Menu

Category Archives: All

Everything

Malware steals data directly from the device to hack Facebook account
RedDrop nasty infects Androids via adult links, records sound, and fires off premium-rate texts
US Navy gives Lockheed Martin $150m big frickin’ laser cannon contract
GitHub knocked briefly offline by biggest DDoS attack ever

At its peak, inbound traffic reached a staggering 1.35 terabits per second (Tbps), outflanking the previously record-setting assault of 1 Tbps at French web hosting provider OVH in September 2016. The post GitHub knocked briefly offline by biggest DDoS attack ever appeared first on WeLiveSecurity

Beware; rTorrent Client Exploited to Mine Monero Cryptocurrency
Chi*a ce*sors the letter ‘N’ from the i*ter*et for a day
20,000 web certificate private keys outed in “business tiff”
Facebook’s see yourself bald app: extreme hackers or extreme hoax?
The rise of AI needs to be controlled, report warns

The experts urge policy-makers to work closely with technical researchers, computer scientists and the cybersecurity community to investigate, understand and prepare for possible malicious uses of AI. The post The rise of AI needs to be controlled, report warns appeared first on WeLiveSecurity

LinuxSecurity.com: Several vulnerabilities have been discovered in SimpleSAMLphp, a framework for authentication, primarily via the SAML protocol. CVE-2016-9814 & CVE-2016-9955

Apple issues advice on how to spot App Store and iTunes phishing scams
Can emojis save you from a terrible password?
Don’t fall for fake iTunes and App Store messages
Memcached servers can be hijacked for massive DDoS attacks
How to start analyzing the security of your IoT devices

The big challenge with IoT devices is that they are all different: Each manufacturer has its own firmware, uses different protocols, and designs its own architecture. So, the first step before carrying out any analysis is to understand the architecture, find out what components are involved, and how they interact and communicate among themselves. The […]

Train to become an expert cyber crime fighter

The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Thanatos Ransomware Causing Major Damage for Victims A new ransomware variant has recently appeared and is proving […]

Github hit by 1.35 Tbps DDoS attack; the largest ever

security update

LinuxSecurity.com: New ntp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Microsoft lobs Skylake Spectre microcode fixes out through its Windows

LinuxSecurity.com: New dhcp packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues.

Bug in HP Remote Management Tool Leaves Servers Open to Attack
HTTPS cert flingers Trustico, SSL Direct go TITSUP after website security blunder blabbed

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Equifax reveals additional 2.4 million users impacted from 2017 breach
Machine learning self defence: how to not shoot yourself in the foot
Sophisticated RedDrop Malware Targets Android Phones

LinuxSecurity.com: An update for quagga is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: This is the One-Year notification for the retirement of Red Hat Enterprise Linux 6.4 Advanced Mission Critical (AMC). This notification applies only to those customers subscribed to the Advanced Mission Critical (AMC) channel for Red Hat Enterprise Linux 6.4.

LinuxSecurity.com: – Update to 2.7.0 Release notes: https://tls.mbed.org/tech- updates/releases/mbedtls-2.7.0-2.1.10-and-1.3.22-released Security Advisory: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security- advisory-2018-01

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Hackers can compromise Memcached Servers for DDoS attacks
Ad Network Circumvents Ad-Blocking Tools To Run In-Browser Cryptojacker Scripts
Smashing Security #067: Cyber stalking and gun control
Equifax finds ANOTHER 2.4 million Americans hit by breach
Personal Data of 21,426 US Marine Force Reserve Personnel Leaked
Equifax peeks under couch, finds 2.4 million more folk hit by breach
Mobile World Congress: Introducing 5G

If we look back at previous incarnations of mobile networks, 1G, 2G and so on, there have been major changes to the technology. The next generation, 5G, delivers, greater speed and lower latency, but also has the advantage of being able to connect many more devices concurrently. The post Mobile World Congress: Introducing 5G appeared […]

1 in 50 publicly readable Amazon buckets are also writable – and that’s a data disaster waiting to happen
27% of under-18s have been sexted, and it’s on the rise
Russia behind compromise of seven states’ voter registration systems
Microsoft still refusing to hand over private email data stored in Ireland
Why Blockchain Will Serve New IT Purposes in 2018
Right to be Forgotten requests stagnate, Google refuses most anyway
Major reform of cybersecurity policies in France

This document, which is described by its authors as a “real white paper on cyber-defense”, is divided into three parts, followed by approximately 20 priority recommendations summarizing the central elements of the document. The post Major reform of cybersecurity policies in France appeared first on WeLiveSecurity

Spectre haunts Intel’s SGX defense: CPU flaws can be exploited to snoop on enclaves

LinuxSecurity.com: An update for rh-dotnet20-dotnet, rh-dotnetcore10-dotnetcore, and rh-dotnetcore11-dotnetcore is now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact

German government confirms hackers blitzkrieged its servers to steal data
23,000 HTTPS certs will be axed in next 24 hours after private keys leak

LinuxSecurity.com: Kelby Ludwig and Scott Cantor discovered that the Shibboleth service provider is vulnerable to impersonation attacks and information disclosure due to incorrect XML parsing. For additional details please refer to the upstream advisory at

In the past, security awareness training for user education—i.e. empowering users to make more savvy IT decisions in their daily routines—was considered a “nice to have,” not a necessity. The decision to adopt user education was typically passed over because of budget, lack of in-house expertise, and the general lack of availability of high-quality, low-cost, […]

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

Unprotected AWS Bucket Exposes 50.4 GB of Financial Giant’s Data

LinuxSecurity.com: It was discovered that the Net::FTP module did not properly process filenames in combination with certain operations. A remote attacker could exploit this flaw to execute arbitrary commands by setting up a malicious FTP server and tricking a user or Ruby application into downloading files with specially crafted names using the Net::FTP module. (CVE-2017-17405) […]

LinuxSecurity.com: quagga: Double free vulnerability in bgpd when processing certain forms of UPDATE message allowing to crash or potentially execute arbitrary code (CVE-2018-5379) SL7 x86_64 quagga-0.99.22.4-5.el7_4.i686.rpm quagga-0.99.22.4-5.el7_4.x86_64.rpm quagga-debuginfo-0.99.22.4-5.el7_4.i686.rpm quagga-debuginfo-0.99.22.4-5.el7_4.x86_64.rpm quagga-contrib-0.99.22.4-5.el7_4.x86_64. [More…]

Misconfigured Memcached Servers Abused to Amplify DDoS Attacks

security update

security update

security update

LinuxSecurity.com: An update for ruby is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: create a separate user for dnsmasq.

LinuxSecurity.com: The textbook ElGamal implementation is not secure. PyCrypto and some other implementations use the wrong algorithm, which may lead to some information disclosure simply by looking at the encrypted text. For a full description, see https://github.com/dlitz/pycrypto/issues/253 This update includes a fix for this problem backported from pycryptodome.

LinuxSecurity.com: Use default RPM build flags and configure parameters (#1539097) Remove group writable bit from some config files (#1528445)

Single Sign-On authentication – the bug that lets you logon as someone else
If any phone can be hacked, should we give up on security? [VIDEO]
Brit spooks slammed over ‘gentlemen’s agreement’ with telcos to get mass comms data
New Android malware record voice calls for extortion & blackmailing
Irish eyes are sighing: Data protection office notes olagoanin’* up 79%
Intel Releases Updated Spectre Fixes For Broadwell and Haswell Chips
Let’s talk about PCI-DSS
Got that itchy GandCrab feeling? Ransomware decryptor offers relief

LinuxSecurity.com: An update is now available for CloudForms Management Engine 5.8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

“Misguided” hacking bill threatens to ice security researchers, say critics
Researchers unveil Veil to make ‘private browsing more private’

The blinding server randomly adds some nonsense code to every webpage. This ‘code obfuscation’, according to the academics, has no effect on what the actual page looks like, but it drastically changes the appearance of the underlying source file. The post Researchers unveil Veil to make ‘private browsing more private’ appeared first on WeLiveSecurity

ISIS recruiter caught by Facebook screenshot
Making private browsing more private
Apple co-founder Steve Wozniak scammed by Bitcoin fraudster

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0350

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0349

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0349

Cryptocurrency scams on Android: do you know what to watch out for?

The recent rise in cryptocurrency scams appearing on the Android platform in disguise has shown that such incidents are not exclusive to PCs and also highlight the importance of knowing what to look out for so you do not unintentionally take part. The post Cryptocurrency scams on Android: do you know what to watch out […]

XM-hell strikes single-sign-on systems: Bugs allow miscreants to masquerade as others
Dutch name authority: DNSSEC validation errors can be eliminated

LinuxSecurity.com: The package mbedtls before version 2.7.0-1 is vulnerable to arbitrary code execution.

Popular cache utility exploited for massive reflected DoS attacks
Intel gives Broadwells and Haswells their Meltdown medicine
Phone-cracking firm advertises that it can unlock any iPhone
NSA boss: Trump won’t pull trigger for Russia election hack retaliation
Massive Malspam Campaign Targets Unpatched Systems
iTunes will no longer work on old PCs & 1st Generation Apple TV

LinuxSecurity.com: An update that solves 9 vulnerabilities and has 40 fixes is now available.