Menu

Category Archives: Security

Articles about security

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

security update

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Post Cyberattack: The Next Steps Your Business Needs to Take
Smashing Security podcast #048: KRACK, North Korea, and an 18th century cyber attack

security update

FBI Asks Businesses to Share Details About DDoS Attacks

LinuxSecurity.com: New wpa_supplicant packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: New xorg-server packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: New libXres packages are available for Slackware 14.1, 14.2, and -current to fix a security issue.

BoundHook Attack Exploits Intel Skylake MPX Feature

Risk Level: Very Low. Type: Trojan.

Hackers can track, spoof locations and listen in on kids’ smartwatches
You can now buy ATM malware on Dark Web for $5000
Hackers can hack your kid’s smartwatch and track their location
Critical Code Execution Flaw Patched in PeopleSoft Core Engine
48% off Kidde Carbon Monoxide Alarm with Display and 10 Year Battery – Deal Alert
BoundHook: Microsoft downplays Windows systems exploit technique
Abuse of RESTEasy Default Providers in JBoss EAP
How to make your Google account more secure than ever before
Secure Wifi Hijacked by KRACK Vulns in WPA2
Linus Torvalds says targeted fuzzing is improving Linux security
National Cybersecurity Awareness Month Twitter Chats part 2

In the first part of our series we addressed issues such as the role an everyday internet user has in making the internet a safer place, and ID theft. The second part of the Twitter chat continues with the theme of Simple Steps to Online Safety. The post National Cybersecurity Awareness Month Twitter Chats part […]

How containers and microservices change security
Ex-TalkTalk chief grilled by MPs on suitability to chair NHS Improvement

LinuxSecurity.com: An update for rh-nodejs6-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Europol cops lean on phone networks, ISPs to dump CGNAT walls that ‘hide’ cyber-crooks
Oracle Hospitality apps rolled out the Big Red carpet to crims
IRS tax bods tells Americans to chill out about Equifax

LinuxSecurity.com: Multiple vulnerabilities have been found in Nagios, the worst of which could lead to the remote execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in libarchive, the worst of which could lead to a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in Ruby, the worst of which could lead to the remote execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Xen, the worst of which may allow local attackers to escalate privileges.

Domino’s Pizza delivers user details to spammers

LinuxSecurity.com: Several vulnerabilities have been discovered in the X.Org X server. An attacker who’s able to connect to an X server could cause a denial of service or potentially the execution of arbitrary code.

uBlock Origin ad-blocker knocked for blocking hack attack squawking
Watch out for Microsoft Word DDE nasties: Now Freddie Mac menaced
Oracle Patches 250 Bugs in Quarterly Critical Patch Update

LinuxSecurity.com: An update for wpa_supplicant is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available.

Flaw in Adobe Flash Player Used to Install FinFisher Spyware

LinuxSecurity.com: An update for rh-sso7-keycloak is now available for Red Hat Single Sign-On 7.1 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for rh-sso7-keycloak is now available for Red Hat Single Sign-On 7.1 for RHEL 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Red Hat Single Sign-On 7.1.3 is now available for download from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Vulnerability in WPA2 Protocol Allows Attackers to Intercept and Decrypt Encrypted Data Traffic

Type: Vulnerability. Adobe Flash Player is prone to a remote code-execution vulnerability; fixes are available.

LinuxSecurity.com: More info: https://koji.fedoraproject.org/koji/buildinfo?buildID=982578

KRACK Wi-Fi attack – the rules haven’t changed
Microsoft bug-tracking database was ‘hacked by Wild Neutron gang’
Lenovo Quietly Patches Massive Bug Impacting Its Android Tablets and Zuk, Vibe Phones
NHS: Remember those patient records we didn’t deliver? Well, we found another 162,000
RAT flies under the radar with exploit-laden file downloaded by decoy Word document
Severe flaw in WPA2 protocol leaves Wi-Fi traffic open to eavesdropping
Linux vulnerable to privilege escalation

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

Devsecops: Add security to complete your devops process
Securing printed data in the ‘paperless’ office

Just as there are ways to audit, manage and protect electronic documents, there are ways to manage printed documents, too. The post Securing printed data in the ‘paperless’ office appeared first on WeLiveSecurity

Release the KRACKen patches: The good, the bad, and the ugly on this WPA2 Wi-Fi drama
Crypto-coin miners caught toiling away in hacked cloud boxes
Russia tweaks Telegram with tiny fine for decryption denial

LinuxSecurity.com: Fix the for the Key Reinstallation Attacks in FT handshake (CVE-2017-13082) – Fix PTK rekeying to generate a new ANonce – Prevent reinstallation of an already in-use group key and extend protection of GTK/IGTK reinstallation of WNM-Sleep Mode cases (CVE-2017-13078,

LinuxSecurity.com: New upstream version

LinuxSecurity.com: xserver 1.19.5 —- Update to xserver 1.19.4, multiple stability fixes.

LinuxSecurity.com: Fix the for the Key Reinstallation Attacks in FT handshake (CVE-2017-13082) – Fix PTK rekeying to generate a new ANonce – Prevent reinstallation of an already in-use group key and extend protection of GTK/IGTK reinstallation of WNM-Sleep Mode cases (CVE-2017-13078,

LinuxSecurity.com: This is security update fixing possible buffer overflow in loadbuf function.

LinuxSecurity.com: Security fix for CVE-2017-13720 and CVE-2017-13722

LinuxSecurity.com: 6.9.9-19

LinuxSecurity.com: 6.9.9-19

LinuxSecurity.com: Update to 1.4.15. Fixes CVE-2017-8911

LinuxSecurity.com: Update to Open vSwitch 2.8.1 Includes security fix for CVE-2017-14970

LinuxSecurity.com: New upstream version

Never mind the WPA2 drama… Details emerge of TPM key cockup that hits tonnes of devices
Google isn’t saying Microsoft security sucks but Chrome for Windows has its own antivirus
Here’s a timeless headline: Adobe rushes out emergency Flash fix after hacker exploits bug
Factorization Flaw in TPM Chips Makes Attacks on RSA Private Keys Feasible

Risk Level: Very Low. Type: Trojan.

Adobe Patches Flash Zero Day Exploited by Black Oasis APT
Brit intel fingers Iran for brute-force attacks on UK.gov email accounts
KRACK Attack Devastates Wi-Fi Security
Apple co-founder Steve Wozniak Launches ‘Woz U’ Online Tech Education Platform
National Cybersecurity Awareness Month Twitter Chats

We’ve gathered our own thoughts on the topics chosen each week for this short series of blogs that will be published twice a week. The post National Cybersecurity Awareness Month Twitter Chats appeared first on WeLiveSecurity

Customers cheesed off after card details nicked in Pizza Hut data breach
DoubleLocker Android ransomware explained

The infection mechanism works well – which is crucial for determining how big of a deal a piece of malware is. The post DoubleLocker Android ransomware explained appeared first on WeLiveSecurity

Remember how you said it was cool if your mobe network sold your name, number and location?
WPA2 KRACK attack smacks Wi-Fi security: Fundamental crypto crapto

LinuxSecurity.com: Mathy Vanhoef of the imec-DistriNet research group of KU Leuven discovered multiple vulnerabilities in the WPA protocol, used for authentication in wireless networks. Those vulnerabilities applies to both the access point (implemented in hostapd) and the station (implemented in wpa_supplicant).

WPA2 security issues pose serious Wi-Fi safety questions

‘KRACK’ or Key Reinstallation AttaCK, as it has been labeled, means third parties could eavesdrop on a network meaning private conversations would no longer be private. The post WPA2 security issues pose serious Wi-Fi safety questions appeared first on WeLiveSecurity

Linus Torvalds lauds fuzzing for improving Linux security
Learn the ins and outs of Europe’s General Data Protection Regulation (GDPR)