Menu

Monthly Archives: December 2017

HMS Queen Lizzie formally joins the Royal Navy
US gov says it can break your encryption without a court order
Virtual keyboard app exposes personal data of 31 million users

The developer’s keyboard apps boast 40 million users across Android and iOS, but “only” Android users were affected by the security lapse. The post Virtual keyboard app exposes personal data of 31 million users appeared first on WeLiveSecurity

Meow! Facial recognition reaches pet doors
Toucan play that game: Talking toy bird hacked
Smashing Security podcast #056: Peeping Toms, prison hacks, and parliamentary passwords

LinuxSecurity.com: George Shuklin from servers.com discovered that Nova, a cloud computing fabric controller, did not correctly enforce its image- or hosts-filters. This allowed an authenticated user to bypass those filters by simply rebuilding an instance.

LinuxSecurity.com: Michael Eder and Thomas Kittel discovered that Heimdal, an implementation of Kerberos 5 that aims to be compatible with MIT Kerberos, did not correctly handle ASN.1 data. This would allow an unauthenticated remote attacker to cause a denial of service (crash of

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.4, Red Hat OpenShift Container Platform 3.5, and Red Hat OpenShift Container Platform 3.6. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

Cryptocurrency mining market NiceHash hacked; $67m might be stolen
NiceHash diced up by hackers, thousands of Bitcoin pilfered
Ashley Madison Found Leaking Private & Explicit Photos of Users

LinuxSecurity.com: An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now available. errata is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now available. errata is now available.

Google Patches Critical Encryption Bug Impacting Pixel, Nexus Phones
Net Neutrality comments “deeply corrupted” – NY Attorney General

LinuxSecurity.com: curl could be made to crash if it received specially crafted input.

LinuxSecurity.com: An update for liblouis is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: libxml2 could be made to crash if it opened a specially craftedfile.

As the holiday season kicks into high gear, keep in mind that shoppers are at an even higher risk of cyberattacks during this time of year. Salesforce projects that mobile users will account for 60 percent of traffic to retail sites around the globe this year. With the increased popularity of shopping on the go, […]

Questions linger as data breach trading site LeakBase disappears
Intel Management Engine pwned by buffer overflow
Former US State Department cyber man: We didn’t see the Russian threat coming
Satori botnet rears its head, exploiting IoT vulnerabilities
Cryptocurrency exchange Bitfinex plagued by DDoS attacks

The cast of characters behind the attacks, or their motives, are unclear. However, the onslaughts come at a time when the bitcoin price hits new highs, possibly triggering efforts on the part of cybercriminals to manipulate and cash in on the price. The post Cryptocurrency exchange Bitfinex plagued by DDoS attacks appeared first on WeLiveSecurity

TeamViewer Vulnerability Lets Attackers Take Full Control of PCs
Hacker who tried to free inmate early may soon join him in jail
Cayla doll too eavesdroppy to put under the Christmas tree, says France
Six things to consider before implementing an ISMS

These factors can be key to the success or failure of the ISMS implementation, due to the day-to-day activities in the organization and the resources required for system operation. The post Six things to consider before implementing an ISMS appeared first on WeLiveSecurity

Google and pals rush to repair Android dev tools, block backdoor risks
Build a Privacy-respecting and Threat-blocking DNS Server
DR.CHECKER – A Soundy Vulnerability Detection Tool for Linux Kernel Drivers
BoopSuite – A Suite of Tools for Wireless Auditing and Security Testing
Deception: Why It’s Not Just Another Honeypot
Naked rowers calendar hit by denial-of-service attack following Russia ‘ban’

LinuxSecurity.com: Several security issues were fixed in linux-firmware.

Mailsploit: It’s 2017, and you can spoof the ‘from’ in email to fool filters
Beware the IDEs of Android: three biggies have vulnerabilities

LinuxSecurity.com: An update that fixes 7 vulnerabilities is now available. An update that fixes 7 vulnerabilities is now available. An update that fixes 7 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

Keyboard app caught collecting users data after 31M records leaked online

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update that solves four vulnerabilities and has two An update that solves four vulnerabilities and has two An update that solves four vulnerabilities and has two fixes is now available. fixes is now available.

TeamViewer Rushes Fix for Permissions Bug
Data-slurping keyboard app makes Mongo mistake with user data

What if cybercriminals could generate money from victims without ever delivering malware to their systems? That’s exactly what a new phenomenon called “cryptojacking” entails, and it’s been gaining momentum since CoinHive first debuted the mining JavaScript a few months ago. The intended purpose: whenever a user visits a site that is running this script, the […]

Authorities dismantle Andromeda Botnet that infected millions of devices
Developers Targeted in ‘ParseDroid’ PoC Attack

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Politicians boast about sharing passwords, bask in blissful ignorance
High schooler hacks his way to a higher GPA
Brit bank Barclays’ Kaspersky Lab diss: It’s cyber balkanisation, hiss infosec bods
ISF predicts increasing impact of data breaches next year

The association expects the increased costs incurred in security breaches to come both from traditional areas, such as network cleanup and customer notification, and newer areas such as litigation. The post ISF predicts increasing impact of data breaches next year appeared first on WeLiveSecurity

Facebook brings Messenger to kids as young as 6
Once again, UK doesn’t rule out buying F-35A fighter jets
PayPal’s TIO Networks breached; PII of 1.6 million users affected
How a hack almost sprung a prisoner out of jail
Modern-day ‘Ferris Bueller’ hacks school, changes grades, applies to Ivy League colleges
DJI drones likely spying for China, claims leaked intelligence bulletin
Turns out Leakbase can keep a secret: It has shut down with zero info
Google prepares 47 Android bug fixes, ten of them rated Critical

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Infosys names a new CEO: welcome to the hot-seat Salil S. Parekh
Dentist-turned bug-biter given a taste of freedom

LinuxSecurity.com: An update for sssd is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Man hacks prison computers & alters records for pal’s early release
International team takes down virus-spewing Andromeda botnet
SEC’s cyber-cops cyber-file cyber-first cyber-fraud cyber-charges

LinuxSecurity.com: This is the final notification for the retirement of Red Hat Enterprise Linux 7.2 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 7.2.

Malware display fake BSOD to sell phony Windows anti-virus for $25

LinuxSecurity.com: Security fix for CVE-2017-1000158

Smile, you’re on hidden webcam Airbnb TV!
Prison hacker who tried to free friend now likely to join him inside
Google Cracks Down On Nosy Android Apps

security update

LinuxSecurity.com: Update to latest releases

LinuxSecurity.com: Update to latest releases

ESET helps law enforcement worldwide to disrupt Gamarue botnet

Throughout its monitoring of the threat, ESET found dozens of C&C servers every month. The bulk of ESET’s research was conducted late last year, with the peak of Wauchos’s activity going back approximately to that time. The post ESET helps law enforcement worldwide to disrupt Gamarue botnet appeared first on WeLiveSecurity

ESET takes part in global operation to disrupt Gamarue

Wauchos is an extensible bot that allows its owner to create and use custom plugins. However, there are some plugins that are widely available and that are used by many different botnets. The post ESET takes part in global operation to disrupt Gamarue appeared first on WeLiveSecurity

PayPal’s TIO Networks breach affects millions of customers
Ursnif Trojan Adopts New Code Injection Technique
Man blocks employer’s tracking with chip packet, plays 140 rounds of golf
Data Breach Index Website “Leakbase” Shut Down
Creepy Cayla doll violates liberté publique, screams French data protection agency
Office 365 phishing examples | Salted Hash Ep 10
Damian Green: Not only my workstation – mystery pr0n all over Parliamentary PCs
Proposed law would jail execs who fail to report data breaches
Brit MP Dorries: I gave my staff the, um, green light to use my login
The lax computer security of British MPs – as detailed in their own tweets
Google to crack down on apps that snoop
PayPal paid $US233m for company that leaked 1.6 million records
Dirty COW redux: Linux devs patch botched patch for 2016 mess

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

RSA coughs to critical-rated bug in its authentication SDK

LinuxSecurity.com: Update to the latest releases

LinuxSecurity.com: Update to the latest releases

UK government bans all Russian anti-virus software from Secret-rated systems
A Tricky PayPal Phishing Scam That Comes From Official PayPal Email