Menu

Monthly Archives: August 2017

Robocall scumbags already target Hurricane Harvey victims
Malware writer offers free trojan to hackers … with one small drawback
Instagram hacked; data of top celebrities stolen and traded
Session Hijacking Bug Exposed GitLab Users Private Tokens
When uploading comments to the FCC, you can now include malware
Bugs in Arris Modems Distributed by AT&T Vulnerable to Trivial Attacks
Angelfire: CIA’ Undetectable Implants Infect Windows Boot Sector
Polyinstantiating /tmp and /var/tmp directories
FDA Recalls 465K Pacemakers Tied to MedSec Research
Pacemaker gets firmware update – go and see your doctor
Beware scammers phishing for disaster charity – or anything else
WikiLeaks official website hacked by OurMine hacking group
Instagram confirms hack against high-profile users’ account info
Reflected XSS Bug Patched in Popular WooCommerce WordPress Plugin
Machine learning for malware: what could possibly go wrong?
UK council fined £70k for leaving vulnerable people’s data open to world+dog
Is your email in the latest cache of 711 million pwnd addresses?
Google removes 300 Android apps following DDoS attack

Google has been forced to remove almost 300 apps from its Play Store after learning that apps were being hijacked for DDoS attacks. The post Google removes 300 Android apps following DDoS attack appeared first on WeLiveSecurity

Patchy PCI compliance putting consumer credit card data at risk
People-rating app Sarahah slurps up contacts for feature that doesn’t exist
Mystery surrounds malware attack that forced German state parliament offline
CyberRehab’s mission? To clean up the internet, one ASN block at a time
No razzle-dazzle here! Hackers target Zazzle with run-of-the-mill brute-force attack
More than 700 million email addresses leaked in huge data breach

Huge data breach sees more than 700 million email addresses and passwords leaked publicly thanks to a misconfigured spambot, dubbed ‘Onliner’. The post More than 700 million email addresses leaked in huge data breach appeared first on WeLiveSecurity

ARM’s embedded TLS library fixes man-in-the-middle fiddle
Instagram’s leaky API exposed celebrities’ contact details
Siemens patches one security vuln, leaves folks to block second
465k Pacemakers vulnerable; users must visit doctors for fix

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

US government: We can jail you indefinitely for not decrypting your data
Intel Confirms Its Much-Loathed ME Feature Has A Kill Switch

security update

Oh, ambassador! You literally are spoiling us: Super-stealthy spyware hits Euro embassy PCs
Turla APT Used WhiteBear Espionage Tools Against Defense Industry, Embassies
New Locky Variant ‘IKARUSdilapidated’ Strikes Again
News in brief: AI writes new GoT book; Google breaks out of the speaker; Cortana and Alexa hook up
Electronics retail giant CeX hacked; data of 2 million customers stolen

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Siemens Fixes Session Hijacking Bug in LOGO!, Warns of Man-in-the-Middle Attacks
‘Open and accessible’ spambot server leaks 711 million records
Bitcoin users, the taxman wants to know what’s in your piggybank
Spambot Contains ‘Mind-Boggling’ Amount of Email, SMTP Credentials
Hidden Kill Switch Identified in Controversial Intel ME controller chip
7 Things to Know About Today’s DDoS Attacks
New Ransomware Email Scam Using FBI and IRS as Bait
Trump’s cybersecurity advisers quit, warning of ‘insufficient attention’
711 MILLION email accounts weaponized by Onliner for spam campaigns
New ESET research uncovers Gazer, the stealthy backdoor that spies on embassies
Another banking trojan is trying to loot your cryptocurrency wallets
WireX botnet offers glimpse of Android DDoS threat
Best Korea fingered for hacks against Bitcoin exchanges in South
CeX data breach impacts two million UK accounts, customers told to change passwords ASAP
Lanarkshire NHS infection named as Bitpaymer variant
Pacemaker patch passes probe by US watchdog

Risk Level: Very Low. Type: Trojan.

Onliner Spambot dump exposes 711 Million email and passwords
Don’t fall for Hurricane Harvey charity scams!
Two million customer records pillaged in IT souk CeX hack attack

security update

Trump appointee says for the ‘past several years’ he has been the victim of ‘multiple cyber attacks’
Google Reminding Admins HTTP Pages Will Be Marked ‘Not Secure’ in October
Researchers Figure Out How to Blind ISPs from Smart Home Device Traffic
Revamped Nukebot Malware Changes Targets, Adds Functions
News in brief: Turing’s documents found; Uber steps back on tracking; feathered threat to police
Are you an adrenaline junkie who takes risks with security?
DMARC should be catnip for email security – why aren’t firms using it?
Insanely Popular White Supremacist Website Stormfront Booted Off
Telnet Credential Leak Reinforces Bleak State of IoT Security
UK infrastructure failing to meet the most basic cybersecurity standards
Dangerous WireX Android DDoS Botnet Killed by Security Giants
Spyware deployed in state-sponsored attacks against India and Pakistan
Facial recognition: how many rogue drivers has it stopped in New York?
DJI Launches Drone Bug Bounty Program
Security and Education

To some extent, the security software industry relies on the idea that there is always a technological answer to a tech problem but ‘always’ is a big word. The post Security and Education appeared first on WeLiveSecurity

Leak of >1,700 valid passwords could make the IoT mess much worse
Google opens up on Titan security: Here’s how chip combats hardware backdoors
Trump signs bill into law allowing warrantless searches in parts of VA, MD and DC
Don’t expose yourself with your boarding pass
Selena Gomez – please tell your 125 million fans to enable two-step verification