Menu

Monthly Archives: February 2019

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Mumsnet breached: Moaning parents could see other users’ privates after cloud migration

Reading Time: ~4 min. In my blog, Password Constraints and Their Unintended Security Consequences, I advocate for the use of passphrases. Embedded in the comments section, one of our readers Ben makes a very astute observation: What happens when attackers start guessing by the word instead of by the letter? Then a four-word passphrase effectively becomes […]

Serious Security: Post-Quantum Cryptography (and why we’re getting it)
Flaw in Multiple Airline Systems Exposes Passenger Data
KeySteal could allow someone to steal your Apple Keychain passwords
Google Chrome extension warns if your password has been leaked
Anyone want to lay claim to the USB drive found in seal poo?
Chrome extension warns users their login credentials have been breached
Unlimited crypotocurrency? Zcash fixes counterfeiting flaw
DanaBot updated with new C&C communication

ESET researchers have discovered new versions of the DanaBot Trojan, updated with a more complicated protocol for C&C communication and slight modifications to architecture and campaign IDs The post DanaBot updated with new C&C communication appeared first on WeLiveSecurity

Trakt app users’ personal data exposed: We were hit by a ‘PHP exploit’… back in 2014
At least Sony offered a t-shirt, says macOS flaw finder: Bug bounties now for Macs if you want this 0-day, Apple
Who are the last people you’d expect to spill thousands of student records? A computer science dept? What a fantastic guess
Smashing Security #114: Darknet Diaries, death, and beauty apps
It’s 2019, and a PNG file can pwn your Android smartphone or tablet: Patch me if you can
MacOS Zero-Day Exposes Apple Keychain Passwords

security update

Clever Phishing Attack Enlists Google Translate to Spoof Login Page
Google rolls out Chrome extension to warn you about compromised logins

The new tool aims to help in an age when billions of login credentials are floating around the internet The post Google rolls out Chrome extension to warn you about compromised logins appeared first on WeLiveSecurity

What are Data Manipulation Attacks, and How to Mitigate Against Them
Patch your Android now against critical .PNG image bug
Microsoft Confirms Serious ‘PrivExchange’ Vulnerability
Accused hacker Laurie Love to sue National Crime Agency to retrieve confiscated computing kit
Modern Cybercrime: It Takes a Village
Jack’d dating app is showing users’ intimate pics to strangers

Reading Time: ~3 min. The WordPress website platform is a vital part of the small business economy, dominating the content management system industry with a 60% market share. It gives businesses the ability to run easily-maintained and customizable websites, but that convenience comes at a price. The easy-to-use interface has given even users who are […]

London’s Met police confess: We made just one successful collar in latest facial recog trial
Firefox 66 will silence autoplaying web audio
Every day should be Safer Internet Day
Just two hacker groups are behind 60% of stolen cryptocurrency
Digital signs left wide open with default password
I won’t bother hunting and reporting more Sony zero-days, because all I’d get is a lousy t-shirt
IoT Scale Flaws Enable Denial of Service, Privacy Issues
Google: All your leaked passwords are belong to us – here’s a Chrome extension to find them

security update

Risk Level: Very Low. Type: Trojan.

Google Patches Critical .PNG Image Bug
Webcast: Arm yourself before you go threat hunting in 2019
European Commission orders recall of children’s smartwatch over privacy concerns

The watch has been found to expose its wearers to a high level of risk of being contacted and monitored by attackers The post European Commission orders recall of children’s smartwatch over privacy concerns appeared first on WeLiveSecurity

EU Recalls Children’s Smartwatch That Leaks Location Data
RIP, RDP: Security house Check Point punches holes in desktop controls
Remote Desktop Protocol Clients Rife with Remote Code-Execution Flaws
Original WWII German message decrypts to go on display at National Museum of Computing
Home DNA kit company says it’s working with the FBI
Half of IoT devices let down by vulnerable apps
Crypto exchange in limbo after founder dies with password
The APT Name Game: How Grim Threat Actors Get Goofy Monikers
The cloud’s weakest security links aren’t where you’re looking
Kids’ GPS watches are still a security ‘train wreck’
Fake fuse: Bloke admits selling counterfeit chips for use in B-1 bomber, other US military gear
Hi, Jack’d: A little PSA for anyone using this dating-hook-up app… Anyone can slurp your private, public snaps

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Boffin suggests Trappist monk approach for Spectre-Meltdown-grade processor flaws, other security holes: Don’t say anything public – zip it
Spy Campaign Spams Pro-Tibet Group With ExileRAT

security update

LibreOffice patches malicious code-execution bug, Apache OpenOffice – wait for it, wait for it – doesn’t
European Commission orders mass recall of creepy, leaky child-tracking smartwatch
‘Collection #1’ Data Dump Hacker Identified
Donald Trump’s ‘Executive Time’ leak – journalists retype documents to protect White House source
SpeakUp Linux Backdoor Sets Up for Major Attack
Houzz discloses data breach, asks some users to reset passwords

Citing an ongoing investigation, the company wouldn’t say how or when the incident occurred The post Houzz discloses data breach, asks some users to reset passwords appeared first on WeLiveSecurity

Security weaknesses in 5G, 4G and 3G could expose users’ locations
Chrome’s hidden lookalike detection feature battles URL imposters
FBI burrowing into North Korea’s big bad botnet
Selling fake likes and follows is illegal, rules New York

security update

security update

security update

security update

New Mac Malware steals iPhone text messages from iTunes backups
Selfie stealing malware found in popular Android beauty camera apps
Authorities shut down xDedic marketplace for selling hacked servers
New Firmware Version of Nintendo Switch Hacked in just 4 Hours
FaceTime bug exposes live audio & video before recipient picks call
What If Your VPN Keeps Logs and Why You Should Care
Meet Aztarna, a tool to find vulnerable Internet connected robots
Beware; hackers are using malicious TeamViewer tool to spread malware
Bug-hunter faces jail for vulnerability reports, DuckDuckPwn (almost), family spied on via Nest gizmo, and more

LinuxSecurity.com: A remote code execution vulnerability exists in PHP’s built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some Drupal code (core, contrib, and custom) may be performing file operations on insufficiently validated user input, thereby being

LinuxSecurity.com: Bug fixes for binutils including one that is preventing Yocot/oe-core from building properly

LinuxSecurity.com: New mariadb packages are available for Slackware 14.1 and 14.2 to fix security issues.

Houzz Urges Password Resets After Data Breach
Year after being blasted for dodgy security, GPS kid tracker biz takes heat again for leaving families’ private info lying around for crims
Chafer APT Takes Aim at Diplomats in Iran with Improved Custom Malware

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Ethical hacker may get 8 years in prison for reporting flaws in Magyar Telekom
Three UK customer details exposed in homepage blunder

Reading Time: ~2 min. Facebook Research App Removed from App Store After seeing their Onavo VPN application removed from the Apple App Store last year, Facebook has re-branded the service as a “research” app and made it available through non-Apple testing services. The app itself requires users download and install a Facebook Enterprise Developer Certificate […]

Threatpost News Wrap Podcast For Feb. 1
FaceTime bug, eavesdropping and digital snooping – what to do? [VIDEO]
Cybercriminals Aim for the Super Bowl Goal Posts
Hackers used Karma tool to hack iPhones of prominent Govt officials
Four new caches of stolen logins put Collection #1 in the shade

The recently discovered tranches of stolen login credentials freely floating around the internet total 2.2 billion records The post Four new caches of stolen logins put Collection #1 in the shade appeared first on WeLiveSecurity