Menu

Monthly Archives: May 2018

Hacker jailed for selling personal data on dark web

Grant West used popular food app Just Eat to gain access to thousands of emails and passwords The post Hacker jailed for selling personal data on dark web appeared first on WeLiveSecurity

FBI to World+Dog: Please, try turning it off and turning it back on
15 years prison for man who hired attackers to DDoS his ex-employer
Starbucks site slurped, Z-Wave locks clocked, mad Mac Monero mining malware and much more
Cola-Cola breach: ex-employee stole hard drive with 8,000 workers’ data
GDPR Oddsmakers: Who, Where, When Will Enforcement Hit First?
Xenotime Attack Group Expands Activity
Ghostery’s goofy GDPR gaffe – someone’s in trouble come Monday!

LinuxSecurity.com: CVE-2017-18248 It was found that by submitting a print job with an invalid username, the CUPS server can be crashed, when D-Bus support is enabled (which

FBI: Protect yourself from VPNFilter malware; reboot your router now

LinuxSecurity.com: Security fix for CVE-2018-10536 CVE-2018-10537 CVE-2018-10538 CVE-2018-10539 CVE-2018-10540

security update

New cryptojacking malware hits Mac devices
Hackers deface Airport screens in Iran with anti-government messages
Starbucks site slurped, Comcast keys clocked, mad Mac Monero mining malware and much more

LinuxSecurity.com: The gitlab security update announced as DSA-4206-1 caused regressions when creating merge requests (returning 500 Internal Server Errors) due to an issue in the patch to address CVE-2017-0920. Updated packages are now available to correct this issue.

Most Expensive Data Breaches Start with Third Parties: Report
Report: Hacker group behind Trisis Malware expanding Activity in Middle East

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Ming: CVE-2018-7866

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: Gabriel Corona discovered that xdg-utils, a set of tools for desktop environment integration, is vulnerable to argument injection attacks. If the environment variable BROWSER in the victim host has a “%s” and the victim opens a link crafted by an attacker with xdg-open, the malicious

Epyc fail? We can defeat AMD’s virtual machine encryption, say boffins

Type: Vulnerability. Adobe Acrobat and Reader are prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Adobe Acrobat and Reader are prone to an arbitrary code-execution vulnerability; fixes are available.

Millions of IoT Devices Vulnerable to Z-Wave Downgrade Attacks, Researchers Claim
Pet Trackers Open to MITM Attacks, Interception
Hundreds of Android devices shipped with pre-installed malware

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate
Bitcoin Gold loses over $18 million after hack attack
Why GDPR affects companies around the world (video)

Learn what businesses need to be mindful of with the new legislation The post Why GDPR affects companies around the world (video) appeared first on WeLiveSecurity

Attackers Cashing In On Cryptocurrency With Increased Scams
Amazon Comes Under Fire for Facial Recognition Platform
Schneider Electric Patches XXE Vulnerability In Software
James Comey: FBI Faces Deep Tech-Related Questions
Ahead of GDPR, Information Governance Comes into Its Own
VPNFilter Malware Infects 500k Routers Including Linksys, MikroTik, NETGEAR
Facebook 2FA no longer needs a phone number: here’s how to set it up
Pornhub’s VPNhub is a free VPN for everyone
Woman says Alexa recorded and shared the private conversation she was having with her husband

It’s every Amazon Alexa owner’s worst nightmare – your private conversations not just being listened to, but shared with random contacts without your knowledge. The post Woman says Alexa recorded and shared the private conversation she was having with her husband appeared first on WeLiveSecurity

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in denial of service, informations leaks or privilege escalation.

Facebook’s counterintuitive way to combat nonconsensual porn
Facebook refines 2FA setup, adds authenticator app support

Do try this at home! If you haven’t taken advantage of the extra protection that two-factor authentication offers, now is a great time to do so. And you don’t even need to hand over your phone number. The post Facebook refines 2FA setup, adds authenticator app support appeared first on WeLiveSecurity

Does your BMW need a security patch?

LinuxSecurity.com: An update that fixes 8 vulnerabilities is now available.

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

More Unsecure Wi-Fi and Phishing? Not So Flashy
UK: We’ll Return Fire Against Deadly State Cyber-Attacks
Trump’s blocking of Twitter users declared unconstitutional
BackSwap malware finds innovative ways to empty bank accounts

ESET researchers have discovered a piece of banking malware that employs a new technique to bypass dedicated browser protection measures The post BackSwap malware finds innovative ways to empty bank accounts appeared first on WeLiveSecurity

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code, denial of service or attacks on encrypted emails.

LinuxSecurity.com: The package thunderbird before version 52.8.0-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure, access restriction bypass, content spoofing and denial of service.

Reading Time: ~2 min.The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Comcast Router Bug Leaves Credentials Unsecured Researchers recently found a flaw in the Comcast […]

LinuxSecurity.com: This update provides mitigations for the Spectre v4 variant in x86-based micro processors. On Intel CPUs this requires updated microcode which is currently not released publicly (but your hardware vendor may have issued an update). For servers with AMD CPUs no microcode update is

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code, denial of service or attacks on encrypted emails.

Electron patches patch after security researcher bypassed said patch
Zimmerman and friends: ‘Are you listening? PGP is not broken’

security update

security update

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: This update upgrades Thunderbird to version 52.8.0. * Mozilla: Memory safety bugs fixed in Firefox 60 and Firefox ESR 52.8 (CVE-2018-5150) * Mozilla: Backport critical security fixes in Skia (CVE-2018-5183) * Mozilla: Use-after-free with SVG animations and clip paths (CVE-2018-5154) * Mozilla: Use-after-free with SVG animations and text paths (CVE-2018-5155) * Mozilla: Integer overflow […]

LinuxSecurity.com: This update upgrades Thunderbird to version 52.8.0. * Mozilla: Memory safety bugs fixed in Firefox 60 and Firefox ESR 52.8 (CVE-2018-5150) * Mozilla: Backport critical security fixes in Skia (CVE-2018-5183) * Mozilla: Use-after-free with SVG animations and clip paths (CVE-2018-5154) * Mozilla: Use-after-free with SVG animations and text paths (CVE-2018-5155) * Mozilla: Integer overflow […]