Menu

Monthly Archives: October 2017

Judge slaps down government’s dragnet trawl of 1.3m website users
Product Testing: Simulation, dissimulation, exasperation

True, most malware isn’t viral any more, but I don’t think that matters in this context. Nor, of course, is the EICAR file a virus, and doesn’t in any respect behave like one. The post Product Testing: Simulation, dissimulation, exasperation appeared first on WeLiveSecurity

Google embarrassed by fake adblocker that served ads
F-35 fighter jet secrets stolen from Australian defence contractor in ‘extensive’ hack
Former policewoman who stalked married man is jailed for 11 months
Centralized security in the cloud is the best security model
What is Grafeas? Better auditing for containers
DoubleLocker: Innovative Android Ransomware

DoubleLocker can change the device’s PIN, preventing victims from accessing their devices, and also encrypts the data it finds in them – a combination that has not been seen previously in the Android ecosystem. The post DoubleLocker: Innovative Android Ransomware appeared first on WeLiveSecurity

More and more websites are mining crypto-coins in your browser to pay their bills, line pockets
Equifax’s malvertising scare, Chromebook TPM RSA key panic, Cuban embassy sonic weapon heard at last – and more
Equifax website hit by malvertising – will the pain never end?

LinuxSecurity.com: An update is now available for Red Hat JBoss BPM Suite. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update is now available for Red Hat JBoss BRMS. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

security update

security update

Malware again checks into Hyatt’s hotels, again checks out months later with victims’ credit cards
DDoS attacks on Sweden’ Transport Agencies Delay Train Service
Locky Gets Updated to ‘Ykcol’, Part of Rapid-Fire Spam Campaigns

LinuxSecurity.com: An update for httpd is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: Security fix for CVE-2017-1495

Over the last year, a handful of cyberattacks have made news headlines and affected families. High-tech toy maker Spiral Toys was the victim of a particularly cunning hacking scheme. The maker of CloudPets stuffed animals reportedly exposed more than two million private voice recordings and the login credentials of 800,000 accounts. While these “smart toys” […]

Equifax Takes Down Compromised Page Redirecting to Adware Download
Equifax Website Hacked To Deliver Malware-bearing Flash Update
Mr Robot season 3 episode Eps3.0_Power-Saver-Mode.H – the security review
Can you trust that ‘Sign in to iTunes Store’ dialog on your iPhone?
Sensitive Data of Australian Navy’s Vessels and Fighter Jets stolen
Down the Rabbit Hole with a BLU Phone Infection
The Pirate Bay Caught Secretly Running Cryptocurrency Miner Again
US government calls for “responsible” – as in breakable – encryption
Are users “luzers” or is it time for an att-IT-ude change? [VIDEO]
10 layers of Linux container security
Apache Patches Optionsbleed Flaw in HTTP Server
Secure Messaging with Onion Services, a How-To
Microsoft Office 0-day headlines Patch Tuesday, update now!
UK Treasury Committee chairman calls on Equifax to answer for breach omnishambles

LinuxSecurity.com: An update for rh-mysql57-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Swiss banking software has Swiss cheese security, says Rapid7

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available. An update that fixes 9 vulnerabilities is now available. An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available. An update that fixes 9 vulnerabilities is now available. An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Smashing Security podcast #047: Kaspersky, AI, and a well-handled data breach
Dear America, best not share that password with your pals. Lots of love, the US Supremes
Millions of PornHub users affected by a year long malvertising campaign
Dumb bug of the week: Outlook staples your encrypted emails to, er, plaintext copies when sending messages

LinuxSecurity.com: These releases are about hardening `git shell` that is used on servers against an unsafe user input, which `git cvsserver` copes with poorly. From the release notes: * “git cvsserver” no longer is invoked by “git shell” by default, as it is old and largely unmaintained. * Various Perl scripts did not use safe_pipe_capture() […]

security update

security update

LinuxSecurity.com: Martin Thomson discovered that nss, the Mozilla Network Security Service library, is prone to a use-after-free vulnerability in the TLS 1.2 implementation when handshake hashes are generated. A remote attacker can take advantage of this flaw to cause an application using the nss

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Judge says US govt has ‘no right to rummage’ through anti-Trump protest website logs
Vendor BPC Banking Silent on Patching SQL Injection in SmartVista Ecommerce Software
iOS Flaw Makes Apple ID Passwords Prone to Phishing Attacks
Watch out for these high-pressure Apple malware scams
iOS Password Prompts are Ripe for Abuse

Risk Level: Very Low. Type: Trojan.

Israel hacked Kaspersky to inform US about Russia stealing NSA exploits
Equifax: Umm, actually hackers stole records of 15.2 million Brits, not 400,000
North Korean hackers allegedly probing US utilities for weaknesses
Equifax: up to 15 million more at risk
RubyGems Patches Remote Code Execution Vulnerability
What’s the fuzz about? Microsoft unveils its latest security tool
Medical Records and Sensitive Data of 150,000 US Patients Exposed
PureVPN Aided FBI to Track CyberStalker by Providing His Logs

LinuxSecurity.com: Several vulnerabilities were discovered in WordPress, a web blogging tool. They would allow remote attackers to exploit path-traversal issues, perform SQL injections and various cross-site scripting attacks.

Five cool things happening for National Cyber Security Awareness Month

National Cyber Security Awareness Month and its events have become top of mind for people and businesses in recent years, given the staggering number of recent data breaches and global ransomware attacks. The post Five cool things happening for National Cyber Security Awareness Month appeared first on WeLiveSecurity

US Treasury denies domestic spying
When Irish data’s leaking: Supermarket shoppers urged to check bank statements
Hackers steal $60 million from Taiwanese bank using bespoke malware

LinuxSecurity.com: An update that fixes 47 vulnerabilities is now available. An update that fixes 47 vulnerabilities is now available. An update that fixes 47 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 143 vulnerabilities is now available. An update that fixes 143 vulnerabilities is now available. An update that fixes 143 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 140 vulnerabilities is now available. An update that fixes 140 vulnerabilities is now available. An update that fixes 140 vulnerabilities is now available.

‘There has never been a right to absolute privacy’ – US deputy AG slams ‘warrant-proof’ crypto

LinuxSecurity.com: 6.9.9-15 —- Rebuilt for ImageMagick 6.9.9-13

LinuxSecurity.com: update to upstream release 0.2.9.12 (SECURITY) (#1494860)

LinuxSecurity.com: 6.9.9-15 —- Rebuilt for ImageMagick 6.9.9-13

‘Israel hacked Kaspersky and caught Russian spies using AV tool to harvest NSA exploits’
Hackers nick $60m from Taiwanese bank in tailored SWIFT attack

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

37K Chrome Users Tricked into Downloading Fake Adblock Plus Extension
It’s 2017… And Windows PCs can be pwned via DNS, webpages, Office docs, fonts – and some TPM keys are fscked too

LinuxSecurity.com: 6.9.9-15 —- Rebuilt for ImageMagick 6.9.9-13

Equifax: About those 400,000 UK records we lost? It’s now 15.2M. Yes, M for MEELLLION
Microsoft Patches Office Bug Actively Being Exploited
Apple’s iOS password prompts prime punters for phishing: Too easy now for apps to swipe secrets, dev warns
Internal Accenture Data, Customer Information Exposed in Public Amazon S3 Bucket
Massive Trove of Sensitive ‘Accenture’ Data Exposed Online
Microsoft Patches Critical Windows DNS Client Vulnerabilities
Porn Site Becomes Hub for Malvertising Campaigns