Menu

Monthly Archives: June 2017

Top Tips on How to Land a Well-Paid Job in Cyber Security
40,000 Subdomains Tied to RIG Exploit Kit Shut Down
53 Percent of Enterprise Flash Installs are Outdated

LinuxSecurity.com: Security fix for CVE-2017-7494

LinuxSecurity.com: Update to latest stable release, include fixes for gnutls and gtk-vnc compatibility.

LinuxSecurity.com: – update to 1.8.20p2 – added sudo package to dnf/yum protected packages —- – update to 1.8.20p1 – fixes CVE-2017-1000367

LinuxSecurity.com: Fixed CVE-2017-6508: CRLF injection in the url_parse function in url.c

LinuxSecurity.com: fix insufficient escaping of user-supplied data (CVE-2017-7692)

LinuxSecurity.com: Update to chromium 58. Move chrome-remote-desktop to user systemd service. Security fixes for CVE-2017-5068, CVE-2017-5057, CVE-2017-5058, CVE-2017-5059, CVE-2017-5060, CVE-2017-5061, CVE-2017-5062, CVE-2017-5063, CVE-2017-5064, CVE-2017-5065, CVE-2017-5066, CVE-2017-5067, CVE-2017-5069 —- Security fix for CVE-2017-5055, CVE-2017-5054, CVE-2017-5052, CVE-2017-5056, CVE-2017-5053

LinuxSecurity.com: Update to chromium 58. Move chrome-remote-desktop to user systemd service. Security fixes for CVE-2017-5068, CVE-2017-5057, CVE-2017-5058, CVE-2017-5059, CVE-2017-5060, CVE-2017-5061, CVE-2017-5062, CVE-2017-5063, CVE-2017-5064, CVE-2017-5065, CVE-2017-5066, CVE-2017-5067, CVE-2017-5069 —- Security fix for CVE-2017-5055, CVE-2017-5054, CVE-2017-5052, CVE-2017-5056, CVE-2017-5053

LinuxSecurity.com: fix insufficient escaping of user-supplied data (CVE-2017-7692)

48% of U.S. Firms Using IoT Devices Suffered Security Breaches – Survey
News in brief: tech firms under fire again; facial recognition prize offered; hack leads to Gulf crisis

Risk Level: Very Low. Type: Trojan.

Facebook safety check: telling loved ones you’re safe is a good thing
Hackers Leak First 8 Episodes of Steve Harvey’s “Funderdome” TV Show
Why ‘I forgot my password’ won’t go down well with a judge
Don’t let politicians use the excuse of murderous assholes to scapegoat the internet
Google will Now Pay Hackers $200,000 for Reporting Bugs in Android
Trends 2017: Fewer vulnerabilities are being reported, but are we any safer?

Fewer vulnerabilities are being reported, but are we any safer? In this short video, we take a look at why it’s still a problem. The post Trends 2017: Fewer vulnerabilities are being reported, but are we any safer? appeared first on WeLiveSecurity

Bid farewell to your browsing data in the stock Android browsers – for better privacy

LinuxSecurity.com: The cPanel Security Team reported a time of check to time of use (TOCTTOU) race condition flaw in File::Path, a core module from Perl to create or remove directory trees. An attacker can take advantage of this flaw to set the mode on an attacker-chosen file to a attacker-chosen

security update

LinuxSecurity.com: Security fixes for CVE-2017-9078 CVE-2017-9079

LinuxSecurity.com: Security fixes for CVE-2017-9078 CVE-2017-9079

Australian Pedophile Arrested as Philippine Cybersex Ring Busted
Man Accidentally Destroyed Production Database on First Day of His Job
Hackers Behind Jaff Ransomware Selling Victims’ Data on Dark Web
Jaff Malware Probe Uncovers Link to Cybercrime Marketplace
Phishing Campaigns Follow Trends

security update

security update

EternalBlue Exploit Spreading Gh0st RAT, Nitol

LinuxSecurity.com: Several vulnerabilities were discovered in NSS, a set of cryptographic libraries, which may result in denial of service or information disclosure.

LinuxSecurity.com: It was discovered that Zookeeper, a service for maintaining configuration information, didn’t restrict access to the computationally expensive wchp/wchc commands which could result in denial of service by elevated CPU consumption.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: OpenLDAP could be made to crash if it received specially crafted network traffic.

LinuxSecurity.com: Several security issues were fixed in libsndfile.

‘Fireball’ Malware Infected 250 Million Mac and Windows Devices
Fireball malware’s flames infect a quarter of a BILLION computers

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. Hackers Blackmail Surgery Patients Hackers have begun contacting victims of a March data leak that exposed […]

SSH Configuration on Nexpose Servers Allowed Weak Encryption Algorithms
OneLogin warns that attacker could be able to decrypt data
“Good hackers” took over billboard to send security warning
Wikileaks reveals pandemic malware for Windows developed by the CIA
OneLogin data breach may have compromised encrypted information

The OneLogin breach once again highlights the importance of how companies protect their encrypted data. The post OneLogin data breach may have compromised encrypted information appeared first on WeLiveSecurity

Get into Infosec Europe 2017 for free, hear great talks!
Threatpost News Wrap, June 2, 2017
Thousands of enterprise apps exposing data on back-end servers
WikiLeaks Dumps CIA Patient Zero Windows Implant
IDG Contributor Network: Choose your devsecops team wisely: Your apps depend on it
Fireball Malware Infects 250 Million Computers Worldwide
Infosecurity Europe: 10 interesting talking points

Just weeks after one of the largest global ransomware attacks in history, Infosecurity Europe returns for its 22nd installment. The post Infosecurity Europe: 10 interesting talking points appeared first on WeLiveSecurity

Facial recognition reunites missing boy with his dad after four years
Silk Road founder Ross Ulbricht loses appeal for new trial
Biker group charged with hacking hundreds of Jeeps, motorcycles in crime spree
Watch this webinar to learn about email security threats
US defense contractor secures Amazon S3 bucket after leaving sensitive data publicly exposed

LinuxSecurity.com: An update that solves two vulnerabilities and has 5 fixes An update that solves two vulnerabilities and has 5 fixes An update that solves two vulnerabilities and has 5 fixes is now available. is now available.

“What are our cybersecurity protocols?” This question is one that has, undoubtedly, been top of mind for CTOs at numerous corporations and government agencies around the world in the wake of recent ransomware attacks. Given the hundreds of thousands of endpoint devices in more than 150 countries that were infected in the latest global attack, […]

Hooligans Biker Gang Arrested for Hacking and Stealing 150 Jeep Wranglers
News in brief: AI detects pain in animals; parallel universe discovered; Silk Road creator loses appeal
Insecure Backend Databases Blamed for Leaking 43TB of App Data
Google: Its Tech Now Blocks 99.9% of Gmail Phishing and Spam Emails
Crowdfunding Effort to Buy ShadowBrokers Exploits Shuts Down
OneLogin Breach Compromised Customer Data, Ability to Decrypt Encrypted Data
Password manager “OneLogin” hacked; data stolen
Hackers shelve crowdfunding drive for Shadow Brokers exploits
WannaCry Development Errors Enable File Recovery
Crooks hold nude plastic surgery pictures to ransom after break-in
Secure XML Processing with JAXP on EAP 7
Secret Pentagon Files Left Unprotected on the Amazon Server
In ongoing phishing fight, Google to delay delivery of suspicious messages to enterprise Gmail customers
Kittens, bears or pandas: who’s behind the biggest cyberattacks?
Shadow Brokers lay out pitch – and name price – for monthly zero-day subscription service
Blockchains are the new Linux, not the new internet
Windows XP ‘did not contribute much’ to WannaCry infection totals
Free Invisible Mobile App Security white paper from VASCO

LinuxSecurity.com: Several vulnerabilities were discovered in wordpress, a web blogging tool. They would allow remote attackers to force password resets, and perform various cross-site scripting and cross-site request forgery attacks.

security update

security update

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.