Menu

Monthly Archives: February 2019

The Kubernetes privilege escalation flaw: Innovation still needs IT security expertise
Understanding the critical Kubernetes privilege escalation flaw in OpenShift 3
Security embargoes at Red Hat
Why real-time intelligence matters for managing third-party risk
Criminal hacking hits Managed Service Providers: Reasons and responses

Recent news articles show that MSPs are now being targeted by criminals, and for a variety of nefarious reasons. Why is this happening, and what should MSPs do about it? The post Criminal hacking hits Managed Service Providers: Reasons and responses appeared first on WeLiveSecurity

450,000 usernames and passwords stolen from Coinmama cryptocurrency broker
When Cyberattacks Pack a Physical Punch

Risk Level: Very Low. Type: Trojan.

Apple sued over death blamed on faulty iPad battery
Apple sued because two-factor authentication… oh, I give up
Mega-crackers back with nearly 100 million new stolen data records
Google: Here’s how we cracked down on bad apps last year

Apps downloaded from Google Play were eight times less likely to compromise a device than apps from other sources The post Google: Here’s how we cracked down on bad apps last year appeared first on WeLiveSecurity

Opera integrates a cryptocurrency wallet – is this Web 3.0?
Will the EU’s new copyright directive ruin the web?
Australian prime minister blames ‘state level’ baddies for Oz parliament breach
Smoke damage and hard drives

A closer look at the damage caused by smoke particles and some steps you can take to aid recovery The post Smoke damage and hard drives appeared first on WeLiveSecurity

Data-spewing Spectre chip flaws can’t be killed by software alone, Google boffins conclude
Tens of millions more web accounts for sale after more sites hacked, Mac malware spreads via Windows.exe, and more

Risk Level: Very Low. Type: Trojan.

security update

What is Ransomware and How to Prevent It?
Dark Web hacker selling 126M accounts stolen from new data breaches
Chinese facial recognition database tracking Muslims left exposed
Website uses Artificial Intelligence to create utterly realistic human faces
Where’s the Equifax Data? Does It Matter?
Data Breach Bonanza: Dating Apps, Equifax, Mass Credential Dumps

security update

Eight Cryptojacking Apps Booted From Microsoft Store
Tips on How to Fight Back Against DNS Spoofing Attacks

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Trickbot Malware Goes After Remote Desktop Credentials
Holby damned! We’ve caught a virus: Brit medical soaps team up for ‘cyber’ episode

Reading Time: ~2 min. Popular Photography Site Breached A major photography site, 500px, recently discovered they had suffered a data breach in July of last year. Data ranging from name and email addresses, to birthdates and user locations, were comprised. While the company did confirm no customer payment data is stored on their servers, all […]

Ultra-Sneaky Phishing Scam Swipes Facebook Credentials
Email service provider loses 2 decades worth of data due to hack attack
Russian to shut down Internet to test its cyber deterrence
An info stealer .exe malware is targeting Mac users around the globe
Critical zero-day vulnerabilities hit Lifesize video conferencing products
Malta’s leading bank resumes operations after cyberheist-induced shutdown

Bank of Valetta, which went dark for a day after the fraudulent transfers of €13 million, is now looking to get the money back The post Malta’s leading bank resumes operations after cyberheist-induced shutdown appeared first on WeLiveSecurity

Apple fighting pirate app developers, will insist on 2FA for coders
Judge won’t unseal legal docs in fight to break Messenger encryption
Should we profit from the sale of our personal data?
Chinese facial recognition database exposes 2.5m people
Photography site 500px resets 14.8 million passwords after data breach
‘This collaboration is absolutely critical going forward’… One positive thing about Meltdown CPU hole? At least it put aside tech rivalries…
Use an 8-char Windows NTLM password? Don’t. Every single one can be cracked in under 2.5hrs
Bad news for WannaCry slayer Marcus Hutchins: Judge rules being young, hungover, and in a strange land doesn’t obviate evidence
Ever-Changing Emotet Evolves Again with Fresh Evasion Tactic
Threatpost Poll: Over Half of Firms Asked Struggle with Mobile Security
Coffee Meets Bagel Dating App Warns Users of Breach
Inside a GandCrab targeted ransomware attack on a hospital
Google Play Cracks Down on Malicious Apps
Hacked versions of popular iOS games available on App Store
Attack at email provider wipes out almost two decades’ worth of data

Instead of seeking financial gain or other goals, the attacker leaves ‘scorched digital earth’ behind The post Attack at email provider wipes out almost two decades’ worth of data appeared first on WeLiveSecurity

US man and Brit teen convict indicted over school bomb threat spree
Hacker arrested for wave of fake bomb and shooting threats against schools
What’s behind this 1,000-character phishing URL?
Apple App Store stuffed with hardcore porn and gambling apps
Google paid out $3.4m in bug bounties last year
Update now! Microsoft and Adobe’s February 2019 Patch Tuesday is here
Critical OkCupid Flaw Exposes Daters to App Takeovers
Electric scooters can be hijacked remotely – no password required
When love becomes a nightmare: Online dating scams

Roses are red, violets are blue, watch out for these scams or it may happen to you The post When love becomes a nightmare: Online dating scams appeared first on WeLiveSecurity

Smashing Security #115: Love, Nests, and is 2FA destroying the world?
Cover your NASes: QNAP acknowledges mystery malware but there’s no patch yet
Oh Snapd! Gimme-root-now security bug lets miscreants sock it to your Ubuntu boxes
US counterintelligence agent helped Iran lob cyber-bombs at America, say Uncle Sam’s lawyers
Top tips for Valentine’s Day – and the rest of the year! [VIDEO]
ACLU: Here’s how FBI tried to force Facebook to wiretap its chat app. Judge: Oh no you don’t
Lenovo Watch X Riddled with Security Vulnerabilities
ThreatList: Banking Trojans Are Still The Top Big Bad for Email

security update

Hackers KO Malta’s Bank of Valletta in attempt to nick €13m
‘Dirty Sock’ Flaw in snapd Allows Root Access to Linux Servers
Another flaw found in macOS Mojave’s privacy protection
Unpatched Apple macOS Hole Exposes Safari Browsing History
Evil USB O.MG Cable opens up Wi-Fi to remote attacks
British and US militaries’ drone swarm hackathon definitely isn’t about army tech
620 million records from 16 websites listed for sale on the Dark Web
Security firm beats Adobe by patching reader flaw first
One click and you’re out: UK makes it an offence to view terrorist propaganda even once
Why you should choose a pseudonym at Starbucks

Innocently providing your name at your local coffee shop is just an example of how easy it can be for miscreants to cut through the ‘privacy’ of social media accounts The post Why you should choose a pseudonym at Starbucks appeared first on WeLiveSecurity

The package python2-django before version 1.11.19-1 is vulnerable to denial of service.

The package python-django before version 2.1.6-1 is vulnerable to denial of service.

The package lib32-libcurl-compat before version 7.64.0-1 is vulnerable to arbitrary code execution.

The package lib32-curl before version 7.64.0-1 is vulnerable to arbitrary code execution.

The package lib32-libcurl-gnutls before version 7.64.0-1 is vulnerable to arbitrary code execution.

The package libcurl-gnutls before version 7.64.0-1 is vulnerable to arbitrary code execution.

The package curl before version 7.64.0-1 is vulnerable to arbitrary code execution.

Siemens Warns of Critical Remote-Code Execution ICS Flaw
Double-Stuffed: Dunkin’ Hit by Another Credential-Stuffing Attack
Microsoft Patches Zero-Day Browser Bug Under Active Attack

security update

Critical WordPress Plugin Flaw Allows Complete Website Takeover
Attackers Completely Destroy VFEmail’s Secure Mail Infrastructure
VFEmail suffers ‘catastrophic’ attack, as hacker wipes email service’s primary and backup data
Ever used VFEmail? No? Well, chances are you never will now: Hackers wipe servers, backups in ‘catastrophic’ attack

The package aubio before version 0.4.9-1 is vulnerable to denial of service.

The package libu2f-host before version 1.1.7-1 is vulnerable to arbitrary code execution.