Menu

Category Archives: Security

Articles about security

Apple Developer site goes down and some users are fearing a hack
Fake Chrome & Firefox Font Update Drops RAT and Locky Ransomware
Tor Project Brings Security Slider Feature to Android App Orfox

security update

security update

Will the new iPhone break the $1,000 barrier? | Tech Talk Ep 1, Pt 4
13-year-old Japanese Kid Caught Selling Malware
IDN Homograph Attack Spreading Betabot Backdoor
Multiple Vulnerabilities Found in NVIDIA, Qualcomm, Huawei Bootloaders
13 Critical Remote Code Execution Bugs Fixed in September Android Update
Energy sector biz hackers are back and badder than ever before
DolphinAttack: Voice Assistant Apps Siri and Alexa Can Be Hacked
France to tack weapons onto spy drones – reports
WireX Variant Capable of UDP Flood Attacks
Tor Project boosts support for anonymous mobile browsing
Scammers Are Targeting Naive Bitcoin Owners With Terribly Simple Trick
CISOs’ Salaries Expected to Edge Above $240,000 in 2018
Mo money mo mobile payments… Security risks? Whatever!
On internet privacy, be very afraid
Microsoft Releases Long-Awaited Security Tool, Sets Linux Preview
MongoDB ransacking starts again: Hackers ransom 26,000 unsecured instances

LinuxSecurity.com: **Version 1.3.0** It contains fixes for two possible security problems. The problems were identified by Brian ‘geeknik’ Carpenter and Agostino Sarubbo using AFL. The changes are: * Support bzip2 compressed zip archives * Improve file progress callback code * Fix zip_fdopen() * CVE-2017-12858: Fix double free(). * CVE-2017-14107: Improve EOCD64 parsing.

Lenovo to Pay $3.5m for Secretly Installing Adware in 750,000 Laptops
Lenovo’s Superfish security fiasco ends in a slap on the wrist
Critical security flaw leaves Fortune 100 firms vulnerable

The discovered weakness would allow hackers to remotely run code on servers that utilize the REST plugin from Apache Struts, and it is reported that all versions since 2008 are affected. The post Critical security flaw leaves Fortune 100 firms vulnerable appeared first on WeLiveSecurity

Give staff privacy at work, Euro human rights court tells bosses
Boffins hijack bootloaders for fun and games on Android
Please, pleeeease let me ban Kaspersky Lab from US govt PCs – senator
Chinese Man Who Sold VPNs Gets 9 Months Prison Sentence
Attacker demands ransom after series of DDoS attacks on Poker site

security update

Tech Talk: Pricey iPhones, intent-based networks, GPS spoofing and smartwatches
Yet another AWS config fumble: Time Warner Cable exposes 4 million subscriber records
Remember when Lenovo sold PCs with Superfish adware? It just got a mild scolding from FTC
Patch Released for Critical Apache Struts Bug
Four Million Time Warner Cable Records Left on Misconfigured AWS S3
Apache Struts you’re stuffed: Vuln allows hackers to inject evil code into biz servers

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Instagram breach deepens with dark web ‘Doxagram’ domain
Military Contractor’s Vendor Leaks Resumes in Misconfigured AWS S3
Spam Campaigns Using Trickbot Banking Trojan Against Cryptocurrencies
Kurat võtku! Estonia identifies security risk in almost 750,000 ID cards
YouTube MP3 Converter Site Shut Down After Labels Win Lawsuit
Bazinga! Social network Taringa ‘fesses up to data breach

LinuxSecurity.com: GD library could be made to crash if it opened a specially crafted file.

LinuxSecurity.com: An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

Chinese cryptocurrency crackdown

China banned the raising of funds using token-based digital currencies and deemed the practice illegal on Monday, in a move seen as an attempt to impose more regulations on the virtual market. The post Chinese cryptocurrency crackdown appeared first on WeLiveSecurity

UK not as keen on mobile wallets as mainland Europe and US
Latin American social media giant Taringa hacked; 28M accounts stolen

LinuxSecurity.com: A vulnerability in MCollective might allow remote attackers to execute arbitrary code.

Leaky S3 bucket sloshes deets of thousands with US security clearance
Trove of Private Military Contractor Job Applicants Exposed Online

LinuxSecurity.com: Libidn2 2.0.4 (released 2017-08-30) integer overflow in bidi.c/_isBidi() * Fix integer overflow in puny_decode.c/decode_digit() * Improve docs * Fix idna_free() to idn_free() * Update fuzzer corpora

LinuxSecurity.com: Several security issues were fixed in FontForge.

LinuxSecurity.com: Qemu: usb: ohci: infinite loop due to incorrect return value [CVE-2017-9330] (#1457698) Qemu: nbd: segmentation fault due to client non-negotiation [CVE-2017-9524] (#1460173) Qemu: qemu-nbd: server breaks with SIGPIPE upon client abort [CVE-2017-10664] (#1466466) Qemu: exec: oob access during dma operation [CVE-2017-11334] (#1471640) revised full fix for XSA-226 (regressed

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available.

Six million Instagram accounts hacked

A hack believed to target only celebrity accounts on Instagram has also accessed millions of users’ private data. The post Six million Instagram accounts hacked appeared first on WeLiveSecurity

LinuxSecurity.com: Several security issues were fixed in Liblouis.

Crypto-busters reverse nearly 320 MEELLION hashed passwords

LinuxSecurity.com: An update that solves 9 vulnerabilities and has two fixes An update that solves 9 vulnerabilities and has two fixes An update that solves 9 vulnerabilities and has two fixes is now available. is now available.

security update

Asterisk RTP bug worse than first thought: think intercepted streams

LinuxSecurity.com: This update fixes CVE-2017-12982.

LinuxSecurity.com: Qemu: usb: ohci: infinite loop due to incorrect return value [CVE-2017-9330] (#1457698) Qemu: nbd: segmentation fault due to client non-negotiation [CVE-2017-9524] (#1460173) Qemu: qemu-nbd: server breaks with SIGPIPE upon client abort [CVE-2017-10664] (#1466466) Qemu: exec: oob access during dma operation [CVE-2017-11334] (#1471640) revised full fix for XSA-226 (regressed

LinuxSecurity.com: This update fixes CVE-2017-12982.

Stolen 6M Celebrities data from Instagram sold on Dark Web

LinuxSecurity.com: Libidn2 2.0.4 (released 2017-08-30) integer overflow in bidi.c/_isBidi() * Fix integer overflow in puny_decode.c/decode_digit() * Improve docs * Fix idna_free() to idn_free() * Update fuzzer corpora

security update

security update

security update

LinuxSecurity.com: **Version 2.2.5** – 2017-08-30 * **Security** – Double-free in gdImagePngPtr(). **CVE-2017-6362** – Buffer over-read into uninitialized memory. **CVE-2017-7890** * **Fixed** – Fix #109: XBM reading fails with printed error – Fix #338: Fatal and normal libjpeg/ibpng errors not distinguishable – Fix #357: 2.2.4: Segfault in test suite – Fix #386:

LinuxSecurity.com: Libidn2 2.0.4 (released 2017-08-30) integer overflow in bidi.c/_isBidi() * Fix integer overflow in puny_decode.c/decode_digit() * Improve docs * Fix idna_free() to idn_free() * Update fuzzer corpora

LinuxSecurity.com: – Update to 2.6.0 Release notes: https://tls.mbed.org/tech- updates/releases/mbedtls-2.6.0-2.1.9-and-1.3.21-released Security Advisory: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security- advisory-2017-02

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has 5 fixes An update that solves three vulnerabilities and has 5 fixes An update that solves three vulnerabilities and has 5 fixes is now available. is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

DailyStormer comes back with Albanian domain; gets booted off

From streaming entertainment to social media to our online bank accounts and software, we are inundated every day with the need to create and remember new passwords. In fact, one study revealed that Americans have an average of 130 online accounts registered to a single email address. And what are the chances that those 130 […]

‘HoeflerText’ Popups Target Browsers With RAT and Locky Ransomware
US cops can’t keep license plate data scans secret without reason
Massive Locky Ransomware Strain Hits US with Over 23 Million Emails
Massive Locky ransomware campaign sends out 23 million emails in 24 hours
Hacker Charged for Crashing Businesses Using Millions of Mirai botnet
‘Independent’ gov law reviewer wants users preemptively identified before they’re ‘allowed’ to use encryption
Threatpost News Wrap, September 1, 2017
No Fix Planned For LabVIEW Bug, Says National Instruments
US Government Site Was Hosting Ransomware
Insecure Office 365 setups could be a ticking time bomb for your business
Blonde girlfriend’s passport let dark-haired man fly from London to Germany
Snoops ‘n’ snitches auditor IPCO gets up and running
China’s cybersecurity law grants government ‘unprecedented’ control over foreign tech
Connect at mine free Wi-Fi! I would knew what I is do! I is cafe boss!
WikiLeaks suffer defacement at the hands of OurMine group

WikiLeaks’ whistleblowing website suffered an attack from the group known as OurMine on Thursday The post WikiLeaks suffer defacement at the hands of OurMine group appeared first on WeLiveSecurity

IRS-Themed Ransomware Using Old-School Tactics Over the past week, researchers have discovered a new ransomware variant that attempts to impersonate both the IRS and the FBI, similar to the FBI lockscreen malware that was popular several years ago. By tricking the victim into opening a link to a fake FBI questionnaire, the ransomware is downloaded […]

Asterisk bugs make a right mess of RTP
AT&T customers with Arris modems at risk, claim infosec bods
Robocall scumbags already target Hurricane Harvey victims
Malware writer offers free trojan to hackers … with one small drawback
Instagram hacked; data of top celebrities stolen and traded