Menu

Category Archives: Security

Articles about security

macOS High Sierra Available—And Vulnerable to Keychain Attack
After The Pirate Bay, Showtime Websites Also Found Mining Cryptocoins
Keychain-busting zero-day disclosed hours before release of macOS High Sierra
Equifax CEO falls on his sword weeks after credit biz admits mega-breach
Mobile Stock Trading App Providers Unresponsive to Glaring Vulnerabilities
Mobile stock trading apps riddled with security holes
Adobe’s security team reveals its private PGP key
1.4 Million New Phishing Sites Launched Each Month
Beyond public key encryption

LinuxSecurity.com: A vulnerability in libsoup might allow remote attackers to execute arbitrary code.

Docs ran a simulation of what would happen if really nasty malware hit a city’s hospitals. RIP :(
Boffins take biometric logins to heart, literally: Cardiac radar IDs users to unlock their PCs
Researchers promise demo of ‘God-mode’ pwnage of Intel mobos

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: An update that fixes 15 vulnerabilities is now available. An update that fixes 15 vulnerabilities is now available. An update that fixes 15 vulnerabilities is now available.

Brit broke anti-terror law by refusing to cough up passwords to cops
CBS’s Showtime caught mining crypto-coins in viewers’ web browsers
Deloitte: ‘Very Few Clients’ Impacted by Cyber Attack
Android Lockscreen Patterns Less Secure Than PINs

LinuxSecurity.com: Multiple vulnerabilities have been found in Chromium, the worst of which could result in the execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in PHP, the worst of which could result in the execution of arbitrary code.

Risk Level: Very Low. Type: Trojan.

TV broadcasts in California interrupted to show “end of the world” alert
Sensitive client emails, usernames, passwords exposed in Deloitte hack
Chris Vickery on Amazon S3 Data Leaks

I’m delighted to join the Webroot team officially today as CEO. We helped define the cybersecurity field in our first 20 years, but I believe our best days are ahead. With this introductory post, I thought I’d let you know where I intend to focus in my first months at Webroot, with the goal of […]

Insteon and Wink home hubs appear to have a problem with encryption
Adobe Private PGP Key Leak a Blunder, But It Could Have Been Worse
Bankbot trojan returns to Google Play with new tricks

The Android banking trojan that we first informed about in the beginning of this year has found its way to Google Play again and contains new tricks designed to get access to the private banking information of the user. The post Bankbot trojan returns to Google Play with new tricks appeared first on WeLiveSecurity

For eight years, hackers have been able to exploit this password-stealing flaw in Joomla
Brit military wants a small-drone-killer system for £20m
Cops shut 28k sites flogging knock-off footie kits and other tat
Security and privacy on the new iOS 11

These new security measures will undoubtedly not only impact the security of data stored on a phone that has been lost or stolen, but could also complicate the progress of criminal investigations requiring the forensic analysis of a phone. The post Security and privacy on the new iOS 11 appeared first on WeLiveSecurity

Pesky users! They’re always compromising endpoints! Security baked into silicon helps

LinuxSecurity.com: Multiple vulnerabilities have been found in Tcpdump, the worst of which may allow execution of arbitrary code.

Spammed-out emails threaten websites with DDoS attack on September 30th

LinuxSecurity.com: This update fixes CVE-2017-14348. —- This update fixes CVE-2017-13735.

Guess – go on, guess – where a vehicle tracking company left half a million records
Shock! Hackers for medieval caliphate are terrible coders

LinuxSecurity.com: Fix for possible buffer overrun in kodak_65000 decoder Fix for possible heap overrun in Canon makernotes parser Fix for CVE-2017-13735 CVE-2017-14265: Additional check for X-Trans CFA pattern data —- Patch for CVE-2017-14348

LinuxSecurity.com: Upgrade to 1.5.3 and also note that 1.5.1 fixed CVE-2017-11424.

LinuxSecurity.com: # Security fixes – fix crash in edge case where a .pc file has misquoting in a fragment list. # Other bug fixes: – fix logic edge case when comparing relocated paths

LinuxSecurity.com: Multiple vulnerabilities have been found in Oracle’s JRE and JDK software suites, and IcedTea, the worst of which may allow execution of arbitrary code. [More…]

New ransomware scam asks for nude pics to unlock files

LinuxSecurity.com: Multiple vulnerabilities have been found in Mercurial, the worst of which could lead to the remote execution of arbitrary code.

LinuxSecurity.com: A vulnerability in Postfix may allow local users to gain root privileges.

LinuxSecurity.com: A vulnerability in Exim may allow local users to gain root privileges.

LinuxSecurity.com: A command injection vulnerability in CVS may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Chromium, the worst of which could result in the execution of arbitrary code.

security update

Over Half a Million Vehicle Records from SVR Tracking Leaked Online
The Pirate Bay Takes Heat for Testing Monero Mining
Joomla patches eight-year-old critical CMS bug

LinuxSecurity.com: New python packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: New libxml2 packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Don’t fear the software shopkeeper: T&Cs banning bad reviews aren’t legal in America
Want to get around app whitelists by pretending to be Microsoft? Of course you can…
Aw, not you too, Verizon: US telco joins list of leaky AWS S3 buckets
Verizon Wireless Internal Credentials, Infrastructure Details Exposed in Amazon S3 Bucket

LinuxSecurity.com: Update to upstream release 1.25.6

LinuxSecurity.com: * [7.x-3.18](https://www.drupal.org/project/views/releases/7.x-3.18) * [7.x-3.17](https://www.drupal.org/project/views/releases/7.x-3.17) * [Moderately Critical – Access Bypass – DRUPAL-SA- CONTRIB-2017-068](https://www.drupal.org/node/2902604)

NBD: Adobe just dumped its PRIVATE PGP key on the internet
Experian Flaw Lets Attacker Obtain Credit Freeze PIN and Access Account
EternalBlue Exploit Used in Retefe Banking Trojan Campaign

Risk Level: Very Low. Type: Trojan.

2016 SEC Hack May Have Benefited Insider Trading
IoT botnet Linux.ProxyM turns its grubby claws to spam rather than DDoS
Samba Update Patches Two SMB-Related MiTM Bugs
CCleaner Backdoor Attack: A State-sponsored Espionage Campaign
What’s New In Android 8.0 Oreo Security
Finance sector is littered with vulns, and guess what – most can be resolved by patching
Threatpost News Wrap, September 24, 207
Ethereum-backed hackathon excavates more security holes
Massive Viacom Data Exposed Through Amazon Web Services

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

Cloud services: What to consider when migrating your infrastructure

Most companies have switched the majority of their services and information over to the cloud. There are many reasons for this, ranging from cost to practicalities. The post Cloud services: What to consider when migrating your infrastructure appeared first on WeLiveSecurity

Mini-Heartbleed info leak bug strikes Apache, airborne malware, NSA algo U-turn, and more
IT plonker stuffed ‘destructive’ logic bomb into US Army servers in contract revenge attack

Risk Level: Very Low. Type: Trojan.

security update

IT fraudster facing four years’ bird time for $10k blackmail
Manchester plod still running 1,500 Windows XP machines
Lloyds Bank payments glitch frustrates merchants
More data lost or stolen in first half of 2017 than the whole of last year

Before chatting with Ann Roberts, systems administrator at Webroot, I had a pretty narrow view of what her role in the IT department required on a day-to-day basis. As it turns out, a systems administrator must wear many hats and support multiple areas of the business. Read on to learn more about this tech career […]

Slain: Unions’ US OPM mega-hack lawsuit against Uncle Sam

LinuxSecurity.com: – Related: CVE-2017-6362 remove problematic function

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

Iranian APT33 Targets US Firms with Destructive Malware
SEC ‘fesses to security breach, says swiped info likely used for dodgy stock-market trading
Locky ransomware campaign launched 20M attacks in a single day
McAfee joins the anti-Kaspersky witch hunt in shitty attempt to sell a few boxes
Joomla Patches Eight-Year-Old LDAP Injection Vulnerability
Researchers claim ISPs are ‘complicit’ in latest FinSpy snooping rounds
SEC reveals hackers might have used stolen data for insider trading
Equifax fooled again! Blundering credit biz directs hack attack victims to parody site
New FinFisher surveillance campaigns: Are internet providers involved?

FinFisher has extensive spying capabilities, such as live surveillance through webcams and microphones, keylogging, and exfiltration of files. What sets FinFisher apart from other surveillance tools, however, are the controversies around its deployments. The post New FinFisher surveillance campaigns: Are internet providers involved? appeared first on WeLiveSecurity

CConsiderations on the CCleaner incident

Regardless of how Piriform was breached, for a tool as widely downloaded as CCleaner, with a userbase running into the hundreds of millions, there will be a large impact worldwide, even though only the 32-bit version was affected. The post CConsiderations on the CCleaner incident appeared first on WeLiveSecurity

How SS7 Flaw Can Be Used to Hack Gmail ID and Bitcoin Wallet