Menu

Monthly Archives: October 2017

Another Hollywood studio is hacked by The Dark Overlord
Popular ‘Circle with Disney’ Parental Control System Riddled With 23 Vulnerabilities

security update

Apple Patches KRACK Vulnerability in iOS 11.1
Firefox Bolsters Privacy, Pulls Plug on Browser Canvas Fingerprinting

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

I can no longer recommend MailChimp

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Equifax is facing a towering pile of class action law suits
Emergency Oracle Patch Closes Bug Rated 10 in Severity
Malicious Chrome Extension Steals ‘All Posted Data’ without Login Credentials
How to better protect your data when you’re on a business trip overseas
Canadian SMBs: How technology can help you go global

As you company grows globally you will be faced with many challenges and it can be easy to forget, unintentionally, some of the steps you have gone through to get to the position your company finds itself in. The post Canadian SMBs: How technology can help you go global appeared first on WeLiveSecurity

Antimalware Day: Genesis of viruses… and computer defense techniques

To honor the work of Dr. Fred Cohen and Professor Len Adleman, and the foundation they laid for research of computer threats, we decided to declare November 3 as the first ever Antimalware Day. The post Antimalware Day: Genesis of viruses… and computer defense techniques appeared first on WeLiveSecurity

SSHGuard 2.1 Released
unCAPTCHA algorithm can Crack Google’s AI System reCAPTCHA

LinuxSecurity.com: This is the final notification for the End Of Life (EOL) of Red Hat ‘Stand-Alone’ Proxy. Red Hat Proxy ‘Stand-Alone’ (Proxy server directly connecting to the Red Hat Network): Systems registered as clients to RHN via a Red Hat Satellite

London Heathrow Airport’s security laid bare by one lost USB stick
Mozilla devs discuss ditching Dutch CA, because cryptowars
Troll gets 5 years for framing brother-in-law as terrorist and paedophile

We’re revealing the top 10 nastiest ransomware attacks from the past year. NotPetya came in on our list as the most destructive ransomware attack of 2017, followed closely by WannaCry and Locky in the number two and three spots, respectively. NotPetya took number one because of its intent to damage a country’s infrastructure. Unlike most […]

LinuxSecurity.com: Several security issues have been corrected in multiple demuxers and decoders of the libav multimedia library. A full list of the changes is available at https://git.libav.org/?p=libav.git;a=blob;f=Changelog;hb=refs/tags/v11.11

security update

Three Monero Mining Malware Apps Found on Play Store
Google’s reCaptcha Cracked Again
Flaw in Google Bug Tracker Exposed Reports About Unpatched Vulnerabilities

security update

LinuxSecurity.com: It was discovered that the bgpd daemon in the Quagga routing suite does not properly calculate the length of multi-segment AS_PATH UPDATE messages, causing bgpd to drop a session and potentially resulting in loss of network connectivity.

LinuxSecurity.com: An update that solves 30 vulnerabilities and has 38 fixes An update that solves 30 vulnerabilities and has 38 fixes An update that solves 30 vulnerabilities and has 38 fixes is now available. is now available.

Google to Ditch Public Key Pinning in Chrome

LinuxSecurity.com: A vulnerability in Jython may lead to arbitrary code execution.

Can ARM save the Internet of Things?
Malicious Chrome Extension Steals Data Posted to Any Website
USB Stick with Heathrow Security and Queen’ Data Found on London Street
Dell forgot to renew the domain it uses for PC backups
Hacking site hacked by hackers
Heathrow security plans ‘found on USB stick left in the street’

LinuxSecurity.com: It was discovered that git-annex, a tool to manage files with git without checking their contents in, did not correctly handle maliciously constructed ssh:// URLs. This allowed an attacker to run an arbitrary shell command.

LinuxSecurity.com: An update for tomcat is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for tomcat6 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

security update

LinuxSecurity.com: Multiple vulnerabilities have been found in Apache, the worst of which may result in the loss of secrets.

LinuxSecurity.com: Multiple vulnerabilities have been found in Oracle’s JDK and JRE software suites, the worst of which can be remotely exploited without authentication. [More…]

LinuxSecurity.com: Niklas Abel discovered that insufficient input sanitising in the the ss-manager component of shadowsocks-libev, a lightweight socks5 proxy, could result in arbitrary shell command execution.

LinuxSecurity.com: An update that solves three vulnerabilities and has 32 An update that solves three vulnerabilities and has 32 An update that solves three vulnerabilities and has 32 fixes is now available. fixes is now available.

security update

security update

LinuxSecurity.com: Multiple vulnerabilities have been found in X.Org Server the worst of which could allow a local attacker to replace shared memory segments.

LinuxSecurity.com: Multiple vulnerabilities have been found in Asterisk, the worst of which allows remote execution of arbitrary shell commands.

LinuxSecurity.com: Antti Levomaeki, Christian Jalio, Joonas Pihlaja and Juhani Eronen discovered two buffer overflows in the HTTP protocol handler of the Wget download tool, which could result in the execution of arbitrary code when connecting to a malicious HTTP server.

The Dark Overlord hacks plastic surgery clinic; demands ransom

LinuxSecurity.com: An update that fixes 21 vulnerabilities is now available. An update that fixes 21 vulnerabilities is now available. An update that fixes 21 vulnerabilities is now available.

Risky online dating apps putting your privacy in danger
Ships Are Vulnerable to Cyber Attacks Due To Maritime Platform Flaw

LinuxSecurity.com: Security fix for [CVE-2017-12173]

LinuxSecurity.com: An update that solves 9 vulnerabilities and has two fixes An update that solves 9 vulnerabilities and has two fixes An update that solves 9 vulnerabilities and has two fixes is now available. is now available.

iPhone apps can access cameras to secretly take photos and record videos
Google slides DNS privacy into ‘Droid developer stream
The Little Black Box That Took Over Piracy
Apache OpenOffice Update Patches Four Vulnerabilities

LinuxSecurity.com: An update that fixes 14 vulnerabilities is now available. An update that fixes 14 vulnerabilities is now available. An update that fixes 14 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: Brian Carpenter, Geeknik Labs and 0xd34db347 discovered that cURL, an URL transfer library, incorrectly parsed an IMAP FETCH response with size 0, leading to an out-of-bounds read.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available. An update that fixes 9 vulnerabilities is now available. An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: New wget packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: New php packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available. An update that fixes 9 vulnerabilities is now available. An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that solves 13 vulnerabilities and has two fixes An update that solves 13 vulnerabilities and has two fixes An update that solves 13 vulnerabilities and has two fixes is now available. is now available.

LinuxSecurity.com: An update for wget is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

The iOS privacy loophole that’s staring you right in the face
Researchers hack vacuum cleaner; turn it into perfect spying device
Google Patches ‘High Severity’ Browser Bug
Rockwell Automation Patches Wireless Access Point against Krack
EternalRomance NSA Exploit a Key Player in Bad Rabbit Ransomware Mayhem
Debate rages over divisive US surveillance law renewal
Honolulu gets tough on people texting while crossing
Slack Plugs ‘Severe’ SAML User Authentication Hole
Microsoft’s new open source tool can scan your website for security and performance headaches

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. Fake Crypto Exchange Apps Found on Google Play Store After being available on the Google Play […]

The Cybersecurity Skills Gap: Educating the next generation

A long-term strategy focused on training and educating the next generation will help to ensure enough people have the right skills for the future. The post The Cybersecurity Skills Gap: Educating the next generation appeared first on WeLiveSecurity

Android takes aim at ISP surveillance with DNS privacy
This malware turns itself into ransomware if you try to remove it
jQuery Blog Gets Hacked – Hackers Compromise CoinHive’s DNS
Google wants you to hack Play Store apps, and it’s paying

LinuxSecurity.com: An update that solves 8 vulnerabilities and has one errata An update that solves 8 vulnerabilities and has one errata An update that solves 8 vulnerabilities and has one errata is now available. is now available.

EternalRomance Exploit Found in Bad Rabbit Ransomware
Ursnif Banking Trojan Spreading In Japan
5 paths to a career in cybersecurity

The U.S. electrical grid is in “imminent danger” from cyberattacks according to a report from the U.S. Energy Department released earlier this year. Such an attack would put much of the infrastructure that we rely on for public safety and basic services in jeopardy—electricity, water, healthcare, and communications systems, among others. Just last week, an […]

Smashing Security podcast #049: Hacking funeral homes, crypto mining websites, and careful with that hairspray
Bad Rabbit ransomware spreading like wildfire but there is a way out
BadRabbit runs out of steam – but be prepared for the next ransomware attack
Rule #1: If you want something to be private, don’t broadcast it (even blurred out!) on TV

LinuxSecurity.com: Fix CVE-2017-2888

Two Critical Vulnerabilities Found In Inmarsat’s SATCOM Systems
How to secure your router to prevent IoT threats?

The router is the first device that you must consider, since it not only controls the perimeter of your network, but all your traffic and information pass through it. The post How to secure your router to prevent IoT threats? appeared first on WeLiveSecurity

Increase your network security: Deploy a honeypot