Menu

Monthly Archives: September 2022

UBER HAS BEEN HACKED, boasts hacker – how to stop it happening to you
Starbucks Singapore warns customers after hacker steals data, offers it for sale on underground forum
Uber’s hacker *irritated* his way into its network, stole internal documents

An update that solves 25 vulnerabilities, contains four features and has 91 fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

The art and science of secure open source software development

Several security issues were fixed in the Linux kernel.

Turbo boost your career in cyber security

Multiple file parsing vulnerabilities have been fixed in libraw. They are concerned with the dng and x3f formats. CVE-2020-35530

An update that solves one vulnerability and has one errata is now available.

Eastern European org hit by second record-smashing DDoS attack
China can destroy US space assets, Space Force ops nominee warns
Uber reels from ‘security incident’ in which cloud systems seemingly hijacked
FBI warns of criminals attacking healthcare payment processors
You never walk alone: The SideWalk backdoor gets a Linux variant

ESET researchers have uncovered another tool in the already extensive arsenal of the SparklingGoblin APT group: a Linux variant of the SideWalk backdoor The post You never walk alone: The SideWalk backdoor gets a Linux variant appeared first on WeLiveSecurity

S3 Ep100: Imagine you went to the moon – how would you prove it? [Audio + Text]
Ex-Broadcom engineer asks for house arrest over IP theft
Building the barricades against identity-based attacks
Iran steps up its cybercrime game and Uncle Sam punches back
What You Need to Know when Considering a VPN on Linux
What Are Checksums & Why Should You Be Using Them?
Debian GNU/Linux 11.5 Bullseye Released with 53 Security Updates and 58 Bug Fixes
Coding Vulnerabilities, Linux Growth, FOSS Friction Cap Summer Highlights

It was found that GLib, a general-purpose portable utility library, could be used to print partial contents from arbitrary files. This could be exploited from setuid binaries linking to GLib for information disclosure of files with a specific format.

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Third‑party cookies: How they work and how to stop them from tracking you across the web

Cross-site tracking cookies have a bleak future but can still cause privacy woes to unwary users The post Third‑party cookies: How they work and how to stop them from tracking you across the web appeared first on WeLiveSecurity

SparklingGoblin deploys new Linux backdoor – Week in security, special edition

ESET Research first spotted this variant of the SideWalk backdoor in the network of a Hong Kong university in February 2021 The post SparklingGoblin deploys new Linux backdoor – Week in security, special edition appeared first on WeLiveSecurity

WordPress-powered sites backdoored after FishPig suffers supply chain attack
Smashing Security podcast #289: Printer peeves, health data hangups, and Twitter tussles – with Rory Cellan-Jones
White House to tech world: Promise you’ll write secure code – or Feds won’t use it

security update

Nearly one in two industry pros scaled back open source use over security fears
Why is my Wi‑Fi slow and how do I make it faster?

Has your Wi-Fi speed slowed down to a crawl? Here are some of the possible reasons along with a few quick fixes to speed things up. The post Why is my Wi‑Fi slow and how do I make it faster? appeared first on WeLiveSecurity

AutoRabit launches devsecops tool for Salesforce environments

An update that solves 15 vulnerabilities and has 11 fixes is now available.

Patch now! Microsoft issues critical security updates as PCs attacked through zero-day flaw
Google and Meta fined over $70m for privacy violations in Korea

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Several security issues were fixed in WebKitGTK.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Ransomware gang threatens 1m-plus medical record leak
Twitter whistleblower Zatko disses bird site as dysfunctional data dump
Microsoft fixes Windows security hole likely widely exploited by miscreants
Serious Security: Browser-in-the-browser attacks – watch out for windows that aren’t!
Patch your Mitel VoIP systems, Lorenz ransomware gang is back on the prowl
ESET Research uncovers new APT group Worok – Week in security with Tony Anscombe

Worok takes aim at various high-profile organizations that operate in multiple sectors and are located primarily in Asia The post ESET Research uncovers new APT group Worok – Week in security with Tony Anscombe appeared first on WeLiveSecurity

How to get inside the mind of hackers
Shadow IT and shadow IoT
One month after Black Hat exposure HP enterprise kit still unpatched
Rust programming language gains dedicated security team
Cisco: Yes, Yanluowang leaked our data. No, it’s not serious

Girl Scouts is proven to help girls thrive. A Girl Scout develops a strong sense of self, displays positive values, seeks challenges and learns from setbacks. I had the absolute honor of spending 3 days with the Girl Scouts in Chicago at the annual Camp CEO. Camp CEO is a chance for the Girl Scouts […]

Chinese-linked cyber crims nab $529 million from Indian nationals
Apple patches iPhone and macOS flaws under active attack
Apple patches zero-day holes – even in the brand new iOS 16

security update

Google Cloud closes $5.4b Mandiant acquisition
Security pros get ability to manually add incidents to Microsoft Sentinel
Reducing the risk of ransomware
Boffins build microphone safety kit to detect eavesdroppers
Retbleed fix slugs Linux VM performance by up to 70 percent
Uncle Sam sanctions Iran’s intel agency over Albanian cyberattack
Shape-shifting cryptominer savaging Linux endpoints and IoT
Data tracking poses a ‘national security risk’ FTC told
Feds freeze $30m in cryptocurrency stolen from Axie Infinity
Meta disbands Responsible Innovation team, spreads it out over Facebook and co
How to deal with dates and times without any timezone tantrums…
Toys behaving badly: How parents can protect their family from IoT threats

It pays to do some research before taking a leap into the world of internet-connected toys The post Toys behaving badly: How parents can protect their family from IoT threats appeared first on WeLiveSecurity

Regional restrictions on NFL game broadcasts and rising membership fees on streaming sites like Netflix, Hulu, and Disney Plus are just some reasons why frustrated consumers turn to illegal streaming sites. Marketed as an alternative to legitimate streaming services, illegal streaming sites have become a portal to connect criminals directly to you (their target). Unlike […]

US seeks standards dominance, lets Huawei access previously forbidden crypto tech
Dump these small-biz routers, says Cisco, because we won’t patch their flawed VPN
Mandiant ‘highly confident’ foreign cyberspies will target US midterm elections
Google urges open source community to fuzz test code
RDP on the radar: An up‑close view of evolving remote access threats

Misconfigured remote access services continue to give bad actors an easy access path to company networks – here’s how you can minimize your exposure to attacks misusing Remote Desktop Protocol The post RDP on the radar: An up‑close view of evolving remote access threats appeared first on WeLiveSecurity

Warning issued about Vice Society ransomware gang after attacks on schools
S3 Ep99: TikTok “attack” – was there a data breach, or not? [Audio + Text]
Private equity suits at Thoma Bravo pull out of Darktrace acquisition
Lazarus Group unleashed a MagicRAT to spy on energy providers
Red Hat extends Common Vulnerabilities and Exposure Program expertise as newly-minted Root organization
Essential Guide to Securing Node.JS Applications
What’s the secret behind a secure password?
Halfords slapped on wrist for breaching email marketing laws
DoJ charges pair over China-linked attempt to build semi-autonomous crypto haven on nuked Pacific atoll
Smashing Security podcast #288: Chiquita banana, dumb criminals, and detecting ring binders

security update

security update

security update

Golang adds vulnerability management tooling
Ransomware protection from the top drawer
US school year opens with reading, writing, and ransomware
DEADBOLT ransomware rears its head again, attacks QNAP devices
Worok: The big picture

Focused mostly on Asia, this new cyberespionage group uses undocumented tools, including steganographically extracting PowerShell payloads from PNG files The post Worok: The big picture appeared first on WeLiveSecurity

Massive hotel group IHG struck by cyberattack which disrupts booking systems