Menu

Category Archives: Security

Articles about security

Equifax Says 145.5M Affected by Breach, Ex-CEO Testifies
Chinese Bitcoin Trading Exchange Blames User For Losing $3M

“I use a Mac, so I don’t need to worry about malware, phishing, or viruses.” Many Mac users turn a blind eye to cybersecurity threats, often noting that most scams and attacks occur on PCs. However, within the last few years, there has been a noted uptick in spyware (a type of software that gathers information […]

Google Warns of DoS and RCE Bugs in Dnsmasq
3 vulnerable WordPress plugins affecting 21,000 websites
‘Critical’ zero-day bug found in three popular WordPress plugins
How does Behavioral Biometrics help financial institutions manage fraud risk? Download VASCO’s white paper now
Schrems busts Privacy Shield wide open
MH370 final report: Aussies still don’t know where it crashed or why
‘I don’t need to understand how encryption works,’ admits UK Home Secretary
ESET at Virus Bulletin 2017

The annual Virus Bulletin International Conference takes place in Madrid, Spain this October and ESET will be well represented across the three-day event. The post ESET at Virus Bulletin 2017 appeared first on WeLiveSecurity

Un-Delled SonicWall beefs up firewall to wrestle ransomware
Patch your Android, peeps, it has up to 14 nasty flaws to flog
Equifax couldn’t find or patch vulnerable Struts implementations
Android keyboard app misled 200 million users about how it was collecting data
HPE coughed up source code for Pentagon’s IT defenses to … Russia
Dnsmasq and the seven flaws: Patch these nasty remote-control holes
Netgear Fixes 50 Vulnerabilities in Routers, Switches, NAS Devices
Judge: FBI Can Keep iPhone Crack and Price Secret
Gary McGraw on BSIMM8 and Software Security
UK National Lottery knocked offline by DDoS attack
UK lotto players quids in: Website knocked offline by DDoS attack

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

‘Phish for the Future’ spearphishing campaign set digital civil liberty activists in its sights
Taboola ads exploited to serve up tech support scams
Banking trojan campaign uses commercial packers to target Brazilian users

security update

security update

security update

Blockchain skills: Don’t Try to Block the Chain
Black Hat Europe 2017: New Briefings Announced
Hikvision Security Cams Compromised to Display “HACKED”

LinuxSecurity.com: **nag 4.2.17** * [jan] SECURITY: Fix unauthorized access to task exports. * [jan] Fix regression when exporting single tags to iCalendar CATEGORIES. * [jan] Officially support PHP 7.

LinuxSecurity.com: **wicked 2.0.8** * [jan] SECURITY: Fix unauthorized access to page attachments.

LinuxSecurity.com: **passwd 5.0.7** * [jan] Officially support PHP 7. * [jan] SECURITY: Fix open redirects.

Java security plagued by crappy docs, complex APIs, bad advice
US yanks staff from Cuban embassy over sonic death ray fears
Siemens Patches Improper Access Vulnerability in Ruggedcom Protocol
ICANN Postpones Scheduled DNS Crypto Key Rollover
Threatpost News Wrap, September 29, 2017
Apple Mac fans told: Something smells EFI in your firmware
Dildon’ts of Bluetooth: Pen test boffins sniff out Berlin’s smart butt plugs
Macs Not Receiving EFI Firmware Security Updates as Expected
Cloud security policy: The questions you need to ask

Cloud services are very much what you make of them, and you need to apply at least an equivalent level of rigorousness, in terms of risk assessment, as you would with assets that are hosted on your own network. The post Cloud security policy: The questions you need to ask appeared first on WeLiveSecurity

Citrix patches Netscaler hole, ARM TrustZone twisted, Android Dirty COW exploited – and more security fails

Showtime Site Found Using Cryptocurrency Miner Following the discovery last week that ThePirateBay has been using a Monero miner to experiment with revenue alternatives for the site, researchers have found that both Showtime.com and ShowtimeAnytime.com have embedded code for similar cryptocurrency mining. The code itself runs only while the user is on the site, and […]

Ouch: Brit council still staggering weeks after ransomware bit its PCs
Internet-wide security update put on hold over fears 60 million people would be kicked offline
Angst in her pants: Alleged US govt leaker Reality Winner stashed docs in her pantyhose

LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.

Google to Enforce HSTS on TLDs it Operates
Civil Liberties Activists Hit By Phishing Campaign

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Your Android lock screen pattern isn’t as safe as a PIN code

What’s safer? Using a numeric PIN code to unlock your Android smartphone or relying on a finger squiggle? The answer might surprise you. The post Your Android lock screen pattern isn’t as safe as a PIN code appeared first on WeLiveSecurity

Windows Defender Bypass Tricks OS into Running Malicious Code
Internet Explorer bug can reveal the contents of your address bar
Patch alert! Easy-to-exploit flaw in Linux kernel rated ‘high risk’
Money-making machine: Monero-mining malware

While far behind Bitcoin in market capitalization, Monero has several features that make it a very attractive cryptocurrency to be mined by malware. The post Money-making machine: Monero-mining malware appeared first on WeLiveSecurity

The UK isn’t ditching Boeing defence kit any time soon

LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available.

Popular GoKeyboard App Spying on Millions of Android Users
?Dios m?o! Spain blocks DNS to silence Catalan independence vote sites
Smashing Security podcast #045: Deloitte fail, CCleaner, and dotards on Twitter
Europol warns ransomware has taken cybercrime ‘to another level’
Microsoft downplays alarm over Windows Defender ‘flaw’
NatWest customer services: We’re aware of security glitch
Ransomware keeping cops, NHS and local UK gov bods awake at night
Mac High Sierra hijinks continue: Nasty apps can pull your passwords

LinuxSecurity.com: New gegl packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

iOS apps can read metadata revealing users’ location histories

security update

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Signal taps up Intel’s SGX to (hopefully) stop contacts falling into hackers, cops’ hands

Another day, another phishing attack. From businesses to consumers, phishing attacks are becoming a more widespread and dangerous online threat every year. One wrong click could quickly turn into a nightmare if you aren’t aware of the current techniques cyber scammers are using to get access to your valuable personal information. A phishing attack is […]

Alleged dark web drug baron cuffed – after he flew to US for World Beard Championships

security update

CCleaner Malware: Here is the Full List of Affected Companies
Gatekeeper Alone Won’t Mitigate Apple Keychain Attack
Facebook-hijacking Faceliker malware is on the rise
Signal Testing New Private Contact Discovery Service
South Korea Blames North Korean Hackers For Stealing Bitcoin
TalkTalk once told GCHQ: Cyberattack? We’d act fast to get sports back up
Remote Wi-Fi Attack Backdoors iPhone 7
Gov contractor nicked on suspicion of Official Secrets Act breach
Heads-up teenage hoodlums! Don’t SWAT Brian Krebs or else…
Bossie Awards 2017: The best networking and security software
Bossies 2017: The Best of Open Source Software Awards
Have MAC, will hack: iThings have trivial-to-exploit Wi-Fi bug
Oracle corrals and patches Struts 2 vulnerabilities

LinuxSecurity.com: This release fixes a crash when parsing an empty code string of a codewscope type.

White House staffers jabbed with probe over private email use
Google reveals Android Robocop AI to spot and destroy malware
Deloitte is a sitting duck: Key systems with RDP open, VPN and proxy ‘login details leaked’

Type: Vulnerability. Adobe Flash Player is prone to an unspecified remote code-execution vulnerability; fixes are available.

Oracle Patches Apache Struts, Reminds Users to Update Equifax Bug

LinuxSecurity.com: Multiple vulnerabilities have been found in RAR and UnRAR, the worst of which may allow attackers to execute arbitrary code.

LinuxSecurity.com: Libplist could be made to crash if it opened a specially crafted file.

LinuxSecurity.com: The 4.13.3 stable update contains a number of important fixes across the tree.