Menu

Category Archives: Security

Articles about security

Office 365 Phishing Campaign Hides Malicious URLs in SharePoint Files
Defcon: 11-year-old modifies Florida Presidential voting results
ThreatList: Financial-Themed Phishing Hooks Targets in Q2
Sex extortion emails now quoting part of their victim’s phone number
Instagram users locked out of accounts en masse

If you’re an Instagrammer, you may want to take some basic precautions, such as picking a strong and unique password and signing up for two-factor authentication sooner rather than later The post Instagram users locked out of accounts en masse appeared first on WeLiveSecurity

Baddies of the internet: It’s all about dodgy mobile apps, they’re so hot right now
NHS Patient Data at Risk from Historic Breach: Report
Podcast: Bugcrowd Founder on Printer Bugs, IoT Bounty Hunting, and New VDP Project
Foreshadow and Intel SGX software attestation: ‘The whole trust model collapses’
Criminals a bit less interested in nicking Brits’ identities this year
Florida Man laundered money for Reveton ransomware. Then Microsoft hired him
Patch Tuesday heats up with pair of exploited zero-days squashed – plus 58 other vulns fixed
IDG Contributor Network: How hybrid IT impacts identity management
Patch Tuesday: Microsoft Addresses Two Zero-Days in 60-Flaw Roundup
Bad news conspiracy theorists. QAnon codes are just a guy mashing his keyboard
Victims Lose Access to Thousands of Photos as Instagram Hack Spreads

security update

Hackers manage – just – to turn Amazon Echoes into snooping devices
Intel CPUs Undermined By Fresh Speculative Execution Flaws
Oracle: Run, don’t walk, to patch this critical Database takeover bug

LinuxSecurity.com: Several security issues were fixed in libarchive.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Worm.

Risk Level: Very Low. Type: Trojan.

Microsoft Flaw Allows Full Multi-Factor Authentication Bypass
Google Services Track User Movements In Privacy Faux Pas
Three more data-leaking security holes found in Intel chips as designers swap security for speed
Millions of Android Devices At Risk of Man-in-the-disk Attack
Researchers Break IPsec VPN Connections with 20-Year-Old Protocol Flaw
Managing risk in the modern world
CVE? Nope. NVD? Nope. Serious must-patch type flaws skipping mainstream vuln lists – report
Faxploit: Hackers can use Fax machines to inject malware into a targeted network
Adobe Patch Tuesday: Fixes for Critical Acrobat and Reader Flaws
Black Hat 2018: AI was supposed to fix security – what happened?

Heralded as the answer to many cybersecurity issues, machine learning hasn’t always delivered The post Black Hat 2018: AI was supposed to fix security – what happened? appeared first on WeLiveSecurity

Black Hat Exclusive Video: The IoT Security Threat Looms for Enterprises
ThreatList: Almost All Security Pros Believe Election Systems Are at Risk
#DEFCON Vote Hacking Village Refute NASS ‘Unfair’ Claims
Butlin’s Customers Face Anxious Holiday After Breach Alert
Podcast: Black Hat and DEF CON 2018 Wrap
Pausing ‘Location history’ doesn’t stop Google tracking your location. Here’s how to stop it

LinuxSecurity.com: Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues:

May the May update be with you: OpenSSL key sniffed from radio signal
Faxploit: Retro hacking of fax machines can spread malware
Cisco patches IOS in response to boffins’ IKE-busting breakthrough
Intel finally emits Puma 1Gbps modem fixes – just as new ping-of-death bug emerges

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Risk Level: Very Low. Type: Trojan.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

security update

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

It’s official: TLS 1.3 approved as standard while spies weep

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: The package thunderbird before version 60.0-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

LinuxSecurity.com: Chris Coulson discovered a use-after-free flaw in the GNOME Display Manager, triggerable by an unprivileged user via a specially crafted sequence of D-Bus method calls, leading to denial of service or potentially the execution of arbitrary code.

New Variant of KeyPass Ransomware Discovered
Blue Team Village, DEF CON 2018 | Salted Hash Ep 43
Black Hat 2018: IoT Security Issues Will Lead to Legal ‘Feeding Frenzy’
GoDaddy Leaks ‘Map of the Internet’ via Amazon S3 Cloud Bucket Misconfig

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

DEF CON 2018: ‘Man in the Disk’ Attack Surface Affects All Android Phones
Black Hat Video Exclusive: Mobile APTs Redefining Phishing Attacks
US voting systems: Full of holes, loaded with pop music, and hacked by an 11-year-old
DEF CON 2018: Voting Hacks Prompt Push Back from Election Officials, Vendors

LinuxSecurity.com: Multiple vulnerabilities have been discovered in various parsers of Blender, a 3D modeller/ renderer. Malformed .blend model files and malformed multimedia files (AVI, BMP, HDR, CIN, IRIS, PNG, TIFF) may result in the execution of arbitrary code.

Can cramming code with bugs make it more secure? Some think so

Unbeknownst to exploit writers, the seemingly mouth-watering bugs would be bogus and non-exploitable The post Can cramming code with bugs make it more secure? Some think so appeared first on WeLiveSecurity

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has 9 fixes is now available.

Security breach in the White House’s Situation Room
PGA of America Struck By Ransomware
#DEFCON DHS Says Collaboration Needed for Secure Infrastructure and Elections
#DEFCON Government Attacks and Surveillance Continue to Increase
Criminal justice software code could send you to jail and there’s nothing you can do about it
Hackers can manipulate Police body cam footages
Prank ‘Give me a raise!’ email nearly lands sysadmin with dismissal
Former NSA top hacker names the filthy four of nation-state hacking
Black Hat: Protecting Industrial Control System

Aiming to protect critical infrastructure against attacks The post Black Hat: Protecting Industrial Control System appeared first on WeLiveSecurity

UK cyber cops: Infosec pros could help us divert teens from ‘dark side’
DEF CON 2018: Critical Bug Opens Millions of HP OfficeJet Printers to Attack
DEF CON 2018: Apple 0-Day (Re)Opens Door to ‘Synthetic’ Mouse-Click Attack
The Enigma of AI & Cybersecurity
NSA Brings Nation-State Details to DEF CON
#DEFCON L0pht Reunite to Find Security Unimproved
DEF CON 2018: Hacking Medical Protocols to Change Vital Signs