Menu

Monthly Archives: January 2019

Google fined $57m for data protection violations
Hijacked Nest cam broadcasts bogus warning about incoming missiles
White-listing Azure cloud connections to grease your Office 365 wheels? About that…

LinuxSecurity.com: New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: Multiple vulnerabilities were found in the journald component of systemd which can lead to a crash or code execution. CVE-2018-16864

Build the wall… around your DNS settings, US govt IT staff urged by Homeland Security amid domain hijackings

LinuxSecurity.com: Fix for CVE-2019-5885 Upgrade notes available at https://github.com/matrix- org/synapse/blob/v0.34.0/UPGRADE.rst#upgrading-to-v0340 – Note this continues to use Python 2.

Plug in your iPhone, iPad, iPod, fire up the App Store: You have new Apple patches to install

LinuxSecurity.com: Several vulnerabilities have been resolved in libjpeg-turbo, Debian’s default JPEG implemenation. CVE-2016-3616

Wow, fancy that. Web ad giant Google to block ad-blockers in Chrome. For safety, apparently
Heads up: Debian’s package manager is APT for root-level malware injection… Fix out now to thwart MITM hijacks
En garde! ‘Cyber-war has begun’ – and France will hack first, its defence sec declares
How Web Apps Can Turn Browser Extensions Into Backdoors
French diplomat: Spies gonna spy – there aren’t any magical cyberspace laws that can prevent it
Google Fined $57M in Largest GDPR Slap Yet
Looks like Uncle Sam has pulled its finger out and appointed a Privacy Shield ombudsperson
Adobe Issues Unscheduled Updates for Experience Manager Platform
Google fined €50 million for violating EU data privacy rules

France’s data protection watchdog issues the first major penalty under the EU’s new privacy regime The post Google fined €50 million for violating EU data privacy rules appeared first on WeLiveSecurity

Stalk my pals on social media and you’ll know that the next words out of my mouth will be banana hammock
Email security does not end with your password

A strong password is a great start, but there are more ways to make sure that your email is as secure as possible The post Email security does not end with your password appeared first on WeLiveSecurity

Rogue websites can turn vulnerable browser extensions into back doors
Bicycle-riding hitman convicted with Garmin GPS watch location data
Get in the bin: Let’s Encrypt gives admins until February 13 to switch off TLS-SNI-01
WhatsApp fights the spread of deadly fake news with recipient limit

LinuxSecurity.com: It was discovered that aria2 (the lightweight command-line download utility) can store passed user credentials in a log file when using the –log option. This might allow local users to obtain sensitive information by reading this file.

DNC targeted by Russian hackers beyond 2018 midterms, it claims

security update

Twitter exposed some Android users’ protected tweets, and didn’t notice for over four years
Angry ex-employee blamed for hack of WordPress plugin developer, and email to customers warning of security hole
Twitter bug may have exposed private tweets of Android users for years

If you use Twitter for Android and want your tweets to be private, you may want to play safe and review your settings The post Twitter bug may have exposed private tweets of Android users for years appeared first on WeLiveSecurity

Is the Ten Year Challenge a Facebook scam???
Twitter bug exposed some Android private tweets to public view
Attackers used a LinkedIn job ad and Skype call to breach bank’s defences
Learn how Starbucks combats credential stuffing & account takeover (ATO)
State agency exposes 3TB of data, including FBI info and remote logins
Websites can steal browser data via extensions APIs
Tim Cook demands a way for users to delete their personal data

LinuxSecurity.com: admin: Prevent access if any authentication agent isn’t available

Twitter bug exposed private tweets of Android users to public for years
New ransomware steals PayPal data with phishing link in ransom note

LinuxSecurity.com: Fix for use after free in affile_dw_reap

LinuxSecurity.com: libssh versions 0.6 and above have an authentication bypass vulnerability in the server code. By presenting the server an SSH2_MSG_USERAUTH_SUCCESS message in place of the SSH2_MSG_USERAUTH_REQUEST message which the server would expect to initiate authentication, the attacker could successfully authentciate

Serious Security: What 2000 years of cryptography can teach us
DDoS sueball, felonious fonts, leaky Android file manager, blundering building security, etc etc
GDPR Suit Filed Against Amazon, Apple
2018’s Most Common Vulnerabilities Include Issues New and Old
How 2018 became Facebook’s worst year in privacy and security
North Korean Hackers Get Access To Chile’s ATM After Employee Falls For Fake Job Interview Over Skyp
The Iceman cometh, his smartwatch told the cops: Hitman jailed after gizmo links him to Brit gangland slayings

LinuxSecurity.com: **PHP version 7.2.14** (10 Jan 2019) **Core:** * Fixed bug php#77369 (memcpy with negative length via crafted DNS response). (Stas) * Fixed bug php#71041 (zend_signal_startup() needs ZEND_API). (Valentin V. Bartenev) * Fixed bug php#76046 (PHP generates “FE_FREE” opcode on the wrong line). (Nikita) **Date:** * Fixed bug php#77097 (DateTime::diff gives wrong diff when the

LinuxSecurity.com: Security fix for CVE-2018-20455 CVE-2018-20456 CVE-2018-20457 CVE-2018-20458 CVE-2018-20459 CVE-2018-20460 CVE-2018-20461 through rebase to 3.2.0

Google Play Removes Malicious Malware-Ridden Apps

security update

US midterms barely over when Russians came knocking on our servers (again), Democrats claim
Fallout EK Retools for a Fresh New 2019 Look
Ingenious! The Android malware which only triggers if you’re moving
Threatpost News Wrap Podcast For Jan. 18
Critical, Unpatched Cisco Flaw Leaves Small Business Networks Wide Open

Risk Level: Very Low. Type: Trojan.

Reading Time: ~2 min. Texas Town Brought to a Halt by Ransomware Several days ago the town of Del Rio, Texas, fell victim to a ransomware attack that knocked most of the town’s major systems offline. While the town’s IT department quickly worked to isolate the infection, remaining departments were forced to switch to hand-written […]

Get 3 Years of NordVPN Service for Just $2.99 Per Month – Deal Alert
Twitter Android Glitch Exposed Private Tweets for Years
Watch as hackers take over a construction crane
Malware can fully compromise building control systems
Cryptopia cryptocurrency exchange hacked; suffers “significant losses”
Bug bounty: Hack Tesla Model 3 to win your own Model 3
The Pirate Bay malware can empty your Cryptocurrency wallet
Microsoft partner portal ‘exposes ‘every’ support request filed worldwide’ today
Two men charged with hacking into SEC in stock-trading scheme

The hacking duo is believed to have exploited a software flaw and compromised several SEC workstations with malware in order to take early peeks at financial disclosures The post Two men charged with hacking into SEC in stock-trading scheme appeared first on WeLiveSecurity

Vast data-berg washes up 1.16 billion pwned records
Google cracks down on access to your Android phone and SMS data
Did you know you can see the ad boxes Facebook sorts us into?
The 773 Million Record “Collection #1” Data Breach
There’s a simple reason why your new smart TV was so affordable: It’s collecting and selling your da
15+ Password Cracking Techniques Used By Hackers 2019
YouTube bans dangerous and harmful pranks and challenges
I used to be a dull John Doe. Thanks to Huawei, I’m now James Bond!
Microsoft blue biz bug bounty bonanza beckons
Old bugs, new bugs, red bugs … yes, it’s Oracle mega-update day again
Got a Drupal-powered website? You may want to get patching now…
Twitter. Android. Private tweets. Pick two… Account bug unlocked padlocked accounts
Microsoft Launches Azure DevOps Bug Bounty Program
Apple CEO Demands Federal Data Privacy Legislation

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Top GP: Medical app Your.MD’s data security wasn’t my remit
Cyber-Jackpot: 773M Credentials Dumped on the Dark Web
773 million records with emails & plain text passwords leaked online
The Collection #1 data breach – what you need to do about it
773 million email IDs, 21 million passwords for anyone to see in massive data dump

The vast dossier of stolen login details appears to have been gathered from data stolen in many breaches The post 773 million email IDs, 21 million passwords for anyone to see in massive data dump appeared first on WeLiveSecurity

Microsoft font gives away forgery in bankruptcy case
Email crooks swindle woman out of $150K from home sale
Cryptomining Malware Uninstalls Cloud Security Products
Magecart hits hundreds of websites via ad supply chain hijack
Change your password! VoIP provider leaves huge database exposed online
New Year’s resolutions: Routing done right

As another thing to improve this year, you may want to route your focus on a device that is the nerve center of your network and, if poorly secured, the epicenter of much potential trouble The post New Year’s resolutions: Routing done right appeared first on WeLiveSecurity

Two charged with hacking company filings out of SEC’s EDGAR system