Menu

Monthly Archives: February 2019

Major Container Security Flaw Threatens Cascading Attacks
Xiaomi M365 Electric Scooter Hacked and Remotely Controlled

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low.

Risk Level: Very Low.

Adobe Fixes 43 Critical Acrobat and Reader Flaws
Linux container bug could eat your server from the inside – patch now!
Apple to pay teenager who uncovered FaceTime bug

The decision to award the bug has been welcomed but one security researcher has said that they need to do more to compensate those who find bugs The post Apple to pay teenager who uncovered FaceTime bug appeared first on WeLiveSecurity

Q. What’s a good thing to put outside a building of spies? A: A banner saying ‘here we are!’
First they came for Equifax and we did nothing because America. Now they are coming for back-end systems and we’re…
Russian ISPs plan internet disconnection test for entire country
Apple sued for ‘forcing’ 2FA on accounts
Kids as young as eight falling victim to online predators
Brave browser explains Facebook whitelist to concerned users
Facebook defends gun-law loophole firm as “political advertisers”
Intel SGX ‘safe’ room easily trashed by white-hat hacking marauders: Enclave malware demo’d

The package spice before version 0.14.0-3 is vulnerable to arbitrary code execution.

The package chromium before version 72.0.3626.81-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, content spoofing and insufficient validation.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

620 million accounts stolen from 16 hacked websites now for sale on dark web, seller boasts
Network kit biz Phoenix takes heat as flaws may leave industrial control system security in ashes
Patch this run(DM)c Docker flaw or you be illin’… Tricky containers can root host boxes. It’s like that – and that’s the way it is

security update

Threatpost Poll: Is It Impossible to Secure Mobile Devices?
U.S. Senators Urge VPN Ban for Federal Workers Over Spying
Temporary Patch Released For Adobe Reader Zero-Day
‘Now is the winter of our disk contents’: Decision on Lauri Love’s seized gear due next week

The package firefox before version 65.0-1 is vulnerable to multiple issues including arbitrary code execution, privilege escalation and access restriction bypass.

The package dovecot before version 2.3.4.1-1 is vulnerable to authentication bypass.

Exposed: Instagram, OKCupid, Mumsnet All Face Data Concerns
First ‘Clipper’ Malware Discovered on Google Play
Managing Enterprise Security After the Data Supernova
Crypto mirror on the wall, who’s the smartest of them all?
Automatic 4K/HD for YouTube extension pulled from Chrome Store for pop-up ad abuse
Accused hacker Lauri Love tries to retrieve Fujitsu lappie and other gear from Britain’s FBI in court
Oh dear, Lads: Spam marketing bosses banned from forming UK firms for clobbering folk with 500k calls and texts
McDonalds app users hatin’ it after being hacked by hungry hamburglars
Secret Service busts online car sales crime ring
What comes after air gaps? DARPA asks world for ideas
Some OkCupid users have their accounts compromised. Why don’t more dating apps use 2FA?
Get-rich-quick social media scams are turning teens into money mules
You can now unsend messages in Facebook Messenger
QNAP NAS user? You’d better check your hosts file for mystery anti-antivirus entries

security update

Botched Mumsnet update allowed users to see details of strangers’ accounts
These iOS apps have been secretly recording your screen activities
Flaws in RDP protocols leaving machines prone to remote code execution
Upcoming Firefox version to offer fingerprinting & cryptomining protection
New cryptocurrency malware SpeakUp hits Linux & Mac devices
Crypto exchange loses access to $145M after CEO dies without giving password
Top 10 Best Antivirus software for 2019
World’s largest data dump surfaces on web with 2.2 billion accounts
Clipper malware on Play Store replaces users BTC & ETH wallet address
EU Parliament Clears a Path to Give Snowden Asylum
Still fuming over HTTPS mishap, Google makes Symantec an offer it can
Teen Who Hacked CIA Director
Vint Cerf and 260 experts give FCC a plan to secure Wi-Fi routers
Journalist convicted of helping Anonymous hack the LA Times
Security awareness is our shared responsibility
10 cutting-edge security threats
CSOs could see 7% raise next year
Arrest of 14-Year-Old Student for Making a Clock: the Fruits of Sustained Fearmongering and Anti-Mus
Alleged SIM swapping crypto-crooks cuffed, iOS app snooping, ad-fraud botnets, and more
Big trouble Down Under as Australian MPs told to reset their passwords amid hack attack fears
Google Boosts Encryption For Low-End Android Devices
Theory: ‘Simple Hack’ Behind Bezos’ Alleged Compromising Images

Reading Time: ~2 min. Members of British Parliament Targeted by Phishing Attack Dozens of MPs from the UK were recently subjected to malicious spam and unauthorized solicitations via their mobile devices. Fortunately, as this wasn’t the first phishing attempt on MPs, many were quick to delete any unusual messages and quickly warned others to do […]

Cop films chap on body-worn cam because he ‘complains about cops a lot’. Chap complains
Android vulnerabilities open Pie to booby-trapped image attacks
FireOS Flaw Allowed Limited Content Injection in Amazon Tablets
iPhone apps record your screen sessions without asking
Webroot dunked in Carbonite: Should be quite well protected – if it survives the freezing process, that is
Update your iOS devices now against the FaceTime eavesdropping bug
Child abuse imagery found in cryptocurrency blockchain
Leaky child-tracking smartwatch maker hits back at bad PR
EE customer: Creepy ex used employee access to change my mobile number, spy on me
Student gets creative with data accidentally blasted out by university
Police tell Waze to stop pinpointing their checkpoints
Facebook ordered to keep apps separate unless users opt in to sharing
OK, Google. Music in 2019 isn’t what it was, but Play nice, will ya?
Housing biz made to pay £1.5k for sticking fingers in its ears when served a subject access request
US lawmakers furious (again) as mobile networks caught (again) selling your emergency location data to bounty hunters (again)

Reading Time: ~2 min. I’m excited to share that Webroot has entered into an agreement to be acquired by Carbonite, a leader in cloud-based data protection for consumers and businesses. Why do I think this is such good news for customers, partners and our employees?   For customers and partners, the combined Webroot and Carbonite will […]

Apple puts bullet through ‘Do Not Track’, FaceTime snooping bug and iOS vulnerabilities
Apple Fixes Pesky FaceTime Bug in iOS 12.1.4 Update

security update

ThreatList: Latest DDoS Trends by the Numbers
Get TotalAV Essential AntiVirus for $19.99 (80% off)
Accused hacker Lauri Love to sue National Crime Agency to retrieve confiscated computing kit

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.