Menu

Category Archives: Security

Articles about security

In a big crop of Windows fixes, Patch Tuesday includes a few surprises
Russian! spies! ‘brains! behind!’ Yahoo! mega-hack! – four! charged!

Type: Vulnerability. Microsoft Office is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows DVD Maker is prone to an unspecified cross-site request-forgery vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows DirectShow is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

NSA hacking chief’s mission impossible: Advising White House on cybersecurity
WhatsApp, Telegram Vulnerabilities Exposed Users to Account Takeover

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

FSB Officers, Criminal Hackers Indicted in Yahoo Breach
JSON Libraries Patched Against Invalid Curve Crypto Attack
WhatsApp blind-sided by booby-trapped photo vulnerability
Maybe Microwaves can be hacked but turn them into cameras? Nah
More Brits’ IDs stolen than ever before
Where Have All The Exploit Kits Gone?
Microsoft stays security bulletins’ termination
U.S. to Charge 4 Hackers Involved in Massive Yahoo Data Breach
Twitter accounts hacked, Twitter Counter steps forward as culprit
Twitter app pwned by pro-Turkey hackers: Users’ accounts sling ‘Nazi’ slurs
Red Hat Product Security Risk Report 2016
Malware found preinstalled on 38 Android phones used by 2 companies
NSA, DOE see China nearing supercomputing leadership
Sorry for the Nazi spam from my Twitter account

LinuxSecurity.com: Security Report Summary

Petya ransomware returns, wrapped in extra VX nastiness
Boffins Rickroll smartphone by tickling its accelerometer
Anonymous Brazil Hacks Football Club for Hiring Goalkeeper Convicted of Murder
Hyper-V guest escape, drive-by PDF pwnage, Office holes, SMB flaws – and more now patched
Apple urged to legalize code injection: Let apps do JavaScript hot-fixes
Proof-of-concept confirms Nintendo Switch videogame console vulnerable to WebKit exploit

security update

Google Eliminates Android Adfraud Botnet Chamois
Patch Tuesday Returns; Microsoft Quiet on Postponement
Beware; 36 Android Devices Shipped with Preinstalled Malware
Misconfigured Drive Leads to Data Leak of Thousands of US Air Force Officials
The NSA’s foreign surveillance: 5 things to know

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: This update fixes a possible heap buffer overflow.

LinuxSecurity.com: Security fix for

LinuxSecurity.com: This kdelibs3 (KDE 3 compatibility libraries) update fixes the security issues:* CVE-2016-6232 (karchive): Extraction of tar files possible to arbitrary systemlocations * CVE-2017-6410 (kio): Information Leak when accessing https whenusing a malicious PAC file for the KDE 3 compatibility libraries. (Securityupdates for KDE Frameworks 5 (kf5-karchive resp. kf5-kio) and for the KDE 4compatibility libraries […]

LinuxSecurity.com: For changes see: https://www.mozilla.org/en-US/thunderbird/45.8.0/releasenotes/

Significant cyberthreat to UK businesses continues to grow

Greater collaboration is needed in order to combat the significant threat of cybercrime to British businesses, according to the UK’s National Crime Agency and the National Cyber Security Centre. The post Significant cyberthreat to UK businesses continues to grow appeared first on WeLiveSecurity

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Adobe Fixes Six Code Execution Bugs in Flash
Facebook bars developers from using data feeds for spying tools
WordPress REST API Bug Could Be Used in Stored XSS Attacks
Manchester’s Munee Hut, Eyebrow Cottage and fresh hot spam from Belize
Cybercriminals getting as good as nation state spies – report
SAP Patches Critical HANA Vulnerability That Allowed Full Access
It’s time to turn on HTTPS: the benefits are well worth the effort
Operation Rosehub patches Java vulnerabilities in open source projects
Mirai is the hydra of IoT security: too many heads to cut off
Brit infosec’s greatest threat? Thug malware holding nation’s devices to ransom – report
6 security essentials the CIA forgot

Wikileaks’ CIA dump is the biggest secret cache released so far. It’s embarrassing to the CIA. It undermines our intelligence efforts. And it didn’t need to happen. The sad fact is that the world’s computers are not configured securely enough to match the confidentiality of the data they are protecting. As a society we allow […]

Poorly-configured online backup leaks US Air Force documents
Today’s WWW is built on pillars of sand: Buggy, exploitable JavaScript libs are everywhere
Naming computers endangers privacy, say ‘Net standards boffins

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

Apache Struts 2 bug bites Canada, Cisco, VMware and others

Type: Vulnerability. Microsoft Windows Uniscribe is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Uniscribe is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Uniscribe is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Uniscribe is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Uniscribe is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Uniscribe is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.