Menu

Monthly Archives: November 2017

ID theft puppet master convicted of huge tax refund scam
Privacy Pass protocol promises private perusing
Unsecure Server Exposed Private Data of Popular Ride-Hailing Service
Google researcher finds 79 Linux USB vulnerabilities
Facebook’s ex-president: we exploited “vulnerability in human psychology”
Estonia cuffs suspect, claims he’s a Russian ‘hacker spy’
Someone hacked N. Korean Radio Station to Play “The Final Countdown”
Apple iPhone X Face ID Fooled by a Mask
Americans’ unease about cybercrime towers over conventional crimes

The high level of fear of cybercrime dovetails with the self-reported rates of victimization, as 25% of the respondents reported that their personal information or that of their household member has been stolen by hackers over the past 12 months. The post Americans’ unease about cybercrime towers over conventional crimes appeared first on WeLiveSecurity

Linux 4.14 arrives and Linus says it should have fewer 0-days
Most UK law firms aren’t ready for GDPR, claims report
Shut the front door: Jewson ‘fesses up to data breach
Sure, Face ID is neat, but it cannot replace a good old fashioned passcode
Think the US is alone? 18 countries had their elections hacked last year
WikiLeaks is wiki-leaked. And it’s still not even a proper wiki anyway

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Media Player is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Word is prone to a memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

NSA rocked after The Shadow Brokers Breach
IDG Contributor Network: KPIs for managing and optimizing devsecops success
Thousand-dollar iPhone X’s Face ID wrecked by ‘$150 3D-printed mask’
Phishing Biggest Threat to Google Account Security
New IcedID Trojan Targets US Banks
You can soon securely unlock smartphone with your “body sweat”
FBI “should not be reluctant” to challenge encryption in court
Homeland Security Hackers Remotely Hack Boeing 757
The Daily Mail whisks up Kaspersky fears – but where’s the meat?
New Vulnerability Exploits Antivirus Programs to Install Malware
Transparency of machine-learning algorithms is a double-edged sword

Unless companies processing citizens’ personal data fully understand the reasoning behind the decisions made based on their machine-learning models, they will find themselves between a rock and a hard place. The post Transparency of machine-learning algorithms is a double-edged sword appeared first on WeLiveSecurity

Ransomware marketplaces and the future of malware | Salted Hash Ep 6
YouTube to crack down on inappropriate videos targeting kids
Stop your moaning, says maker of buggy Bluetooth sex toy

LinuxSecurity.com: An update for rh-eclipse46-jackson-databind is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-eclipse47-jackson-databind is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Ride-share upstart ‘Fasten’ revealed as Hive of insecurity

Risk Level: Very Low. Type: Trojan.

Amazon moves to stop S3 buckets leaking business data

LinuxSecurity.com: Multiple vulnerabilities have been found in eGroupWare, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability was discovered in VDE which may allow local users to gain root privileges.

CopperheadOS stops updates to thwart knock-off phone floggers

security update

All it took for researchers was a mask to bypass iPhone X Face ID

LinuxSecurity.com: An update that fixes 19 vulnerabilities is now available. An update that fixes 19 vulnerabilities is now available. An update that fixes 19 vulnerabilities is now available.

LinuxSecurity.com: This update includes a rebase from 8.0.46 up to 8.0.47 which resolves a single CVE along with various other bugs/features: rhbz#1497682 CVE-2017-12617 tomcat: Remote Code Execution bypass for CVE-2017-12615

Firefox to offer tracking protection for all in its next update

LinuxSecurity.com: This update fixes several vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or the execution of arbitrary code if malformed GIF, TTF, SVG, TIFF, PCX, JPG or SFW files

security update

Muslim Hacktivists Hack ISIS website; expose 20,000 subscribers list

LinuxSecurity.com: Multiple vulnerabilities have been found in Cacti, the worst of which could lead to the remote execution of arbitrary code.

Simple exploit can be used to disable Brother printers remotely
Someone Hacked Swedish Radio Station to Play Pro-ISIS Song
26,000 blockchain projects launched in 2016, 92 percent are now dead
Researchers find almost EVERY computer with an Intel Skylake and above CPU can be owned via USB
Vault 8: WikiLeaks Releases Source Code For Hive – CIA’s Malware Control System
Manic miners, hideous hackers, frightful flaws, vibrating mock cock app shock – and more

LinuxSecurity.com: 1.6, multiple security fixes.

LinuxSecurity.com: * Fix ppc64 KVM failure (bz #1501936) * CVE-2017-15038: 9p: information disclosure when reading extended attributes (bz #1499111) * CVE-2017-15268: potential memory exhaustion via websock connection to VNC (bz #1496882) —- qemu-pr-helper didn’t work due to a change in the libmultipath/libmpathpersist APIs exposed by device-mapper-multipath-devel. This has been fixed now. Other

LinuxSecurity.com: Security fix for CVE-2017-12629

LinuxSecurity.com: – Update to 1.1.26 – CVE-2017-15194 Release notes: https://www.cacti.net/release_notes.php?version=1.1.26

LinuxSecurity.com: For changes see: https://www.mozilla.org/en-US/thunderbird/52.4.0/releasenotes/

Parity’s $280m Ethereum wallet freeze was no accident: It was a HACK, claims angry upstart
Cyberhitmen hired for sustained DDoS attacks against mans ex-employer

security update

security update

security update

security update

How did someone hijack your Gmail? Phishing, keylogger or password reuse, we’re guessing

LinuxSecurity.com: Wen Bin discovered that bchunk, an application that converts a CD image in bin/cue format into a set of iso and cdr/wav tracks files, did not properly check its input. This would allow malicious users to crash the application or potentially execute arbitrary code.

Microsoft president says the world needs a digital Geneva Convention
The teen who bought a car bomb on the Dark Web
“Eavesdropper” Flaw Exposes Millions of Call, Texts and Recordings
AutoIt Scripting Used By Overlay Malware to Bypass AV Detection
Intel’ Management Engine Tech Just Got Exposed Through USB Ports

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. UK-Based Cryptocurrency Hit By Cyberattack Prior to the official launch of Electroneum, a UK-based cryptocurrency that […]

Latest Intelligence for October 2017
Symantec research shows users to be twice as likely to encounter threats through email as any other infection vector, and the spam rate declines slightly [...]
Threatpost News Wrap Podcast for Nov. 10
What do Microsoft’s highly secure Windows 10 device standards tell us?