Menu

Category Archives: Security

Articles about security

John McAfee’ Twitter account hack: “Most likely my phone was compromised”
2018 Security Predictions – Double Up on Linux Attacks
New ibm linux-only mainframe delivers breakthrough security for next-gen applications
Introduction to GPG Encryption and git-crypt
One Small Step to Harden USB Over IP on Linux
Kubernetes, standardization, and security dominated 2017 Linux container news
Hackers Can Rickroll Thousands of Sonos and Bose Speakers Over the Internet
Best practices when running Node.js with port 80 (Ubuntu / Linode)
How to Generate CSR (Certificate Signing Request) in Linux
The state of Linux security in 2017
Gaps in software slowing down security professionals
FreeBSD-Based TrueOS 17.12 Focuses on Faster Boot, Bhyve and LibreSSL Support
The hacks that left us exposed in 2017

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any questions? Just ask. WordPress Backdoor Found on Over 300,000 Machines Recently, researchers found a WordPress plugin containing a backdoor that […]

My Twitter was hacked, claims John McAfee
EA servers down; Battlefield 1, Battlefront 2, Star Wars & FIFA 18 Affected
Sound Waves can Help Hackers Disrupt Functions of Hard Disk Drives
Code Used in Zero Day Huawei Router Attack Made Public

LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 14 vulnerabilities is now available. An update that fixes 14 vulnerabilities is now available. An update that fixes 14 vulnerabilities is now available.

Bose & Sonos Smart Speakers can be Hacked to Play Disturbing Sounds

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Cybersecurity review of 2017: The year of wake-up calls – part 2

Courtesy of its highly customizable nature – along with its ability to persist in the system and to provide valuable information for fine-tuning the highly configurable payloads – the malware can be adapted for attacks against any environment, making it extremely dangerous. The post Cybersecurity review of 2017: The year of wake-up calls – part […]

LinuxSecurity.com: This update fixes several vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or the execution of arbitrary code if malformed image files are processed.

LinuxSecurity.com: Patch for CVE-2016-6328

LinuxSecurity.com: This update addresses the following vulnerabilities: * [CVE-2017-13866](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13866), [CVE-2017-13870](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13870), [CVE-2017-7156](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7156), [CVE-2017-13856](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13856)

LinuxSecurity.com: Update to upstream 14.7.4 release to address AST-2017-012 security issue —- Update to upstream 14.7.3 release for security alert AST-2017-013 —- Update to upstream 14.7.2 release for bug fixes

LinuxSecurity.com: Update to version 0.0.11, see http://metadata.ftp- master.debian.org/changelogs/main/s/sensible-utils/sensible- utils_0.0.11_changelog for details.

LinuxSecurity.com: Disable SSHv1 options.

Leaky RootsWeb Server Exposes Some Ancestry.com User Data

LinuxSecurity.com: Update to 0.8.3, fixing CVE-2017-15612 and CVE-2017-16876

Ancestry.com’ RootsWeb breach: 300,000 plaintext accounts leaked

LinuxSecurity.com: Multiple security issues have been found in the Mozilla Thunderbird mail client including information leaks, unintended JavaScript execution and sender address spoofing.

LinuxSecurity.com: Update to version 0.0.11, see http://metadata.ftp- master.debian.org/changelogs/main/s/sensible-utils/sensible- utils_0.0.11_changelog for details.

LinuxSecurity.com: Update to upstream 13.18.4 release to address AST-2017-012/CVE-2017-17664 security issue

LinuxSecurity.com: – update to the latest upstream pre-release (fixes CVE-2017-1000211)

LinuxSecurity.com: Disable SSHv1 options.

Software used in FBI’s biometric database contains Russian code: Report
The worst passwords of the year revealed

Need a New Year’s resolution? How about this one? Start taking password security more seriously. The post The worst passwords of the year revealed appeared first on WeLiveSecurity

Cybersecurity review of 2017: The year of wake-up calls – part 1

Ransomware and data breaches remain major thorns in the sides of users and organizations across the world, often piercing their defenses without too much effort. The post Cybersecurity review of 2017: The year of wake-up calls – part 1 appeared first on WeLiveSecurity

5 Best mobile security apps in Android & iOS, Free Download
Mozilla Patches Critical Bug in Thunderbird

LinuxSecurity.com: Several vulnerabilities have been discovered in the interpreter for the Ruby language. The Common Vulnerabilities and Exposures project identifies the following problems:

LinuxSecurity.com: Several vulnerabilities have been discovered in the interpreter for the Ruby language. The Common Vulnerabilities and Exposures project identifies the following problems:

Spoofed Emails from Supposedly Corporate Printer Vendors Install Backdoor
Catelites Android Malware Poses as 2,200 Bank Apps
US Navy Tweets about Julian Assange after his account disappeared
Opera 50 Beta Version to Come with Cryptocurrency Mining Blocker
Man Arrested for Threatening Firm with Cyber Attacks for Not Hiring Him

LinuxSecurity.com: An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available.

security update

Holiday and Christmas scams users should be aware of

LinuxSecurity.com: Hanno B?ck found several buffer overflows in GIMP, the GNU Image Manipulation Program, which could lead to application crash or other unspecified behaviour if a user opened untrusted input files.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Irssi, a terminal based IRC client, which may lead to denial of service or other unspecified impact.

The 5 Common network channels used by malware
Edward Snowden’s Haven app turns your laptop into a security system

LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Lizard Squad & PoodleCorp Founder Pleads Guilty to DDoS Attacks

LinuxSecurity.com: An update that fixes 17 vulnerabilities is now available. An update that fixes 17 vulnerabilities is now available. An update that fixes 17 vulnerabilities is now available.

LinuxSecurity.com: Multiple vulnerabilities were discovered in Enigmail, an OpenPGP extension for Thunderbird, which could result in a loss of confidentiality, faked signatures, plain text leaks and denial of service. Additional information can be found under

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: Several vulnerabilities were discovered in rsync, a fast, versatile, remote (and local) file-copying tool, allowing a remote attacker to bypass intended access restrictions or cause a denial of service.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

Nissan Canada cyber attack; millions of customer accounts stolen
Huawei Router Vulnerability Used to Spread Mirai Variant

LinuxSecurity.com: New mozilla-thunderbird packages are available for Slackware 14.2 and -current to fix a security issue.

LinuxSecurity.com: An update that contains security fixes can now be installed. An update that contains security fixes can now be installed. An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that solves 32 vulnerabilities and has one errata An update that solves 32 vulnerabilities and has one errata An update that solves 32 vulnerabilities and has one errata is now available. is now available.

LinuxSecurity.com: An update that contains security fixes can now be installed. An update that contains security fixes can now be installed. An update that contains security fixes can now be installed.

security update

security update

security update

Two arrested for Hacking DC Security Cameras Before Trump Inauguration
Nissan Canada Finance Notifies 1.1 Million of Data Breach
Hackers Spreading Digmine Monero Mining Malware via Facebook
UK Foreign Sec Bojo to tell Kremlin: Stop your cyber shenanigans… or else!
Merry Christmas, UK prosecutors: Here’s a special gift… a slap from the privacy watchdog
Detecting ROBOT and other vulnerabilities using Red Hat testing tools.
Braking news: Nissan Canada hacked, up to 1.1m Canucks exposed
US capital’s surveillance cam network allegedly hijacked by Romanian ransomware suspects

LinuxSecurity.com: Hanno Boeck, Juraj Somorovsky and Craig Young discovered that the TLS implementation in Bouncy Castle is vulnerable to an adaptive chosen ciphertext attack against RSA keys.

Crooks Switch from Ransomware to Cryptocurrency Mining
Fake Bitcoin Wallet Apps Found on Google Play Store

LinuxSecurity.com: Several vulnerabilities were discovered in wordpress, a web blogging tool. The Common Vulnerabilities and Exposures project identifies the following issues.

LinuxSecurity.com: Gabriel Corona reported that sensible-browser from sensible-utils, a collection of small utilities used to sensibly select and spawn an appropriate browser, editor or pager, does not validate strings before launching the program specified by the BROWSER environment variable,

LinuxSecurity.com: Multiple vulnerabilities were discovered in Enigmail, an OpenPGP extension for Thunderbird, which could result in a loss of confidentiality, faked signatures, plain text leaks and denial of service. Additional information can be found under

security update

Get 3 Years of NordVPN Service for Just $2.75 Per Month – Holiday Deal Alert

LinuxSecurity.com: This is the One-Year notification for the retirement of Red Hat Enterprise Linux 6.7 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 6.7.

Google Play Boots 3 Fake Bitcoin Wallet Apps

Risk Level: Very Low. Type: Trojan.

EtherDelta cryptocurrency exchange hacked in fake website scam
Adventures in cybersecurity research: risk, cultural theory, and the white male effect – part 2

Armed with the cultural theory described in part one as a possible explanation for why some people do not heed expert advice, we fielded a survey that queried US adults about their attitudes to 15 different technology hazards, including six that were cyber-related. The post Adventures in cybersecurity research: risk, cultural theory, and the white […]

WordPress Captcha Plugin Contains Backdoor- 300,000 Websites at Risk
Sednit update: How Fancy Bear Spent the Year

Over the past few years the Sednit group has used various techniques to deploy their various components on targets computers. The attack usually starts with an email containing either a malicious link or malicious attachment. The post Sednit update: How Fancy Bear Spent the Year appeared first on WeLiveSecurity

Smashing Security podcast #058: Face ID, Firefox, and Windows SNAFUs, plus Bitcoin FOMO
Twitter just got more serious about two-factor authentication. Here’s how to better protect your account