Menu

Category Archives: Security

Articles about security

Cookie code compromise caper caught and crumbled

LinuxSecurity.com: Several vulnerabilities were discovered in MAD, an MPEG audio decoder library, which could result in denial of service if a malformed audio file is processed.

LinuxSecurity.com: New python packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Report: Intel Facing New Spectre-Like Security Flaws
Pr0nbot is Back – and Evading Twitter Censors
Abbott Addresses Life-Threatening Flaw in a Half-Million Pacemakers
Anti-theft software LoJack hijacked by Russian Fancy Bear group
The Pentagon bans Huawei and ZTE smartphone sales at military bases worldwide
A bug stored Twitter passwords in plain text so change your password
Twitter advises all users to change passwords after glitch

A bug exposed the passwords of an undisclosed number of users in plain text within Twitter’s internal systems The post Twitter advises all users to change passwords after glitch appeared first on WeLiveSecurity

What to do after a data breach: 5 steps to minimize risk
UK Phisher Pleads Guilty to Just Eat Scam
Yes, you should change your Twitter password – but don’t panic
How to secure SaaS: Understanding the cloud’s security layers
Google rolls out .app domains with built-in HTTPS

The move is part of the company’s HTTPS-everywhere vision for the internet The post Google rolls out .app domains with built-in HTTPS appeared first on WeLiveSecurity

Penetrate the mind of the cyber criminal at SANS London July 2018

Reading Time: ~2 min.The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Cyberattack Shuts Down Mexico Central Bank Within the past week, several payment systems associated […]

Reading Time: ~1 min.Our most recent release of the DNS Protection agent provided customers with added features and enhancements designed to improve the overall product experience and its capabilities delivered to end users. We revamped the network detection functionality to improve accuracy and speed for roaming and off-site clients who frequently change networks. We also […]

Fresh fright of data-spilling Spectre CPU design flaws haunt Intel
It’s World (Terrible) Password (Advice) Day!
4chan hackers tried changing voting results of NASA student challenge
Twitter Urges Users to Change Passwords Due to Glitch
European Space Agency wants in on quantum comms satellites
Twitter: No big deal, but everyone needs to change their password

security update

Hurry up patching those Oracle bugs: Attackers aren’t waiting
MassMiner Takes a Kitchen-Sink Approach to Cryptomining
Phone Maker BLU Settles with FTC Over Unauthorized User Data Extraction
A Look Inside: Bug Bounties and Pen Testing

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Kitty Cryptomining Malware Cashes in on Drupalgeddon 2.0
Scammers bought Twitter ads to run verified badge phishing scam
Critical Cisco WebEx Bug Allows Remote Code Execution
Kitty malware gets its claws into Drupal websites to mine Monero
Poker tournaments disrupted after DDoS attacks on Americas Cardroom

LinuxSecurity.com: It was discovered that jackson-databind, a Java library used to parse JSON and other data formats, improperly validated user input prior to deserializing because of an incomplete fix for CVE-2017-7525.

Using Docker and Windows Server Containers? There’s a patch for that
Firms running Cisco WebEx are told to update their software… again!

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

Recycling is a must, but why would you reuse your password?

World Password Day, celebrated on the first Thursday of every May, is a timely reminder of the fact that our passwords are the key to a wealth of personal information about us. The post Recycling is a must, but why would you reuse your password? appeared first on WeLiveSecurity

Free Speech Advocates Blast Amazon Over Threats Against Signal
Fedora 28 “Cutting Edge” Linux Distro Released With New Features
A critical security flaw in popular industrial software put power plants at risk
Boutique Shops Offering Rewards Points Pop Up on the Dark Web

LinuxSecurity.com: An update for rh-php70-php is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for go-toolset-7 and go-toolset-7-golang is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Quit WebEx now if you want to live! (Bad bugs, not killer slideware)
Goodbye Cambridge Analytica, hello Emerdata?
Oracle Access Manager is a terrible doorman: Get patching this bug

security update

LinuxSecurity.com: Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the execution of arbitrary code.

LinuxSecurity.com: A buffer overflow in Python might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability was discovered in hesiod which may allow remote attackers to gain root privileges.

LinuxSecurity.com: Two vulnerabilities were found in the Quassel IRC client, which could result in the execution of arbitrary code or denial of service. Note that you need to restart the ‘quasselcore’ service after upgrading

Smashing Security #076: Spying phones, hacked ski lifts, and World Password Day

LinuxSecurity.com: An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.

security update

security update

Hacktivists, Tech Giants Protest Georgia’s ‘Hack-Back’ Bill
Fancy that, Fancy Bear: LoJack anti-laptop theft tool caught phoning home to the Kremlin

LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

FacexWorm malware steals cryptocurrency & Facebook credentials
Facebook Introduces ‘Clear History’ Option Amid Data Scandal
Vlad that’s over: Remote code flaws in Schneider Electric apps whacked
Schneider Electric Patches Critical RCE Vulnerability
Hands off! Arm pitches tamper-resistant Cortex-M35-P CPU cores

LinuxSecurity.com: An update for redhat-release-virtualization-host and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update for python-paramiko is now available for Red Hat Virtualization 4 Management Agent for RHEL 7 and Red Hat Virtualization Manager 4.1. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

WiFi or Ethernet: Which is faster and which is safer?

There is a lot of debate about WiFi speeds and whether they can offer higher potential speeds than a cable connection, but in practice Ethernet connections turn out to be not only faster but also safer. The post WiFi or Ethernet: Which is faster and which is safer? appeared first on WeLiveSecurity

City of London Police Takes Cybercrime Fight to Businesses
A Quarter of UK CNI Firms Have Suffered Cyber-Attack Outages

LinuxSecurity.com: Update to 1.8.8

North Korea’s antivirus software whitelisted mystery malware

LinuxSecurity.com: Red Hat Mobile Application Platform 4.6.0 Release – Container Images 2. Description: Red Hat Mobile Application Platform (RHMAP) 4.6.0 consists of three main components:

AWS sends noise to Signal: You can’t use our servers to beat censors
Scammers using Google Maps to skirt link-shortener crackdown
A cryptocurrency platform exposed sensitive data of 25,000 users
Millions of Home Fiber Routers Vulnerable to Complete Takeover
Samples of SiliVaccine Offer Rare Peek Inside North Korea’s Antivirus Software
Volkswagen Cars Open To Remote Hacking, Researchers Warn

Risk Level: Very Low. Type: Trojan, Worm.

Tens of Thousands of Malicious Apps Using Facebook APIs
Researchers find critical security flaws in popular car models
GravityRAT malware evades detection and targets users in India
Controlling children’s use of technology: a preventive measure or an invasion of privacy?

How to use parental control apps to protect children and the fine line that exists between controlling the use of technology and invasion of privacy The post Controlling children’s use of technology: a preventive measure or an invasion of privacy? appeared first on WeLiveSecurity

Cyber Security Breaches Survey 2018
North Korea Ramps Up ‘Operation GhostSecret’ Cyber Espionage Campaign
Defending against mobile technology threats | Salted Hash Ep 24

Reading Time: ~3 min.Text messages are now a common way for people to engage with brands and services, with many now preferring texts over email. But today’s scammers have taken a liking to text messages or smishing, too, and are now targeting victims with text message scams sent via shortcodes instead of traditional email-based phishing […]

Bitcoin hijackers found at least one sucker for scam Chrome extension
USB Sticks Can Trigger BSOD – Even on a Locked Device
KRACK Vulnerability Puts Medical Devices At Risk
Failbreak: Bloke gets seven years in the clink for trying to hack his friend out of jail
Someone hacked this highway sign & defaced it with “Hail Hitler” text