Menu

Category Archives: Security

Articles about security

Republican Data Broker Exposes 198M Voter Records
Stack Clash Vulnerability in Linux, BSD Systems Enables Root Access
4 School Districts in Florida Attacked By Moroccan Hackers
Universal Plug ‘n’ Pwn! Pinkslipbot malware exploits UPnP to help it steal credentials
IoT Malware Activity Already More Than Doubled 2016 Numbers
Pervert arrested for taking candid photos of women, posting on Twitter

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

Industroyer: ICS were developed decades ago with no security in mind

Senior ESET malware researcher Robert Lipovsky discusses Industroyer, the biggest threat to Industrial Control Systems (ICS) since Stuxnet. The post Industroyer: ICS were developed decades ago with no security in mind appeared first on WeLiveSecurity

Industroyer poses the highest risk for critical infratstructure since Stuxnet

ESET researchers have been analyzing samples of dangerous malware – detected by ESET as Win32/Industroyer, and named Industroyer – which is capable of performing an attack on power supply infrastructure. Robert Lipovsky, a researcher at ESET, tells us more. The post Industroyer poses the highest risk for critical infratstructure since Stuxnet appeared first on WeLiveSecurity

Risk Level: Very Low. Type: Trojan.

security update

security update

Google is having a hard time getting rid of malicious Android apps
Disruptive Ransomware Group ‘FIN10’ Hacked Casinos, Mining Firms
Erebus Ransomware Targets Linux Servers
Enhancing the security of the OS with cryptography changes in Red Hat Enterprise Linux 7.4
Hackers can exploit E-Cigarettes to hack computers

security update

security update

Wikileaks Alleges Years of CIA D-Link and Linksys Router Hacking Via ‘Cherry Blossom’ Program

LinuxSecurity.com: It was discovered that RT::Authen::ExternalAuth, an external authentication module for Request Tracker, is vulnerable to timing side-channel attacks for user passwords. Only ExternalAuth in DBI (database) mode is vulnerable.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system. The Common Vulnerabilities and Exposures project identifies the following problems:

LinuxSecurity.com: An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

LinuxSecurity.com: libmwaw could be made to crash or run programs as your login if it opened a specially crafted file.

LinuxSecurity.com: zziplib could be made to crash or run programs as your login if it opened a specially crafted file.

Someone Failed to Contain WannaCry
Hundreds of Malicious Android Apps Masked as Anti-virus Software

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. New Mobile Phishing Attacks are Using URL Padding In an attempt to trick mobile browsing users […]

What’s worse than getting phished? Getting phished *and* sending a selfie of your Photo ID and credit card
Threatpost News Wrap, June 16, 2017
Hackers Using Chinese Malware to Rob ATMs Using Outdated Windows XP
Seven years after Stuxnet: Industrial systems security once again in the spotlight

Seven years after Stuxnet first came to light, industrial systems security once again in the spotlight, reports ESET’s Robert Lipovsky. The post Seven years after Stuxnet: Industrial systems security once again in the spotlight appeared first on WeLiveSecurity

Erosion of ISP Privacy Rules Sparks New Anti-Snooping Efforts
Would you trust your smartphone with your life?

Smartphone security is, of course, essential these days, but how confident are you in your device’s ability to help keep you safe and secure? The post Would you trust your smartphone with your life? appeared first on WeLiveSecurity

Facebook staff had their identities exposed to suspected terrorists due to security lapse
Brit hacker admits he siphoned info from US military satellite network
CIA has been hacking into Wi-Fi routers for years, leaked documents show
Cybersecurity labor crunch to hit 3.5 million unfilled jobs by 2021
Buggy devices and lazy operators make VoLTE a security nightmare
Parrot Security OS Devs Mock systemd: It’s an Immature Init System for GNU/Linux
British hacker admits stealing satellite data from US Department of Defense

LinuxSecurity.com: – new upstream update (54.0)

The 2 cloud security myths that must die

LinuxSecurity.com: Update to version 1.8.2. The upstream release notes: https://mail.gnome.org/archives/ftp-release-list/2017-June/msg00015.html

LinuxSecurity.com: **Rebase to 10.1.24** Plugin oqgraph enabled Plugin jemalloc enabled Sphinx engine enabled Build dependecies Bison and Libarchive added, others corrected Disabling Mroonga engine for i686 architecture, as it is not supported by MariaDB **Removed patches: (fixed by upstream)** Patch5: %{pkgnamepatch}-file-contents.patch Patch14: %{pkgnamepatch}-example-config-

Ransomware attack against University College London blamed on poisoned website
Cherry Blossom: WikiLeaks’ Latest Dump Exposes CIA Wireless Hacking Tools

security update

Nigerian BEC Scams Hit 500 Companies in 50 Countries
Ransomware Attack Hobbles Prestigious University College London
University College London hit by a major ransomware attack

Webroot SecureAnywhere® Business solutions will now give admins more ease of control within the Global Site Manager (GSM). From web overrides to Mac- and PC-specific enhancements, we’re delivering new features you asked for to ensure the best multi-vector protection possible. Webroot protects endpoints against myriad threats at multiple attack stages spanning a variety of attack […]

Metadata Analysis Draws its Own Conclusions on WannaCry Authors
Millions of Android users left vulnerable due to Samsung’s ignorance
Disney, Depp and the cyber supply chain risk management problem

Multimillion dollar movies and TV shows are increasingly being targeted by cybercriminals. ESET’s Stephen Cobb investigates the cyber supply chain risk management problem and explains what to do about it. The post Disney, Depp and the cyber supply chain risk management problem appeared first on WeLiveSecurity

The 15 worst data security breaches of the 21st Century
DevSecOps is Not a Security Panacea
BlackArch Linux Ethical Hacking and Pen Testing OS Now Offers over 1,800 Tools
Children still at risk from inappropriate online content

A new survey published by the NSPCC suggests children across the UK are still at risk of accessing inappropriate and potentially harmful content online, despite increased calls for heightened security. The post Children still at risk from inappropriate online content appeared first on WeLiveSecurity

LinuxSecurity.com: Firefox could be made to crash or run programs as your login if it opened a malicious website.

LinuxSecurity.com: Gajim 0.16.8 * Fix rejoining MUCs after connection loss * Fix Groupchat invites * Fix encoding problems with newer GnuPG versions * Fix old messages randomly reappearing in the chat window * Fix some problems with IBB filetransfer * Make XEP-0146 Commands opt-in * Improve sending messages to your own resources * Improve reliability […]

LinuxSecurity.com: FIx for CVE-2017-8366

Smashing Security #029: Exploits to get your English teeth into
Compromised websites redirecting tech support scam hosted on numeric domains

LinuxSecurity.com: Gajim 0.16.8 * Fix rejoining MUCs after connection loss * Fix Groupchat invites * Fix encoding problems with newer GnuPG versions * Fix old messages randomly reappearing in the chat window * Fix some problems with IBB filetransfer * Make XEP-0146 Commands opt-in * Improve sending messages to your own resources * Improve reliability […]

LinuxSecurity.com: FIx for CVE-2017-8366

LinuxSecurity.com: fixes buffer overflows for flac and pcm

LinuxSecurity.com: This update addresses the following vulnerabilities: * [CVE-2017-2496](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2496), [CVE-2017-2539](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2539), [CVE-2017-2510](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2510) Additional fixes: * Fix URL shown in the title of beforeunload dialogs. * Focus

LinuxSecurity.com: CVE-2017-7511 poppler: Null pointer dereference in pdfunite via crafted documents

LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.2, and -current to fix security issues.

LinuxSecurity.com: New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: Update to a bugfix release of yara.

Europol arrest 6 over malware crypter and counter anti-virus platform

security update

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Mozilla Fixes 32 Vulnerabilities in Firefox 54
Decryption Utility Unlocks Files Encrypted by Jaff Ransomware

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: Multiple security vulnerabilities have been found in oSIP, a library implementing the Session Initiation Protocol, which might result in denial of service through malformed SIP messages.

DHS, FBI Warn of North Korea ‘Hidden Cobra’ Strikes Against US Assets
Abuse of Apple Search Ads Feature Leading to Fraud
Criminals snatching iPhones to scam users twice
A Dark Web service claims to track any phone and read text messages
Post-WannaCry, 5.5 Million Devices Still Expose SMB Port
Rare XP Patches Fix Three Remaining Leaked NSA Exploits
Employees have “low cyber IQ” despite high corporate confidence

Businesses are confident that they have sufficient cybersecurity systems in place to protect them, but in reality the weak link may be their employees, who lack basic skills and knowledge. The post Employees have “low cyber IQ” despite high corporate confidence appeared first on WeLiveSecurity

Pirates dance around AACS 2 encryption to offer UHD Blu-Ray movies online
Raspberry Pi sours thanks to mining malware

LinuxSecurity.com: It was discovered that a side channel attack in the EdDSA session key handling in Libgcrypt may result in information disclosure. For the stable distribution (jessie), this problem has been fixed in

security update

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

security update

Microsoft Patches Two Critical Vulnerabilities Under Attack
Risk of ‘Destructive Cyber Attacks’ Prompts Microsoft to Update XP Again
Mazda cars hacked with just a USB
Adobe Fixes 21 Critical Vulnerabilities with June Patch Tuesday Update

LinuxSecurity.com: fixes buffer overflows for flac and pcm

LinuxSecurity.com: Security fix for CVE-2017-5645