Menu

Category Archives: Security

Articles about security

Android Password Manager You Trust Could be Exposing Login Data
We found a hidden backdoor in Chinese Internet of Things devices – researchers
FCC halts data security regulations for broadband providers
Why Internet of Things is the world’s greatest cyber security threat
Yahoo execs botched its response to 2014 breach, investigation finds
Google reCaptcha Bypass Technique Uses Google’s Own Tools
Smashing Security #010: The dolls must be destroyed
Famed Hacker Kevin Mitnick Shows You How to Go Invisible Online
Researchers find “severe” flaw in WordPress plugin with 1 million installs
Over a million websites could be at risk from critical WordPress gallery plugin flaw
Dark net webmail provider Sigaint still in the, er, dark
Major internet safety strategy to ‘bolster online safety’ for children in the UK

The UK is developing an internet safety strategy in an attempt to secure a position as “the safest place in the world for young people to go online”. The post Major internet safety strategy to ‘bolster online safety’ for children in the UK appeared first on WeLiveSecurity

Chatting with David Dufour, senior director of engineering, Webroot, is always interesting. Quite frankly, so is pinning him down for a short Q+A  about his experience at RSA 2017. One thing I could be sure of, though, was David having an opinion and being a straight shooter. As a first time attendee, I was curious […]

LinuxSecurity.com: Security Report Summary

Yahoo! dysfunction! meant! security! warnings! were! ignored!
Slack only took five hours to fix bug that could have allowed hackers to hijack your account

LinuxSecurity.com: Security Report Summary

Yahoo CEO Marissa Mayer will miss out on cash bonus after security breaches

security update

Come see me speaking at The Shard in London about security
Online shops plundered by bank card-stealing malware after bungling backend Aptos hacked
US-Europe Privacy Shield not worth the paper it’s printed on – civil liberties groups
Old Windows malware may have tampered with 132 Android apps
WordPress photo plugin opens ‘a million sites’ to SQLi database feasting
CloudPets Notifies California AG of Data Breach

security update

LinuxSecurity.com: The newest upstream commit, CVE-2017-6350 vim: Integer overflow at anunserialize_uep memory allocation site, CVE-2017-6349 vim: Integer overflow at au_read_undo memory allocation site

LinuxSecurity.com: fix CVE-2017-3156 (rhbz#1425455,1425458)

Slack Fixes Cross-Origin Token Theft Bug

LinuxSecurity.com: Security fix for CVE-2017-2586, CVE-2017-2587 and CVE-2017-5849, —- Addlicense information file copyright_summary —- New version of netpbm isavailable (10.77.00) —- add missing directives about bundled librariesjasper and jbigkit —- New version of netpbm is available (10.76.00)

LinuxSecurity.com: An update for openstack-puppet-modules is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for openstack-puppet-modules is now available for Red Hat OpenStack Platform 9.0 (Mitaka). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

Robots Rife With Cybersecurity Holes
Software engineer detained at JFK airport; forced to prove he is really an engineer
Smart teddy bear maker faces scrutiny over data breach response
Infosec white-coats: Robots are riddled with software security bugs
Coachella festival website hacked; user data at risk
Vice News YouTube commenter set for retrial over ‘menacing’ posts
Speaking in Tech: A chat with Web 2.0 MySpace worm dude Samy Kamkar
Million-Plus WordPress Sites Exposed by Vulnerable Plugin
Massive Bug May Have Leaked User Data From Millions of Sites. So … Change Your Passwords
Here’s Why Net Neutrality is Essential in Trump’s America
Google shifts on email encryption tool, leaving its fate unclear
Palo Alto Networks buys LightCyber for $105m
Talking Android ransomware extorts victims

Talking Android ransomware sounds like something out of a science fiction movie. It’s not – it’s very real, explains ESET’s Lukas Stefanko. The post Talking Android ransomware extorts victims appeared first on WeLiveSecurity

How to recover from the OSX/Filecoder.E ransomware on your Mac
Prisoners’ ‘innovative’ anti-IMSI catcher defence was… er, tinfoil
Gatekeeper-like feature for Windows 10 only allows apps to be installed from the Microsoft Store

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

Tricksy bugs in Zscaler admin portal let you ruin a coworker’s day
CloudPets’ woes worsen: Webpages can turn kids’ stuffed toys into creepy audio bugs

LinuxSecurity.com: Security Report Summary

security update

Amazon Web Services suffer massive outage taking popular sites down
Google Discloses Critical Existing Bug in Internet Explorer and Edge
Siemens RUGGEDCOM NMS Equipment Vulnerable to CSRF, XSS

LinuxSecurity.com: This update rebases RPM to the official 4.13.0.1 release(http://rpm.org/wiki/Releases/4.13.0.1) which includes several importantsecurity and regression fixes.

LinuxSecurity.com: cirrus_bitblt_cputovideo does not check if memory region is safe [XSA-209,CVE-2017-2620] (#1425420)

LinuxSecurity.com: New release (1.10a). Security fix for CVE-2016-6265

LinuxSecurity.com: Security fix for CVE-2017-2616

LinuxSecurity.com: Security fix for CVE-2016-8745

LinuxSecurity.com: Security fix for CVE-2016-6265

Dridex Trojan Gets A Major ‘AtomBombing’ Update
Security slip-ups in 1Password and other password managers ‘extremely worrying’
IDG Contributor Network: The dangers of the public internet
Unpatched SMB Zero Day Easily Exploitable
Stuffed Toys manufacturer hacked; millions of accounts and voice messages stolen
Children’s Voice Messages Leaked in CloudPets Database Breach
Torvalds Downplays SHA-1 Threat to Git
Our TV Viewing Habits Can Be Monitored for the Benefit of Marketers
10 reasons why cybercriminals target smartphones

There is a real feeling that smartphones are becoming a bigger target for cybercriminals. So why are they so eager to get into our devices? The post 10 reasons why cybercriminals target smartphones appeared first on WeLiveSecurity

Over 800,000 user account details stolen from vulnerable forums running vBulletin
Health firm gets £200k slap after IVF patients’ data leaks online
Will a cyber crisis add to chaos of Trump’s first 100 days?
This tiny chip could revolutionize smartphone and IoT security
Carders capitalize on Cloudflare problems, claim 150 million logins for sale
Google End-to-End encrypted email code goes open-source
Red alert! Beware of insiders bearing APTs

We live in a global society. While your country’s economy may be stagnating or barely growing, someone else’s economy is probably booming. It’s no wonder your company is reaching across international borders to establish new business ties and revenue sources. That’s all well and good. But you should also know that I’ve consulted for a […]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5.6 Long Life. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

Germany, France lobby hard for terror-busting encryption backdoors – Europe seems to agree

LinuxSecurity.com: An update for java-1.7.0-ibm is now available for Red Hat Enterprise Linux 5 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary and Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for java-1.6.0-ibm is now available for Red Hat Enterprise Linux 5 Supplementary and Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

Two million recordings of families imperiled by cloud-connected toys’ crappy MongoDB
ESET antivirus cracks opens Apple Macs to remote root execution via man-in-middle diddle
Microsoft slaps Apple Gatekeeper-like controls on Windows 10: Install only apps from store
Apple’s macOS is the safer choice – but not for the reason you think
Google Chrome 56’s crypto tweak ‘borked thousands of computers’ using Blue Coat security
Boeing Notifies 36,000 Employees Following Breach

security update

126 vBulletin forums hacked; 819,977 accounts leaked on hacking forums

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 9.0 (Mitaka). Red Hat Product Security has rated this update as having a security impact [More…]