metadata Analysis Draws its Own Conclusions on WannaCry Authors
More evidence Mac ransomware exists
New project to expose congress’ Browsing Habits
Millions of Android users left vulnerable due to Samsung’s ignorance
Disney, Depp and the cyber supply chain risk management problem

Multimillion dollar movies and TV shows are increasingly being targeted by cybercriminals. ESET’s Stephen Cobb investigates the cyber supply chain risk management problem and explains what to do about it. The post Disney, Depp and the cyber supply chain risk management problem appeared first on WeLiveSecurity

The 15 worst data security breaches of the 21st Century
DevSecOps is Not a Security Panacea
BlackArch Linux Ethical Hacking and Pen Testing OS Now Offers over 1,800 Tools
Children still at risk from inappropriate online content

A new survey published by the NSPCC suggests children across the UK are still at risk of accessing inappropriate and potentially harmful content online, despite increased calls for heightened security. The post Children still at risk from inappropriate online content appeared first on WeLiveSecurity

LinuxSecurity.com: Firefox could be made to crash or run programs as your login if it opened a malicious website.

LinuxSecurity.com: Gajim 0.16.8 * Fix rejoining MUCs after connection loss * Fix Groupchat invites * Fix encoding problems with newer GnuPG versions * Fix old messages randomly reappearing in the chat window * Fix some problems with IBB filetransfer * Make XEP-0146 Commands opt-in * Improve sending messages to your own resources * Improve reliability […]

LinuxSecurity.com: FIx for CVE-2017-8366

Smashing Security #029: Exploits to get your English teeth into
Compromised websites redirecting tech support scam hosted on numeric domains

LinuxSecurity.com: Gajim 0.16.8 * Fix rejoining MUCs after connection loss * Fix Groupchat invites * Fix encoding problems with newer GnuPG versions * Fix old messages randomly reappearing in the chat window * Fix some problems with IBB filetransfer * Make XEP-0146 Commands opt-in * Improve sending messages to your own resources * Improve reliability […]

LinuxSecurity.com: fixes buffer overflows for flac and pcm

LinuxSecurity.com: FIx for CVE-2017-8366

LinuxSecurity.com: CVE-2017-7511 poppler: Null pointer dereference in pdfunite via crafted documents

LinuxSecurity.com: This update addresses the following vulnerabilities: * [CVE-2017-2496](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2496), [CVE-2017-2539](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2539), [CVE-2017-2510](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2510) Additional fixes: * Fix URL shown in the title of beforeunload dialogs. * Focus

LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.2, and -current to fix security issues.

LinuxSecurity.com: New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: Update to a bugfix release of yara.