Menu

Monthly Archives: February 2019

Reading Time: ~6 min. This is the third of a three-part report on the state of three malware categories: miners, ransomware and information stealers. Ransomware is any malware that holds your data ransom. These days it usually involves encrypting a victim’s data before asking for cash (typically cryptocurrency) to decrypt it. Ransomware ruled the malware world since […]

Surprise, surprise, yet another cryptocurrency creator collared, hit with $6 million fraud rap

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.

In the cloud, things aren’t always what they SIEM: Microsoft rolls out AI-driven Azure Sentinel

Reading Time: ~5 min. The landscape of digital security is rapidly shifting, and even the largest tech giants are scrambling to keep up with new data regulations and cybersecurity threats. Small to medium-sized businesses (SMBs) are often left out of these important conversations, leaving themselves — and their users — vulnerable. In an effort to […]

Qbot malware’s back, and latest strain relies on Visual Basic script to slip into target machines
Coinhive to Mine Its Last Monero in March
Coinhive, the in-browser cryptomining service beloved by hackers, is dead
A video about cybersecurity threats that doesn’t feature any computers

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

Coinhive cryptocurrency miner to call it a day next week

The service became notorious for its use by ne’er-do-wells looking to make a quick buck by hijacking the processing power of victim machines to generate virtual money The post Coinhive cryptocurrency miner to call it a day next week appeared first on WeLiveSecurity

LinuxSecurity.com: Several security issues were fixed in GD.

Cisco Fixes Critical Flaw in Wireless VPN, Firewall Routers
Thunderclap: Apple Macs at risk from malicious Thunderbolt peripherals
US House and Senate debate new data privacy law

LinuxSecurity.com: ultiple vulnerabilities have been discovered in SoX (Sound eXchange), a sound processing program: CVE-2017-15370

US pushed Russian troll factory offline during US midterm elections
Businesses warned of malware spread via LinkedIn job offers

LinuxSecurity.com: An update for java-11-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Several vulnerabilities were found in QEMU, a fast processor emulator: CVE-2018-12617

LinuxSecurity.com: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Smashing Security #117: SWATs on a plane

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Risk Level: Very Low. Type: Trojan.

Web hacker ‘Alfabeto Virtual’ thrown in the clink for 3 months by US judge who wanted to ‘send a message’
Intel: Let’s talk about SGX, baby. Let’s talk about 2U and me. Let’s talk about all the good things, and the bad…
Friendly reminder to Drupal admins: Secure your sh!t before latest RCE-holes get you

LinuxSecurity.com: An update that solves two vulnerabilities and has four fixes is now available.

Card-Skimming Scripts Hide Behind Google Analytics, Angular
Ring Doorbell Flaw Opens Door to Spying
Cisco Patches High-Severity Webex Vulnerability For Third Time
Thunderclap Flaws Shatter Peripheral Security

LinuxSecurity.com: An information leak issue was discovered in phpMyAdmin. An attacker can read any file on the server that the web server’s user can access. This is related to the mysql.allow_local_infile PHP

LinuxSecurity.com: A regression was introduced in the previous chromium security update. The browser would always crash when launched in headless mode. This update fixes this problem.

Running Elasticsearch 1.4.2 or earlier? There’s targeted malware going for your boxen
‘Highly critical’ bug exposes unpatched Drupal sites to attacks

Worse, attackers have already been spotted targeting the flaw to deliver cryptocurrency miners and other payloads The post ‘Highly critical’ bug exposes unpatched Drupal sites to attacks appeared first on WeLiveSecurity

Bronze Union APT Updates Remote Access Trojans in Fresh Wave of Attacks

LinuxSecurity.com: An update that solves 5 vulnerabilities and has 7 fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has 7 fixes is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

Nvidia patches eight security flaws in graphics products
Researchers break e-signatures in 22 common PDF viewers
Police bust their own radio shop manager for dodgy software updates
Millions of utilities customers’ passwords stored in plain text
How to spot if your password was stolen in a security breach

Following the revelation that a list containing millions of stolen usernames and passwords had appeared online, we tell you a few different ways to find out if your credentials were stolen in that—or any other—security breach The post How to spot if your password was stolen in a security breach appeared first on WeLiveSecurity

Protect you and your biz by learning the tricks of cyber criminals’ trade at SANS London in March
Ready for another fright? Spectre flaws in today’s computer chips can be exploited to hide, run stealthy malware

LinuxSecurity.com: New openssl packages are available for Slackware 14.2 to fix a security issue.

LinuxSecurity.com: Security fix for CVE-2018-16741,CVE-2018-16744,CVE-2018-16745

Thunder, thunder, thunder… Thunderclap: Feel the magic, hear the roar, macOS, Windows pwnage tools are loose
Up up and Huawei in my beautiful buffoon: Trump sparks panic by tying tech kit ban, charges to China trade negotiations
Latest 4G, 5G phone-location slurp attack is a doozy, but won’t Torpedo Average Joe or Jane
‘Cloudborne’ IaaS Attack Allows Persistent Backdoors in the Cloud

LinuxSecurity.com: The package logstash before version 6.6.1-1 is vulnerable to information disclosure.

LinuxSecurity.com: The package elasticsearch before version 6.6.1-1 is vulnerable to privilege escalation.

Harassment, hate and bile, suicide instructions for kids… anything else social media’s good at? Ah yes, cybercrime

LinuxSecurity.com: An update for polkit is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

6 Pieces of Tech Every Office Needs
High-Severity SHAREit App Flaws Open Files for the Taking

LinuxSecurity.com: LDB could be made to crash if it received specially crafted network traffic.

LinuxSecurity.com: USN-3866-2 introduced a regression in Ghostscript.

LinuxSecurity.com: GNOME Keyring could be made to expose sensitive information.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

Critical WinRAR Flaw Found Actively Being Exploited
Google aims for password-free app and site logins on Android

With FIDO2 certification for Android, Google is setting the stage for password-less app and website sign-ins on a billion devices The post Google aims for password-free app and site logins on Android appeared first on WeLiveSecurity

LinuxSecurity.com: ultiple vulnerabilities have been discovered in liblivemedia, the LIVE555 RTSP server library: CVE-2019-6256

Mozilla fears encryption law could turn its employees into insider threats
ICANN demands DNSSEC combats DNS hijacking

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 7 vulnerabilities is now available.

LinuxSecurity.com: The package kibana before version 6.6.1-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

Two weeks after hackers tried to steal 13 million euros, Bank of Valletta goes offline again
The Dark Sides of Modern Cars: Hacking and Data Collection
Facebook apps secretly sending sensitive data back to the mothership
Android nudges passwords closer to the cliff edge with FIDO2 support
Who needs malware? IBM says most hackers just PowerShell through boxes now, leaving little in the way of footprints
Threatpost Data: Password Managers Are Worth the Risk, Readers Say
Jeez, what a Huawei to go: Now US senators want Chinese kit ripped out of national leccy grid
Check your VPN DNS test tool legitimacy: Is it “good” or deceptive
China’s tech giants are a security threat to the UK, says Brit spy bigwig

LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

Risk Level: Very Low. Type: Trojan.

ToRPEDO Privacy Attack on 4G/5G Networks Affects All U.S. Carriers
Russian creator of NeverQuest banking trojan pleads guilty in American court

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Burger chain Wendy’s serves up settlement, NeverQuest hacker guilty, cloudy payroll users hacked and more
Escalating DNS attacks have domain name steward worried

The keeper of the internet’s ‘phone book’ is urging a speedy adoption of security-enhancing DNS specifications The post Escalating DNS attacks have domain name steward worried appeared first on WeLiveSecurity

LinuxSecurity.com: Several security issues were fixed in Bind.

Google Ditches Passwords in Latest Android Devices
Your $350 Nike self-lacing sneakers aren’t as smart as you hoped
Missile warning sent from hijacked Tampa mayor’s Twitter account