Menu

Category Archives: Security

Articles about security

security update

Advanced VPNFilter malware menacing routers worldwide
Ransomware Most Commonly Used Malicious Software: How to Protect Your Business
Mobile Fraud Soars as Social Sites Help Scammers
Brit Attorney General: Nation state cyber attack is an act of war
Malicious PHP Script Infects 2,400 Websites in the Past Week
TeenSafe Tracking App Exposes Thousands of Private Records
Roaming Mantis Swarms Globally, Spawning iOS Phishing, Cryptomining
WeLiveSecurity in running for European Security Blogger Awards. Vote now!

We’re not in it for prizes (or cakes), but there’s no denying that we’re thrilled to be a finalist for the European Security Blogger Awards – and in five categories at that! The post WeLiveSecurity in running for European Security Blogger Awards. Vote now! appeared first on WeLiveSecurity

800,000 DrayTek routers at risk of DNS hijacking attack – update your firmware!
Amazon Rekognition a possible threat to the civil rights of citizens

Use of software by law enforcement as a surveillance tool is a real concern for groups The post Amazon Rekognition a possible threat to the civil rights of citizens appeared first on WeLiveSecurity

£120,000 fine for university after details of 20,000 staff and students exposed in data breach
Big bimmer bummer: Bavaria’s BMW buggies battered by bad bugs

security update

ISP TalkTalk’s Wi-Fi passwords Walk Walk thanks to Awks Awks router security hole
Donald Trump’s smartphone security: an inconvenient truth
Intel Responds to Spectre-Like Flaw In CPUs

LinuxSecurity.com: Matthias Gerstner discovered that PackageKit, a DBus abstraction layer for simple software management tasks, contains an authentication bypass flaw allowing users without privileges to install local packages.

Turla Mosquito: A shift towards more generic tools

ESET researchers have observed a significant change in the campaign of the infamous espionage group The post Turla Mosquito: A shift towards more generic tools appeared first on WeLiveSecurity

Brit water firms, power plants with crap cyber security will pay up to £17m, peers told
14 free online courses about computer security

Get a better understanding of cybersecurity with this list of free online courses that you can take to become more cyber-aware The post 14 free online courses about computer security appeared first on WeLiveSecurity

Salted Hash – SC 01: What an Apple phishing attack looks like
Malware campaign expands to add cryptocurrency mining and iOS phishing attacks
You’ve got to be kitten: Vet recruiter told to pay £1k after pinching info from ex-employer
How deception technologies use camouflage to attract attackers | Salted Hash Ep 26
Summoners of web tsunamis have moved to layer 7, says Cloudflare

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

LinuxSecurity.com: The system could be made to expose sensitive information.

Victoria’s educational apps-for-students let creeps contact kids

LinuxSecurity.com: Side channel execution mitigations were added to QEMU.

security update

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Microsoft, Google: We’ve found a fourth data-leaking Meltdown-Spectre CPU hole
Multilingual malware hits Android devices for phishing & cryptomining

LinuxSecurity.com: Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in privilege escalation.

Penetration tester pokes six holes in Dell EMC’s RecoverPoint products
High-end router flinger DrayTek admits to zero day in bunch of Vigor kit
See me speak at the Sunny Side Up Security breakfast event in London next month
Wicked Botnet Uses Passel of Exploits to Target IoT
Greenwich uni fined £120k: Hole in computing school site leaked 20k people’s data
Best Security Podcast: “Smashing Security” up for top award
Cybersecurity training still neglected by many employers

While training employees will not guarantee complete cyber safety for companies, it could go a long way to making workers more cyber-aware The post Cybersecurity training still neglected by many employers appeared first on WeLiveSecurity

Syrian Electronic Army Members Indicted for Conspiracy

LinuxSecurity.com: An update that fixes 13 vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes 13 vulnerabilities is now available.

You are not alone; The Pirate Bay is down around the world

LinuxSecurity.com: The package libcurl-compat before version 7.60.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: The package libcurl-gnutls before version 7.60.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: The package lib32-libcurl-gnutls before version 7.60.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: The package lib32-libcurl-compat before version 7.60.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: The package lib32-curl before version 7.60.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

Someone hacked California’s live congressional debate to run gay porn

Advance notification for upcoming end-of-life for Debian 8

security update

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1414

Hurdles Remain After Senate Votes To Restore Net Neutrality
Latin American ‘Biñeros’ Bond Over Fraudulent Purchase Scheme
WiFi hacker- 10 best Android & Desktop WiFi hacking apps free download
Tech Talk: As GDPR looms, companies rush to comply
2018: Scariest Year of Evil Things on the Internet
California Teen Arrested for Phishing Teachers to Change Grades

LinuxSecurity.com: Security update for CVE-2017-17723, CVE-2017-17725, CVE-2018-5772

LinuxSecurity.com: Security update for CVE-2017-17723, CVE-2017-17725, CVE-2018-5772

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Misconfigured Reverse Proxy Servers Spill Credentials
RedDawn Espionage Campaign Shows Mobile APTs on the Rise
BYOD Threats Exposed: 61% of UK SMEs Suffer Cyber-Attacks
New Research Seeks to Shorten Attack Dwell Time
Signal bugs, car hack antics, the Adobe flaw you may have missed, and much more

security update

Threatpost News Wrap Podcast for May 18

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: Updated collectd packages are now available for Red Hat OpenStack Platform 10.0 Operational Tools for RHEL 7. Red Hat Product Security has rated this update as having a security impact of

LinuxSecurity.com: An update for sensu is now available for Red Hat OpenStack Platform 10. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives adetailed severity rating, is available for each vulnerability from

LinuxSecurity.com: Hans Jerry Illikainen discovered a type conversion vulnerability in the MP4 demuxer of the VLC media player, which could result in the execution of arbitrary code if a malformed media file is played.

Tracking firm caught leaking realtime location data of US Mobile users
TeleGrab Malware Steals Telegram Desktop Messaging Sessions, Steam Credentials
Critical Linux Flaw Opens the Door to Full Root Access
WinstarNssmMiner Monero mining malware crashes PC upon detection
Suspected Syrian Electronic Army hackers indicted for conspiracy and identity theft
Open source code is ubiquitous and so are many vulnerabilities

One-third of audited codebases that contain Apache Struts suffer from the same vulnerability that facilitated the Equifax hack a year ago The post Open source code is ubiquitous and so are many vulnerabilities appeared first on WeLiveSecurity

DHS Unveils National Cybersecurity Risk Strategy
IT Pros Worried About IoT But Not Prepared to Secure It
Tech Talk: Prepping for GDPR

LinuxSecurity.com: The package curl before version 7.60.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: Several vulnerabilities were discovered in MAD, an MPEG audio decoder library, which could result in denial of service if a malformed audio file is processed.

Man faces up to 35 years in prison for helping hackers evade detection by anti-virus software

Reading Time: ~2 min.Chili’s Restaurant Reveals Payment Card Breach In the last week, officials have discovered a data breach that affects an unknown number of the chain’s 1,600 restaurants across the country. It is believed that the breach could affect customers who visited the restaurant between March and April of this year, and likely includes […]

LocationDumb: Phone tracker foul-up exposes world+dog to tracking