Menu

Monthly Archives: September 2017

Consumer Credit Reporting Agency Equifax Suffers Cyberattack Affecting 143 Million Customers Equifax announced hackers gained access to sensitive company data that potentially compromised information for 143 million American consumers, including Social Security numbers, driver’s license information, and credit card details. This is the third major cybersecurity incident for the agency since 2015. Most concerning, Equifax […]

Ex cop and child porn suspect to remain in jail until he decrypts drives
Your voice assistant can hear things you can’t – such as a hacker
Latest Intelligence for August 2017
August saw increases in the malware and spam rates, and new phishing warnings from the IRS Read More

LinuxSecurity.com: An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: Libidn2 2.0.4 (released 2017-08-30) integer overflow in bidi.c/_isBidi() * Fix integer overflow in puny_decode.c/decode_digit() * Improve docs * Fix idna_free() to idn_free() * Update fuzzer corpora

LinuxSecurity.com: An update that solves 21 vulnerabilities and has 92 fixes An update that solves 21 vulnerabilities and has 92 fixes An update that solves 21 vulnerabilities and has 92 fixes is now available. is now available.

Budding malware author uses same Skype ID across job applications and IoT botnet ads
Equifax hack could affect half the population of the US

The credit reporting agency, Equifax, has revealed that they suffered a huge cyberattack that could affect up 143 million Americans. The post Equifax hack could affect half the population of the US appeared first on WeLiveSecurity

40 days after discovering data leak, Equifax warns that 143 million US consumers could be at risk
Credit Reporting Firm Equifax Hacked; SSNs of 143M Americans Stolen
Equifax data breach defense: freezing your credit file
Equifax Says Breach Affects 143 Million Americans

Type: Vulnerability. Microsoft Windows is prone to a denial-of-service vulnerability.

Type: Vulnerability. Microsoft SQL Server is prone to a cross-site scripting vulnerability; fixes are available.

New Dridex Phishing Campaign Delivers Fake Accounting Invoices
Phishing Scam: Hackers Steal $11 Million from Canadian University
Ransomware: What you need to know now | Salted Hash Ep 1, Pt 4
U.S. Cyber Command gains status | Salted Hash Ep 1, Pt 2
Salted Hash: Kaspersky Lab, U.S. Cyber Command, Hollywood hacking and ransomware
Hollywood’s hacking woes | Salted Hash Ep 1, Pt 3
Kaspersky Lab and the Russia connection | Salted Hash Ep 1, Pt 1
Microsoft Won’t Fix Security Bypass Vulnerability in Edge
Hackers Have Reportedly Infiltrated The US Power Grids

LinuxSecurity.com: **Version 2.2.5** – 2017-08-30 * **Security** – Double-free in gdImagePngPtr(). **CVE-2017-6362** – Buffer over-read into uninitialized memory. **CVE-2017-7890** * **Fixed** – Fix #109: XBM reading fails with printed error – Fix #338: Fatal and normal libjpeg/ibpng errors not distinguishable – Fix #357: 2.2.4: Segfault in test suite – Fix #386:

LinuxSecurity.com: This update fixes CVE-2017-12858.

LinuxSecurity.com: An update that solves 5 vulnerabilities and has one errata An update that solves 5 vulnerabilities and has one errata An update that solves 5 vulnerabilities and has one errata is now available. is now available.

News in brief: hacker fail; voting fail; Twitter fail
Heading off to university? Watch out for phishing scams
Unsecured databases are (still) the low-hanging fruit of the internet
New NSA Data Dump: ShadowBrokers Release UNITEDRAKE Malware
Thought you’d blocked a Twitter user? Here’s how they can still dogpile you
Microsoft Programming Error is Behind Dangerous Kernel Bug, Researchers Claim

LinuxSecurity.com: An update that solves two vulnerabilities and has 58 fixes An update that solves two vulnerabilities and has 58 fixes An update that solves two vulnerabilities and has 58 fixes is now available. is now available.

Over the past eight years, I’ve been honored to work alongside a world-class group of professionals—including the Webroot team, and our growing network of partners and customers. Our security community has grown into something special, and powerful. With tremendous gratitude for that experience, I am sharing my plan to retire as CEO of Webroot. Mike Potts will be joining Webroot as CEO and a member of the Board of Directors on September 25, 2017, and […]

What’s under the hood of the new Brave browser?
How hackers could send secret commands to speech recognition systems with ultrasound
Smashing Security #041: Hacking Instagram, facial failures, and spying bosses
Learn a lesson from Nissan – own your brand’s website domain, or else…
Apple Developer site goes down and some users are fearing a hack
Fake Chrome & Firefox Font Update Drops RAT and Locky Ransomware
Tor Project Brings Security Slider Feature to Android App Orfox

security update

security update

Will the new iPhone break the $1,000 barrier? | Tech Talk Ep 1, Pt 4
13-year-old Japanese Kid Caught Selling Malware
IDN Homograph Attack Spreading Betabot Backdoor
News in brief: Warning over Bitcoin scam app; Samsung facial recognition bypassed; Apple squares up to India
Multiple Vulnerabilities Found in NVIDIA, Qualcomm, Huawei Bootloaders
13 Critical Remote Code Execution Bugs Fixed in September Android Update
Lenovo settles lawsuits with 32 states over Superfish
Energy sector biz hackers are back and badder than ever before
DolphinAttack: Voice Assistant Apps Siri and Alexa Can Be Hacked
Apache Struts “serialisation” vulnerability – what you need to know
France to tack weapons onto spy drones – reports
Fur flies over Android bootloader flaws: here’s what you need to know
WireX Variant Capable of UDP Flood Attacks
Tor Project boosts support for anonymous mobile browsing
Scammers Are Targeting Naive Bitcoin Owners With Terribly Simple Trick
CISOs’ Salaries Expected to Edge Above $240,000 in 2018
Mo money mo mobile payments… Security risks? Whatever!
On internet privacy, be very afraid
Microsoft Releases Long-Awaited Security Tool, Sets Linux Preview
MongoDB ransacking starts again: Hackers ransom 26,000 unsecured instances
Why some gift cards are still a gift to hackers

LinuxSecurity.com: **Version 1.3.0** It contains fixes for two possible security problems. The problems were identified by Brian ‘geeknik’ Carpenter and Agostino Sarubbo using AFL. The changes are: * Support bzip2 compressed zip archives * Improve file progress callback code * Fix zip_fdopen() * CVE-2017-12858: Fix double free(). * CVE-2017-14107: Improve EOCD64 parsing.

Lenovo to Pay $3.5m for Secretly Installing Adware in 750,000 Laptops
Lenovo’s Superfish security fiasco ends in a slap on the wrist
Critical security flaw leaves Fortune 100 firms vulnerable

The discovered weakness would allow hackers to remotely run code on servers that utilize the REST plugin from Apache Struts, and it is reported that all versions since 2008 are affected. The post Critical security flaw leaves Fortune 100 firms vulnerable appeared first on WeLiveSecurity

Give staff privacy at work, Euro human rights court tells bosses
Boffins hijack bootloaders for fun and games on Android
Please, pleeeease let me ban Kaspersky Lab from US govt PCs – senator
Chinese Man Who Sold VPNs Gets 9 Months Prison Sentence
Attacker demands ransom after series of DDoS attacks on Poker site

security update

Tech Talk: Pricey iPhones, intent-based networks, GPS spoofing and smartwatches
Yet another AWS config fumble: Time Warner Cable exposes 4 million subscriber records
Remember when Lenovo sold PCs with Superfish adware? It just got a mild scolding from FTC
News in brief: veterans among S3 leak victims; court rules on email privacy; man jailed for VPN sales
Patch Released for Critical Apache Struts Bug
Four Million Time Warner Cable Records Left on Misconfigured AWS S3
Apache Struts you’re stuffed: Vuln allows hackers to inject evil code into biz servers

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

London police’s use of facial recognition falls flat on its face
Instagram breach deepens with dark web ‘Doxagram’ domain
Military Contractor’s Vendor Leaks Resumes in Misconfigured AWS S3
Spam Campaigns Using Trickbot Banking Trojan Against Cryptocurrencies
Would-be cyberattackers caught by malware with a sting in the tail
Kurat võtku! Estonia identifies security risk in almost 750,000 ID cards
YouTube MP3 Converter Site Shut Down After Labels Win Lawsuit
Yahoo! braces itself for enormous class-action suit over breaches
Bazinga! Social network Taringa ‘fesses up to data breach

LinuxSecurity.com: GD library could be made to crash if it opened a specially crafted file.

LinuxSecurity.com: An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

Chinese cryptocurrency crackdown

China banned the raising of funds using token-based digital currencies and deemed the practice illegal on Monday, in a move seen as an attempt to impose more regulations on the virtual market. The post Chinese cryptocurrency crackdown appeared first on WeLiveSecurity

UK not as keen on mobile wallets as mainland Europe and US
Latin American social media giant Taringa hacked; 28M accounts stolen