Menu

Monthly Archives: January 2019

Facebook Boots Hundreds of Iran-Linked Accounts For Spreading Misinformation
TheMoon Rises Again, With a Botnet-as-a-Service Threat

Reading Time: ~5 min. This is the second of a three-part report on the state of three malware categories: miners, ransomware, and information stealers.  As noted in the last blog, mining malware is on a decline, partly due to turmoil affecting cryptocurrencies. Ransomware is also on a decline (albeit a slower one). These dips are at […]

security update

security update

security update

Prepare to Defend Your Network Against Swarm-as-a-Service
2019 Already Marred By Slew of Data Breach Incidents
Airbus Data Takes Flight; and Billions of Credentials Dumped on Dark Web
U.S. Government Goes After North Korea’s Joanap Botnet
Kwik-Fit hit by MOT fail, that’s Malware On Target
Japan to probe citizens’ IoT devices in the name of security

Smart devices were targeted by more than one-half of cyberattacks detected in the country in 2017 The post Japan to probe citizens’ IoT devices in the name of security appeared first on WeLiveSecurity

Hackers hit Airbus, steal personal details of employees
Texas lawyer suing Apple over FaceTime bug claims it was used to snoop on a meeting
Google Pulls Data-Chugging App From iOS Devices
Mac “CookieMiner” Malware Aims to Gobble Crypto Funds
Update now! Chrome and Firefox patch security flaws
14k HIV+ records leaked, Singapore says sorry
Personal data slurped in Airbus hack – but firm’s industrial smarts could be what crooks are after
Phone cloner gets 65 months in jail
Cybercrime black markets: Dark web services and their prices

A closer look at cybercrime as a service on the dark web The post Cybercrime black markets: Dark web services and their prices appeared first on WeLiveSecurity

LinuxSecurity.com: Several security issues were fixed in Avahi.

Apple kicks Facebook’s snoopy Research app out of the App Store

LinuxSecurity.com: The package ghostscript before version 9.26-2 is vulnerable to sandbox escape.

What’s Farsi for ‘as subtle as a nuke through a window’? Foreign diplomats in Iran hit by renewed Remexi nasty
The D in SystemD stands for Danger, Will Robinson! Defanged exploit code for security holes now out in the wild
Smashing Security #113: FaceTime, Facebook, faceplant
Team America tries to crash Little Rocket Man’s Joanap botnet from within, warns owners of infected boxes
Attackers Can Track Kids’ Locations via Connected Watches

security update

Furious Apple revokes Facebook’s enty app cert after Zuck’s crew abused it to slurp private data
Stealthy Malware Disguises Itself as a WordPress License Key
Apple Blasts Facebook Over Data-Sucking ‘Research’ App
‘We’re coming for you’, global police tell DDoS attack buyers

First closing in on operators, now on users, as the hunt continues and law enforcement in many countries is about to swoop on people who bought DDoS attacks on WebStresser The post ‘We’re coming for you’, global police tell DDoS attack buyers appeared first on WeLiveSecurity

Matrix under the microscope: what a niche ransomware can teach us
Researchers Allege ‘Systemic’ Privacy, Security Flaws in Popular IoT Devices
“Love you” malspam gets a makeover for massive Japan-targeted campaign

ESET researchers have detected a substantial new wave of the “Love you” malspam campaign, updated to target Japan and spread GandCrab 5.1 The post “Love you” malspam gets a makeover for massive Japan-targeted campaign appeared first on WeLiveSecurity

Exposed! Facebook pays teenagers to install app that harvests personal data

Reading Time: ~4 min. Like many technology companies, Webroot is constantly on the hunt for a diverse pool of engineering and technical cybersecurity talent. According to Jon Oltsik, senior principal analyst with Enterprise Security Group, a cybersecurity skills deficit holds the top position for problematic skills in ESG’s annual survey of IT professionals. In fact, the […]

Privilege escalation vulnerability uncovered in Microsoft Exchange
Firefox makes it easier for users to dodge ad-trackers
It’s mop-up time for WebStresser DDoS-for-hire users
Scammers steal social media videos to wring hearts and wallets

LinuxSecurity.com: New mozilla-firefox packages are available for 14.2 and -current to fix security issues.

LinuxSecurity.com: Security fix for CVE-2019-6706.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

You think election meddling is bad now? Buckle up for 2020, US intel chief tells Congress
And it’s go, go, go for class-action lawsuits against Equifax after 148m personal records spilled in that mega-hack
Japan to Hunt Down Citizens’ Insecure IoT Devices
2019 and Beyond: The (Expanded) RSAC Advisory Board Weighs in on What’s Next: Pt. 2
Judge! snuffs! Yahoo!’s attempt! to! settle! 2013! megahack! class-action!
Feds Dismantle Dark Web Credentials Market
Mozilla Firefox 65 Ups the Ante on Privacy with Anti-Tracking Efforts

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Apple takes Group FaceTime offline after discovery of spying bug

The company is rushing to fix a glitch that may let other iPhone users hear and see you – before you answer the call The post Apple takes Group FaceTime offline after discovery of spying bug appeared first on WeLiveSecurity

Hey boffin, take a walk on the wild side: Stuffy academics need to let out their inner black hat
Apple Disables Group FaceTime Following Major Privacy Glitch
Apple scrambles to fix FaceTime eavesdropping bug
Singapore fingers deported fraudster for leak of list of thousands of HIV+ people

Reading Time: ~4 min. It’ll cost you a buck. Just like everyone else’s. The use of a Social Security Number (SSN) as unique identifiers has long been a contentious subject. SSNs were never intended to be used for identification, and their ubiquitous abuse for identification and authentication has lead me to call them “Social Insecurity […]

Hear me out! Thousands tell UK taxman to wipe their voice IDs

Even so, the database has grown to seven million voiceprints amid a controversy that puts the spotlight on the privacy implications of the collection of biometric information The post Hear me out! Thousands tell UK taxman to wipe their voice IDs appeared first on WeLiveSecurity

Japanese government will try to hack its citizens’ IOT devices
Mozilla security policy cracks down on creepy web trackers, holds supercookies over fire
Facebook to tie together WhatsApp, Instagram and Facebook Messenger
Thieves’ names and descriptions made public on B&Q database
The race to lock down industrial control systems | Salted Hash Ep 44
Credential-stuffing attack prompts Dailymotion password reset
I helped catch Silk Road boss Ross Ulbricht: Undercover agent tells all
Did you know? Monday was Data Privacy Day. Now it’s Tuesday. Back to business as usual!
Q. What do you call an IT admin for 20-plus young children? A. A teacher
Apple races to fix FaceTime bug that lets you spy on someone *before* they pick up your call

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

PSA: Disable FaceTime. Miscreants can snoop on your iPhone, Mac mic before you pick up call

LinuxSecurity.com: Several issues in wireshark, a network traffic analyzer, have been found. Dissectors of – ISAKMP, a Internet Security Association and Key Management Protocol

2019 and Beyond: The (Expanded) RSAC Advisory Board Weighs in on What’s Next

Reading Time: ~4 min. This is the first of a three-part report on the state of three malware categories: miners, ransomware and information stealers. In Webroot’s 2018 mid-term threat report, we outlined how cryptomining, and particularly cryptojacking, had become popular criminal tactics over the first six months of last year. This relatively novel method of cybercrime […]

Dailymotion Fights Ongoing Credential-Stuffing Attack

Risk Level: Very Low. Type: Trojan.

Active Scans Target Vulnerable Cisco Routers for Remote Code-Execution
WordPress Users Urged to Delete Zero-Day-Ridden Plugin
Russia hit by new wave of ransomware spam

Among the increased number of malicious JavaScript email attachments observed in January 2019, ESET researchers have spotted a large wave of ransomware-spreading spam targeting Russian users The post Russia hit by new wave of ransomware spam appeared first on WeLiveSecurity

User of the world’s biggest DDoS-for-hire website? Police say they’re coming after you
How my Instagram account got hacked
How to protect yourself this Data Privacy Day
BGP secure routing experiment ends in online row
Twitter scammers jump in on real-time complaints to companies
Suspected GDPR violations prompt over 95,000 complaints

Eight months after the landmark rules came into effect, data released by the European Commission provides a glimpse into the law’s application The post Suspected GDPR violations prompt over 95,000 complaints appeared first on WeLiveSecurity

Even Microsoft can’t escape ‘reply all’ email storms
YouTube subscribers getting spammed by celebrity imposters