Menu

Monthly Archives: August 2017

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge and Internet Explorer are prone to a remote memory-corruption vulnerability; fixes are available.

Risk Level: Very Low. Type: Trojan.

Marcus Hutchins’ Only Certainty is Uncertainty
Flaws in ISP gateways let attackers remotely tap internet traffic
Lawsuit Alleges Disney Illegally Tracks Children Via Apps
News in brief: Ariana Grande hacked; new data laws unveiled; Marcus Hutchins due to be released
Tech Support Scammers Cast a Wider Net
Cyberattacks on GPS leave ships sailing in dangerous waters
Microsoft not releasing patch for 20-year-old SMB flaw
Self-Driving Cars Can Be Tricked Into Misreading Street Signs
Congress looks to take the wheel on autonomous vehicles
Good guys and bad guys race against time over disclosing vulnerabilities

Last week, we covered the results of our survey of more than 600 IT decision-makers at medium-sized companies in the U.S., U.K., and Australia. Participants shared valuable insights into their cybersecurity understanding and preparedness, and I gave my own analysis of what the numbers indicate. Quick recap I’ve been in the security industry for more […]

Game of Thrones Season 7 Episode 4 leaked online

security update

Polish Kidnapper Tried Selling British Model on Dark Web
Attackers could shut down power grids by abusing solar panel flaws

security update

security update

WannaCry hero gets bail; pleading not guilty over Kronos malware

LinuxSecurity.com: Several vulnerabilities have been discovered in the chromium web browser. CVE-2017-5087

LinuxSecurity.com: Fix IV Reuse in GCM Mode.

LinuxSecurity.com: Multiple vulnerabilities were found in qemu, a fast processor emulator: CVE-2017-9524

LinuxSecurity.com: This update adds security fixes for CVE-2017-5052 and CVE-2017-5054, backported to Chromium 49 / QtWebEngine 5.6 by the Qt developers.

LinuxSecurity.com: Fix IV Reuse in GCM Mode.

LinuxSecurity.com: An update that solves 6 vulnerabilities and has two fixes An update that solves 6 vulnerabilities and has two fixes An update that solves 6 vulnerabilities and has two fixes is now available. is now available.

LinuxSecurity.com: An update that solves 7 vulnerabilities and has one errata An update that solves 7 vulnerabilities and has one errata An update that solves 7 vulnerabilities and has one errata is now available. is now available.

Radio Station Broadcast Cold War Era Messages Despite Being Non-operational
A Dangerous Vulnerability in Solar Panels can Cause Power Outage
Hacker Who Stopped WannaCry Charged With Writing Banking Malware
WannaCry crooks cash out their ransom
Attackers Use Typo-Squatting To Steal npm Credentials

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available.

Exploits Available for Siemens Molecular Imaging Vulnerabilities

LinuxSecurity.com: Security fix for CVE-2016-6127 CVE-2017-5361 CVE-2017-5943 CVE-2017-5944

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Security fix for CVE-2016-6127 CVE-2017-5361 CVE-2017-5943 CVE-2017-5944

LinuxSecurity.com: – CVE-2017-1000083: Evince command injection vulnerability in CBT handler (#1468488)

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has 6 fixes An update that solves three vulnerabilities and has 6 fixes An update that solves three vulnerabilities and has 6 fixes is now available. is now available.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Man implants microchip in his hands to open doors & unlock car with ease
Tor Developer Busts Myths, Announces New Features
Threatpost News Wrap, August 4, 2017
Latest Intelligence for July 2017
Email malware rate continues to increase and WannaCry, Petya inspire other threats to add self-spreading components. Read More
Amazon reaches out to users with bad security before the crooks do
A Reddit User Has Leaked Upcoming Episode 4 of ‘Game of Thrones’
Google wants to track you in real life – privacy group says, ‘No way!’
Invisible Man malware lifts banking credentials by abusing Android accessibility services

LinuxSecurity.com: Update to 5.2.24: fixes XSS vulnerability CVE-2017-11503.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. Amazon Echo Resolves Security Flaw Researchers have recently discovered a major security flaw that affects several […]

Uber drivers game the system – force up fares
Amazon Echo hacked to allow continuous remote eavesdropping
It’s 2017 and Hayes AT modem commands can hack luxury cars
Should IoT vendors be told what to do by the government? [VIDEO]
FBI arrests WannaCry’s ‘accidental hero’ in connection with Kronos banking trojan
Bateleur, the new malware backdoor targeting restaurant chains, from the makers of Carbanak
WannaCry hero arrested For “creating and distributing Kronos trojan”
Cisco Fixes DoS, Authentication Bypass Vulnerabilities, OSPF Bug
WannaCry Hero Arrested, One of Two Charged with Distribution of Kronos Malware

Type: Vulnerability. Oracle Java SE is prone to a remote code execution vulnerability; fixes are available.

Do developers care about security?
Safeguarding power grids and other critical infrastructure from data leaks
News in brief: WannaCry ‘kill switch’ man detained; Firefox file encryption; DDoS fails to persuade
WannaCry Bitcoin Withdrawn; ‘Killswitch’ Researcher Detained in Nevada
Hero Researcher Who Halted WannaCry Ransomware Arrested by FBI

Risk Level: Very Low. Type: Worm.

Researchers display “CAN do” skill in vehicle DoS

DEF CON 25 has come and gone, but the cybersecurity world is still reeling from some of the research and advanced threats demonstrated at this annual convention of the world’s foremost hackers. Security professionals are more aware than ever of the increasing number of threats targeting everyday devices—from smart appliances to voting machines. Keep reading […]

Chrome’s built-in adblocker arrives for early adopters
Someone DDoSed Chinese Telecom Firm For 11 Days
Can US senators secure the Internet of Things?
44% off Aukey Dash Cam, Full HD Wide Angle With Night Vision – Deal Alert
Vault 7: CIA’ Dumbo Project Hijacking Webcams and Microphones
Hackers hijack popular Chrome extension to inject code into web developers’ browsers

LinuxSecurity.com: Security fix for CVE-2016-6127 CVE-2017-5361 CVE-2017-5943 CVE-2017-5944

AI quickly cooks malware that AV software can’t spot
Security This Week: The Very Best Hacks From Black Hat and Defcon
12 signs you’ve been hacked — and how to fight back
What do the words ‘Tor’ and ‘Dark Web’ mean to you? [VIDEO]
Two Popular IP Cameras Riddled With Vulnerabilities
Fired employee caught by keylogger wins case
Amazon Echo Can Be Hacked to act as a Surveillance device

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available.

What’s the cost of a free lunch?

We all know that there is no such thing as a free lunch, or security product, so what’s the catch? The post What’s the cost of a free lunch? appeared first on WeLiveSecurity

Smashing Security #036: Flash? Clunk flush… and hacking security researchers

Last week, Black Hat USA 2017 brought an impressive 15,000+ cybersecurity professionals to Las Vegas to talk shop about the biggest issues facing businesses today. Here’s a recap from the perspective of the Webroot security experts who attended. A hacker’s economy Black Hat 2017 continued a recent trend of more corporate and business involvement than […]