Menu

Category Archives: Security

Articles about security

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Word is prone to a memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

NSA rocked after The Shadow Brokers Breach
IDG Contributor Network: KPIs for managing and optimizing devsecops success
Thousand-dollar iPhone X’s Face ID wrecked by ‘$150 3D-printed mask’
Phishing Biggest Threat to Google Account Security
New IcedID Trojan Targets US Banks
You can soon securely unlock smartphone with your “body sweat”
Homeland Security Hackers Remotely Hack Boeing 757
The Daily Mail whisks up Kaspersky fears – but where’s the meat?
New Vulnerability Exploits Antivirus Programs to Install Malware
Transparency of machine-learning algorithms is a double-edged sword

Unless companies processing citizens’ personal data fully understand the reasoning behind the decisions made based on their machine-learning models, they will find themselves between a rock and a hard place. The post Transparency of machine-learning algorithms is a double-edged sword appeared first on WeLiveSecurity

Ransomware marketplaces and the future of malware | Salted Hash Ep 6
Stop your moaning, says maker of buggy Bluetooth sex toy

LinuxSecurity.com: An update for rh-eclipse46-jackson-databind is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-eclipse47-jackson-databind is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Ride-share upstart ‘Fasten’ revealed as Hive of insecurity

Risk Level: Very Low. Type: Trojan.

Amazon moves to stop S3 buckets leaking business data

LinuxSecurity.com: Multiple vulnerabilities have been found in eGroupWare, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability was discovered in VDE which may allow local users to gain root privileges.

CopperheadOS stops updates to thwart knock-off phone floggers

security update

All it took for researchers was a mask to bypass iPhone X Face ID

LinuxSecurity.com: An update that fixes 19 vulnerabilities is now available. An update that fixes 19 vulnerabilities is now available. An update that fixes 19 vulnerabilities is now available.

LinuxSecurity.com: This update includes a rebase from 8.0.46 up to 8.0.47 which resolves a single CVE along with various other bugs/features: rhbz#1497682 CVE-2017-12617 tomcat: Remote Code Execution bypass for CVE-2017-12615

LinuxSecurity.com: This update fixes several vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or the execution of arbitrary code if malformed GIF, TTF, SVG, TIFF, PCX, JPG or SFW files

security update

Muslim Hacktivists Hack ISIS website; expose 20,000 subscribers list

LinuxSecurity.com: Multiple vulnerabilities have been found in Cacti, the worst of which could lead to the remote execution of arbitrary code.

Someone Hacked Swedish Radio Station to Play Pro-ISIS Song
26,000 blockchain projects launched in 2016, 92 percent are now dead
Researchers find almost EVERY computer with an Intel Skylake and above CPU can be owned via USB
Vault 8: WikiLeaks Releases Source Code For Hive – CIA’s Malware Control System
Manic miners, hideous hackers, frightful flaws, vibrating mock cock app shock – and more

LinuxSecurity.com: * Fix ppc64 KVM failure (bz #1501936) * CVE-2017-15038: 9p: information disclosure when reading extended attributes (bz #1499111) * CVE-2017-15268: potential memory exhaustion via websock connection to VNC (bz #1496882) —- qemu-pr-helper didn’t work due to a change in the libmultipath/libmpathpersist APIs exposed by device-mapper-multipath-devel. This has been fixed now. Other

LinuxSecurity.com: 1.6, multiple security fixes.

LinuxSecurity.com: – Update to 1.1.26 – CVE-2017-15194 Release notes: https://www.cacti.net/release_notes.php?version=1.1.26

LinuxSecurity.com: Security fix for CVE-2017-12629

LinuxSecurity.com: For changes see: https://www.mozilla.org/en-US/thunderbird/52.4.0/releasenotes/

Parity’s $280m Ethereum wallet freeze was no accident: It was a HACK, claims angry upstart
Cyberhitmen hired for sustained DDoS attacks against mans ex-employer

security update

security update

security update

security update

How did someone hijack your Gmail? Phishing, keylogger or password reuse, we’re guessing

LinuxSecurity.com: Wen Bin discovered that bchunk, an application that converts a CD image in bin/cue format into a set of iso and cdr/wav tracks files, did not properly check its input. This would allow malicious users to crash the application or potentially execute arbitrary code.

Microsoft president says the world needs a digital Geneva Convention
“Eavesdropper” Flaw Exposes Millions of Call, Texts and Recordings
AutoIt Scripting Used By Overlay Malware to Bypass AV Detection
Intel’ Management Engine Tech Just Got Exposed Through USB Ports

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. UK-Based Cryptocurrency Hit By Cyberattack Prior to the official launch of Electroneum, a UK-based cryptocurrency that […]

Threatpost News Wrap Podcast for Nov. 10
Experts share perspective on the state of journalists’ cybersafety

These days, journalists and publishers are increasingly concerned about protecting themselves, their work, and their sources. Rightfully so, for we live in a time when nearly every aspect of publishing occurs online. The post Experts share perspective on the state of journalists’ cybersafety appeared first on WeLiveSecurity

WikiLeaks drama alert: CIA forged digital certs imitating Kaspersky Lab
What to consider when deploying a next-generation firewall
Fighting persistent malware with a UEFI scanner

The biggest news in malware so far this year has been WannaCryptor a.k.a. WannaCry, and one reason that particular ransomware spread so fast was because it used a “top secret” exploit developed by the NSA, an agency known to have dabbled in UEFI compromise. The post Fighting persistent malware with a UEFI scanner appeared first […]

LinuxSecurity.com: An update that solves 29 vulnerabilities and has two fixes An update that solves 29 vulnerabilities and has two fixes An update that solves 29 vulnerabilities and has two fixes is now available. is now available.

LinuxSecurity.com: An update that solves one vulnerability and has 6 fixes is An update that solves one vulnerability and has 6 fixes is An update that solves one vulnerability and has 6 fixes is now available. now available.

LinuxSecurity.com: An update that solves 23 vulnerabilities and has 6 fixes is An update that solves 23 vulnerabilities and has 6 fixes is An update that solves 23 vulnerabilities and has 6 fixes is now available. now available.

LinuxSecurity.com: Multiple vulnerabilities have been found in libxml2, the worst of which could result in the execution of arbitrary code.

Judge bins sueball lobbed at Malwarebytes by rival antivirus maker for torpedoing its tool
WikiLeaks’ Vault 8 Leaks Show CIA Impersonated Kaspersky Lab

Risk Level: Very Low. Type: Trojan.

Learn client-server C programming – with this free tutorial from the CIA

LinuxSecurity.com: It was discovered that the pg_ctlcluster, pg_createcluster and pg_upgradecluster commands handled symbolic links insecurely which could result in local denial of service by overwriting arbitrary files.

LinuxSecurity.com: Several vulnerabilities have been found in the PostgreSQL database system: CVE-2017-15098

LinuxSecurity.com: A vulnerabilitiy has been found in the PostgreSQL database system: Denial of service and potential memory disclosure in the json_populate_recordset() and jsonb_populate_recordset() functions.

US government seizes Texas gun mass murder to demand backdoors

security update

Google just can not get rid of BankBot malware from Play Store
Eavesdropper Vulnerability Exposes Mobile Call, Text Data

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

Google Chrome will automatically block forced website redirects
Uni staffer’s health info blabbed in email list snafu
Microsoft Provides Guidance on Mitigating DDE Attacks
Windows Movie Maker Scam spreads massively due to high Google ranking

ESET detected a modified version of Windows Movie Maker that aims to collect money from unaware users. The spread has been boosted by SEO. The post Windows Movie Maker Scam spreads massively due to high Google ranking appeared first on WeLiveSecurity

Not even ordering pizza is safe from the browser crypto-mining scourge
Microsoft issues advisory to users after macro-less malware attacks
Smashing Security podcast #051: Robots, romance, passwords, and CrunchyRoll
Evil pixels: researcher demos data-theft over screen-share protocols
Microsoft pals up with partners for threat-hunting