Menu

Category Archives: Security

Articles about security

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Free Mac-Based Ransomware-as-a-Service MacRansom Surfaces
Blinking Router LEDs Leak Data From Air-Gapped Networks
Stolen UAE InvestBank, Qatar National Bank Data Sold on Dark Web

LinuxSecurity.com: Multiple security flaws were found on oniguruma currently being shipped on Fedora. This new rpm should fix the issue. Fixed CVEs: CVE-2017-9226 CVE-2017-9225 CVE-2017-9224 CVE-2017-9227 CVE-2017-9229 CVE-2017-9228

LinuxSecurity.com: Fixed CVE-2017-6508: CRLF injection in the url_parse function in url.c

LinuxSecurity.com: Multiple security flaws were found on oniguruma currently being shipped on Fedora. This new rpm should fix the issue. Fixed CVEs: CVE-2017-9226 CVE-2017-9224 CVE-2017-9227 CVE-2017-9229 CVE-2017-9228

LinuxSecurity.com: It has been discovered that Tor, a connection-based low-latency anonymous communication system, contain a flaw in the hidden service code when receiving a BEGIN_DIR cell on a hidden service rendezvous circuit. A remote attacker can take advantage of this flaw to cause a

LinuxSecurity.com: – Update to upstream 3.5.13 release

LinuxSecurity.com: Security fix for CVE-2017-9432

LinuxSecurity.com: fixes buffer overflows for flac and pcm

LinuxSecurity.com: FIx for CVE-2017-8366

LinuxSecurity.com: Security fixes.

LinuxSecurity.com: Security fix for CVE-2017-5645

LinuxSecurity.com: * fixed CVE-2017-6508 CRLF injection in the url_parse function in url.c * fixed use of .netrc

LinuxSecurity.com: This release fixes a possible setting arbitrary mode on an arbitrary file in rmtree() and remove_tree() calls known as CVE-2017-6512.

Phishing Scams: 5 Excellent Tips That Will Protect You
Malware that infects users without needing to click anything
Watch out! Scammers are making a fortune in the iOS App Store
‘The Most Sophisticated Mac Ransomware’ Being Sold on Dark Web
Come see me speaking at Codenomi-con in Las Vegas about security
Mac users beware! Hackers are selling ‘the most sophisticated’ Mac malware ever
Attackers Mining Cryptocurrency Using Exploits for Samba Vulnerability
Industroyer: Biggest threat to industrial control systems since Stuxnet

ESET has analyzed a sophisticated and extremely dangerous malware, known as Industroyer, which is designed to disrupt critical industrial processes. The post Industroyer: Biggest threat to industrial control systems since Stuxnet appeared first on WeLiveSecurity

Google adds Recaptcha API to Android to block the bots

security update

security update

GameStop notifies customers about massive credit card breach
Persirai malware in action: IP cameras all across the world compromised
EtherApe – Graphical Network Monitor
A Porn Bot Sprung a Leak and We Got to See What Was Behind It

security update

Fraud ring that resold customers’ Apple data busted by Chinese police
Video: Graham Cluley interviewed on Security Weekly
GameStop Online Shoppers Officially Warned of Breach
WannaCry Copycat ‘WannaLocker’ Ransomware Hits Android Devices
Google Releases reCAPTCHA API for Android
A Malware That can Bypass Windows Firewall Using Intel’s Management Tech

LinuxSecurity.com: An update that solves 8 vulnerabilities and has 68 fixes is An update that solves 8 vulnerabilities and has 68 fixes is An update that solves 8 vulnerabilities and has 68 fixes is now available. now available.

LinuxSecurity.com: An update that fixes 8 vulnerabilities is now available. An update that fixes 8 vulnerabilities is now available. An update that fixes 8 vulnerabilities is now available.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Platinum APT First to Abuse Intel Chip Management Feature
24% off Resqme Keychain Car Escape Tool 2-Pack – Deal Alert
Threatpost News Wrap, June 9, 2017
Cyberpunk 2077 developers blackmailed after hackers steal plans for upcoming video game
Android Malware with Code Injecting Capability Found on Google Play Store
Tor Browser 7.0 is released
How to buy Bitcoins, and where you can do it
Trends 2017: Mobile security – the reality of malware … augmented

It is clear today that our smartphones and tablets have evolved beyond this point, creating new means of technological interaction not previously imagined. The post Trends 2017: Mobile security – the reality of malware … augmented appeared first on WeLiveSecurity

LinuxSecurity.com: This update fixes CVEs 2017-7511 and 2017-9083.

LinuxSecurity.com: Upgrade FreeRADIUS to upstream v3.0.14 release. The release includes fixes for various issues, including security issues, one of which is CVE-2017-9148.

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. Internet Cameras Showcase Major Security Flaws Researchers recently discovered as many as 18 different vulnerabilities with […]

LinuxSecurity.com: This update fixes CVEs 2017-7511 and 2017-9083.

It’s been an exciting week for our partner ConnectWise – they started offering customers Webroot SecureAnywhere DNS Protection. To get insight into why this matters, I sat down with George Anderson, Webroot’s product marketing director for business solutions, and Gavin Gamber, vice president of Channel Sales and Alliances at ConnectWise. Can we start with the […]

LinuxSecurity.com: Agostino Sarubbo and AromalUllas discovered that ettercap, a network security tool for traffic interception, contains vulnerabilities that allowed an attacker able to provide maliciously crafted filters to cause a denial-of-service via application crash.

security update

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Al Jazeera News Platforms Hit by Massive Cyber Attacks
Motorola Moto G4, G5 Vulnerable to Local Root Shell Attacks
Hackers are using popular chat apps to control malware operation

LinuxSecurity.com: FreeRADIUS would allow unintended access over the network.

LinuxSecurity.com: USN-3253-1 introduced a regression in Nagios.

Malicious Android app installs ‘impossible to remove’ adware
VMware Patches Critical Vulnerabilities in vSphere Data Protection
What the hacking of Gordon Ramsay’s email teaches us all
Android malware hid in Google Play apps to inject code into system runtime libraries
Bitcoin, Litecoin Exchange BTC-E Suffers Massive DDoS Attacks
Cisco Patches Critical Flaws in Prime Data Center Network Manager
New App Will Stop Voice Hacks Using Smartphone Compass
Russian Hackers Control Malware via Britney Spears Instagram Posts
14-year-old Japanese Student Caught for Creating Ransomware
How to Protect Yourself From Hackers – Useful Tips For Small Business Owners
Leaked NSA Exploit ‘EternalBlue’ Being Used in New Trojan Attacks
Smashing Security #024: Reality Winner, Gordon Ramsay and a leaky bucket
Fines for poor data security double in UK

A report from PwC found that many companies across the UK are still unprepared for GDPR measures, despite fines for non-compliance doubling in a year. The post Fines for poor data security double in UK appeared first on WeLiveSecurity

Authentication Bypass, Potential Backdoors Plague Old WiMAX Routers
IP Security Cameras Vulnerable to Hostile Takeovers
What’s the difference between first- and third-party cookies?
Testing, marketing, and rummaging in the FUD banks

Early in 2017, Kevin Townsend invited David Harley and others to comment on vendor hype. Here he expands on his original commentary. The post Testing, marketing, and rummaging in the FUD banks appeared first on WeLiveSecurity

5 Tips For Choosing The Right Open Source Code
Encryption leaves authorities ‘not in a good place’: Former US intelligence chief
The Dark Web is the place to go to find bugs before public disclosure
Google Removes Rooting Trojan Dvmap From Play Store

LinuxSecurity.com: New irssi packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: – update to 1.8.20p2 – added sudo package to dnf/yum protected packages —- – update to 1.8.20p1 – fixes CVE-2017-1000367

EFF Sues DOJ Over National Security Letter Disclosure Rules
Annoying Android app demands admin rights to display ads
Windows 10 Mitigations Make Future EternalBlue Attacks Difficult
Facebook patents emotion-sensing technology to ‘deliver better content’
In UAE Supporting Qatar on the Internet is Now a Cybercrime
Zusy Malware Installs Via Mouseover – No Clicking Required

LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available.