Menu

Monthly Archives: October 2017

Hackers hijack Coinhive cryptocurrency miner through an old password
Why Patching Software Is Hard: Organizational Challenges
Mr. Robot eps3.2_legacy.so – the security review
National Cybersecurity Awareness Month Twitter Chats part 4

In our previous blog entries we covered Simple Steps to Online Safety and Cybersecurity in the Workplace. In the blog today we will be talking about some of today’s predictions when it comes to the internet of tomorrow. The post National Cybersecurity Awareness Month Twitter Chats part 4 appeared first on WeLiveSecurity

security update

Creep signs plea deal for celebrity nudes hack
Hackers Prepping IOTroop Botnet with Exploits
Bad Rabbit Linked to ExPetr/Not Petya Attacks

LinuxSecurity.com: Multiple vulnerabilities have been found in MuPDF, a PDF file viewer, which may result in denial of service or the execution of arbitrary code. CVE-2017-14685, CVE-2017-14686, and CVE-2017-14687

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves four vulnerabilities and has one An update that solves four vulnerabilities and has one An update that solves four vulnerabilities and has one errata is now available. errata is now available.

Risk Level: Low. Type: Trojan, Worm.

Hackers steal compromising photos from plastic surgery clinic
Malvertising Campaign Redirects Browsers To Terror Exploit Kit
Canadian SMBs: How technology can help you stay energized

Canadian small and medium businesses (SMBs) use a multitude of skills and resources to continuously improve all aspects of their companies’ performance. The post Canadian SMBs: How technology can help you stay energized appeared first on WeLiveSecurity

DDoS Attack Takes Czech Election Sites Offline
4 extra-strength container security tools for Docker and Kubernetes

Risk Level: Low. Type: Trojan, Worm.

Risk Level: Low. Type: Trojan, Worm.

Risk Level: Very Low. Type: Trojan.

FIN7 Spear Phishing Attacks Now Aim At Avoiding Detection
Bad Rabbit ransomware outbreak

LinuxSecurity.com: Security fix for [CVE-2017-12173]

LinuxSecurity.com: Fix CVE-2017-2888

LinuxSecurity.com: This update adds support for the IBM858 codepage (RHBZ#1416405). It moves the `nss_compat` NSS service module to the main glibc package (RHBZ#1400538). As a security hardening measure, stdio streams are no longer flushed on process abort/assertion failure (RHBZ#1498880). `/var/db/Makefile` is now included in the `nss_db` package (RHBZ#1498900). Fixes installation related failures for IBM

BadRabbit Ransomware Attacks Hitting Russia, Ukraine
Bad Rabbit: Not-Petya is back with improved ransomware

A new ransomware outbreak today has hit some major infrastructure in Ukraine including Kiev metro. Here are some details about this new variant of Petya. The post Bad Rabbit: Not-Petya is back with improved ransomware appeared first on WeLiveSecurity

Whois Maintainer Accidentally Makes Password Hashes Available For Download
Fake Cryptocurrency Apps on Play Store Stealing User Data
How to get a job in cybersecurity
Hackers hit plastic surgery, threaten to release patient list and photographs
DUHK Attack Exposes Gaps in FIPS Certification
Reaper IoT botnet could be more devastating than Mirai
Kiev metro hit with a new variant of the infamous Diskcoder ransomware

Public sources have confirmed that computer systems in the Kiev Metro, Odessa naval port, Odessa airport, Ukrainian ministries of infrastructure and finance, and also a number of organizations in Russia are among the affected organizations. The post Kiev metro hit with a new variant of the infamous Diskcoder ransomware appeared first on WeLiveSecurity

Twitter reveals plan for tackling abuse. Again.
US-CERT: hackers are targeting our critical infrastructure
87% of banks don’t identify fraud in real time. Download the ‘2017 Faces of Fraud Survey’ report now!

LinuxSecurity.com: An update for java-1.6.0-sun is now available for Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

National Cybersecurity Awareness Month Twitter Chats part 3

In the first two parts of our series we have looked at the role an everyday internet user has in making the internet a safer place, and ID theft. This time around we focus on the role everyone has when it comes to cybersecurity best practices in the workplace. The post National Cybersecurity Awareness Month […]

LinuxSecurity.com: An update for httpd24, httpd24-curl, httpd24-httpd, httpd24-mod_auth_kerb, and httpd24-nghttp2 is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: New curl packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Reaper malware outshines Mirai; hits millions of IoT devices worldwide
Microsoft’ New Feature to Protect Windows 10 from Ransomware
Just say “No!” – how to stop the DDE email attack [VIDEO]
Facebook security chief stands by “college campus” comments

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Latest Sofacy Campaign Targeting Security Researchers
DHS Alert on Dragonfly APT Contains IOCs, Rules Likely to Trigger False Positives
FBI failed to break into nearly 7000 mobiles due to encryption
Fake cryptocurrency trading apps on Google Play

With all the hype around cryptocurrencies, cybercriminals are trying to grab whatever new opportunity they can – be it hijacking users’ computing power to mine cryptocurrencies via browsers or by compromising unpatched machines, or various scam schemes utilizing phishing websites and fake apps. The post Fake cryptocurrency trading apps on Google Play appeared first on […]

Google: This surge in Chrome HTTPS traffic shows how much safer you now are online
Hackers target security researchers with malware-laden document
Microsoft tears into Chrome security as patching feud continues

LinuxSecurity.com: An update for rh-nodejs4, rh-nodejs4-node-gyp, and rh-nodejs4-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Multiple vulnerabilities have been found in Dnsmasq, the worst of which may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in OpenJPEG, the worst of which may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in the PCRE Library, the worst of which may allow remote attackers to cause a Denial of Service condition. [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Go, the worst of which may result in the execution of arbitrary commands.

TODAY IS 22nd Oct 2017, AND IT’S CAPS LOCK DAY
US warns of ongoing attacks on energy firms and critical infrastructure
Office DDE attack works in Outlook too – here’s what to do

security update

Found a flaw in a popular Android app? Google might give you $1000
New Magniber Ransomware Targets South Korea, Asia Pacific
Your Browser Could Be Mining Cryptocurrency For a Stranger

LinuxSecurity.com: An update that solves 8 vulnerabilities and has three fixes An update that solves 8 vulnerabilities and has three fixes An update that solves 8 vulnerabilities and has three fixes is now available. is now available.

A plethora of patches, Kaspersky hits back, new hope for Wannacry Brit hero – and more
Hackers infect Mac users with Proton malware using Elmedia Player

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that solves 8 vulnerabilities and has one errata An update that solves 8 vulnerabilities and has one errata An update that solves 8 vulnerabilities and has one errata is now available. is now available.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 8 vulnerabilities is now available. An update that fixes 8 vulnerabilities is now available. An update that fixes 8 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

security update

security update

LinuxSecurity.com: Two unspecified vulnerabilities were discovered in OpenJFX, a rich client application platform for Java. For the stable distribution (stretch), these problems have been fixed in

Malware hidden in vid app is so nasty, victims should wipe their Macs
Hack-back bill would legalize companies hacking their attackers
‘IOTroop’ Botnet Could Dwarf Mirai in Size and Devastation, Says Researcher

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.58, which includes additional changes, such as performance improvements, bug fixes, new features, and possibly incompatible

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

What’s coming next in the world of malware? [VIDEO]
Google’s Advanced Protection Program: extra security at a cost
Google might block embedded cryptocurrency mining with new Chrome feature
Necurs-Based DDE Attacks Now Spreading Locky Ransomware
Canada’s Spy Agency Releases its Cyber-Defense Tool for Public
5 ways to do 15 minutes of cybersecurity without a computer
Threatpost News Wrap, Oct. 20, 2017