Menu

Category Archives: Security

Articles about security

APT29 Domain Fronting With TOR
Someone is putting lots of work into hacking Github developers
Aviation-Related Phishing Campaigns Seeking Credentials
Jenkins users can shore up software security with plugins
Want privacy? Congress says you’ll have to pay for it

Don’t wait for a system failure, ransomware attack, or for your laptop to be stolen before you start thinking about backing up your data. Why back up? According to a 2016 study by Acronis, 1 in 3 people have suffered data loss and are willing to pay up to $500 or more to recover lost […]

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

Facebook, Google, etc: Yeah, yeah, we’ll work on the nasty stuff about bombs – but we ain’t doing no backdoors
Researchers steal data from shared cache of two cloud VMs
WONTFIX: No patch for Windows Server 2003 IIS critical bug – Microsoft
Minnesota, Illinois rebel over America’s ISP privacy massacre, mull fresh info protections
Blizzard’s World of Warcraft fans hit by phishing scam

security update

How to Keep Your Web Hosting Account Safe From Hackers
New Mirai Variant Carries Out 54-Hour DDoS Attacks
Is this a solution to Trump signing away your digital privacy? We give Invizbox Go a go
Millions of websites affected by unpatched flaw in Microsoft IIS 6 web server
Github Repository Owners Targeted by Data-Stealing Malware
NukeBot Banking Trojan Source Code Leaked Online by Author

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for curl is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: New mariadb packages are available for Slackware 14.2 and -current to fix security issues. [More Info…]

LinuxSecurity.com: Security Report Summary

Financial fraud losses in the UK last year topped £20m a day – report
UK cops arrest 20-year-old on suspicion of blackmail and hacking
Malware campaign targets open source developers on GitHub

Be on your guard if you’re a developer who uses GitHub – someone could be trying to infect your computer with malware. The post Malware campaign targets open source developers on GitHub appeared first on WeLiveSecurity

New Mirai variant launched a 54 hour DDoS attack on a US college
Security co-operation unlikely to change post Brexit, despite threats
LastPass has a secret major vulnerability – and, as yet, there’s no fix
Carbon Paper: Peering into Turla’s second stage backdoor

The Turla espionage group has been targeting various institutions for many years. Recently, ESET found several new versions of Carbon. The post Carbon Paper: Peering into Turla’s second stage backdoor appeared first on WeLiveSecurity

Open-source developers targeted in sophisticated malware attack
Hacker Who Used Linux Botnet to Send Millions of Spam Emails Pleads Guilty
Five scams that won’t make you laugh on April Fool’s Day
VMware patches critical virtual machine escape flaws
Trump extends Obama executive order on cyberattacks
More fun in the sandbox: Experts praise security improvements to Edge
Industry Braces for Repeal of ISP Privacy Rules
Smashing Security #014: Protecting webmail
Encryp-xit: Europe will go all in for crypto backdoors in June
How to leak data from an air-gapped PC – using, er, a humble scanner
Kremlin-backed APT28 doesn’t even bother hiding its attacks, says Finnish secret police
Hey FCC, when you’re not busy screwing our privacy, how about those SS7 cell network security flaws, huh?
Recruiters considered really harmful: Devs on GitHub hit with booby-trapped fake job emails

Risk Level: Very Low. Type: Trojan.

Bloke is paid to scour hashtags for threats, spots civil rights boss’s tweets, gets fired, sues
Trojan source code leak could spur new online banking attacks

security update

Publicly Attacked Microsoft IIS Zero Day Unlikely to be Patched
US ISPs to Snub Users Privacy by Collecting Personal Data
Workarounds Available for Flaws in Siemens RUGGEDCOM Gear
Apple issues iPhone software update after fake police ransomware scam
VMware Patches Pwn2Own VM Escape Vulnerabilities
‘Anonymous’ FTP Servers Leaving Healthcare Data Exposed
Strange Mirai botnet brew blamed for powerful application layer attack
Changes coming to TLS: Part One
Phishers target World of Warcraft users with fake in-game pet offer
Harley Geiger on Cybersecurity Policy
Scareware scammers lock iOS Safari to extort ransom from users
The uncrackable problem of end-to-end encryption
Scammers scare iPhone users into paying to unlock not-really-locked Safari
US House votes to undo broadband privacy rules
Microsoft Offers Analysis of Zero-Day Exploited By Zirconium Group
46% off CyberPower Surge Protector 3-AC Outlet with 2 USB (2.1A) Charging Ports – Deal Alert
Intel Optane memory announced: A steroid to speed up your computer

security update

security update

security update

security update

security update

Vulnerable Smartphones, IoT Devices: 400% increase in infection rate
Apple Fixes 223 Vulnerabilities Across macOS, iOS, Safari

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

Risk Level: Very Low. Type: Trojan.

LastPass is scrambling to fix another serious vulnerability
Laptops With More than 3.7 Million Hong Kong Voters’ Data Stolen
RIP: Antivirus veteran Raimund Genes, 54

Ransomware authors are pivoting their attacks from individuals to government entities and health care institutions, causing a threat to public safety. Traditionally, crypto ransomware targeted individuals and encrypted their personal data and files as a form of extortion for hundreds of dollars. Ransomware has evolved to target businesses and government agencies for much larger financial […]

Apple squashes cert-handling bug affecting macOS and iOS
Close to 1.4 billion data records compromised in 2016

Over a billion data records were compromised globally in 2016, according to Gemalto’s latest Breach Level Index. The post Close to 1.4 billion data records compromised in 2016 appeared first on WeLiveSecurity

API flaws said to have left Symantec SSL certificates vulnerable to compromise
How to respond to device and software backdoors inserted or left by vendors
World+dog had 1.4 BEEEELLION of its data records exposed last year
Free public certificate authorities: Nice idea, big flaw

Readers often ask me how I feel about the latest free, public certificate authorities (CAs). I always tell them the same thing: It’s difficult for a free CA to actually provide any security assurance. There is no free lunch.I was reminded of this maxim when I read a recent article from HashedOut revealing that the […]

“Unique and Highly Sophisticated” Vulnerability Found in LastPass Manager
As of today, iThings are even harder for police to probe
CompSci boffins propose scheme to protect privacy in database searches

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.