Menu

Monthly Archives: August 2017

US cops point at cell towers and say: Give us every phone number that’s touched that mast
What code is running on Apple’s Secure Enclave security chip? Now we have a decryption key…
Don’t panic, Chicago, but an AWS S3 config blunder exposed 1.8 million voter records
Cisco Patches Privilege Escalation Bugs in APIC
Drupal Patches Critical Access Bypass in Core Engine
Speakers and Mics hacked to turn Music Into Surveillance Tool

NOTE: This blog post discusses active research by Webroot into an emerging threat. This information should be considered preliminary and will be updated as more data comes in. New variants of Locky—Diablo and Lukitus—have surfaced from the ransomware family presumed by many to be dead. After rising to infamy as one of the first major […]

Rowhammer Attacks Come to MLC NAND Flash Memory

Risk Level: Very Low. Type: Trojan.

News in brief: new Bitcoin fork; HBO hacked; China cracks down
Woman targeted with 120 images on public transport via AirDrop
Hacker Sells 2FA bypass flaw in Poloniex exchange after 2 months wait
Vendor-neutral smart car bug has ‘dangerous’ and ‘even fatal’ consequences
5 Best Game Hacking Apps for Android
Nigerian Man Hacked Thousands of Global Oil & Gas and Energy Firms
Social media accounts of HBO, Game of Thrones and others hacked
Uber faces privacy audits every two years until 2037, rules FTC
London council ‘failed to test’ parking ticket app, exposed personal info
Lessons to learn after hackers hijack HBO’s Facebook and Twitter accounts
Buying encryption? Five good questions to ask before you do

General Data Protection Regulation (GDPR) together with the growing number of data breaches are the most pressing reasons why small and medium businesses are implementing data protection technologies – including encryption. The post Buying encryption? Five good questions to ask before you do appeared first on WeLiveSecurity

Got an iPhone? Here’s what we think about the security of iOS11
It’s baaaack: Locky ransomware is on the rise again
Smashing Security #038: Gents! Stop airdropping your pics!
UK govt steams ahead with £5m facial recog system amid furore over innocents’ mugshots
Bank IT fella accused of masterminding multimillion-dollar insider-trading scam
Rowhammer RAM attack adapted to hit flash storage

security update

NotPetya ransomware attack cost us $300m – shipping giant Maersk
Neo Nazi site DailyStormer moves to dark web that’s as good as dead
Locky Ransomware Variant Slips Past Some Defenses
LG service centers in S.Korea Possibly Hit By WannaCry ransomware
Disgraced US Secret Service agent coughs to second Bitcoin heist
News in brief: micro robots heal mice; Scottish Parliament hacked; Google Allo on desktops
Supply chain attack inserted backdoor into popular server management software
Flash’s Final Countdown Has Begun
Maersk Shipping Reports $300M Loss Stemming from NotPetya Attack
Judge orders LinkedIn to stop blocking third-party use of your data
Who will own the data from your autonomous car?
Google Removes Chrome Extension Used in Banking Fraud
7 More Chrome Extensions Hacked via Phishing Scam
Take Part in a Study to Help Improve Onion Services
Google awards student $10k for discovery of App Engine data leak flaw
OLE flaw lets malware infected PowerPoint files evade antivirus detection
Top 10 Enterprise Encryption Products
HBO Game Of Thrones leak: Four ‘techies’ arrested in India
31% off WD 4TB My Passport Portable External USB 3.0 Hard Drive – Deal Alert
Bot armies of fake followers are the footsoldiers of fake news
HBO accidentally aires upcoming episode 6 of Game of Thrones
Toronto woman joins the fight against creepshot image sites
She’s arrived! HMS Queen Lizzie enters Portsmouth Naval Base
Och. Scottish Parliament under siege from brute-force cyber attack
Speaking in Tech: Tomorrow’s infosec fiasco is a ‘we’re not a company any more’ fiasco
Four people arrested in connection with Game of Thrones episode leak
Hackers try to break into Scottish parliament email accounts weeks after Westminster attack
Months after breach at the ‘UnBank’ Ffrees, customers complain: No one told us
Google pays $10,000 for student’s bug

Google has rewarded a Uruguayan student with $10,000 after he exposed a security flaw that could allow hackers to access sensitive data. The post Google pays $10,000 for student’s bug appeared first on WeLiveSecurity

Russian malware scum post new rent-an-exploit
Creepy backdoor found in NetSarang server management software
Hacker unlocks vehicle for family who’d lost keys months ago

security update

Blizzard Entertainment hit by massive DDoS attack
Uber to bend over, take privacy probe every two years for next 20 years
Seven More Chrome Extensions Compromised
WannaCry hero back on Twitter after pleading not guilting over Kronos
Attackers Backdoor Another Software Update Mechanism
News in brief: teen scoops Excel prize; four arrested over GoT leak; web firm fights DoJ ‘overreach’
Fancy Bear bites hotel networks as EternalBlue mystery deepens
Fresh Microsoft Office franken-exploit flops – and you should have patched by now anyway
Too many big online brands allow terrible passwords
How shared Android libraries could be weaponized for data theft
Spam Domains Imitating Popular Banks Spreading Trickbot Banking Trojan
Friendly neighborhood hacker helps family regain access to locked car
Open Banking APIs under PSD2: Security Threats and Solutions. Download this free white paper
Web Host Asked to handover IP Addresses of Anti-Trump Website Visitors
APT-style attack against over 4,000 infrastructure firms blamed on lone Nigerian 20-something
How much HBO hackers have is hazy; what they want is clear – cash

Over the last couple of years, I’ve written and spoken regularly about the changing roles of the Chief Information Security Officer (CISO). And what better way to demonstrate the many skills the position requires – from the technical to the managerial – than journaling a day’s work. A CISO has to be the strategic partner […]

Drone-maker DJI’s Go app contains naughty Javascript hot-patching framework
US Govt demands details of 1.3 million internet users who visited Trump resistance website
MalwareTech is back online, as he pleads not guilty to Kronos malware charges
US military spies: We’ll capture enemy malware, tweak it, lob it right back at our adversaries

Risk Level: Very Low. Type: Trojan.

Blizzard Entertainment Hit With Weekend DDoS Attack
India arrest 4 for leaking ‘Game Of Thrones’ Episode 4 of Season 7

security update

security update

security update

AWS unveils AI monitoring for Amazon S3
Windows Search Bug Worth Watching, and Squashing
Smart Locks Bricked by Bad Update
HBO hackers leak episodes for Insecure and Curb Your Enthusiasm
Hundreds of ‘smart’ locks bricked by flubbed remote update
News in brief: update bricks 500 smart locks; Hutchins pleads not guilty; drone landed on warship
Dashboard tracks ‘desire in foreign councils’ to meddle with democracy
WannaCry vanquisher Marcus Hutchins pleads not guilty to flogging banking trojan Kronos
Researchers Find Phishing Site Encrypted with AES
Court records system has been open to hackers for decades
If Anonymous ‘pwnd’ the Daily Stormer, they did a spectacularly awful job
Thousands of Android-spying apps in the wild: what to do about SonicSpy
GoDaddy bans neo-nazi DailyStormer website