Menu

Category Archives: Security

Articles about security

security update

User claims Facebook employees went through his file sent in private chat
Google Search Results Exploited to Distribute Zeus Panda Banking Trojan
Flaw in Tor Browser Leads to Leaking of Your Real IP Address
WAFNinja – Web Application Firewall Attack Tool – WAF Bypass
Unencrypted USB stick with 2.5GB of data detailing airport security found in street
Tor Browser Users Urged to Patch Critical ‘TorMoil’ Vulnerability

security update

LinuxSecurity.com: Multiple vulnerabilities have been discovered in OpenSSL, a Secure Sockets Layer toolkit. The Common Vulnerabilities and Exposures project identifies the following issues:

LinuxSecurity.com: Multiple vulnerabilities have been discovered in OpenSSL, a Secure Sockets Layer toolkit. The Common Vulnerabilities and Exposures project identifies the following issues:

security update

No Prison for Student who Developed Spam Botnet to Pay College Fee

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Irssi, a terminal based IRC client. The Common Vulnerabilities and Exposures project identifies the following problems:

Poisoned Search Results Deliver Banking Malware

LinuxSecurity.com: An update for liblouis is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for samba is now available for Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Mobile Pwn2Own: Hackers pwn iPhone, Huawei, Galaxy and Pixel Phone
Threatpost News Wrap Podcast for Nov. 3
“Silence” Malware Steals Your Cash Silently
Siemens Update Patches SIMATIC PCS 7 Bug in Some Versions
Would you like to get involved in cybersecurity? Take the test and discover your ideal job!

If you see yourself often being curious about the behavior of computer threats, maybe it’s time you consider getting involved in cybersecurity. The post Would you like to get involved in cybersecurity? Take the test and discover your ideal job! appeared first on WeLiveSecurity

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. DoubleLocker Takes Android Ransomware to Next Level While the concept of ransomware is nothing new, DoubleLocker […]

If your websites use WordPress, put down that coffee and upgrade to 4.8.3.
Hackers abusing digital certs smuggle malware past security scanners
Official list of hacker and cyber crime movies
Introducing GoCrack: A Managed Password Cracking Tool
Google can read your corporate data. Are you OK with that?

LinuxSecurity.com: New openssl packages are available for Slackware 14.2 and -current to fix a security issue.

LinuxSecurity.com: New mariadb packages are available for Slackware 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: An update that solves 8 vulnerabilities and has two fixes An update that solves 8 vulnerabilities and has two fixes An update that solves 8 vulnerabilities and has two fixes is now available. is now available.

LinuxSecurity.com: Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in impersonation of Kerberos services, denial of service, sandbox bypass or HTTP header injection.

security update

LinuxSecurity.com: An update is now available for Red Hat JBoss Fuse and Red Hat JBoss A-MQ. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Web Server 2.1.2 for RHEL 6 and Red Hat JBoss Enterprise Web Server 2.1.2 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Web Server 2.1.2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update that solves one vulnerability and has four fixes An update that solves one vulnerability and has four fixes An update that solves one vulnerability and has four fixes is now available. is now available.

LinuxSecurity.com: An update that solves 36 vulnerabilities and has 22 fixes An update that solves 36 vulnerabilities and has 22 fixes An update that solves 36 vulnerabilities and has 22 fixes is now available. is now available.

Hackers Stole $150,000 from Cryptocurrency Wallets Using CryptoShuffler Trojan

LinuxSecurity.com: updated to aarch64-jdk8u151-b12 (from aarch64-port/jdk8u)

LinuxSecurity.com: 3.10.6 bz #1504256

LinuxSecurity.com: Security fix for CVE-2017-12629

Taking HTTPS Denial to an Absurd Level
Chain of 11 Bugs Takes Down Galaxy S8 at Mobile Pwn2Own
Researcher Identifies Bugs in Google’ Bug Tracker Program
Let’s call them… how two computer scientists made history

Can you imagine how Dr. Cohen actually created the virus or how Prof. Adleman came up with its name? The work of these men ended up inspiring a constant development of computer defense techniques, and constant research on computer threats The post Let’s call them… how two computer scientists made history appeared first on WeLiveSecurity

Devilish ONI Attacks in Japan Use Wiper to Cover Tracks
Learn how a research lab works

The story of viruses took place in a university laboratory and, keeping in mind the parallelism, we want to show you what is a malware research laboratory like and what exactly happens there. The post Learn how a research lab works appeared first on WeLiveSecurity

Google’s bug-tracking system contained its own vulnerabilities, researcher discovers
Smashing Security podcast #050: MailChimp, Piers Morgan, and the Dark Overlord

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code or denial of service. For the oldstable distribution (jessie), these problems have been fixed

security update

WordPress Delivers Second Patch For SQL Injection Bug

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Silence Gang Borrows From Carbanak To Steal From Banks
Professor Len Adleman explains how he coined the term “computer virus”

So this is how two computer scientists made history and why we want to honor their early work. They laid the foundation for research on computer threats, and for what later came to be our mission on antimalware protection. The post Professor Len Adleman explains how he coined the term “computer virus” appeared first on […]

All websites running WordPress urged to update NOW
USB stick found in West London contained Heathrow security data
Fine, OK, no backdoors, says Deputy AG. Just keep PLAINTEXT copies of everyone’s messages
Another Hollywood studio is hacked by The Dark Overlord
Popular ‘Circle with Disney’ Parental Control System Riddled With 23 Vulnerabilities

security update

Apple Patches KRACK Vulnerability in iOS 11.1
Firefox Bolsters Privacy, Pulls Plug on Browser Canvas Fingerprinting

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

I can no longer recommend MailChimp

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Emergency Oracle Patch Closes Bug Rated 10 in Severity
Malicious Chrome Extension Steals ‘All Posted Data’ without Login Credentials
How to better protect your data when you’re on a business trip overseas
Canadian SMBs: How technology can help you go global

As you company grows globally you will be faced with many challenges and it can be easy to forget, unintentionally, some of the steps you have gone through to get to the position your company finds itself in. The post Canadian SMBs: How technology can help you go global appeared first on WeLiveSecurity

Antimalware Day: Genesis of viruses… and computer defense techniques

To honor the work of Dr. Fred Cohen and Professor Len Adleman, and the foundation they laid for research of computer threats, we decided to declare November 3 as the first ever Antimalware Day. The post Antimalware Day: Genesis of viruses… and computer defense techniques appeared first on WeLiveSecurity

SSHGuard 2.1 Released
unCAPTCHA algorithm can Crack Google’s AI System reCAPTCHA

LinuxSecurity.com: This is the final notification for the End Of Life (EOL) of Red Hat ‘Stand-Alone’ Proxy. Red Hat Proxy ‘Stand-Alone’ (Proxy server directly connecting to the Red Hat Network): Systems registered as clients to RHN via a Red Hat Satellite

Mozilla devs discuss ditching Dutch CA, because cryptowars

We’re revealing the top 10 nastiest ransomware attacks from the past year. NotPetya came in on our list as the most destructive ransomware attack of 2017, followed closely by WannaCry and Locky in the number two and three spots, respectively. NotPetya took number one because of its intent to damage a country’s infrastructure. Unlike most […]

LinuxSecurity.com: Several security issues have been corrected in multiple demuxers and decoders of the libav multimedia library. A full list of the changes is available at https://git.libav.org/?p=libav.git;a=blob;f=Changelog;hb=refs/tags/v11.11

security update

Three Monero Mining Malware Apps Found on Play Store
Google’s reCaptcha Cracked Again
Flaw in Google Bug Tracker Exposed Reports About Unpatched Vulnerabilities

security update

LinuxSecurity.com: It was discovered that the bgpd daemon in the Quagga routing suite does not properly calculate the length of multi-segment AS_PATH UPDATE messages, causing bgpd to drop a session and potentially resulting in loss of network connectivity.

LinuxSecurity.com: An update that solves 30 vulnerabilities and has 38 fixes An update that solves 30 vulnerabilities and has 38 fixes An update that solves 30 vulnerabilities and has 38 fixes is now available. is now available.

Google to Ditch Public Key Pinning in Chrome

LinuxSecurity.com: A vulnerability in Jython may lead to arbitrary code execution.

Malicious Chrome Extension Steals Data Posted to Any Website
USB Stick with Heathrow Security and Queen’ Data Found on London Street
Heathrow security plans ‘found on USB stick left in the street’

LinuxSecurity.com: It was discovered that git-annex, a tool to manage files with git without checking their contents in, did not correctly handle maliciously constructed ssh:// URLs. This allowed an attacker to run an arbitrary shell command.

LinuxSecurity.com: An update for tomcat is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for tomcat6 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

security update

LinuxSecurity.com: Multiple vulnerabilities have been found in Apache, the worst of which may result in the loss of secrets.

LinuxSecurity.com: Multiple vulnerabilities have been found in Oracle’s JDK and JRE software suites, the worst of which can be remotely exploited without authentication. [More…]

LinuxSecurity.com: Niklas Abel discovered that insufficient input sanitising in the the ss-manager component of shadowsocks-libev, a lightweight socks5 proxy, could result in arbitrary shell command execution.

LinuxSecurity.com: An update that solves three vulnerabilities and has 32 An update that solves three vulnerabilities and has 32 An update that solves three vulnerabilities and has 32 fixes is now available. fixes is now available.