Menu

Monthly Archives: February 2018

Open source turns 20 years old, looks to attract normal people
Think you have a tracker on your phone? Learn how to make your device more resilient

While it certainly doesn’t hurt to ask for help from local law enforcement, know that even major cities may not have the expertise or the bandwidth to investigate compromised mobile devices. The most important objective is to take steps to make sure you’re safe. Ask for help, but do not wait for others to help […]

LinuxSecurity.com: Security fix for CVE-2017-17969 (from Debian)

LinuxSecurity.com: This is a security fix release that fixes a sandbox escape in the flatpak dbus proxy. This issue was found by Gabriel Campana of The Google Security Team. Major changes in 0.10.3 * Fix dbus proxy vulnerability in authentication phase * Make permission handling ignore unknown permissions for forwards compatibility * Removed incorrect error […]

LinuxSecurity.com: ClamAV 0.99.3 recommended for all ClamAV users. Please see details below: 1. ClamAV UAF (use-after-free) Vulnerabilities (CVE-2017-12374) ————————————————————— The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could

Safer Internet Day: 3 things your social networks can do for you
Safer Internet Day: 3 things you can do for your social networks
Cops find ATM spewing cash, car with dodgy plates, stack of $20 bills and hacking kit inside
X.509 metadata can carry information through the firewall
T-Mobile US let hackers nick my phone number, drain my crypto-wallets, cries man who lost $20k
Grammarly user? Patch now to stop crooks stealing all your data…
Grammarly Patches Chrome Extension Bug That Exposed Users’ Docs
Authorities shut down Luminosity RAT used by buyers in 78 countries

security update

Don’t worry, it’ll be all Reich! Googler saves Grammarly nazis from hacker invasion
Covert Data Channel in TLS Dodges Network Perimeter Protection
New Monero Crypto Mining Botnet Leverages Android Debugging Tool

LinuxSecurity.com: It was discovered that an XHR/AJAX call did not properly encode user input in the “dokuwiki” wiki platform. This resulted in a reflected file download vulnerability.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Lauri Love judgment: Extradition would be ‘oppressive’ and breach forum bar
GCHQ unit claims it has ‘objectively’ made the UK a less desirable target to cybercrims
Alleged hacker Lauri Love avoids US extradition: “Try him in England”
Lauri Love won’t be extradited to the United States to face hacking charges
British Hacker Lauri Love will not be extradited to the United States
Buying Bitcoin on your credit card? Not any more…
It’s time to say ‘Welcome to dumpsville Adobe Flash’, as new unpatched flaw exploited by criminals

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available.

What online sex toys can teach you about secure coding
Accused Brit hacker Lauri Love will NOT be extradited to America

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 6 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Vulnerabilities reached a historic peak in 2017

In 2017, the number of vulnerabilities smashed records set in previous years. According to CVE Details, more than 14,600 vulnerabilities were reported in 2017, compared to 6447 in 2016. The post Vulnerabilities reached a historic peak in 2017 appeared first on WeLiveSecurity

Russian-monitoring Shetlands radar station was nearly sold off
Knock, knock. Who’s there? Another Amazon Key door-lock hack

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

LinuxSecurity.com: ‘landave’ discovered a heap-based buffer overflow vulnerability in the NCompress::NShrink::CDecoder::CodeReal method in p7zip, a 7zr file archiver with high compression ratio. A remote attacker can take advantage of this flaw to cause a denial-of-service or, potentially the

LinuxSecurity.com: New php packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Internet Crime Complaint Center Impersonated for Malware & Phishing Scam
BeeToken’s ICO Hit by Phishing Scam; $1M worth of Ethereum Stolen
Spectre shenanigans, Nork hackers upgrade, bad WD drives and more
Japanese boy arrested for developing cryptocurrency stealing malware
JenX Botnet Has Grand Theft Auto Hook
New Western Digital My Cloud Bugs Give Local Attackers Root on NAS Devices
139 Malware Samples Identified that Exploit Meltdown & Spectre Flaws
Adobe warns of Flash zero-day, patch to come next week
Get 3 Years of NordVPN Service for Just $2.75 Per Month

The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Multiple Dutch Banks Fall Victim to Week-long Cyberattack String Over the last week, several of the largest […]

Bluetooth ‘Panty Buster’ smart mock-cock fails penetration test
Fileless WannaMine Cryptojacking Malware Using NSA Exploit
On the NHS tech team? Weep at ugly WannaCry post-mortem, smile as Health dept outlines plan
California says no, you can’t cover your license plate
Critical Infrastructure More Vulnerable Than Ever Before
GDPR: These are the organisations which are least prepared
Meltdown-Spectre: Malware is already being tested by attackers
A giant botnet is forcing Windows servers to mine cryptocurrency
What is microsegmentation? How getting granular improves network security
How to eliminate the default route for greater security
Deepfakes AI porn GIFs purged from Gfycat platform
Smart, Smarter… Dumbest…

While the evolution of new smartphones creates more possibilities for the user, these new devices also creates more possibilities for hackers. The post Smart, Smarter… Dumbest… appeared first on WeLiveSecurity

Venture into the security thickets at CyberThreat18
Hey, you know what the internet needs? Yup, more industrial control systems for kids to hack
New Monero mining malware infected 500K PCs by using 2 NSA exploits

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0262

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0262

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0260

Oracle MICROS POS Vulnerability Puts 300,000 Systems at Risk
Nork hackers exploit Flash bug to pwn South Koreans. And Adobe will deal with it next week
Over 700,000 bad apps removed from Google Play store in 2017
Ignore that FBI. We’re the real FBI, says the FBI that’s totally the FBI

LinuxSecurity.com: Several security issues were fixed in Dovecot.

Adobe Flash Player Zero-Day Spotted in the Wild

security update

LinuxSecurity.com: Dovecot could be made to crash if it received specially crafted input.

Crypto Miners May Be the ‘New Payload of Choice’ for Attackers
Samsung is working on producing cryptocurrency mining chips
3 of 5 Fortune 500 companies vulnerable due to ManageEngine flaws
Hospital MRI and CT scanners at risk of cyberattack
Massive Smominru Cryptocurrency Botnet Rakes In Millions
Smominru! Half a million PCs hit by cryptomining botnet
Smashing Security #063: Carole’s back!
Cryptomining – is it the new ransomware? [REPORT]
Facebook sued for not stopping killer who gave 4 minute notice

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Facebook bans cryptocurrency ads
Who can save us? It’s 2018 and some email is still sent as cleartext

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: Several vulnerabilities have been discovered in the chromium web browser. CVE-2017-15420

LinuxSecurity.com: An update that fixes 89 vulnerabilities is now available.

Good news, everyone: Ransomware declining. Bad news: Miscreants are turning to crypto-mining on infected PCs

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: curl could be made to expose sensitive information.