Menu

Category Archives: Security

Articles about security

How To Tell If Your Linux Server Has Been Compromised
Another Cyberattack Spotted Targeting Mideast Critical Infrastructure Organizations
Massive leak exposes data on 123 million US households
What does revoking Net Neutrality mean for security?

Imagine the scenario where an Internet Service Provider (ISP) allows a security company providing malware protection the option to pay for their traffic to be prioritized and a lower the priority level imposed on all other providers. The post What does revoking Net Neutrality mean for security? appeared first on WeLiveSecurity

How much will Britain’s next F-35s cost? Not telling, says MoD
Fooling Windows 10 facial authentication with a photo
Euro ransomware probe: Five Romanians cuffed
EMC admin? Plug this hole before the holidays
Infosec controls relaxed a little after latest Wassenaar meeting
Hackers leak personal videos of WWE Diva Paige

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: Francesco Sirocco discovered a flaw in otrs2, the Open Ticket Request System, which could result in session information disclosure when cookie support is disabled. A remote attacker can take advantage of this flaw to take over an agent’s session if the agent is tricked into clicking a

LinuxSecurity.com: Marcin Noga discovered two vulnerabilities in LibreOffice, which could result in the execution of arbitrary code if a malformed PPT or DOC document is opened.

LinuxSecurity.com: CVE-2017-17432 It was discovered that malformed jumbogram packets could result in denial of service against OpenAFS, an implementation of the Andrew

Sensitive Data of 123 Million American Households Exposed​

LinuxSecurity.com: Francesco Sirocco discovered a flaw in otrs2, the Open Ticket Request System, which could result in session information disclosure when cookie support is disabled. A remote attacker can take advantage of this flaw to take over an agent’s session if the agent is tricked into clicking a

CHM Help Files Deliver Brazilian Banking Trojan

LinuxSecurity.com: An update that solves 32 vulnerabilities and has one errata An update that solves 32 vulnerabilities and has one errata An update that solves 32 vulnerabilities and has one errata is now available. is now available.

LinuxSecurity.com: An update that fixes 26 vulnerabilities is now available. An update that fixes 26 vulnerabilities is now available. An update that fixes 26 vulnerabilities is now available.

Once your home WiFi network is up and running and your family’s devices are connected, it’s normal to turn a blind eye to your router. After all, it’s mostly out of sight and out of mind. Unfortunately, that small, seemingly harmless box isn’t as secure as you may think. Your router is your gateway to […]

New Cryptocurrency Mining Scheme Uses NSA Exploits EternalBlue & EternalSynergy
UK teen dodges jail time for role in DDoSes on Natwest, Amazon and more
AnubisSpy Malware: Stealing photos, videos & spying on Android users
Bolt Will Tackle Thunderbolt 3 Security on Linux
Linux Privilege Escalation – Tradecraft Security Weekly

LinuxSecurity.com: New ruby packages are available for Slackware 14.2 and -current to fix a security issue.

Ghostery, uBlock lead the anti-track pack
Windows 10 Hello face recognition can be fooled with photos
WordPress captcha plugin on 300,000 sites had a sneaky backdoor
Youbit Bitcoin exchange quits operation after 2 hacks in 8 months
U.S. Government Blames North Korea for WannaCry

Risk Level: Very Low. Type: Trojan.

Adventures in cybersecurity research: risk, cultural theory, and the white male effect – part 1

Again and again we have seen security breaches occur because people did not heed advice that we and other people with expertise in security have been disseminating for years, advice about secure system design, secure system operation, and appropriate security strategy. The post Adventures in cybersecurity research: risk, cultural theory, and the white male effect […]

TalkTalk banbans TeamTeamviewerviewer againagain
Project Zero Chains Bugs for ‘aPAColypse Now’ Attack on Windows 10
New Android Malware Loapi Attacks Phones in Five Different Ways
Foreign Office confirms WannaCry culprit: It woz the Norks wot done it
Why we should fight for Net Neutrality

Granting ISPs the right to shape traffic, allowing for some traffic to be prioritized due to a commercial agreement, may have a negative effect on the outcome of using the service for both the consumer and the company providing the service. The post Why we should fight for Net Neutrality appeared first on WeLiveSecurity

HMS Queen Elizabeth has sprung a leak and everyone’s all a-tizzy

LinuxSecurity.com: An update that fixes 15 vulnerabilities is now available. An update that fixes 15 vulnerabilities is now available. An update that fixes 15 vulnerabilities is now available.

LinuxSecurity.com: An update for rh-ruby24-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Android trojan has miner so aggressive it can bork your battery
Alleged Uber black ops lawyer would rather not have his Xmas holiday ruined by Waymo, ta
Hackers using Google Adwords & Google Sites to spread malware

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

SCOLD WAR: Kaspersky drags Uncle Sam into court to battle AV ban

LinuxSecurity.com: Fix for CVE-2017-1000158

security update

security update

security update

LinuxSecurity.com: An update for cfme, cfme-appliance, and cfme-gemset is now available for CloudForms Management Engine 5.7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

User ‘Gross Negligence’ Leaves Hundreds of Lexmark Printers Open to Attack
Bitcoin FOMO or FOJI?
Two critical and unpatched flaws identified in vBulletin
30% off APC 1500VA Compact UPS Battery Backup & Surge Protector
Zero Trust networks and enterprise security strategy | Salted Hash Ep 12
Bitfinex cryptocurrency exchange hit by “heavy DDoS” attack again
Malware Decompiler Tool Goes Open Source
Firefox users are ticked after Mozilla secretly installed Mr. Robot add-on

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Windows 10 bundles a briefly vulnerable password manager
No hack needed: Anonymisation beaten with a dash of SQL
Chinese woman unlocks colleague’s iPhone X through Face ID

LinuxSecurity.com: It was discovered that there was a command-injection vulnerability in kildclient, a “MUD” multiplayer real-time virtual world game. For Debian 7 “Wheezy”, this issue has been fixed in kildclient version

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

Lazarus group conducting malware attacks to steal Bitcoins

security update

Russian oil pipeline computer hacked to mine Monero coins

LinuxSecurity.com: The package tor before version 0.3.1.9-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

LinuxSecurity.com: The package openssl-1.0 before version 1.0.2.m-1 is vulnerable to multiple issues including information disclosure and denial of service.

LinuxSecurity.com: The package chromium before version 63.0.3239.108-1 is vulnerable to cross-site scripting.

Dune! Game App Leaking Sensitive Data of Millions of Android Users
Keeper Password Manager in Windows 10 Exposed Saved Passwords
Hackers steal 19M California voter records after holding database for ransom
Everything you need to know about virtual private networks (VPN)

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update is now available for JBoss Core Services on RHEL 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update is now available for JBoss Core Services on RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update is now available for Red Hat JBoss Core Services. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Merry Xmas, fellow code nerds: Avast open-sources decompiler

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

IDG Contributor Network: 3 predictions for devsecops in 2018
New OSX.Pirrit Malware floods Mac devices with ads; spies on users

LinuxSecurity.com: Reportbug, a tool designed to make the reporting of bugs in Debian easier, was further enhanced to automatically detect bug reports for potential regressions caused by a security update. After user confirmation an additional email with a copy of the report will be

LinuxSecurity.com: It was discovered that there was a vulnerability in sensible-browser, a utility to start the most suitable web browser based on your environment or configuration.

Triton Malware Targets Industrial Control Systems in Middle East
Hackers Deploy Triton Malware to Shut Down Power Station
New tool exposes websites that have suffered data breaches
We need to talk about mathematical backdoors in encryption algorithms
Business Email Compromise scammer sentenced to 41 months in prison
Russia could chop vital undersea web cables, warns Brit military chief

LinuxSecurity.com: An erlang TLS server configured with cipher suites using RSA key exchange, may be vulnerable to an Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) against RSA, which when exploited, may result in plaintext recovery of encrypted messages and/or a Man-in-the-middle (MiTM)

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.