Menu

Monthly Archives: November 2017

It’s 2017 and you can still pwn Android gear with Wi-Fi packets – so get patching now

LinuxSecurity.com: Several vulnerabilities have been discovered in the chromium web browser. In addition, this message serves as an annoucment that security support for chromium in the oldstable release (jessie), Debian 8, is now discontinued.

Let’s get ready to grumble! UFC secretly choke slams browsers with Monero miners
Comcast Internet service crippled; affecting users across US

security update

Hackers Leak Nude Photos of WWE Diva Maria Kanellis AGAIN
OpenSSL patches, Apple bug fixes, Hilton’s $700k hack bill, Kim Dotcom raid settlement, Signal desktop app, and more
Over a million Android users fooled by fake WhatsApp app in official Google Play Store
Equifax execs sold shares before mega-hack reveal. All above board – Equifax probe
Estonia government locks down ID smartcards: Refresh or else
Biggest Tor overhaul in a decade adds layers of security improvements
El Reg assesses crypto of UK banks: Who gets to wear the dunce cap?
US says it’s identified six Ruski officials as DNC hack suspects
Hackers tiptoe out, launch Silence trojan, quietly raid banks of meeelllions
Subscription disappointments keep FireEye in the red
FBI: Student wrestler grappled grades after choking passwords from PCs using a key logger
Virtually everyone in Malaysia pwned in telco, govt data hack spree
America’s 2020 Census systems are a $15bn cyber-security tire fire
US-CERT Warns of Crypto Bugs in IEEE Standard
Hole in Tor causes TorMoil, update now

Risk Level: Very Low.

VerticalScope hacked again; 2.7 million user accounts affected
Cisco Patches DoS Flaw in BGP over Ethernet VPN Implementation
Paradise Papers were not an inside job, says leaky offshore law firm
1M Downloads Later, Google Pulls Phony WhatsApp From Google Play
Student Arrested For Using Keylogger and Changing Grades 90 Times
Data Pours from Cloud—And ‘The Enemy is Us’
School cafeteria TV monitor plays porn leaving students baffled
ATM fees shake-up may push Britain towards cashless society
Meet Russian Twitter troll Jenna Abrams and her 2,752 friends
Businesses and GDPR: What they need to do to be compliant?

While this may sound daunting and the consequences of non-compliance are significant, it’s considered unlikely that regulators will make an example of small businesses that can demonstrate they have a plan and have attempted to comply fully with requirements. The post Businesses and GDPR: What they need to do to be compliant? appeared first on […]

ViaSat hops into bed with European Space Agency in €68m deal
Crumbs! Crunchyroll distributed malware for a couple of hours

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

DoS scum attacked one-third of the ‘net between 2015 and 2017

LinuxSecurity.com: This update fixes several vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or the execution of arbitrary code if malformed image files are processed.

Over 1 million Android users downloaded fake WhatsApp app
Turkish hackers deface Times of Israel website for Palestine
Hackers leak WhatsApp chat and private photos of WWE Diva Paige

security update

security update

User claims Facebook employees went through his file sent in private chat
Google Search Results Exploited to Distribute Zeus Panda Banking Trojan
Flaw in Tor Browser Leads to Leaking of Your Real IP Address
WAFNinja – Web Application Firewall Attack Tool – WAF Bypass
Unencrypted USB stick with 2.5GB of data detailing airport security found in street
Tor Browser Users Urged to Patch Critical ‘TorMoil’ Vulnerability

security update

LinuxSecurity.com: Multiple vulnerabilities have been discovered in OpenSSL, a Secure Sockets Layer toolkit. The Common Vulnerabilities and Exposures project identifies the following issues:

LinuxSecurity.com: Multiple vulnerabilities have been discovered in OpenSSL, a Secure Sockets Layer toolkit. The Common Vulnerabilities and Exposures project identifies the following issues:

security update

No Prison for Student who Developed Spam Botnet to Pay College Fee

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Irssi, a terminal based IRC client. The Common Vulnerabilities and Exposures project identifies the following problems:

Poisoned Search Results Deliver Banking Malware
Smart Lock and iCloud Keychain – password managers for the rest of us

LinuxSecurity.com: An update for liblouis is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for samba is now available for Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Mobile Pwn2Own: Hackers pwn iPhone, Huawei, Galaxy and Pixel Phone
Senators act to SAVE voting machines
Threatpost News Wrap Podcast for Nov. 3
“Silence” Malware Steals Your Cash Silently
2018 Malware Forecast: learning from the long summer of ransomware
Siemens Update Patches SIMATIC PCS 7 Bug in Some Versions
Would you like to get involved in cybersecurity? Take the test and discover your ideal job!

If you see yourself often being curious about the behavior of computer threats, maybe it’s time you consider getting involved in cybersecurity. The post Would you like to get involved in cybersecurity? Take the test and discover your ideal job! appeared first on WeLiveSecurity

Google bug tracker hole lets outsiders wriggle in

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. DoubleLocker Takes Android Ransomware to Next Level While the concept of ransomware is nothing new, DoubleLocker […]

If your websites use WordPress, put down that coffee and upgrade to 4.8.3.
Hackers abusing digital certs smuggle malware past security scanners
Official list of hacker and cyber crime movies
Introducing GoCrack: A Managed Password Cracking Tool
Google can read your corporate data. Are you OK with that?

LinuxSecurity.com: New openssl packages are available for Slackware 14.2 and -current to fix a security issue.

LinuxSecurity.com: New mariadb packages are available for Slackware 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: An update that solves 8 vulnerabilities and has two fixes An update that solves 8 vulnerabilities and has two fixes An update that solves 8 vulnerabilities and has two fixes is now available. is now available.

LinuxSecurity.com: Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in impersonation of Kerberos services, denial of service, sandbox bypass or HTTP header injection.

security update

LinuxSecurity.com: An update is now available for Red Hat JBoss Fuse and Red Hat JBoss A-MQ. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Web Server 2.1.2 for RHEL 6 and Red Hat JBoss Enterprise Web Server 2.1.2 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Web Server 2.1.2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update that solves one vulnerability and has four fixes An update that solves one vulnerability and has four fixes An update that solves one vulnerability and has four fixes is now available. is now available.

LinuxSecurity.com: An update that solves 36 vulnerabilities and has 22 fixes An update that solves 36 vulnerabilities and has 22 fixes An update that solves 36 vulnerabilities and has 22 fixes is now available. is now available.

iPhones get a KRACK patch and a Wi-Fi 0-day on the same day
Hackers Stole $150,000 from Cryptocurrency Wallets Using CryptoShuffler Trojan

LinuxSecurity.com: updated to aarch64-jdk8u151-b12 (from aarch64-port/jdk8u)

LinuxSecurity.com: 3.10.6 bz #1504256

LinuxSecurity.com: Security fix for CVE-2017-12629

Taking HTTPS Denial to an Absurd Level
Chain of 11 Bugs Takes Down Galaxy S8 at Mobile Pwn2Own
Researcher Identifies Bugs in Google’ Bug Tracker Program
How to wear your password on your sleeve, literally
Let’s call them… how two computer scientists made history

Can you imagine how Dr. Cohen actually created the virus or how Prof. Adleman came up with its name? The work of these men ended up inspiring a constant development of computer defense techniques, and constant research on computer threats The post Let’s call them… how two computer scientists made history appeared first on WeLiveSecurity

Devilish ONI Attacks in Japan Use Wiper to Cover Tracks
Learn how a research lab works

The story of viruses took place in a university laboratory and, keeping in mind the parallelism, we want to show you what is a malware research laboratory like and what exactly happens there. The post Learn how a research lab works appeared first on WeLiveSecurity

Mr. Robot eps3.3_metadata.par2 – the security review
Google’s bug-tracking system contained its own vulnerabilities, researcher discovers
Smashing Security podcast #050: MailChimp, Piers Morgan, and the Dark Overlord