Menu

Category Archives: All

Everything

Survey shows sloppy password habits among young Brits

Young people were singled out as increasingly likely victims of internet-borne fraud, including because of their penchant for liberal sharing of personal information. The post Survey shows sloppy password habits among young Brits appeared first on WeLiveSecurity

How one guy could have taken over any Tinder account (but didn’t)
Tesla cryptojacked by currency miners
LA Times homicide website throttles cryptojacking attack
Friendly warnings left in unsecured Amazon S3 buckets which expose private data
Another baby monitor is allowing strangers to spy on children

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: An update for rh-maven35-jackson-databind is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

uTorrent file-swappers urged to upgrade after PC hijack flaws fixed
Hey, you. App dev. You like secure software? Let’s learn from Tinder, Facebook’s blunders
Smashing Security #066: Passwords, pirates, and postcards

LinuxSecurity.com: The package strongswan before version 5.6.2-1 is vulnerable to denial of service.

Guys, you’re killing us! LA Times homicide site hacked to mine crypto-coins on netizens’ PCs

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Guess who else Spectre is haunting? Yes, it’s AMD. Four class-action CPU flaw lawsuits filed
uTorrent Users Warned of Remote Code Execution Vulnerability
Intel Issues Updated Spectre Firmware Fixes For Newer Processors
Life-saving Pacemakers, Defibrillators Can Be Hacked and Turned Off
New BEC Spam Campaign Targets Fortune 500 Businesses
Cyber Aware – are passwords past it? (Hint: no.) [VIDEO]
Coldroot Mac Malware Silently Performs System-Wide Keylogging

LinuxSecurity.com: Security fix for CVE-2018-6942.

LinuxSecurity.com: New upstream release, including security fixes for CVE-2016-10713, CVE-2018-6951, CVE-2018-6952.

“Wire bank transfer” malware phishing scam hits SWIFT banking system
Intel hurls Spectre 2 microcode patch fix at world
Apple defuses ‘text bomb’ bug

A number of text-based apps crashed, became unresponsive or entered an endless bootloop when attempting to show the otherwise little-used character from a language that is spoken by some 75 million people. The post Apple defuses ‘text bomb’ bug appeared first on WeLiveSecurity

JDK approach to address deserialization Vulnerability
Is your child a victim of identity theft?
Flight simulator comes bundled with password stealing stowaway
World’s cyber attacks hit us much harder in past year – major infosec chief survey
Artificial intelligence reads privacy policies so you don’t have to
Read the 200,000 Russian Troll tweets Twitter deleted
Bad news: 43% of login attempts ‘malicious’ Good news: Er, umm…
Hackers Compromise Tesla Cloud Server to Mine Cryptocurrency

LinuxSecurity.com: It was discovered that there was a uncontrolled memory allocation issue in zziplib, a ZIP archive library. Remote attackers could leverage this vulnerability to cause a denial of service via a specially-crafted file.

Flight Sim Labs’ ‘Heavy Handed’ Anti-Piracy Tactics Raise Hackles

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

security update

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that solves 10 vulnerabilities and has two fixes is now available.

Hackers Exploite Tegra Chipset Flaw to Run Linux OS on Nintendo Switch
Flight Sim Lab installed Chrome passwords stealer in piracy check tool
Cybercrime weighs most heavily on financial service firms

A further breakdown of the overall figures shows that, in all, the actual cost hinges on a number of variables. The factors that enter heavily into the equation include attack types and their frequency, along with the organization’s size and even the country in which an organization is based. The post Cybercrime weighs most heavily […]

Facebook SMS spam risks spoiling adoption of 2FA
Year-Old Coldroot RAT Targets MacOS, Still Evades Detection
Facebook to verify election ad buyers by snail mail
UK local gov: 37 cyber attacks a minute but little mandatory training
Apple fixes that “1 character to crash your Mac and iPhone” bug

The way people shop has changed drastically over the last 10 years. E-commerce continues to boom. In fact, 80% of Americans made an online purchase in the past month, according to the Omni-Channel Retail Report from BigEcommerce. Because what’s not to love about shopping online, receiving your items in just two days, and not having […]

Apple fixes ‘killer text bomb’ vulnerability with new update for iOS, macOS, watchOS, and tvOS
Facebook told to stop tracking users that aren’t logged in
Oracle open-sources DTrace under the GPL
Year-old vuln turns Jenkins servers into Monero mining slaves

LinuxSecurity.com: A vulnerability has been found in Ruby which may allow for arbitrary command execution.

LinuxSecurity.com: A vulnerability in LibreOffice might allow remote attackers to read arbitrary files.

LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities were found in MySQL, the worst of which may allow remote execution of arbitrary code.

Google reveals Edge bug that Microsoft has had trouble fixing

LinuxSecurity.com: An update that solves 9 vulnerabilities and has 44 fixes is now available.

Dark Web’s worst pedophile sentenced to 32 years in prison

LinuxSecurity.com: Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the execution of arbitrary code.

LinuxSecurity.com: Several security issues have been corrected in multiple demuxers and decoders of the libav multimedia library. A full list of the changes is available at https://git.libav.org/?p=libav.git;a=blob;f=Changelog;hb=refs/tags/v11.12

LinuxSecurity.com: Bind could be made to crash if it received specially crafted network traffic.

Hackers made $3M on Jenkins server in one of biggest mining ops ever
Google drops new Edge zero-day as Microsoft misses 90-day deadline
Critical macOS Sierra disk image flaw leads to data loss
Millions bagged in two bank cyber-heists

This hack is said to be reminiscent of a particularly brazen bank cyber-heist from February 2016, in which hackers successfully pilfered $81 million from the account of the central bank of Bangladesh at the Federal Reserve Bank of New York. The post Millions bagged in two bank cyber-heists appeared first on WeLiveSecurity

‘Killer text bomb’ crashes iPhones, iPads, Macs, and Apple Watches
5 Proven Cyber Security Certifications That Will Boost Your Salary in 2018
Broadband network plagued by wheezy old cryptomining gadget
US and UK condemn Russia for NotPetya worm attack
Hackers sentenced for SQL injections that cost $300 million

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Ransomware: Do you pay the ransom? | Salted Hash Ep 19
Crims pull another SWIFT-ie, Indian bank stung for nearly US$2m
Australia’s new insta-pay scheme has insta-lookup of any user’s phone number
Hacker erase 1 terabyte of data from spyware developers server
Austria seeks Interpol’s help to bust Bitcoin scammers who stole $115M

security update

Monero Mining Malware Infecting Android Smart TVs & Smartphones
TrickBot Variant Steals Bitcoin by Hijacking Cryptocurrency Transactions
Man admits hacking former employer’s computer system for revenge
Global security crackdown, a host of code nasties, Brit cops mocked, and more
New EU Privacy Law May Weaken Security
Meltdown-Spectre flaws: We’ve found new attack variants, say researchers
Raw sockets backdoor gives attackers complete control of some Linux servers
Hands up who HASN’T sued Intel over Spectre, Meltdown chip flaws

security update

security update

LinuxSecurity.com: Several vulnerabilities have been discovered in Quagga, a routing daemon. The Common Vulnerabilities and Exposures project identifies the following issues:

LinuxSecurity.com: Krzysztof Sieluzycki discovered that the notifier for removable devices in the KDE Plasma workspace performed insufficient sanitisation of FAT/VFAT volume labels, which could result in the execution of arbitrary shell commands if a removable device with a malformed disk label is

LinuxSecurity.com: BIND, a DNS server implementation, was found to be vulnerable to a denial of service flaw was found in the handling of DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly with an

119,000 FedEx users​ ​passports, security ID & driving licenses exposed

security update

Mueller bombshell: 13 Russian ‘troll factory’ staffers charged with allegedly meddling in US presidential election
Apple Rushes Fix for Latest ‘Text Bomb’ Bug As Abuse Spreads

LinuxSecurity.com: The package irssi before version 1.1.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.