Menu

Category Archives: Security

Articles about security

You never walk alone: The SideWalk backdoor gets a Linux variant

ESET researchers have uncovered another tool in the already extensive arsenal of the SparklingGoblin APT group: a Linux variant of the SideWalk backdoor The post You never walk alone: The SideWalk backdoor gets a Linux variant appeared first on WeLiveSecurity

Ex-Broadcom engineer asks for house arrest over IP theft
Building the barricades against identity-based attacks
Iran steps up its cybercrime game and Uncle Sam punches back
What You Need to Know when Considering a VPN on Linux
What Are Checksums & Why Should You Be Using Them?
Debian GNU/Linux 11.5 Bullseye Released with 53 Security Updates and 58 Bug Fixes
Coding Vulnerabilities, Linux Growth, FOSS Friction Cap Summer Highlights

It was found that GLib, a general-purpose portable utility library, could be used to print partial contents from arbitrary files. This could be exploited from setuid binaries linking to GLib for information disclosure of files with a specific format.

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Third‑party cookies: How they work and how to stop them from tracking you across the web

Cross-site tracking cookies have a bleak future but can still cause privacy woes to unwary users The post Third‑party cookies: How they work and how to stop them from tracking you across the web appeared first on WeLiveSecurity

SparklingGoblin deploys new Linux backdoor – Week in security, special edition

ESET Research first spotted this variant of the SideWalk backdoor in the network of a Hong Kong university in February 2021 The post SparklingGoblin deploys new Linux backdoor – Week in security, special edition appeared first on WeLiveSecurity

WordPress-powered sites backdoored after FishPig suffers supply chain attack
Smashing Security podcast #289: Printer peeves, health data hangups, and Twitter tussles – with Rory Cellan-Jones
White House to tech world: Promise you’ll write secure code – or Feds won’t use it

security update

Nearly one in two industry pros scaled back open source use over security fears
Why is my Wi‑Fi slow and how do I make it faster?

Has your Wi-Fi speed slowed down to a crawl? Here are some of the possible reasons along with a few quick fixes to speed things up. The post Why is my Wi‑Fi slow and how do I make it faster? appeared first on WeLiveSecurity

AutoRabit launches devsecops tool for Salesforce environments

An update that solves 15 vulnerabilities and has 11 fixes is now available.

Patch now! Microsoft issues critical security updates as PCs attacked through zero-day flaw
Google and Meta fined over $70m for privacy violations in Korea

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Several security issues were fixed in WebKitGTK.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Ransomware gang threatens 1m-plus medical record leak
Twitter whistleblower Zatko disses bird site as dysfunctional data dump
Microsoft fixes Windows security hole likely widely exploited by miscreants
Patch your Mitel VoIP systems, Lorenz ransomware gang is back on the prowl
ESET Research uncovers new APT group Worok – Week in security with Tony Anscombe

Worok takes aim at various high-profile organizations that operate in multiple sectors and are located primarily in Asia The post ESET Research uncovers new APT group Worok – Week in security with Tony Anscombe appeared first on WeLiveSecurity

How to get inside the mind of hackers
Shadow IT and shadow IoT
One month after Black Hat exposure HP enterprise kit still unpatched
Rust programming language gains dedicated security team
Cisco: Yes, Yanluowang leaked our data. No, it’s not serious

Girl Scouts is proven to help girls thrive. A Girl Scout develops a strong sense of self, displays positive values, seeks challenges and learns from setbacks. I had the absolute honor of spending 3 days with the Girl Scouts in Chicago at the annual Camp CEO. Camp CEO is a chance for the Girl Scouts […]

Chinese-linked cyber crims nab $529 million from Indian nationals
Apple patches iPhone and macOS flaws under active attack

security update

Google Cloud closes $5.4b Mandiant acquisition
Security pros get ability to manually add incidents to Microsoft Sentinel
Reducing the risk of ransomware
Boffins build microphone safety kit to detect eavesdroppers
Retbleed fix slugs Linux VM performance by up to 70 percent
Uncle Sam sanctions Iran’s intel agency over Albanian cyberattack
Shape-shifting cryptominer savaging Linux endpoints and IoT
Data tracking poses a ‘national security risk’ FTC told
Feds freeze $30m in cryptocurrency stolen from Axie Infinity
Meta disbands Responsible Innovation team, spreads it out over Facebook and co
Toys behaving badly: How parents can protect their family from IoT threats

It pays to do some research before taking a leap into the world of internet-connected toys The post Toys behaving badly: How parents can protect their family from IoT threats appeared first on WeLiveSecurity

Regional restrictions on NFL game broadcasts and rising membership fees on streaming sites like Netflix, Hulu, and Disney Plus are just some reasons why frustrated consumers turn to illegal streaming sites. Marketed as an alternative to legitimate streaming services, illegal streaming sites have become a portal to connect criminals directly to you (their target). Unlike […]

US seeks standards dominance, lets Huawei access previously forbidden crypto tech
Dump these small-biz routers, says Cisco, because we won’t patch their flawed VPN
Mandiant ‘highly confident’ foreign cyberspies will target US midterm elections
Google urges open source community to fuzz test code
RDP on the radar: An up‑close view of evolving remote access threats

Misconfigured remote access services continue to give bad actors an easy access path to company networks – here’s how you can minimize your exposure to attacks misusing Remote Desktop Protocol The post RDP on the radar: An up‑close view of evolving remote access threats appeared first on WeLiveSecurity

Warning issued about Vice Society ransomware gang after attacks on schools
Private equity suits at Thoma Bravo pull out of Darktrace acquisition
Lazarus Group unleashed a MagicRAT to spy on energy providers
Red Hat extends Common Vulnerabilities and Exposure Program expertise as newly-minted Root organization
Essential Guide to Securing Node.JS Applications
What’s the secret behind a secure password?
Halfords slapped on wrist for breaching email marketing laws
DoJ charges pair over China-linked attempt to build semi-autonomous crypto haven on nuked Pacific atoll
Smashing Security podcast #288: Chiquita banana, dumb criminals, and detecting ring binders

security update

security update

security update

Golang adds vulnerability management tooling
Ransomware protection from the top drawer
US school year opens with reading, writing, and ransomware
Worok: The big picture

Focused mostly on Asia, this new cyberespionage group uses undocumented tools, including steganographically extracting PowerShell payloads from PNG files The post Worok: The big picture appeared first on WeLiveSecurity

Massive hotel group IHG struck by cyberattack which disrupts booking systems
Mandiant links APT42 to Iranian ‘terrorist org’
QNAP tells NAS users to “take immediate action” after new wave of DeadBolt ransomware attacks
Cybercriminals target games popular with kids to distribute malware
As Cybersecurity Week begins, Beijing claims US attacked Uni doing military research
Pakistan politicians label government cybersecurity team ‘incompetent’

security update

Go programming language arrives at security warnings that are useful
Cyberattack brings down InterContinental Hotels’ booking systems
Ransomware gang hits second-largest US school district
Newly discovered cyberspy crew targets Asian governments and corporations
Unhappy about excluding nation-state attacks from cyberinsurance? Get ready to pay
Maximum protection against hostile incursions
NATO investigates after criminals claim to be selling its stolen missile plans
Microsoft mistakenly rated Chromium, Electron, as malware
China orders tech companies to ‘improve traceability’ of users to control ‘rumours and false information’
Will cyber‑insurance pay out? – Week in security with Tony Anscombe

What if your organization is hit by a cyberattack that is attributed to a nation state? Would your insurance cover the costs of the attack? The post Will cyber‑insurance pay out? – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Google, YouTube ban election trolls ahead of US midterms

security update

Convicted felon busted for 3D printing gun parts
Revealed: US telcos admit to storing, handing over location data
Indian court directs chat app Telegram to disclose details of copyright infringers