Menu

Monthly Archives: November 2017

Apple served with warrant for Texas mass killer’s iCloud data
Loake Shoes admits: We’ve fallen victim to cybercrims
Once more unto the breach: El Reg has a go at crisis management
Crypto-jackers enlist Google Tag Manager to smuggle alt-coin miners
Apple: Sure, we banned VPN iOS apps in China, but, um, er, art!
Uber Reveals 2016 Breach of 57 Million User Accounts

LinuxSecurity.com: Change default COPR URL route from http://copr.fedoraproject.org to https://copr.fedorainfracloud.org

LinuxSecurity.com: Fixes a command injection vulnerability (CVE-2008-7319)

Iranian military hacker fingered for ‘Game of p0wns’ HBO leak
Microsoft says Win 8/10’s weak randomisation is ‘working as intended’
Wait, did Oracle tip off world to Google’s creepy always-on location tracking in Android?
Uber suffered massive data breach, then paid hackers to keep quiet
Google collects Android location data even if location service is off
Uber: Hackers stole 57m passengers, drivers’ info. We also bribed the thieves $100k to STFU
Uber paid hackers $100,000 to keep data breach quiet
Sacramento Regional Transit System in California Held for $7,000 Ransom
Intel Patches CPU Bugs Impacting Millions of PCs, Servers
Ex-Facebook privacy manager dishes the dirt on your data
US Senate takes aim at “warrantless surveillance”
GitHub starts scanning millions of projects for insecure components
Hackers steal $30 million worth of cryptocurrency in Tether hack
New campaigns spread banking malware through Google Play

For a user, it can be difficult to figure out whether an app is malicious. First off it is always good only to install applications from the Google Play store, since most malware is still mainly spread through alternative stores. The post New campaigns spread banking malware through Google Play appeared first on WeLiveSecurity

Germany bans sale, distribution and possession of kids’ smartwatches
National Cyber Security Centre boss: For the love of $DEITY, use 2FA on your emails, peeps
Cybersecurity for journalists and the news media

In journalism, having good contacts is key and this is true when it comes to defending your digital assets. The following are some sources – of information and, possibly, assistance – that you might want to cultivate. The post Cybersecurity for journalists and the news media appeared first on WeLiveSecurity

Scammed via Western Union? Claim your share of a $586 million refund now!
Linus Torvalds: ‘I don’t trust security people to do sane things’
White House Releases New Charter for Using, Disclosing Security Vulnerabilities
Captain Crunch aka John Draper banned from DefCon for sexual misconduct
Only…zero days left until the holiday shopping season!

The holidays are a time when people purchase gifts for their friends, families, and yes, even for themselves. Increasingly, children are using and accessing more and more digital devices — making it important for everyone to work together to secure these devices. The post Only…zero days left until the holiday shopping season! appeared first on […]

Working remotely? It only takes a moment on a free WiFi connection for a hacker to access to your personal accounts. While complimentary WiFi is convenient, protecting your connection with a VPN is the best way stay safe on public networks, keeping your data and browsing history secure.   What is a VPN? VPN stands for […]

Vigilante or bug hunter?
Patch on way ‘this week’ for HP printer vulns

LinuxSecurity.com: New libtiff packages are available for Slackware 14.2 and -current to fix security issues.

Windows 8 broke Microsoft’s memory randomisation

security update

Intel finds critical holes in secret Management Engine hidden in tons of desktop, server chipsets
BankBot banking malware found in flashlight and solitaire apps
Cops jam a warrant into Apple to make it cough up Texas mass killer’s iPhone, iCloud files
US-CERT Warns of ASLR Implementation Flaw In Windows
It was El Reg wot won it: Bing banishes bogus Brit bank banner ad
Amazon Echo and Google Home patched against BlueBorne threat
US intelligence can’t break vulnerability hoarding habit
CENTCOM Says Massive Data Cache Found on Leaky Server is Benign
Germany slaps ban on kids’ smartwatches for being ‘secret spyware’
FCC: robocalls can go get BLOCKED
Android Flaw Lets Attackers Capture Screen and Record Audio
Android malware found in hundreds of music player apps on Play Store
Amazon to fix Key home security vulnerability
Kids’ smartwatches banned in Germany over spying concerns

German parents are being told to destroy smartwatches they have bought for their children after the country’s telecoms regulator put a blanket ban in place to prevent sale of the devices, amid growing privacy concerns. The post Kids’ smartwatches banned in Germany over spying concerns appeared first on WeLiveSecurity

Matrix Banker malware spreads to multiple industries | Salted Hash Ep 7
The First Threatpost Alumni Podcast
UK’s ICO issues stark reminder of backlash for privacy invasion

The Information Commissioner’s Office (ICO) in the United Kingdom has issued a stark reminder and straight-to-the-point warning for all employees who might be tempted to snoop on others’ personal data. The post UK’s ICO issues stark reminder of backlash for privacy invasion appeared first on WeLiveSecurity

LinuxSecurity.com: A security update for .NET Core on RHEL is now available. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Container ship loading plans are ‘easily hackable’
Is your business ready for the Holiday Season?

Unfortunately, as with every opportunity, there are people who want to benefit from your success without putting in the hard work. Cybercriminals will view the increase in traffic and spending as opportunities to make extra money. The post Is your business ready for the Holiday Season? appeared first on WeLiveSecurity

It’s 2017, and command injection is still the top threat to web apps
DNS resolver 9.9.9.9 will check requests against IBM threat database
F5 DROWNing, not waving, in crypto fail
User experience test tools: a privacy accident waiting to happen
Some ‘security people are f*cking morons’ says Linus Torvalds
A banking trojan that steals Gmail, Facebook, Twitter and Yahoo Password

LinuxSecurity.com: A use-after-free vulnerability was discovered in XML::LibXML, a Perl interface to the libxml2 library, allowing an attacker to execute arbitrary code by controlling the arguments to a replaceChild() call.

LinuxSecurity.com: Jakub Wilk reported a heap-based buffer overflow vulnerability in procmail’s formail utility when processing specially-crafted email headers. A remote attacker could use this flaw to cause formail to crash, resulting in a denial of service or data loss.

security update

security update

security update

YouTube terminated its own channel “Citizentube” for multiple or severe violations
Misconfigured Amazon S3 Buckets Exposed US Military’s Social Media Spying Campaign
Researchers demonstrate Amazon Key system can be hacked
Multiple Vulnerabilities in LibXL Library Open Door to RCE Attacks
Germany bans kids smartwatches, asks parents to destroy them

security update

security update

Massive US military social media spying archive left wide open in AWS S3 buckets
Amazon Promises Fix to Stop Key Service Hack
Skype faces fine after refusing to allow eavesdropping
Digital certs authority StartCom to shut up shop

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Twitter gets tough on white supremacists with new policy
For goodness sake, stop the plod using facial recog, London mayor told
McAfee’s ClickProtect Apparently Infected Devices with Banking Malware
Lloyds’ Avios Reward credit cardholders report fraudulent activity
Kaspersky Investigators Reveal How NSA Hacking Tools Were Stolen
Bug that deleted $300m could have been fixed months ago
KeePass – a password manager that’s cloud-less (but complex)
One-third of internet pounded by DoS attacks

Simple DoS attacks, which are a one-on-one affair, have been all but supplanted by DDoS attacks. The latter involve concerted campaigns from armies of devices conscripted into botnets which, as if lined up and marching in lockstep, aim to knock the unlucky target offline. The post One-third of internet pounded by DoS attacks appeared first […]

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. Brothers Printers Vulnerable to Major Exploit Researchers have discovered an exploit in several Brothers printer models […]

Fake news ‘as a service’ booming among cybercrooks

LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.

LinuxSecurity.com: New libplist packages are available for Slackware 14.2 and -current to fix security issues.

Mr. Robot eps3.5_kill-process.inc – the security review

LinuxSecurity.com: An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Kaspersky: Clumsy NSA leak snoop’s PC was packed with malware