Menu

Category Archives: Security

Articles about security

Inside Uber’s $100,000 Payment to a Hacker, and the Fallout
Are mass transit systems the next cybersecurity target? | Salted Hash Ep 14
Customers reporting credit card fraud after using OnePlus webstore
CES 2018: Why doesn’t everyone use VR already?

One side effect of slower than expected uptake of VR is that virtual reality application developers have been slow to invest in creating content. In this sort of chicken-and-egg cycle, growth tends to be slow, not explosive. The post CES 2018: Why doesn’t everyone use VR already? appeared first on WeLiveSecurity

UK.gov denies data processing framework is ‘sinister’ – but admits ICO has concerns
Meltdown/Spectre fixes made AWS CPUs cry, says SolarWinds
Hawaii’s ballistic missile false alarm and a user interface failure

LinuxSecurity.com: Multiple vulnerabilities have been found in PolarSSL, the worst of which may allow remote attackers to execute arbitrary code.

Oracle still silent on Meltdown, but lists patches for x86 servers among 233 new fixes

LinuxSecurity.com: Multiple vulnerabilities have been found in Xen, the worst of which could allow for privilege escalation.

LinuxSecurity.com: Philip Huppert discovered the Shibboleth service provider is vulnerable to impersonation attacks and information disclosure due to mishandling of DTDs in the XMLTooling XML parsing library. For additional details please refer to the upstream advisory at

LinuxSecurity.com: The package qtpass before version 1.2.1-1 is vulnerable to private key recovery.

security update

LinuxSecurity.com: Tavis Ormandy discovered a vulnerability in the Transmission BitTorrent client; insecure RPC handling between the Transmission daemon and the client interface(s) may result in the execution of arbitrary code if a user visits a malicious website while Transmission is running.

Intel puts security on the todo list, Tavis topples torrent tool, and more
Let’s Encrypt plugs hole that let miscreants grab HTTPS web certs for strangers’ domains
Feds may have to explain knowledge of security holes – if draft law comes into play
How to Protect Your Personal Data in 3 Simple Ways

LinuxSecurity.com: Rebased to 1.37.0.

Hacker demands ransom in Bitcoin after taking over hospital servers

security update

Cisco’s new tool will detect malware in encrypted traffic
Lenovo removes backdoor present in networking switches since 2004
60 Android apps for kids found infected with Pornographic malware
Fruitfly malware spied on Mac users for 13 years – man charged

LinuxSecurity.com: Philip Huppert discovered the Shibboleth service provider is vulnerable to impersonation attacks and information disclosure due to mishandling of DTDs in the XMLTooling XML parsing library. For additional details please refer to the upstream advisory at

Intel AMT Loophole Allows Hackers to Gain Control of Some PCs in Under a Minute
Attackers Exploit Oracle WebLogic Flaw to Mine $266K in Monero

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has 5 fixes is now available.

Boffins split on whether Spectre fix needs tweaked hardware
Critical Intel AMT Flaw Lets Attackers Hack Laptops in Mere Seconds
Intel AMT security locks bypassed on corp laptops – research

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst with a passion for all things security. Any questions? Just ask. Exploitable Backdoor Found in Western Digital NAS Drives Western Digital has recently released numerous patches for the vulnerabilities that were […]

Data protection is best managed from the centre
Apps Exposing Children to Porn Ads Booted From Google Play
WhatsApp Vulnerability Lets Anyone Spy on Group Chats
‘Mummy, what’s felching?’ Tot gets smut served by Android app
Malware infected fake Telegram Messenger app found in Play Store

LinuxSecurity.com: It was discovered that gifsicle, a tool for manipulating GIF image files, contained a flaw that could lead to arbitrary code execution. For the oldstable distribution (jessie), this problem has been fixed

Let’s Encrypt disables TLS-SNI-01 validation
Linux vs Meltdown: Ubuntu gets second update after first one fails to boot
FBI chief claims encryption is an ‘urgent public safety issue’
Security event in Taiwan ‘rewards’ quiz winners with malware-laden USB drives

The distribution of the USB sticks was halted on December 12 after some of the quiz’s successful entrants reported that their rewards had been flagged by their security software as containing malware. The post Security event in Taiwan ‘rewards’ quiz winners with malware-laden USB drives appeared first on WeLiveSecurity

Intel’s Meltdown fix freaked out some Broadwells, Haswells

LinuxSecurity.com: Security fix for CVE-2017-1000501

Brace yourselves for the ‘terabyte (sic) of death’, warns US army IT boss

security update

LinuxSecurity.com: A vulnerability in PySAML2 might allow remote attackers to bypass authentication.

LinuxSecurity.com: Multiple vulnerabilities have been found in TigerVNC, the worst of which may lead to arbitrary code execution.

LinuxSecurity.com: Multiple vulnerabilities have been found in icoutils, the worst of which may lead to arbitrary code execution.

LinuxSecurity.com: The package intel-ucode before version 20180108-1 is vulnerable to access restriction bypass.

Man used Fruitfly Mac malware to spy on US citizens for 13 years
House Votes to Reauthorize Controversial Spy Provision, Section 702
WhatsApp Downplays Damage of a Group Invite Bug
Everything running smoothly at the plant? *Whips out mobile phone* Wait. Nooo…
WhatsApp flaw could allow anyone to sneak into your private group chat

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Ming: CVE-2017-11732

FBI supports & blames encryption for 7,800 devices it can’t unlock
Fedora 28 Looking To Replace Glibc’s libcrypt With libxcrypt
Adobe patches information leak vulnerability
CES 2018: The price of tech is dropping, kids can do this!

Row after row of startup tech here has tiny modules designed to be mashed up into the next big thing if their founders have anything to say about it, and the trend continues. The post CES 2018: The price of tech is dropping, kids can do this! appeared first on WeLiveSecurity

Smashing Security #060: Meltdown, Spectre, and personal devices in the White House

LinuxSecurity.com: Stephan Zeisberg discovered that poco, a collection of open source C++ class libraries, did not correctly validate file paths in ZIP archives. An attacker could leverage this flaw to create or overwrite arbitrary files.

Ohio coder accused of infecting Macs, PCs with webcam, browser spyware for 13 years

security update

Risk Level: Very Low. Type: Trojan.

Android Malware written in Kotlin found on Play Store stealing data

security update

Leaky credit report biz face massive fines if US senators get their way

Type: Vulnerability. Microsoft Office is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Outlook is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Word is prone to a memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Access is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Outlook is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Word is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Word is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Word is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Word is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Word is prone to a remote code-execution vulnerability; fixes are available.

FBI Director Calls Smartphone Encryption an ‘Urgent Public Safety Issue’

Risk Level: Very Low. Type: Trojan.

Netgear’s New Gaming Router Offers Protection Against DDoS Attacks
Tank-traps versus trappings in virtual currencies: A cybersecurity minefield

Bitcoin, the progenitor of the entire cryptocurrency boom and still the most popular virtual currency, experienced a truly heady run-up in value. Its price surge was punctuated with a crescendo midway through December, when a single bitcoin approached $20,000. The post Tank-traps versus trappings in virtual currencies: A cybersecurity minefield appeared first on WeLiveSecurity

Best Encrypted Email Services for 2018
Post-hack, VTech has to pay $650,000 in FTC settlement – but doesn’t have to admit any wrongdoing

LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Taiwanese cops give malware-laden USB sticks as prizes for security quiz
Russia claims it repelled home-grown drone swarm in Syria

LinuxSecurity.com: The system could be made to expose sensitive information.

IBM’s complete Meltdown fix won’t land until mid-February
Intel, Microsoft confess: Meltdown, Spectre may slow your servers

LinuxSecurity.com: The system could be made to expose sensitive information.