Menu

Monthly Archives: July 2017

Dutch police share list of identified, active, and arrested Hansa vendors and buyers
ShieldFS Can Detect Ransomware, Recover Files

LinuxSecurity.com: USN 3366-1 introduced a regression in OpenJDK 8.

Voting Machines Hacked with Ease at DEF CON
Android Banking Trojan Svpeng Adds Keylogger
Airborne Drones can be hijacked using $15 BBC’ Micro:bit
DEF CON attendees make short work of electronic voting machines

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

News in brief: Roomba data not for sale; thief-catching wallet; Windows Bounty Program
Should Adobe make Flash open source? [POLL]
Hackers steal information on 400,000 customers of Italy’s biggest bank
Microsoft Releases Outlook and Office Click-to-Run Patches
Feds Seize BTC-E exchange website – CoinBase suffers DDoS attacks
‘Ghost Telephonist’ Attack Exploits 4G LTE Flaw to Hijack Phone Numbers
One lousy click: the phishing blunder that sank an entire product
Dark Web criminals caught after reusing passwords
Pre-installed Trojan in Cheap Android Devices Steal Data, Intercept Chats

LinuxSecurity.com: Several security issues were fixed in Apache HTTP Server.

LinuxSecurity.com: Update to latest snapshot that contains fixes for the latest Talos discovered CVEs.

LinuxSecurity.com: Update to latest snapshot that contains fixes for the latest Talos discovered CVEs.

LinuxSecurity.com: Fix for multiple CVEs

The New York gas pumps that steal your credit card

This past May, Webroot surveyed more than 600 IT decision-makers at medium-sized companies (with between 100 and 499 employees) in the U.S., U.K., and Australia. The survey focused on how these small businesses perceived new threats facing their organizations. Were they prepared to manage fallout and recovery process after a cyberattack? Did they understand the […]

How Google Shrunk The Android Attack Surface

LinuxSecurity.com: Several security issues were fixed in NSS.

Risk Level: Very Low. Type: Trojan.

security update

security update

For hackers at Defcon hacking US voting machines was a piece of cake
iOS VPN apps removed from Apple’s Chinese App Store
Apple has removed all major VPN apps from Chinese App Store
Healthcare Clinic Suffers Ransomware Attack; 300K Patients Impacted

LinuxSecurity.com: Update to 5.2.24: fixes XSS vulnerability CVE-2017-11503.

LinuxSecurity.com: MinGW cross compiled librsvg 2.40.18 release, fixing CVE-2017-11464 (division- by-zero in the Gaussian blur code).

LinuxSecurity.com: Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.57, which includes additional changes, such as performance improvements, bug fixes, new features, and possibly incompatible

LinuxSecurity.com: MinGW cross compiled librsvg 2.40.18 release, fixing CVE-2017-11464 (division- by-zero in the Gaussian blur code).

LinuxSecurity.com: In DSA 3918 Thunderbird was upgraded to the latest ESR series. This update upgrades Enigmail, the OpenPGP extention for Thunderbird, to version 1.9.8.1 to restore full compatibility.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Wikileaks Exposes CIA’ 3 Linux/macOS Malware- Aeris, Achilles, SeaPea
Watch: Hackers take over Tesla Model X; control brakes and doors
Privacy Isn’t Dead. It’s More Popular Than Ever
‘SambaCry’ malware scum return with a Windows encore
How a Bug in an Obscure Chip Exposed a Billion Smartphones to Hackers
Car wash security flaws let hackers ‘physically attack’ people

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. Mac Backdoor Just Discovered, Active For Years Researchers have only recently discovered a previously undetectable backdoor […]

Become a sysadmin – learn how to fit right in [VIDEO]
How A Coffee Machine Infected Factory Computers with Ransomware

LinuxSecurity.com: New squashfs-tools packages are available for Slackware 14.2 and -current to fix security issues.

Bringing behavioral game theory to security defenses
Simple tips to keep your devices secure when you travel
News in brief: beware the hacked carwash; man sentenced over Mirai attack; farewell to the iPod
Watch: Researcher hacking, unlocking a smart gun with $15 magnets
Lipizzan spyware linked to cyberarms firm plunders SMS, logs and photos
Are you a Sysadmin? Find out now for free!
Update your phone: Avoid being Pwned by bug residing in WiFi chip
Police crack seized phones of inauguration day protesters
BTC-e exchange’ owner arrested over money laundering accusation

LinuxSecurity.com: MinGW cross compiled librsvg 2.40.18 release, fixing CVE-2017-11464 (division- by-zero in the Gaussian blur code).

Facebook joins heavy hitters to fund group standing up to post-truth

LinuxSecurity.com: An update that fixes 21 vulnerabilities is now available. An update that fixes 21 vulnerabilities is now available. An update that fixes 21 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 21 vulnerabilities is now available. An update that fixes 21 vulnerabilities is now available. An update that fixes 21 vulnerabilities is now available.

Are smartphones threatening the security of our IoT devices?

The number of IoT devices is set to surpass 20 billion by 2020. We take a look at how connected things threaten our security as cybercriminals exploit weaknesses in the smartphones that control them. The post Are smartphones threatening the security of our IoT devices? appeared first on WeLiveSecurity

BlackHat: FBI Talks Avalanche Botnet Takedown
Shorting-For-Profit Viable Business Model For Security Community
Today’s the day – celebrate your sysadmin superheroes!
Going on holiday? Here are our tips for a security-minded trip
Black Hat: Hacking the firmware, the next frontier

Trick the firmware and you have access to the whole system. Here at Black Hat, there are a lot of people doing just that. The post Black Hat: Hacking the firmware, the next frontier appeared first on WeLiveSecurity

ESET’s Anton Cherepanov picks up Pwnie for Best Backdoor

Anton Cherepanov, a malware researcher at ESET, has picked up a Pwnie Award for Best Backdoor at this year’s ceremony at Black Hat USA 2017 in Las Vegas. The post ESET’s Anton Cherepanov picks up Pwnie for Best Backdoor appeared first on WeLiveSecurity

How to hack a Sysadmin – jump the IT support queue every time!
11 arrested in Chinese Fireball malware investigation

Risk Level: Very Low. Type: Trojan.

Attack Uses Docker Containers To Hide, Persist, Plant Malware
Hackers can take over Car Wash, trap you and smash your vehicle
ShadowBrokers Remain an Enigma
How DevOps and cloud will speed up security
News in brief: US indicts Russian BTC-e ‘mastermind’; Blu still phoning home; bug bounty offers $250k

Risk Level: Very Low.

Risk Level: Very Low. Type: Trojan.

Google Study Quantifies Ransomware Profits
Don’t want your SMSs stolen? Don’t download these Android apps
CowerSnail Backdoor Targeting Windows Devices
Independent labs to probe medical devices for security flaws
APT Group Uses Catfish Technique To Ensnare Victims
Wells Fargo apologizes for spilling trove of data on wealthy clients
Black Hat speaker denied entry to US in another needless hit to security research

LinuxSecurity.com: This update addresses the following vulnerabilities: * [CVE-2017-7018](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7018), [CVE-2017-7030](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7030), [CVE-2017-7034](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7034), [CVE-2017-7037](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7037),

LinuxSecurity.com: ## 2.8.25 (2017-07-17) * security #23507 [Security] validate empty passwords again (xabbuh) * bug #23526 [HttpFoundation] Set meta refresh time to 0 in RedirectResponse content (jnvsor) * bug #23540 Disable inlining deprecated services (alekitto) * bug #23468 [DI] Handle root namespace in service definitions (ro0NL) * bug #23256 [Security] Fix authentication.failure event

LinuxSecurity.com: – Upgrade to upstream v3.0.15 release. See upstream ChangeLog for details (in freeradius-doc subpackage). – Resolves: Bug#1471848 CVE-2017-10978 freeradius: Out-of-bounds read/write due to improper output buffer size check in make_secret() – Resolves: Bug#1471860 CVE-2017-10983 freeradius: Out-of-bounds read in

LinuxSecurity.com: Rebuilt to new upstream version 2.7.1 fixes rhbz#1443071 and rhbz#1443129

LinuxSecurity.com: This update fixes multiple security vulnerabilities (CVE-2017-7515, CVE-2017-9775, CVE-2017-9776, CVE-2017-9865).

LinuxSecurity.com: * Bump to 1.8.3 * Security fix for CVE-2017-8932 * add support for 28+bit OIDs in asn1

Homograph attacks: Don’t believe everything you see

A homograph attack is what happens when attackers register domains that are similar to the originals, with valid certificates. The post Homograph attacks: Don’t believe everything you see appeared first on WeLiveSecurity

Start-up accused of undermining popular open-source tools
Wait, this email isn’t for me – what’s it doing in my inbox?
Black Hat 2017 industrial hacking: The song remains the same

If industry frameworks are to inform and secure the critical infrastructure writ large, here at Black Hat there a lot of people punching holes in them, and in simple ways. The post Black Hat 2017 industrial hacking: The song remains the same appeared first on WeLiveSecurity

Black Hat 2017: Non-standard hacking platforms reign supreme

This year at Black Hat, tiny automated hacking platforms are everywhere, loaded with tasty purpose-built tools that can be used to break into your systems. The post Black Hat 2017: Non-standard hacking platforms reign supreme appeared first on WeLiveSecurity

Android Sypware Still Collects PII Despite Outcry

Risk Level: Very Low. Type: Trojan.

Smashing Security #035: Up the Roomba with mandatory Chinese spyware