Menu

Monthly Archives: December 2017

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Vulnerability Found in Two Keyless Entry Locks
In-Store WiFi Provider Used Starbucks Website to Generate Monero Coins
Mailsploit: using emails to attack mail software

security update

security update

As 2017 comes to a close, we’re looking back at the 10 most significant (or simply the most devastating) cybersecurity stories of the year. Read through the list below to see which attacks, data breaches, and other events left a lasting impact on both the security industry and the global online community overall. Which story […]

Leftover Debugger Doubles as a Keylogger on Hundreds of HP Laptop Models
New Ruski hacker clan exposed: They’re called MoneyTaker, and they’re gonna take your money
Lifestyle pin-up site Pinterest: Hack attempts blamed on ‘credential stuffing’
Vietnamese man hacked Australian airport computers; stole security data
Banking malware on Google Play targets Polish banks

Besides delivering the promised functionalities, the malicious apps can display fake notifications and login forms seemingly coming from legitimate banking applications, harvest credentials entered into the fake forms, as well as intercept text messages to bypass SMS-based 2-factor authentication. The post Banking malware on Google Play targets Polish banks appeared first on WeLiveSecurity

Lil Bub, a special-needs celebrity cat, gets hacked
Is Bulgaria sitting on $3.5 BILLION worth of Bitcoin seized from criminals?
Blighty flogs Qatar a bunch of missiles and Typhoon fighter jets
Hackers’ delight: Mobile bank app security flaw could have smacked millions
Warrantless surveillance can continue until April, say Feds
Happy holidays, scam spotters!

Businesses are often sent fake invoices and waybills which install ransomware. Teach staff to avoid these. If questionable, ask your IT dept to look at it. E-cards have been a target in the past and may be used again in holiday-themed attacked. The post Happy holidays, scam spotters! appeared first on WeLiveSecurity

Language bugs infest downstream software, fuzzer finds
Leftover Synaptics debugger puts a keylogger on HP laptops
Dynamics 365 sandbox leaked TLS certificates

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

LinuxSecurity.com: It discovered that the Private Browsing mode in the Mozilla Firefox web browser allowed to fingerprint a user across multiple sessions via IndexedDB.

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code or denial of service. For the oldstable distribution (jessie), these problems have been fixed

Someone hacked this traffic sign with anti-Trump messages
A Trove of 1.4 Billion Clear Text Credentials File Found on Dark Web

LinuxSecurity.com: Update to latest upstream version.

LinuxSecurity.com: – fix NTLM buffer overflow via integer overflow (CVE-2017-8816) – fix FTP wildcard out of bounds read (CVE-2017-8817)

Update payment method: Netflix phishing scam steals login credentials

security update

security update

Researcher finds pre-installed keylogger in hundreds of HP laptops

LinuxSecurity.com: It was discovered that wireshark, a network protocol analyzer, contained several vulnerabilities in the dissectors for CIP Safety, IWARP_MPA, NetBIOS, Profinet I/O and AMQP, which result in denial of dervice or the execution of arbitrary code.

LinuxSecurity.com: An update that solves three vulnerabilities and has two An update that solves three vulnerabilities and has two An update that solves three vulnerabilities and has two fixes is now available. fixes is now available.

Security Vulnerabilities in Certificate Pinning
10 useful ncat (nc) Command Examples for Linux Systems
WordPress hit with keylogger, 5,400 sites infected

LinuxSecurity.com: This is a cumulative update to the Mozilla CA certificates trust list version 2.20, which has been published as part of Mozilla NSS 3.34.1. It also includes the changes that were previously released as version 2.18 as part of NSS 3.34. For additional details, please refer to the release notes of NSS 3.34.1 https://developer.mozilla.org/en-

LinuxSecurity.com: Upstream released new version. See https://collectd.org/news.shtml#news106 for the list of changes. Fixes CVE-2017-16820 (double free in snmp plugin)

LinuxSecurity.com: Patch CVE-2017-16927.

LinuxSecurity.com: New openssl packages are available for Slackware 14.2 and -current to fix security issues.

security update

Bitcoin investors targeted by Orcus RAT in new phishing campaign
Android Flaw Poisons Signed Apps with Malicious Code
Android flaw lets attack code slip into signed apps

security update

security update

Man who threw away $121m of Bitcoin wants to dig up landfill site
Apple Fixes Flaw Impacting HomeKit Devices
Phishing embraces HTTPS, hoping you’ll “check for the padlock”
UK.gov law resources now untrustworthy, according to browsers
StrongPity2 spyware replaces FinFisher in MitM campaign – ISP involved?

As we reported in September, in campaigns we detected in two different countries, man-in-the-middle attacks had been used to spread FinFisher, with the “man” in both cases most likely operating at the ISP level. The post StrongPity2 spyware replaces FinFisher in MitM campaign – ISP involved? appeared first on WeLiveSecurity

Four hours after being taught the rules of chess, AlphaZero became the strongest player the world has ever seen
Next-gen telco protocol Diameter has last-gen security – researchers

LinuxSecurity.com: An update that fixes 41 vulnerabilities is now available. An update that fixes 41 vulnerabilities is now available. An update that fixes 41 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 18 vulnerabilities is now available. An update that fixes 18 vulnerabilities is now available. An update that fixes 18 vulnerabilities is now available.

LinuxSecurity.com: An update that solves 5 vulnerabilities and has three fixes An update that solves 5 vulnerabilities and has three fixes An update that solves 5 vulnerabilities and has three fixes is now available. is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves 5 vulnerabilities and has three fixes An update that solves 5 vulnerabilities and has three fixes An update that solves 5 vulnerabilities and has three fixes is now available. is now available.

Google AI teaches itself ‘superhuman’ chess skills in four hours
Quantum Computing Is the Next Big Security Risk
The Most Exciting Linux Kernel Stories Of 2017
FCC Chair Ajit Pai Falsely Claims Killing Net Neutrality Will Help Sick and Disabled People
Sloppy coding + huge PSD2 changes = Lots of late nights for banking devs next year

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any questions? Just ask. PayPal Plagued by Phishing Emails Recently, many PayPal users have received emails about a fake transaction failure […]

LinuxSecurity.com: It was discovered that the TLS server in Erlang is vulnerable to an adaptive chosen ciphertext attack against RSA keys. For the oldstable distribution (jessie), this problem has been fixed

VMware and Carbon Black: you complete me, no you complete me

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: An update for rh-postgresql96-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for rh-postgresql95-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for rh-postgresql94-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for postgresql is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Uber disguised $100,000 hacker payoff as bug bounty, claims Reuters

LinuxSecurity.com: Several security issues were fixed in the kernel.

Apple fills the KRACK on iPhones – at last

security update

Security industry needs to be less trusting to get more secure
More than 5,000 WordPress websites plagued with Keylogger
Oops! This Android keyboard app accidentally leaked 31 million users’ personal details
Apple gets around to patching all the other High Sierra security holes
Banking Apps Found Vulnerable to MITM Attacks

LinuxSecurity.com: An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Man turns shed into top rated restaurant on TripAdvisor
Mr. Robot eps3.8_stage3.torrent – the security review
NiceHash cryptomining exchange hacked; everything’s gone

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Worm.

Process Doppelgänging attack affects all Windows version & evades AV products