Menu

Monthly Archives: November 2017

Experts share perspective on the state of journalists’ cybersafety

These days, journalists and publishers are increasingly concerned about protecting themselves, their work, and their sources. Rightfully so, for we live in a time when nearly every aspect of publishing occurs online. The post Experts share perspective on the state of journalists’ cybersafety appeared first on WeLiveSecurity

WikiLeaks drama alert: CIA forged digital certs imitating Kaspersky Lab
How Twitter outrage hatches in tiny fringe groups on 4chan and Reddit
What to consider when deploying a next-generation firewall
Fighting persistent malware with a UEFI scanner

The biggest news in malware so far this year has been WannaCryptor a.k.a. WannaCry, and one reason that particular ransomware spread so fast was because it used a “top secret” exploit developed by the NSA, an agency known to have dabbled in UEFI compromise. The post Fighting persistent malware with a UEFI scanner appeared first […]

LinuxSecurity.com: An update that solves 29 vulnerabilities and has two fixes An update that solves 29 vulnerabilities and has two fixes An update that solves 29 vulnerabilities and has two fixes is now available. is now available.

LinuxSecurity.com: An update that solves one vulnerability and has 6 fixes is An update that solves one vulnerability and has 6 fixes is An update that solves one vulnerability and has 6 fixes is now available. now available.

LinuxSecurity.com: An update that solves 23 vulnerabilities and has 6 fixes is An update that solves 23 vulnerabilities and has 6 fixes is An update that solves 23 vulnerabilities and has 6 fixes is now available. now available.

LinuxSecurity.com: Multiple vulnerabilities have been found in libxml2, the worst of which could result in the execution of arbitrary code.

Judge bins sueball lobbed at Malwarebytes by rival antivirus maker for torpedoing its tool
WikiLeaks’ Vault 8 Leaks Show CIA Impersonated Kaspersky Lab

Risk Level: Very Low. Type: Trojan.

Learn client-server C programming – with this free tutorial from the CIA

LinuxSecurity.com: It was discovered that the pg_ctlcluster, pg_createcluster and pg_upgradecluster commands handled symbolic links insecurely which could result in local denial of service by overwriting arbitrary files.

LinuxSecurity.com: Several vulnerabilities have been found in the PostgreSQL database system: CVE-2017-15098

LinuxSecurity.com: A vulnerabilitiy has been found in the PostgreSQL database system: Denial of service and potential memory disclosure in the json_populate_recordset() and jsonb_populate_recordset() functions.

US government seizes Texas gun mass murder to demand backdoors

security update

Hackers hired for year-long DDoS attack against former employer
Google just can not get rid of BankBot malware from Play Store
Eavesdropper Vulnerability Exposes Mobile Call, Text Data

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

Google Chrome will automatically block forced website redirects
$300m… deleted! How a tiny bug flushed away a fortune
Uni staffer’s health info blabbed in email list snafu
Microsoft Provides Guidance on Mitigating DDE Attacks
Windows Movie Maker Scam spreads massively due to high Google ranking

ESET detected a modified version of Windows Movie Maker that aims to collect money from unaware users. The spread has been boosted by SEO. The post Windows Movie Maker Scam spreads massively due to high Google ranking appeared first on WeLiveSecurity

Not even ordering pizza is safe from the browser crypto-mining scourge
Microsoft issues advisory to users after macro-less malware attacks
No jail time for botnet creator who promises to go straight
Mr. Robot eps3.4_runtime-err0r.r00 – the security review
Smashing Security podcast #051: Robots, romance, passwords, and CrunchyRoll
Evil pixels: researcher demos data-theft over screen-share protocols
Microsoft pals up with partners for threat-hunting
Brit moron tried buying a car bomb on dark web, posted it to his address. Now he’s screwed
Intel’s management engine – in most CPUs since 2008 – can be p0wned over USB
Quantum computers could crack Bitcoin, but fixes are available now

Conventional wisdom about passwords is shifting, as they are increasingly seen as a less-than-ideal security measure for securing digital accounts. Even the recommended rules for creating strong passwords were recently thrown out the window. Average users are just too unreliable to regularly create secure passwords that are different across all accounts, so using technology to […]

security update

Risk Level: Very Low.

LinuxSecurity.com: Update to ansible 2.4.1.0 with various bugfixes. See https://github.com/ansible/ansible/blob/stable-2.4/CHANGELOG.md for a full list of changes.

LinuxSecurity.com: Update to ansible 2.4.1.0 with various bugfixes. See https://github.com/ansible/ansible/blob/stable-2.4/CHANGELOG.md for a full list of changes.

LinuxSecurity.com: It was discovered that libpam4j, a Java library wrapper for the integration of PAM did not call pam_acct_mgmt() during authentication. As such a user who has a valid password, but a deactivated or disabled account could still log in.

A tricky Netflix phishing scam users should be aware of
Marissa! Mayer! pulled! out! of! retirement! to! explain! Yahoo! hack! to! Senators!

LinuxSecurity.com: Marcin Noga discovered two vulnerabilities in LibreOffice, which could result in the execution of arbitrary code if a malformed PPT or DOC document is opened.

IoT is Insecure, Get Over It! Say Researchers

security update

security update

A Dark Web hacker is offering services to track anyone anywhere
Is Wi-Fi still safe to use? [VIDEO]
Facebook and Instagram Suffer Worldwide Outage
Hundreds of Millions in Digital Currency Remains Frozen
Hijackers deface 800 school websites with pro-Islamic State messages
Employee surveillance – how far is too far?

Risk Level: Very Low.

Google Patches KRACK Vulnerability in Android
Multi-Sig Wallets worth $300M Mistakenly Blocked by User
15% off APC 11-Outlet Surge Protector with USB Charging Ports and SurgeArrest – Deal Alert
Privacy Clouds Form Over Mantistek Gaming Keyboard
Five tips for keeping your database secure

In general, these are the most basic and essential precautions any systems manager must consider. However, depending on the system you want to protect, there are some additional issues to take into account. The post Five tips for keeping your database secure appeared first on WeLiveSecurity

Tor patches flaw that could expose MacOS and Linux IP addresses

LinuxSecurity.com: Several vulnerabilities have been discovered in the chromium browser. CVE-2017-15398

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

Not on Facebook? News flash: Facebook still knows about you

LinuxSecurity.com: An update that solves 33 vulnerabilities and has two fixes An update that solves 33 vulnerabilities and has two fixes An update that solves 33 vulnerabilities and has two fixes is now available. is now available.

Give Facebook your nude pics to tackle revenge porn
Is the 1.6TB Paradise Papers exposé a leak or a hack?
Credential-stuffing defence tech aims to defuse password leaks
Where hackers haven’t directly influenced polls, they’ve undermined our faith in democracy
SSL spy boxes on your network getting you down? But wait, here’s an IETF draft to fix that
You know what’s coming next: FBI is upset it can’t get into Texas church gunman’s smartphone

security update

Risk Level: Very Low.

Chinese Keyboard Developer Spies on User Through Built-in Keylogger
KRACK whacked, media playback holes packed, other bugs go splat in Android patch pact
Sick of Twitter’s 140-character limit? These guys gave themselves 30,000!
Don’t worry about those 40 Linux USB security holes. That’s not a typo
Texas Shooter’s Phone Encrypted

security update

Parity calamity! Wallet code bug destroys $280 MEEELLION in Ethereum
Hackers can conduct DoS attacks Using Flaw in Brother Printers
Assessing Weaknesses in Public Key Infrastructure
Mirai, Mirai, pwn them all, who’s the greatest botnet on the whole?
Send Your Nude Pics to Facebook to Prevent Revenge Porn
Marcher Android Banking Trojan Combines 3 Threats Into 1 Scheme
Oh Brother: Hackers can crash your unpatched printers – researchers
Brother Printers Susceptible to Remote Denial of Service Attacks
Google’s Halloween lock-out caused by false positive
Blade Runner 2049: A reflection on our use of technology

At present, virtual assistants are a long way from the image depicted in Blade Runner 2049. However, we are seeing companies take major steps in this direction. We have Siri, Cortana, and Alexa, to name but a few. The post Blade Runner 2049: A reflection on our use of technology appeared first on WeLiveSecurity

2018 Malware Forecast: the onward march of Android malware
Hackers Poison Google Search Results to Deliver Zeus Panda
A draft US law to secure election computers that isn’t braindead. Well, I’m stunned! I gotta lie dow
Fake WhatsApp pulled from Google Play after 1m downloads
Can you see why this WhatsApp message can’t be trusted?
Apache OpenOffice: We’re OK with not being super cool… PS: Watch out for that Mac bug
Boffins tear into IEEE’s tissue-thin anti-hacker chip blueprint crypto

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves 12 vulnerabilities and has four fixes An update that solves 12 vulnerabilities and has four fixes An update that solves 12 vulnerabilities and has four fixes is now available. is now available.

LinuxSecurity.com: An update that solves 8 vulnerabilities and has two fixes An update that solves 8 vulnerabilities and has two fixes An update that solves 8 vulnerabilities and has two fixes is now available. is now available.