Menu

Category Archives: Security

Articles about security

security update

Blizzard Entertainment hit by massive DDoS attack
Uber to bend over, take privacy probe every two years for next 20 years
Seven More Chrome Extensions Compromised
WannaCry hero back on Twitter after pleading not guilting over Kronos
Attackers Backdoor Another Software Update Mechanism
Fresh Microsoft Office franken-exploit flops – and you should have patched by now anyway
Spam Domains Imitating Popular Banks Spreading Trickbot Banking Trojan
Friendly neighborhood hacker helps family regain access to locked car
Open Banking APIs under PSD2: Security Threats and Solutions. Download this free white paper
Web Host Asked to handover IP Addresses of Anti-Trump Website Visitors
APT-style attack against over 4,000 infrastructure firms blamed on lone Nigerian 20-something

Over the last couple of years, I’ve written and spoken regularly about the changing roles of the Chief Information Security Officer (CISO). And what better way to demonstrate the many skills the position requires – from the technical to the managerial – than journaling a day’s work. A CISO has to be the strategic partner […]

Drone-maker DJI’s Go app contains naughty Javascript hot-patching framework
US Govt demands details of 1.3 million internet users who visited Trump resistance website
MalwareTech is back online, as he pleads not guilty to Kronos malware charges
US military spies: We’ll capture enemy malware, tweak it, lob it right back at our adversaries

Risk Level: Very Low. Type: Trojan.

Blizzard Entertainment Hit With Weekend DDoS Attack
India arrest 4 for leaking ‘Game Of Thrones’ Episode 4 of Season 7

security update

security update

security update

AWS unveils AI monitoring for Amazon S3
Windows Search Bug Worth Watching, and Squashing
Smart Locks Bricked by Bad Update
HBO hackers leak episodes for Insecure and Curb Your Enthusiasm
Hundreds of ‘smart’ locks bricked by flubbed remote update
WannaCry vanquisher Marcus Hutchins pleads not guilty to flogging banking trojan Kronos
Researchers Find Phishing Site Encrypted with AES
If Anonymous ‘pwnd’ the Daily Stormer, they did a spectacularly awful job
GoDaddy bans neo-nazi DailyStormer website
Gmail now warns iOS users about suspicious links, in fight against phishing threats
HBO offered its hackers $250,000 after attack, leaked email claims
Is your corporate inbox smelling a bit ‘phishy’ these days?
Sneaky devs could abuse shared libraries to slurp smartphone data
Leaky PostgreSQL passwords plugged
Top repo managers clone, then close, a nasty SSH vector

security update

Over a thousand spyware-infected Android apps discovered
Someone DDoSed Ukraine’ national postal service for 48 hours
OpDomesticTerrorism: Anonymous shut down Charlottesville city website

security update

security update

Type: Vulnerability. Oracle Java SE is prone to a remote code execution vulnerability.

Thousands of Android Apps Infected with SonicSpy Spyware
Russian Hackers Spying on VIP Hotel Guests Using Leaked NSA Tool
APT28 Using EternalBlue to Attack Hotels in Europe, Middle East
The Showdown: Hackers vs. Accountants
Kremlin’s hackers ‘wield stolen NSA exploit to spy on hotel guests in Europe, Mid East’
Git, SVN and Mercurial Open-Source Version Control Systems Update for Critical Security Vulnerabilit
The DDoS Threat: Ukraine’s Postal Service Hit by Two-Day Attack
Hackers are now using the exploit behind WannaCry to snoop on hotel Wi-Fi

security update

security update

17-years-old kid hacks US air force for the good

security update

security update

security update

security update

Infosec eggheads rig USB desk lamp to leak passwords via Bluetooth
Digital exchange joins law enforcement in hunt for WannaCry ransom bitcoins
Many Factors Conspire in ICS/SCADA Attacks
Apps Infected With SonicSpy Spyware Removed From Google Play
Facebook password stealer; hacking the attacker rather than victim 
HMS Queen Lizzie impugned by cheeky Scot’s drone landing
Crosstalk Flaw: Hackers can steal sensitive data with unsecure USBs
Threatpost News Wrap, August 11, 2017
Ukrainian Man Arrested, Charged in NotPetya Distribution
Researchers Encode Physical DNA with Malware To infect Computers
Good Lord: Former UK spy boss backs crypto

Solar Panel Vulnerabilities Could Lead to Hot Issues A recent study on several of the top solar panel manufacturers checked for any exploitable vulnerabilities in their products. One outcome of the study found that if a large volume of solar panels were exploited at once, it could cause catastrophic problems for the main power grid […]

Black Hat at 20, DefCon at 25: Not just about breaking things

Ironically named for the criminal hackers that cybersecurity pros spend their days – and not a few nights – defending against, the Black Hat Briefings quickly earned a reputation for excellent technical content. The post Black Hat at 20, DefCon at 25: Not just about breaking things appeared first on WeLiveSecurity

Ukrainian man, 51, cuffed on suspicion of distributing NotPetya
World’s first hack using DNA? Malware in genetic code could wreck police CSI work
TalkTalk fined £100,000 after carelessly exposing customer data. Again.
How to prevent the hacked AI apocalypse
‘Adversarial DNA’ breeds buffer overflow bugs in PCs

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

WikiLeaks: CIA’ CouchPotato Tool Remotely Collects Video Streams
SMS touch a security and privacy nightmare for iOS users
Schoolboy bags $10,000 reward from Google with easy HTTP Host bypass
IDG Contributor Network: How cloud-native security can prevent modern attacks
Man caught downloading child porn during raid; gets 10 years in prison

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Patched Flash Player Sandbox Escape Leaked Windows Credentials
Juniper Issues Security Alert Tied to Routers and Switches
High Schooler Nets $10,000 For Google Bug
Kaspersky axes antitrust complaints against Microsoft after Windows giant vows to play nice
Nasty Mamba ransomware that encrypts entire hard drive resurfaces
Amber Rudd tricked by email prankster who duped White House officials

When I started prepping for this interview, I wasn’t entirely sure what a quality assurance (QA) engineer did on a day-to-day basis. However, in a world where STEM (Science Technology Engineering and Mathematics) has become the buzzword du jour, I knew this important technical role was something more and more companies will need in the […]

Avoid getting lost in encryption with these easy steps

Encryption can be the answer to many data security issues faced by small and medium businesses. Apart from protecting sensitive information from unauthorized use,this technology can also represent another step towards compliance with legislation. The post Avoid getting lost in encryption with these easy steps appeared first on WeLiveSecurity

Lauri Love and Gary McKinnon’s lawyer, UK supporters rally around Marcus Hutchins
More on the Vulnerabilities Equities Process
TalkTalk fined £100k for exposing personal sensitive info
Mingis on Tech: Android vs iOS – Which is more secure?
Smashing Security #037: Boobs, dragons and data breaches