Menu

Category Archives: Security

Articles about security

LinuxSecurity.com: An update that solves two vulnerabilities and has 5 fixes An update that solves two vulnerabilities and has 5 fixes An update that solves two vulnerabilities and has 5 fixes is now available. is now available.

“What are our cybersecurity protocols?” This question is one that has, undoubtedly, been top of mind for CTOs at numerous corporations and government agencies around the world in the wake of recent ransomware attacks. Given the hundreds of thousands of endpoint devices in more than 150 countries that were infected in the latest global attack, […]

Hooligans Biker Gang Arrested for Hacking and Stealing 150 Jeep Wranglers
Insecure Backend Databases Blamed for Leaking 43TB of App Data
Google: Its Tech Now Blocks 99.9% of Gmail Phishing and Spam Emails
Crowdfunding Effort to Buy ShadowBrokers Exploits Shuts Down
OneLogin Breach Compromised Customer Data, Ability to Decrypt Encrypted Data
Password manager “OneLogin” hacked; data stolen
WannaCry Development Errors Enable File Recovery
Secure XML Processing with JAXP on EAP 7
Secret Pentagon Files Left Unprotected on the Amazon Server
In ongoing phishing fight, Google to delay delivery of suspicious messages to enterprise Gmail customers
Shadow Brokers lay out pitch – and name price – for monthly zero-day subscription service
Blockchains are the new Linux, not the new internet
Windows XP ‘did not contribute much’ to WannaCry infection totals
Free Invisible Mobile App Security white paper from VASCO

LinuxSecurity.com: Several vulnerabilities were discovered in wordpress, a web blogging tool. They would allow remote attackers to force password resets, and perform various cross-site scripting and cross-site request forgery attacks.

security update

security update

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Smashing Security #023: Covfefe

security update

security update

security update

Hack Department of Homeland Security Act Would Bring Bug Bounty Program to DHS
Ransom Fail: Hackers Leak Thousands of Naked Photos of Plastic Surgery Patients

LinuxSecurity.com: A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make […]

LinuxSecurity.com: A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make […]

LinuxSecurity.com: A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make […]

LinuxSecurity.com: Karsten Heymann discovered that the OpenLDAP directory server can be crashed by performing a paged search with a page size of 0, resulting in denial of service. This vulnerability is limited to the MDB storage backend.

LinuxSecurity.com: New sudo packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes is now available. is now available.

LinuxSecurity.com: An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes is now available. is now available.

LinuxSecurity.com: Sudo could be made to overwrite files as the administrator.

Shadow Brokers to Start Monthly Paid Dump Service
Patches Available for Linux Sudo Vulnerability
Cisco, Netgear Readying Patches for Samba Vulnerability

Risk Level: Very Low. Type: Trojan, Virus, Worm.

New Machine Learning Behind Early Phishing Detection in Gmail
Someone hacked a road sign in Houston with “Impeach Trump” Message
Man Hacks Chinese Video Giant; Steals Millions of Dollars – Gets Caught
Privacy Issue Fixed in Yopify Ecommerce Notification Plugin
ESET releases decryptor for AESNI ransomware variants, including XData

ESET has released a decryptor for AESNI ransomware variants, including XData. Victims who still have encrypted files can now download it from ESET’s utilities page. The post ESET releases decryptor for AESNI ransomware variants, including XData appeared first on WeLiveSecurity

Cosmetic surgery hacked. Nude photos and data exposed on the dark web, as hackers blackmail patients
What is VPN and how does it work?

Keen to understand what a virtual private network is? You’ve come to the right place. The post What is VPN and how does it work? appeared first on WeLiveSecurity

How to build your own VPN if you’re (rightfully) wary of commercial options
82% of Databases Left Unencrypted in Public Cloud
How to remove all your cookies, cached data, and browsing history from Opera

LinuxSecurity.com: An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes is now available. is now available.

LinuxSecurity.com: An update for sudo is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for sudo is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. Samsung’s Latest Iris Scanners are Easily Fooled Recently, ethical hackers have been able to bypass Samsung’s […]

Risk Level: Very Low. Type: Trojan, Virus, Worm.

security update

iPhone – the likely cause of the EgyptAir Flight 804 crash
FreeRADIUS Update Resolves Authentication Bypass

LinuxSecurity.com: It was discovered that pattern-based ACLs in the Mosquitto MQTT broker could be bypassed. For the stable distribution (jessie), this problem has been fixed in

LinuxSecurity.com: A security fix for a systemd-resolved crash on a crafted DNS packet. Relevant only to systemd-resolved users (not enabled by default). No need to reboot or logout.

LinuxSecurity.com: This update addresses the following vulnerabilities: * [CVE-2017-2496](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2496), [CVE-2017-2539](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2539), [CVE-2017-2510](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2510) Additional fixes: * Fix URL shown in the title of beforeunload dialogs. * Focus

LinuxSecurity.com: Fix for CVE-2016-8728 CVE-2016-8729 —- Rebuild with new jbig2dec

LinuxSecurity.com: An issue in `git-shell` could allow remote users to run an interactive pager. From the [update announcement](https://public- inbox.org/git/xmqq8tm5ziat.fsf@gitster.mtv.corp.google.com/): … fix a recently disclosed problem with “git shell”, which may allow a user who comes over SSH to run an interactive pager by causing it to spawn “git

Risk Level: Very Low. Type: Trojan.

Bug Lets Chrome Stealthily Record Audio and Video
Surprise! Extortionists have no qualms about claiming they ‘hacked’ your business
ShadowBrokers Put Price on Monthly Zero Day Leaks
Judy malware campaign victimized as many as 36.5 million Android users
Get hacked, and watch your company’s share price plummet
How to get away with hacking the Department of Homeland Security

LinuxSecurity.com: strongSwan could be made to crash or hang if it received specially crafted network traffic.

LinuxSecurity.com: Several security issues were fixed in WebKitGTK+.

LinuxSecurity.com: Several security issues were fixed in ImageMagick.

LinuxSecurity.com: USN-3212-1 caused a regression in LibTIFF.

LinuxSecurity.com: Two denial of service vulnerabilities were identified in strongSwan, an IKE/IPsec suite, using Google’s OSS-Fuzz fuzzing project. CVE-2017-9022

LinuxSecurity.com: An update for nss is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for nss is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Chinese Scam Website Caught Selling Hacked Xbox Accounts
US May Expand Laptop Ban to All International Flights
How Companies can stay Secure while using Omni-Channel

security update

Google Scraps Judy Malware Infected Apps Downloaded By 36M Android Users
Android ‘design shortcomings’ allow for Cloak and Dagger series of attacks
The good old NTFS bug in Windows strikes back but with a different name
Microsoft Quietly Patches Another Critical Malware Protection Engine Flaw
IT outage chaos: All British Airways Flights Canceled
Thousands of Critical Security Flaws Leave Pacemaker Vulnerable to Hackers
Democracy-minded DEF CON hackers promise punishing probe on US election computers
New Android Exploit ‘Cloak and Dagger’ Lets Attackers Steal User Data

security update

security update

Hackers alter stolen emails for clandestine attacks against Putin’s critics

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Mark Dowd on Exploit Mitigation Development
Pacemaker Ecosystem Fails its Cybersecurity Checkup
Threatpost News Wrap, May 26, 2017
Rash Of Phishing Attacks Use HTTPS To Con Victims
3 types of employees that can cause a data breach

When it comes to cybersecurity, what type of employee is most likely to cause a data breach? And how can companies protect themselves? The post 3 types of employees that can cause a data breach appeared first on WeLiveSecurity

A wormable code-execution bug has lurked in Samba for 7 years. Patch now!