Menu

Monthly Archives: August 2017

Gmail now warns iOS users about suspicious links, in fight against phishing threats
HBO offered its hackers $250,000 after attack, leaked email claims
Why China’s quantum satellites do not herald ‘unhackable’ networks
Is your corporate inbox smelling a bit ‘phishy’ these days?
Sneaky devs could abuse shared libraries to slurp smartphone data
Leaky PostgreSQL passwords plugged
Top repo managers clone, then close, a nasty SSH vector

security update

Over a thousand spyware-infected Android apps discovered
Someone DDoSed Ukraine’ national postal service for 48 hours
OpDomesticTerrorism: Anonymous shut down Charlottesville city website

security update

security update

Type: Vulnerability. Oracle Java SE is prone to a remote code execution vulnerability.

Thousands of Android Apps Infected with SonicSpy Spyware
Russian Hackers Spying on VIP Hotel Guests Using Leaked NSA Tool
APT28 Using EternalBlue to Attack Hotels in Europe, Middle East
The Showdown: Hackers vs. Accountants
Kremlin’s hackers ‘wield stolen NSA exploit to spy on hotel guests in Europe, Mid East’
Git, SVN and Mercurial Open-Source Version Control Systems Update for Critical Security Vulnerabilit
The DDoS Threat: Ukraine’s Postal Service Hit by Two-Day Attack
Hackers are now using the exploit behind WannaCry to snoop on hotel Wi-Fi

security update

security update

17-years-old kid hacks US air force for the good

security update

security update

security update

security update

Infosec eggheads rig USB desk lamp to leak passwords via Bluetooth
Digital exchange joins law enforcement in hunt for WannaCry ransom bitcoins
News in brief: facial recognition planned for Carnival; spy chief backs encryption; ginger emoji planned
Many Factors Conspire in ICS/SCADA Attacks
Apps Infected With SonicSpy Spyware Removed From Google Play
Facebook password stealer; hacking the attacker rather than victim 
Firefox 55 makes Flash click-to-run, fixes security bugs
‘You could see why someone might want to hack DNA’
HMS Queen Lizzie impugned by cheeky Scot’s drone landing
Crosstalk Flaw: Hackers can steal sensitive data with unsecure USBs
Threatpost News Wrap, August 11, 2017
Ukrainian Man Arrested, Charged in NotPetya Distribution
Researchers Encode Physical DNA with Malware To infect Computers
Latest viral sensation app Sarahah raises concerns about cyberbullying
Why NIST’s Bill Burr shouldn’t regret his 2003 password advice
Good Lord: Former UK spy boss backs crypto

Solar Panel Vulnerabilities Could Lead to Hot Issues A recent study on several of the top solar panel manufacturers checked for any exploitable vulnerabilities in their products. One outcome of the study found that if a large volume of solar panels were exploited at once, it could cause catastrophic problems for the main power grid […]

Black Hat at 20, DefCon at 25: Not just about breaking things

Ironically named for the criminal hackers that cybersecurity pros spend their days – and not a few nights – defending against, the Black Hat Briefings quickly earned a reputation for excellent technical content. The post Black Hat at 20, DefCon at 25: Not just about breaking things appeared first on WeLiveSecurity

Ukrainian man, 51, cuffed on suspicion of distributing NotPetya
World’s first hack using DNA? Malware in genetic code could wreck police CSI work
TalkTalk fined £100,000 after carelessly exposing customer data. Again.
How to prevent the hacked AI apocalypse
‘Adversarial DNA’ breeds buffer overflow bugs in PCs

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

WikiLeaks: CIA’ CouchPotato Tool Remotely Collects Video Streams
SMS touch a security and privacy nightmare for iOS users
Schoolboy bags $10,000 reward from Google with easy HTTP Host bypass
IDG Contributor Network: How cloud-native security can prevent modern attacks
Man caught downloading child porn during raid; gets 10 years in prison

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Patched Flash Player Sandbox Escape Leaked Windows Credentials
Juniper Issues Security Alert Tied to Routers and Switches
High Schooler Nets $10,000 For Google Bug
.why .it’s .time .to .fix .localhost
Kaspersky axes antitrust complaints against Microsoft after Windows giant vows to play nice
Watch out for Emotet, the trojan that’s nearly a worm
Nasty Mamba ransomware that encrypts entire hard drive resurfaces
Sorry, who did you say you were? We’ve forgotten about you
Amber Rudd tricked by email prankster who duped White House officials
Debian move marks beginning of the end for TLS 1.0 and 1.1

When I started prepping for this interview, I wasn’t entirely sure what a quality assurance (QA) engineer did on a day-to-day basis. However, in a world where STEM (Science Technology Engineering and Mathematics) has become the buzzword du jour, I knew this important technical role was something more and more companies will need in the […]

Avoid getting lost in encryption with these easy steps

Encryption can be the answer to many data security issues faced by small and medium businesses. Apart from protecting sensitive information from unauthorized use,this technology can also represent another step towards compliance with legislation. The post Avoid getting lost in encryption with these easy steps appeared first on WeLiveSecurity

Lauri Love and Gary McKinnon’s lawyer, UK supporters rally around Marcus Hutchins
More on the Vulnerabilities Equities Process
Self-hosted search option is a new approach to bursting the filter bubble
TalkTalk fined £100k for exposing personal sensitive info
Mingis on Tech: Android vs iOS – Which is more secure?
Smashing Security #037: Boobs, dragons and data breaches
Can GCHQ order techies to work as govt snoops? Experts fear: ‘Yes’
At last! Firefox puts another nail in Flash’s coffin
So you’re thinking about becoming an illegal hacker – what’s your business plan?
Salesforce sacks two top security engineers for their DEF CON talk
Microsoft bins unloved Chinese cert shops
Carbon Black denies its IT security guard system oozes customer secrets

security update

security update

US court system bug opened hole for hackers to scoop up legal docs for free on victims’ dime
Hotspot Shield VPN accused of logging user data, selling it to advertisers

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available.

SAP Patch Tuesday Update Resolves 19 Flaws, Three High Severity
US border cops must get warrants to search phones, devices – EFF

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

It’s August 2017 and your Android gear can be pwned by, oh look, just patch the things