Menu

Monthly Archives: April 2019

Reading Time: ~2 min. Hackers Breach Private Keys to Steal Cryptocurrency A possible coding error allowed hackers to compromise at least 732 unique, improperly secured private keys used in the Ethereum blockchain. By exploiting a vulnerability, hackers have successfully stolen 38,000 Ethereum coins so far, translating to over $54 million in stolen funds, though the […]

An update that fixes two vulnerabilities is now available.

Facial Recognition ‘Consent’ Doesn’t Exist, Threatpost Poll Finds

An update that solves three vulnerabilities and has four fixes is now available.

In the recently uploaded systemd security update (215-17+deb8u12 via DLA-1762-1), a regression was discovered in the fix for CVE-2017-18078.

NSA asks to end mass phone surveillance
Fingerprint glitch in passports swapped left and right hands
Microsoft drops password expiration from Windows 10 security
Cops can try suspect’s fingers on locked iPhones found at crime scene
Thank you, your DNA data will help secure your… oh dear, we’ve lost that too
There’s NordVPN odd about this, right? Infosec types concerned over strange app traffic

An update that solves two vulnerabilities and has three fixes is now available.

An update that fixes one vulnerability is now available.

Zuck it up: Facebook hit with triple whammy of legal probes, action in Canada, US, Ireland
NSA: That ginormous effort to slurp up Americans’ phone records that Snowden exposed? Ehhh, we don’t need that no more
Android-Based Sony Smart-TVs Open to Image Pilfering
Ride-hailing app leaks personal data of millions of Iranians

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has 5 fixes is now available.

Microsoft: Yo dawg, we heard you liked Windows password expiry policies. So we expired your expiry policy
BEC fraud losses almost doubled last year

On the good news front, the FBI notes the success of its newly-established team in recovering some of the funds lost in BEC scams The post BEC fraud losses almost doubled last year appeared first on WeLiveSecurity

Avengers: End Game leaked online soon after releasing in China
Amazon Employees Given ‘Broad Access’ to Personal Alexa Info
Qualcomm Critical Flaw Exposes Private Keys For Android Devices
Operation ShadowHammer: Hackers planted malware code in video games
ExtraPulsar backdoor based on leaked NSA code – what you need to know

An update that solves 13 vulnerabilities and has one errata is now available.

An update that solves one vulnerability and has four fixes is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

It was discovered that there was a path traversal vulnerability in the “mercurial” distributed revision version control system. Symbolic links and subrepositories could be used defeat Mercurial’s

Hacker could locate thousands of cars and kill their engines remotely via poorly-secured GPS tracking apps

Reading Time: ~3 min. Public concern about online privacy and security is rising, and not without reason. High-profile data breaches make headlines almost daily and tax season predictably increases instances of one of the most common types of identity theft, the fraudulent filings for tax returns known as tax-related identity theft.  As a result, more than half of global internet users are more concerned about their safety than […]

Blochainbandit stole $54 million of Ethereum by guessing weak keys
DNSpionage group’s Karkoff malware selectively pick victims
Atlanta Hawks fall prey to Magecart credit card skimming group
Teen sues Apple for $1 billion over Apple stores’ facial recognition

An update that solves two vulnerabilities and has four fixes is now available.

An update that fixes one vulnerability is now available.

It’s your what in a box? Here’s a thing to make your bosses think about malware responses
Smashing Security #125: Pick of the thief!
Over 23 million breached accounts used ‘123456’ as password

The notorious six-digit string continues to ‘reign supreme’ among the most-hacked passwords The post Over 23 million breached accounts used ‘123456’ as password appeared first on WeLiveSecurity

Bind could be made to consume resources if it received specially crafted network traffic.

tcpflow could be made to crash or expose sensitive information over the network if it opened a specially crafted file or received specially crafted network traffic.

Several security issues were fixed in PHP.

Updated Red Hat AMQ Clients 2.3.1 packages are now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

FYI: Yeah, the cops can force your finger onto a suspect’s iPhone to see if it unlocks, says judge
Facebook May Face $5 Billion FTC Fine for Data Misuse
Sophos antivirus tools. Working Windows box. Latest Patch Tuesday fixes. Pick two: ‘Puters knackered by bad combo

Reading Time: ~4 min. These are the places your digital tracks can be dug up. With a little sleuthing. Experts have warned for years of the risks of using public computers such as those found in libraries, hotels, and airline lounges.  Many warnings focused on the potential for hackers to plant keystroke loggers, or intercept […]

Hackers using Google Sites to spread banking malware
Adware-Ridden Apps in Google Play Infect 30 Million Android Users
WiFi finder app exposes millions of WiFi network passwords
‘We’re not omnipotent,’ trills National Cyber Security Centre in open-armed pitch to UK biz
Point Blank Gamers Targeted with Backdoor Malware
Poll: Are You Creeped Out by Facial Recognition?
Brit spy chief: We need trust or we won’t have a ‘licence to operate in cyberspace’

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves four vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has 24 fixes is now available.

An update that fixes three vulnerabilities is now available.

Latest Qbot Variant Evades Detection, Infects Thousands
Facial Recognition is Here: But Are We Ready?
Ex-student records himself using USB Killer to fry college computers

An update that solves one vulnerability and has 23 fixes is now available.

The package dovecot before version 2.3.5.2-1 is vulnerable to denial of service.

The package flashplugin before version 32.0.0.171-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

The package jenkins before version 2.172-1 is vulnerable to multiple issues including access restriction bypass and cross-site scripting.

The package ghostscript before version 9.27-1 is vulnerable to sandbox escape.

NYPD forgets to redact facial recognition docs, asks for them back
Gunpoint domain hijack turns out to have been a family affair
DNS over HTTPS is coming whether ISPs and governments like it or not
Bodybuilding.com suffers data breach; issues password reset for all users
WannaCryptor ‘accidental hero’ pleads guilty to malware charges

Marcus Hutchins, who is best known for his inadvertent role in blunting the WannaCryptor outbreak two years ago, may now face a stretch behind bars The post WannaCryptor ‘accidental hero’ pleads guilty to malware charges appeared first on WeLiveSecurity

Carbanak Source Code Unveils a Startlingly Complex Malware
Exploits for Social Warfare WordPress Plugin Reach Critical Mass
Wall Street market exit scam? Admins steal $30 million worth of crypto
FBI: BEC Scam Losses Almost Double To Reach $1.2 Billion
Phone fingerprint scanner fooled by chewing gum packet

AdvanceCOMP could be made to run arbitrary code if it opened a specially crafted file.

Hotspot finder app blabs 2 million Wi-Fi network passwords

A security update is now available for Red Hat Single Sign-On 7.2 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Security updates for Red Hat Single Sign-On 7.2.7 packages are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Security updates for Red Hat Single Sign-On 7.2.7 packages are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Once again, it’s 123456: the password that says ‘I give up’

An update that fixes 6 vulnerabilities is now available.

Building a VPN for Mobile Devices at the Network Level

Reading Time: ~5 min. From Landline Hacking to Cryptojacking By its very nature, cybercrime must evolve to survive. Not only are cybersecurity experts constantly working to close hacking loopholes and prevent zero-day events, but technology itself is always evolving. This means cybercriminals are constantly creating new attacks to fit new trends, while tweaking existing attacks to avoid detection. To understand how cybercrime might evolve […]

Several security issues were fixed in PHP.

An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kernel-alt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for ovmf is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Cedric Buissart discovered two vulnerabilities in Ghostscript, the GPL PostScript/PDF interpreter, which could result in bypass of file system restrictions of the dSAFER sandbox.

Several security issues were fixed in PHP.

Several security issues were fixed in Pacemaker.

Like that other bloke who rose from the grave, the El Reg security desk is back this week…