Menu

Monthly Archives: September 2017

security update

security update

Blockchain skills: Don’t Try to Block the Chain
Black Hat Europe 2017: New Briefings Announced
Hikvision Security Cams Compromised to Display “HACKED”

LinuxSecurity.com: **nag 4.2.17** * [jan] SECURITY: Fix unauthorized access to task exports. * [jan] Fix regression when exporting single tags to iCalendar CATEGORIES. * [jan] Officially support PHP 7.

LinuxSecurity.com: **wicked 2.0.8** * [jan] SECURITY: Fix unauthorized access to page attachments.

LinuxSecurity.com: **passwd 5.0.7** * [jan] Officially support PHP 7. * [jan] SECURITY: Fix open redirects.

Java security plagued by crappy docs, complex APIs, bad advice
US yanks staff from Cuban embassy over sonic death ray fears
Equifax mea-culpas with free credit “locks” forever
Signal app’s address book security could upset governments
Siemens Patches Improper Access Vulnerability in Ruggedcom Protocol
ICANN Postpones Scheduled DNS Crypto Key Rollover
Threatpost News Wrap, September 29, 2017
Apple Mac fans told: Something smells EFI in your firmware
Android malware ZNIU exploits DirtyCOW vulnerability
Dildon’ts of Bluetooth: Pen test boffins sniff out Berlin’s smart butt plugs
Macs Not Receiving EFI Firmware Security Updates as Expected
Cloud security policy: The questions you need to ask

Cloud services are very much what you make of them, and you need to apply at least an equivalent level of rigorousness, in terms of risk assessment, as you would with assets that are hosted on your own network. The post Cloud security policy: The questions you need to ask appeared first on WeLiveSecurity

iPhone X Face ID baffled by kids, twins, siblings, doppelgängers
Citrix patches Netscaler hole, ARM TrustZone twisted, Android Dirty COW exploited – and more security fails

Showtime Site Found Using Cryptocurrency Miner Following the discovery last week that ThePirateBay has been using a Monero miner to experiment with revenue alternatives for the site, researchers have found that both Showtime.com and ShowtimeAnytime.com have embedded code for similar cryptocurrency mining. The code itself runs only while the user is on the site, and […]

Ouch: Brit council still staggering weeks after ransomware bit its PCs
Internet-wide security update put on hold over fears 60 million people would be kicked offline
Angst in her pants: Alleged US govt leaker Reality Winner stashed docs in her pantyhose

LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.

Google to Enforce HSTS on TLDs it Operates
Civil Liberties Activists Hit By Phishing Campaign
DHS expanding surveillance of immigrants to social media

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Your Android lock screen pattern isn’t as safe as a PIN code

What’s safer? Using a numeric PIN code to unlock your Android smartphone or relying on a finger squiggle? The answer might surprise you. The post Your Android lock screen pattern isn’t as safe as a PIN code appeared first on WeLiveSecurity

Windows Defender Bypass Tricks OS into Running Malicious Code
Internet Explorer bug can reveal the contents of your address bar
Patch alert! Easy-to-exploit flaw in Linux kernel rated ‘high risk’
Android unlock patterns are too easy to guess, stop using them
Money-making machine: Monero-mining malware

While far behind Bitcoin in market capitalization, Monero has several features that make it a very attractive cryptocurrency to be mined by malware. The post Money-making machine: Monero-mining malware appeared first on WeLiveSecurity

The UK isn’t ditching Boeing defence kit any time soon

LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available.

Popular GoKeyboard App Spying on Millions of Android Users
The sorry state of stock trading mobile app security revealed
?Dios m?o! Spain blocks DNS to silence Catalan independence vote sites
Smashing Security podcast #045: Deloitte fail, CCleaner, and dotards on Twitter
Europol warns ransomware has taken cybercrime ‘to another level’
Microsoft downplays alarm over Windows Defender ‘flaw’
NatWest customer services: We’re aware of security glitch
Ransomware keeping cops, NHS and local UK gov bods awake at night
Mac High Sierra hijinks continue: Nasty apps can pull your passwords

LinuxSecurity.com: New gegl packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

iOS apps can read metadata revealing users’ location histories

security update

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Signal taps up Intel’s SGX to (hopefully) stop contacts falling into hackers, cops’ hands

Another day, another phishing attack. From businesses to consumers, phishing attacks are becoming a more widespread and dangerous online threat every year. One wrong click could quickly turn into a nightmare if you aren’t aware of the current techniques cyber scammers are using to get access to your valuable personal information. A phishing attack is […]

Alleged dark web drug baron cuffed – after he flew to US for World Beard Championships

security update

CCleaner Malware: Here is the Full List of Affected Companies
Gatekeeper Alone Won’t Mitigate Apple Keychain Attack
Facebook-hijacking Faceliker malware is on the rise
Signal Testing New Private Contact Discovery Service
Waiting for Skynet? Don’t hold your breath
South Korea Blames North Korean Hackers For Stealing Bitcoin
Instagram now lets you block people from commenting on your posts
TalkTalk once told GCHQ: Cyberattack? We’d act fast to get sports back up
Remote Wi-Fi Attack Backdoors iPhone 7
Gov contractor nicked on suspicion of Official Secrets Act breach
Campaigner who refused to hand over passwords found guilty
US Army Black Hawk helicopter damaged in drone crash
Heads-up teenage hoodlums! Don’t SWAT Brian Krebs or else…
Bossies 2017: The Best of Open Source Software Awards
Bossie Awards 2017: The best networking and security software
Have MAC, will hack: iThings have trivial-to-exploit Wi-Fi bug
Oracle corrals and patches Struts 2 vulnerabilities

LinuxSecurity.com: This release fixes a crash when parsing an empty code string of a codewscope type.

White House staffers jabbed with probe over private email use
Google reveals Android Robocop AI to spot and destroy malware
Deloitte is a sitting duck: Key systems with RDP open, VPN and proxy ‘login details leaked’

Type: Vulnerability. Adobe Flash Player is prone to an unspecified remote code-execution vulnerability; fixes are available.

Oracle Patches Apache Struts, Reminds Users to Update Equifax Bug

LinuxSecurity.com: Multiple vulnerabilities have been found in RAR and UnRAR, the worst of which may allow attackers to execute arbitrary code.

LinuxSecurity.com: Libplist could be made to crash if it opened a specially crafted file.

LinuxSecurity.com: The 4.13.3 stable update contains a number of important fixes across the tree.

macOS High Sierra Available—And Vulnerable to Keychain Attack
After The Pirate Bay, Showtime Websites Also Found Mining Cryptocoins
Keychain-busting zero-day disclosed hours before release of macOS High Sierra
What’s at risk from nRansom? Your memories of Thomas the Tank Engine
Equifax CEO falls on his sword weeks after credit biz admits mega-breach
Mobile Stock Trading App Providers Unresponsive to Glaring Vulnerabilities
Mobile stock trading apps riddled with security holes
WordPress 4.8.2 is out, update your website now
Adobe’s security team reveals its private PGP key
1.4 Million New Phishing Sites Launched Each Month
Beyond public key encryption
Another thug learns that SWATting Brian Krebs is a bad idea
Suspected mass-spoofing of ships’ GPS in the Black Sea

LinuxSecurity.com: A vulnerability in libsoup might allow remote attackers to execute arbitrary code.

Docs ran a simulation of what would happen if really nasty malware hit a city’s hospitals. RIP :(
Boffins take biometric logins to heart, literally: Cardiac radar IDs users to unlock their PCs
Researchers promise demo of ‘God-mode’ pwnage of Intel mobos