Menu

Monthly Archives: June 2017

Risk Level: Very Low. Type: Trojan.

Al Jazeera News Platforms Hit by Massive Cyber Attacks
Motorola Moto G4, G5 Vulnerable to Local Root Shell Attacks
Hackers are using popular chat apps to control malware operation

LinuxSecurity.com: FreeRADIUS would allow unintended access over the network.

LinuxSecurity.com: USN-3253-1 introduced a regression in Nagios.

News in brief: man jailed for hacking celebrity chef; US could add domestic flights to laptop ban; flaws found in ‘security’ cameras
Malicious Android app installs ‘impossible to remove’ adware
It is not OK to break the law to catch criminals, judge rules
VMware Patches Critical Vulnerabilities in vSphere Data Protection
What the hacking of Gordon Ramsay’s email teaches us all
Android malware hid in Google Play apps to inject code into system runtime libraries
Bitcoin, Litecoin Exchange BTC-E Suffers Massive DDoS Attacks
Cisco Patches Critical Flaws in Prime Data Center Network Manager
Russian Hackers Control Malware via Britney Spears Instagram Posts
New App Will Stop Voice Hacks Using Smartphone Compass
How to Protect Yourself From Hackers – Useful Tips For Small Business Owners
14-year-old Japanese Student Caught for Creating Ransomware
Leaked NSA Exploit ‘EternalBlue’ Being Used in New Trojan Attacks
Smashing Security #024: Reality Winner, Gordon Ramsay and a leaky bucket
Supreme Court to rule on warrants for cellphone location data
Fines for poor data security double in UK

A report from PwC found that many companies across the UK are still unprepared for GDPR measures, despite fines for non-compliance doubling in a year. The post Fines for poor data security double in UK appeared first on WeLiveSecurity

Authentication Bypass, Potential Backdoors Plague Old WiMAX Routers
IP Security Cameras Vulnerable to Hostile Takeovers
What’s the difference between first- and third-party cookies?
Testing, marketing, and rummaging in the FUD banks

Early in 2017, Kevin Townsend invited David Harley and others to comment on vendor hype. Here he expands on his original commentary. The post Testing, marketing, and rummaging in the FUD banks appeared first on WeLiveSecurity

5 Tips For Choosing The Right Open Source Code
Encryption leaves authorities ‘not in a good place’: Former US intelligence chief
The Dark Web is the place to go to find bugs before public disclosure
Apple’s Safari is going to use AI to track who’s tracking you
Google Removes Rooting Trojan Dvmap From Play Store

LinuxSecurity.com: New irssi packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: – update to 1.8.20p2 – added sudo package to dnf/yum protected packages —- – update to 1.8.20p1 – fixes CVE-2017-1000367

EFF Sues DOJ Over National Security Letter Disclosure Rules
Annoying Android app demands admin rights to display ads
Windows 10 Mitigations Make Future EternalBlue Attacks Difficult
Facebook patents emotion-sensing technology to ‘deliver better content’
In UAE Supporting Qatar on the Internet is Now a Cybercrime
Zusy Malware Installs Via Mouseover – No Clicking Required

LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available.

LinuxSecurity.com: Multiple vulnerabilities have been found in FreeType, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: An out-of-bounds data access in minicom might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Wireshark, the worst of which allows remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: A vulnerability in PCRE library allows remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: A vulnerability in Pidgin might allow remote attackers to execute arbitrary code.

News in brief: computers trained to spot catfish; Trump cautioned on blocks; Apple locks out older phones
Hackers can steal large amount of data using router’s LEDs
InfoSec 2017: Brexit+GDPR = business disaster?
Firms stockpiling Bitcoins ready to pay off ransomware crooks
InfoSec 2017: ‘One disaster away from governments doing something’ on IoT
Russians apparently ‘targeted US election via phishing attacks’
Why you must patch the new Linux sudo security hole
Botnets overshadowed by ransomware (in media)

Regardless of how prominent and effective ransomware appears to be, it is not the most dangerous form of malware. The post Botnets overshadowed by ransomware (in media) appeared first on WeLiveSecurity

You think that post is secret? Beware – it can come back and bite you
See a real attack on a virtual network in this free webinar by Nehemiah Security
Mingis on Tech: The alphabet soup of mobile device management
InfoSec 2017: how to protect yourself against the next WannaCry
UK cops arrest man picked out by automatic facial recognition software
Trends 2017: Ransomware of Things

Welcome to the Ransomware of Things, where all connected devices are at risk of being compromised, locked and held to ransom by cybercriminals. The post Trends 2017: Ransomware of Things appeared first on WeLiveSecurity

LinuxSecurity.com: Multiple vulnerabilities have been found in WebKitGTK+, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: The system could be made to run programs as an administrator.

LinuxSecurity.com: The system could be made to run programs as an administrator.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

How The Intercept might have helped unmasked Reality Winner to the NSA
Curiosity Kills Security When it Comes to Phishing
IBM Backup Bug Gets Workaround Fix After Nine Months of Exposure

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: Several security issues were fixed in Puppet.

News in brief: spy chief warns on blame; FBI arrests NSA contractor; Japan holds teen on ransomware

Risk Level: Very Low. Type: Trojan.

Google Fixes 30 Vulnerabilities, Five High Severity, in Chrome 59
Two cheers for Google’s native Chrome ad-blocker
NSA’s EternalBlue Exploit Ported to Windows 10
Neuroanatomy of Facial Processing Decoded – by Reading Minds of Monkeys
InfoSec 2017: a look at the family album of ransomware
Federal Contractor Caught Leaking Classified NSA Documents to News Outlet
Turla’s watering hole campaign: An updated Firefox extension abusing Instagram

The Turla espionage group is still using watering hole techniques to redirect potentially interesting victims to their C&C infrastructure. The post Turla’s watering hole campaign: An updated Firefox extension abusing Instagram appeared first on WeLiveSecurity

Google ads for tech support scams – would you spot one?
CIA’s Pandemic Toolkit
Hackers leak 8 unaired episodes of ABC’s Steve Harvey’s Funderdome TV series
British Airways blames IT meltdown on human error
QakBot trojan triggers Active Directory lockouts while seeking to drain bank accounts

LinuxSecurity.com: A vulnerability in a bundled copy of PuTTY in FileZilla might allow remote attackers to execute arbitrary code or cause a denial of service. [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in MuPDF, the worst of which allows remote attackers to cause a Denial of Service condition or have other unspecified impact. [More…]

LinuxSecurity.com: A vulnerability has been found in Libtirpc and RPCBind which may allow a remote attacker to cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in ImageWorsener, the worst of which allows remote attackers to cause a Denial of Service condition or have other unspecified impact. [More…]

LinuxSecurity.com: Multiple vulnerabilities in D-Bus might allow an attacker to overwrite files with a fixed filename in arbitrary directories or conduct a symlink attack. [More…]

LinuxSecurity.com: A vulnerability in Git might allow remote attackers to bypass security restrictions.

LinuxSecurity.com: Multiple vulnerabilities have been found in QEMU, the worst of which may allow a remote attacker to cause a Denial of Service or gain elevated privileges from a guest VM. [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in Shadow, the worst of which might allow privilege escalation.

LinuxSecurity.com: Gentoo’s MUNGE ebuilds are vulnerable to privilege escalation due to improper permissions.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

LinuxSecurity.com: CVE-2017-7511 poppler: Null pointer dereference in pdfunite via crafted documents

LinuxSecurity.com: Update to 4.12 (#1456190)

QakBot Returns, Locking Out Active Directory Accounts