Menu

Monthly Archives: December 2017

LinuxSecurity.com: An update that contains security fixes can now be installed. An update that contains security fixes can now be installed. An update that contains security fixes can now be installed.

security update

security update

security update

It’s Christmas, you have 9900 seconds of free time, how do you spend it?
Two arrested for Hacking DC Security Cameras Before Trump Inauguration
Toys: they’re getting smarter, but are they secure?
Nissan Canada Finance Notifies 1.1 Million of Data Breach
Hackers Spreading Digmine Monero Mining Malware via Facebook
Apple admits to slowing iPhones, you’re not imagining it
UK Foreign Sec Bojo to tell Kremlin: Stop your cyber shenanigans… or else!
Washington DC’s surveillance cameras hacked… to send spam
Merry Christmas, UK prosecutors: Here’s a special gift… a slap from the privacy watchdog
Data on 123 million US households exposed
Is Die Hard a Christmas movie? – the (not a) security review
Detecting ROBOT and other vulnerabilities using Red Hat testing tools.
Braking news: Nissan Canada hacked, up to 1.1m Canucks exposed
US capital’s surveillance cam network allegedly hijacked by Romanian ransomware suspects

LinuxSecurity.com: Hanno Boeck, Juraj Somorovsky and Craig Young discovered that the TLS implementation in Bouncy Castle is vulnerable to an adaptive chosen ciphertext attack against RSA keys.

Crooks Switch from Ransomware to Cryptocurrency Mining
Fake Bitcoin Wallet Apps Found on Google Play Store

LinuxSecurity.com: Several vulnerabilities were discovered in wordpress, a web blogging tool. The Common Vulnerabilities and Exposures project identifies the following issues.

LinuxSecurity.com: Gabriel Corona reported that sensible-browser from sensible-utils, a collection of small utilities used to sensibly select and spawn an appropriate browser, editor or pager, does not validate strings before launching the program specified by the BROWSER environment variable,

LinuxSecurity.com: Multiple vulnerabilities were discovered in Enigmail, an OpenPGP extension for Thunderbird, which could result in a loss of confidentiality, faked signatures, plain text leaks and denial of service. Additional information can be found under

security update

Get 3 Years of NordVPN Service for Just $2.75 Per Month – Holiday Deal Alert

LinuxSecurity.com: This is the One-Year notification for the retirement of Red Hat Enterprise Linux 6.7 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 6.7.

Google Play Boots 3 Fake Bitcoin Wallet Apps
What do techies really want for Christmas?

Risk Level: Very Low. Type: Trojan.

EtherDelta cryptocurrency exchange hacked in fake website scam
Adventures in cybersecurity research: risk, cultural theory, and the white male effect – part 2

Armed with the cultural theory described in part one as a possible explanation for why some people do not heed expert advice, we fielded a survey that queried US adults about their attitudes to 15 different technology hazards, including six that were cyber-related. The post Adventures in cybersecurity research: risk, cultural theory, and the white […]

5 Romanian ransomware distributors arrested after police raid
WordPress Captcha Plugin Contains Backdoor- 300,000 Websites at Risk
Facebook fights imposter accounts with facial recognition
Sednit update: How Fancy Bear Spent the Year

Over the past few years the Sednit group has used various techniques to deploy their various components on targets computers. The attack usually starts with an email containing either a malicious link or malicious attachment. The post Sednit update: How Fancy Bear Spent the Year appeared first on WeLiveSecurity

Smashing Security podcast #058: Face ID, Firefox, and Windows SNAFUs, plus Bitcoin FOMO
Twitter just got more serious about two-factor authentication. Here’s how to better protect your account
Coinbase investigates insider trading after Bitcoin Cash price spike
How To Tell If Your Linux Server Has Been Compromised
Another Cyberattack Spotted Targeting Mideast Critical Infrastructure Organizations
Massive leak exposes data on 123 million US households
What does revoking Net Neutrality mean for security?

Imagine the scenario where an Internet Service Provider (ISP) allows a security company providing malware protection the option to pay for their traffic to be prioritized and a lower the priority level imposed on all other providers. The post What does revoking Net Neutrality mean for security? appeared first on WeLiveSecurity

How much will Britain’s next F-35s cost? Not telling, says MoD
Fooling Windows 10 facial authentication with a photo
Euro ransomware probe: Five Romanians cuffed
EMC admin? Plug this hole before the holidays
Infosec controls relaxed a little after latest Wassenaar meeting
Hackers leak personal videos of WWE Diva Paige

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: Francesco Sirocco discovered a flaw in otrs2, the Open Ticket Request System, which could result in session information disclosure when cookie support is disabled. A remote attacker can take advantage of this flaw to take over an agent’s session if the agent is tricked into clicking a

LinuxSecurity.com: Marcin Noga discovered two vulnerabilities in LibreOffice, which could result in the execution of arbitrary code if a malformed PPT or DOC document is opened.

LinuxSecurity.com: CVE-2017-17432 It was discovered that malformed jumbogram packets could result in denial of service against OpenAFS, an implementation of the Andrew

Sensitive Data of 123 Million American Households Exposed​

LinuxSecurity.com: Francesco Sirocco discovered a flaw in otrs2, the Open Ticket Request System, which could result in session information disclosure when cookie support is disabled. A remote attacker can take advantage of this flaw to take over an agent’s session if the agent is tricked into clicking a

CHM Help Files Deliver Brazilian Banking Trojan

LinuxSecurity.com: An update that solves 32 vulnerabilities and has one errata An update that solves 32 vulnerabilities and has one errata An update that solves 32 vulnerabilities and has one errata is now available. is now available.

LinuxSecurity.com: An update that fixes 26 vulnerabilities is now available. An update that fixes 26 vulnerabilities is now available. An update that fixes 26 vulnerabilities is now available.

Once your home WiFi network is up and running and your family’s devices are connected, it’s normal to turn a blind eye to your router. After all, it’s mostly out of sight and out of mind. Unfortunately, that small, seemingly harmless box isn’t as secure as you may think. Your router is your gateway to […]

Teen sentenced for vDOS rampage
New York to crack open its code, looking for bias
New Cryptocurrency Mining Scheme Uses NSA Exploits EternalBlue & EternalSynergy
UK teen dodges jail time for role in DDoSes on Natwest, Amazon and more
AnubisSpy Malware: Stealing photos, videos & spying on Android users
Windows 10 password manager bug is hiding good news
WhatsApp and Facebook told to stop sharing data
Bolt Will Tackle Thunderbolt 3 Security on Linux
Linux Privilege Escalation – Tradecraft Security Weekly

LinuxSecurity.com: New ruby packages are available for Slackware 14.2 and -current to fix a security issue.

Ghostery, uBlock lead the anti-track pack
Windows 10 Hello face recognition can be fooled with photos
WordPress captcha plugin on 300,000 sites had a sneaky backdoor
Youbit Bitcoin exchange quits operation after 2 hacks in 8 months
U.S. Government Blames North Korea for WannaCry
Happy holidays – and don’t get scammed! [VIDEO]

Risk Level: Very Low. Type: Trojan.

LinkedIn accused of chilling access to information online
Adventures in cybersecurity research: risk, cultural theory, and the white male effect – part 1

Again and again we have seen security breaches occur because people did not heed advice that we and other people with expertise in security have been disseminating for years, advice about secure system design, secure system operation, and appropriate security strategy. The post Adventures in cybersecurity research: risk, cultural theory, and the white male effect […]

TalkTalk banbans TeamTeamviewerviewer againagain
GPS is off so you can’t be tracked, right? Wrong
Project Zero Chains Bugs for ‘aPAColypse Now’ Attack on Windows 10
New Android Malware Loapi Attacks Phones in Five Different Ways
Foreign Office confirms WannaCry culprit: It woz the Norks wot done it
Facebook admits that social media can be bad for you
Why we should fight for Net Neutrality

Granting ISPs the right to shape traffic, allowing for some traffic to be prioritized due to a commercial agreement, may have a negative effect on the outcome of using the service for both the consumer and the company providing the service. The post Why we should fight for Net Neutrality appeared first on WeLiveSecurity

HMS Queen Elizabeth has sprung a leak and everyone’s all a-tizzy

LinuxSecurity.com: An update that fixes 15 vulnerabilities is now available. An update that fixes 15 vulnerabilities is now available. An update that fixes 15 vulnerabilities is now available.

LinuxSecurity.com: An update for rh-ruby24-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Android trojan has miner so aggressive it can bork your battery
Microsoft Word slams the door on DDEAUTO malware attacks
Alleged Uber black ops lawyer would rather not have his Xmas holiday ruined by Waymo, ta
Hackers using Google Adwords & Google Sites to spread malware

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

SCOLD WAR: Kaspersky drags Uncle Sam into court to battle AV ban

LinuxSecurity.com: Fix for CVE-2017-1000158

security update

security update

security update