Menu

Category Archives: Security

Articles about security

Android YouTube download apps flood devices with ads to secure high ratings for droppers
‘Nigerian princes’ snatch billions from Western biz via fake email – Interpol
MAC randomization: A massive failure that leaves iPhones, Android mobes open to tracking

security update

What a Flake: Congress mulls trashing privacy rules, letting ISPs go to town on your data
Want a Career in Cybersecurity? Find Out Which Degrees Can Get You There
Hundreds of Thousands of Vulnerable IP Cameras Easy Target for Botnet, Researcher Says
640,000 Decrypted PlayStation Accounts Being Sold on DarkWeb

security update

The convenience of having some kind of internet connection on more and more of the devices we use each day is undeniable. However, without proper security vetting, this convenience may come at a hefty price. In the past year alone, we’ve seen millions of routers, DVRs, IP cameras, cars, and more get hacked and either […]

Zero-days? Sexy, sure, but crap passwords and phishing are probably more pressing

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Attacks Heating Up Against Apache Struts 2 Vulnerability
Consumer Reports launches new privacy and data security standard

The US-based nonprofit organization Consumer Reports has come up with a new standard that aims to boost consumer confidence in privacy and data security. The post Consumer Reports launches new privacy and data security standard appeared first on WeLiveSecurity

Instagram phishing apps pulled from Google Play
Brit ISP TalkTalk blocks control tool TeamViewer
Google Patched Hundreds of Android Security Flaws in March Update
Apache Struts bug is under attack, patch now
New Instagram credential stealers discovered on Google Play

ESET researchers discovered 13 new Instagram credential stealers on Google play and looked into the motivations behind their fraudulent schemes. The post New Instagram credential stealers discovered on Google Play appeared first on WeLiveSecurity

Royal Navy’s newest ship formally named in Glasgow yard
Smashing Security #011: WikiLeaks and the CIA
Bots: Biggest player on the cybercrime block
Hackers exploit Apache Struts vulnerability to compromise corporate web servers
WikiLeaks publishes docs from what it says is trove of CIA hacking tools
Google’s ‘SHA-1 Countdown Clock’ Could Undermine Enterprise Security
Ways in which to plug the infosec talent gap

ESET’s Lysa Myers looks at the shortage of qualified information security talent to fill positions, discussing ways in which to plug the infosec talent gap. The post Ways in which to plug the infosec talent gap appeared first on WeLiveSecurity

Oops! 185,000-plus Wi-Fi cameras on the web with insecure admin panels

In honor of International Women’s Day, we hosted our quarterly Women of Webroot meeting this afternoon at our World Headquarters in Broomfield. Women of Webroot brings together women from all parts of our business to celebrate wins and provide support for issues women in tech may face. Although there are more women in technology-related positions […]

Apache Struts 2 needs patching, without delay. It’s under attack now
Buggy backups! Unplug your WD My Cloud until these flaws are fixed

Risk Level: Very Low. Type: Trojan.

FBI boss: ‘Memories are not absolutely private in America’
Senator Demands Answers About CloudPets Breach
Dark Web Suffers After Anonymous Hacked Firm Hosting Child Porn Sites
Leaked docs suggest NSA and CIA behind Equation cyberespionage group
CIA hacking dossier leak reignites debate over vulnerability disclosure
Confide Updates App After Critical Security Issues Are Raised
Facebook Call Cops on BBC for Exposing Child Abuse Content
Apple has already fixed most of the iOS exploits the CIA used
Firefox 52 Expands Non-Secure HTTP Warnings, Enables SHA-1 Deprecation
Good Weather App radio interview with Alexis Dorais-Joncas and Marc Saltzman

A full radio interview with ESET’s Alexis Dorais-Joncas and radio and TV personality Marc Saltzman – on NewsTalk 1010 – talking about a malicious weather app that was found on Google Play. The post Good Weather App radio interview with Alexis Dorais-Joncas and Marc Saltzman appeared first on WeLiveSecurity

Verifone downplays impact of recent breach
Comey Talks Strong Crypto, Silent on WikiLeaks
Wikileaks Vault 7: CIA hacked Smart TVs, Phones, Trucks and Computers
CIA false flag team repurposed Shamoon data wiper, other malware
Messaging app used by Trump aides ‘riddled with security bugs’
Dahua security camera owners urged to update firmware after vulnerability found
Rate this as five stars or we’ll bombard you with pop-up ads
Aggressive ad-displaying Google Play app tricks users into leaving high ratings

ESET researchers have observed an increased number of apps on Google Play using social engineering techniques to boost their ratings, ranging from legitimate apps, through adware to malware. The post Aggressive ad-displaying Google Play app tricks users into leaving high ratings appeared first on WeLiveSecurity

Lame comment spam campaign attempts to promote iPhone app
Wikileaks Just Dumped a Cache of Information on Alleged CIA Hacking Tools
Next Generation Security: No, Dorothy, there is no magic wand

LinuxSecurity.com: Fixed CVE 2017-2590: freeipa: ipa: Insufficient permission check for ca-del, ca-disable and ca-enable commands [fedora-all]

LinuxSecurity.com: * [7.x-1.21](https://www.drupal.org/project/metatag/releases/7.x-1.21) *[Moderately Critical – Information disclosure – SA-CONTRIB-2017-019](https://www.drupal.org/node/2852937)

LinuxSecurity.com: Security fix for CVE-2017-5884, CVE-2017-5885

LinuxSecurity.com: This is a new upstream feature and security release. Improvements include:bypass; pre-filter — fast packet keywords; TLS improvements; ICS protocoladditions: DNP3 CIP/ENIP; SHA1/SHA256 for file matching, logging & extraction;NIC offloading disabled by default; unix socket enabled by default; and AppLayer stats. Documentation: http://suricata.readthedocs.io/en/suricata-3.2/

Time’s up for SHA-1 hash algo, but one in five websites still use it

LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary and Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: * [7.x-1.21](https://www.drupal.org/project/metatag/releases/7.x-1.21) *[Moderately Critical – Information disclosure – SA-CONTRIB-2017-019](https://www.drupal.org/node/2852937)

LinuxSecurity.com: cirrus_bitblt_cputovideo does not check if memory region is safe [XSA-209,CVE-2017-2620] (#1425420)

LinuxSecurity.com: – Update to 1.0.4 Release notes: http://www.cacti.net/release_notes_1_0_0.phphttp://www.cacti.net/release_notes_1_0_1.phphttp://www.cacti.net/release_notes_1_0_2.phphttp://www.cacti.net/release_notes_1_0_3.phphttp://www.cacti.net/release_notes_1_0_4.php

LinuxSecurity.com: Security fix for CVE-2017-5884, CVE-2017-5885

LinuxSecurity.com: This is a new upstream feature and security release. Improvements include:bypass; pre-filter — fast packet keywords; TLS improvements; ICS protocoladditions: DNP3 CIP/ENIP; SHA1/SHA256 for file matching, logging & extraction;NIC offloading disabled by default; unix socket enabled by default; and AppLayer stats. Documentation: http://suricata.readthedocs.io/en/suricata-3.2/

That CIA exploit list in full: The good, the bad, and the very ugly
Top tip: Unplug your WD My Cloud boxen – now

LinuxSecurity.com: Security Report Summary

Dahua video kit left user credentials in plain sight
Is the CIA’s Weeping Angel spying on TV viewers?
US Senator snaps on glove, probes insecure IoT toymaker CloudPets

LinuxSecurity.com: New mozilla-thunderbird packages are available for Slackware 14.1, 14.2, and -current to fix security issues. [More Info…]

Firefox 52 warns when you try to enter passwords on non-encrypted websites
Ohi-D’oh! US prison hands inmates’ SSNs over to… an identity thief
Hacking the hackers: Draft US bill would allow hacking victims to hack back

security update

As if the job market isn’t hard enough to break into, rising seniors and recent college graduates are employment scam targets. In January, the FBI issued a warning that employment scams targeting college students are still alive and well. Employment Scams – A Public Service Announcement According to the FBI, scammers advertise phony job opportunities […]

Windows snooping patches KB 2952664, KB 2976978 are back (again)
WikiLeaks Reveals CIA’s Hacking Capabilities in ‘Vault 7’ series documents
WordPress 4.7.3 Patches Half-Dozen Vulnerabilities
Spies do spying, part 97: Shock horror as CIA turn phones, TVs, computers into surveillance bugs
Unpatched Western Digital Bugs Leave NAS Boxes Open to Attack
Dahua Patching Backdoor in DVRs, IP Cameras

LinuxSecurity.com: An update for ansible and openshift-ansible is now available for Red Hat OpenShift Container Platform 3.2, Red Hat OpenShift Container Platform 3.3, and Red Hat OpenShift Container Platform 3.4. [More…]

WordPress fixes XSS, CSRF flaws in latest core update
Android gets patches for critical OpenSSL, mediaserver, and kernel driver flaws
Why email is safer in Office 365 than on your Exchange server
Google Increases its Bug Bounty Program Reward Money
Cybercrooks charging more than the price of a new car for undetectable Mac malware
Active Defense Bill Raises Concerns Of Potential Consequences
Facebook shopped BBC hacks to National Crime Agency over child abuse images probe
Scammers hired hundreds of ‘staff’ to defraud TalkTalk customers
WordPress webmasters urged to upgrade to version 4.73 to patch six security holes
HackerOne offers bug bounty service for free to open-source projects
The Border Patrol can take your password. Now what?
4 strategies to root out your security risks

You’ll never reduce your security risk if you can’t identify and mitigate the root causes of those vulnerabilities. It isn’t enough to have a list of malware programs that your antimalware has detected. You need to to determine how viruses and hackers have penetrated your environment in the past. In the vast majority of organizations, […]

LinuxSecurity.com: Security fix for CVE-2017-6060 CVE-2017-5896 —- Add comment with explanationof disabled debuginfo

LinuxSecurity.com: – Update to 1.0.4 Release notes: http://www.cacti.net/release_notes_1_0_0.phphttp://www.cacti.net/release_notes_1_0_1.phphttp://www.cacti.net/release_notes_1_0_2.phphttp://www.cacti.net/release_notes_1_0_3.phphttp://www.cacti.net/release_notes_1_0_4.php

Boffins show Intel’s SGX can leak crypto keys
That big scary 1.4bn leak was basically nothing but email addresses
Shamoon malware spawns even nastier ‘StoneDrill’