Menu

Category Archives: Security

Articles about security

The Most Exciting Linux Kernel Stories Of 2017
FCC Chair Ajit Pai Falsely Claims Killing Net Neutrality Will Help Sick and Disabled People
Sloppy coding + huge PSD2 changes = Lots of late nights for banking devs next year

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any questions? Just ask. PayPal Plagued by Phishing Emails Recently, many PayPal users have received emails about a fake transaction failure […]

LinuxSecurity.com: It was discovered that the TLS server in Erlang is vulnerable to an adaptive chosen ciphertext attack against RSA keys. For the oldstable distribution (jessie), this problem has been fixed

VMware and Carbon Black: you complete me, no you complete me

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: An update for rh-postgresql95-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for rh-postgresql96-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for postgresql is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for rh-postgresql94-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Several security issues were fixed in the kernel.

security update

Security industry needs to be less trusting to get more secure
More than 5,000 WordPress websites plagued with Keylogger
Oops! This Android keyboard app accidentally leaked 31 million users’ personal details
Apple gets around to patching all the other High Sierra security holes
Banking Apps Found Vulnerable to MITM Attacks

LinuxSecurity.com: An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Worm.

Process Doppelgänging attack affects all Windows version & evades AV products
HMS Queen Lizzie formally joins the Royal Navy
Virtual keyboard app exposes personal data of 31 million users

The developer’s keyboard apps boast 40 million users across Android and iOS, but “only” Android users were affected by the security lapse. The post Virtual keyboard app exposes personal data of 31 million users appeared first on WeLiveSecurity

Toucan play that game: Talking toy bird hacked
Smashing Security podcast #056: Peeping Toms, prison hacks, and parliamentary passwords

LinuxSecurity.com: George Shuklin from servers.com discovered that Nova, a cloud computing fabric controller, did not correctly enforce its image- or hosts-filters. This allowed an authenticated user to bypass those filters by simply rebuilding an instance.

LinuxSecurity.com: Michael Eder and Thomas Kittel discovered that Heimdal, an implementation of Kerberos 5 that aims to be compatible with MIT Kerberos, did not correctly handle ASN.1 data. This would allow an unauthenticated remote attacker to cause a denial of service (crash of

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.4, Red Hat OpenShift Container Platform 3.5, and Red Hat OpenShift Container Platform 3.6. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

Cryptocurrency mining market NiceHash hacked; $67m might be stolen
NiceHash diced up by hackers, thousands of Bitcoin pilfered
Ashley Madison Found Leaking Private & Explicit Photos of Users

LinuxSecurity.com: An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now available. errata is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now available. errata is now available.

Google Patches Critical Encryption Bug Impacting Pixel, Nexus Phones

LinuxSecurity.com: curl could be made to crash if it received specially crafted input.

LinuxSecurity.com: An update for liblouis is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: libxml2 could be made to crash if it opened a specially craftedfile.

As the holiday season kicks into high gear, keep in mind that shoppers are at an even higher risk of cyberattacks during this time of year. Salesforce projects that mobile users will account for 60 percent of traffic to retail sites around the globe this year. With the increased popularity of shopping on the go, […]

Intel Management Engine pwned by buffer overflow
Former US State Department cyber man: We didn’t see the Russian threat coming
Satori botnet rears its head, exploiting IoT vulnerabilities
Cryptocurrency exchange Bitfinex plagued by DDoS attacks

The cast of characters behind the attacks, or their motives, are unclear. However, the onslaughts come at a time when the bitcoin price hits new highs, possibly triggering efforts on the part of cybercriminals to manipulate and cash in on the price. The post Cryptocurrency exchange Bitfinex plagued by DDoS attacks appeared first on WeLiveSecurity

TeamViewer Vulnerability Lets Attackers Take Full Control of PCs
Six things to consider before implementing an ISMS

These factors can be key to the success or failure of the ISMS implementation, due to the day-to-day activities in the organization and the resources required for system operation. The post Six things to consider before implementing an ISMS appeared first on WeLiveSecurity

Google and pals rush to repair Android dev tools, block backdoor risks
Build a Privacy-respecting and Threat-blocking DNS Server
DR.CHECKER – A Soundy Vulnerability Detection Tool for Linux Kernel Drivers
BoopSuite – A Suite of Tools for Wireless Auditing and Security Testing
Deception: Why It’s Not Just Another Honeypot
Naked rowers calendar hit by denial-of-service attack following Russia ‘ban’

LinuxSecurity.com: Several security issues were fixed in linux-firmware.

Mailsploit: It’s 2017, and you can spoof the ‘from’ in email to fool filters
Beware the IDEs of Android: three biggies have vulnerabilities

LinuxSecurity.com: An update that fixes 7 vulnerabilities is now available. An update that fixes 7 vulnerabilities is now available. An update that fixes 7 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

Keyboard app caught collecting users data after 31M records leaked online

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update that solves four vulnerabilities and has two An update that solves four vulnerabilities and has two An update that solves four vulnerabilities and has two fixes is now available. fixes is now available.

TeamViewer Rushes Fix for Permissions Bug
Data-slurping keyboard app makes Mongo mistake with user data

What if cybercriminals could generate money from victims without ever delivering malware to their systems? That’s exactly what a new phenomenon called “cryptojacking” entails, and it’s been gaining momentum since CoinHive first debuted the mining JavaScript a few months ago. The intended purpose: whenever a user visits a site that is running this script, the […]

Authorities dismantle Andromeda Botnet that infected millions of devices
Developers Targeted in ‘ParseDroid’ PoC Attack

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Brit bank Barclays’ Kaspersky Lab diss: It’s cyber balkanisation, hiss infosec bods
ISF predicts increasing impact of data breaches next year

The association expects the increased costs incurred in security breaches to come both from traditional areas, such as network cleanup and customer notification, and newer areas such as litigation. The post ISF predicts increasing impact of data breaches next year appeared first on WeLiveSecurity

Once again, UK doesn’t rule out buying F-35A fighter jets
How a hack almost sprung a prisoner out of jail
Modern-day ‘Ferris Bueller’ hacks school, changes grades, applies to Ivy League colleges
DJI drones likely spying for China, claims leaked intelligence bulletin
Turns out Leakbase can keep a secret: It has shut down with zero info
Google prepares 47 Android bug fixes, ten of them rated Critical

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Infosys names a new CEO: welcome to the hot-seat Salil S. Parekh
Dentist-turned bug-biter given a taste of freedom

LinuxSecurity.com: An update for sssd is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Man hacks prison computers & alters records for pal’s early release
International team takes down virus-spewing Andromeda botnet
SEC’s cyber-cops cyber-file cyber-first cyber-fraud cyber-charges

LinuxSecurity.com: This is the final notification for the retirement of Red Hat Enterprise Linux 7.2 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 7.2.

Malware display fake BSOD to sell phony Windows anti-virus for $25

LinuxSecurity.com: Security fix for CVE-2017-1000158

Prison hacker who tried to free friend now likely to join him inside
Google Cracks Down On Nosy Android Apps

security update

LinuxSecurity.com: Update to latest releases

LinuxSecurity.com: Update to latest releases

ESET helps law enforcement worldwide to disrupt Gamarue botnet

Throughout its monitoring of the threat, ESET found dozens of C&C servers every month. The bulk of ESET’s research was conducted late last year, with the peak of Wauchos’s activity going back approximately to that time. The post ESET helps law enforcement worldwide to disrupt Gamarue botnet appeared first on WeLiveSecurity

ESET takes part in global operation to disrupt Gamarue

Wauchos is an extensible bot that allows its owner to create and use custom plugins. However, there are some plugins that are widely available and that are used by many different botnets. The post ESET takes part in global operation to disrupt Gamarue appeared first on WeLiveSecurity

PayPal’s TIO Networks breach affects millions of customers
Ursnif Trojan Adopts New Code Injection Technique
Data Breach Index Website “Leakbase” Shut Down
Creepy Cayla doll violates liberté publique, screams French data protection agency
Office 365 phishing examples | Salted Hash Ep 10
Damian Green: Not only my workstation – mystery pr0n all over Parliamentary PCs
Brit MP Dorries: I gave my staff the, um, green light to use my login
The lax computer security of British MPs – as detailed in their own tweets