Menu

Category Archives: Security

Articles about security

‘Zombie script’ deluges Internet Explorer 11 with pop-up alerts until user closes tab
How to Install TOR on Android and iOS Devices
Microsoft catches up to Valentine’s Day Flash flaw massacre
Boffins exfiltrate data by blinking hard drives’ LEDs
Linux kernel gets patch for 11-year-old local-root-hole security bug
Firefox certificate cache leaks user information
US judge halts mass fingerprint harvesting by cops to unlock iPhones

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

New MacOS ransomware spotted in the wild
Criminals Monetizing Attacks Against Unpatched WordPress Sites
Chrome Users Beware- Do Not Fall Prey to Missing Font Malware Campaign
Netflix Stethoscope gives users a BYOD security checkup
Blundering Boeing bod blabbed spreadsheet of 36,000 coworkers’ personal details in email
BugDrop Malware Campaign Obtains Data by Compromising PC Microphones
Google Upspin Secure File-Sharing Released to Open Source
Intermediate CA Caching Could Be Used to Fingerprint Firefox Users

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Android malware: It doesn’t hurt to know about this

Android malware is an increasing problem … but worry not – n this infographic, we highlight some of the key things you should be aware of. The post Android malware: It doesn’t hurt to know about this appeared first on WeLiveSecurity

Gordon Ramsay’s father-in-law charged with hacking celebrity chef’s email
Privacy concerns over gaps in eBay crypto
Good news and bad news on the Microsoft patch front
South Korea’s Asiana Airlines Website Hacked with Pro-Serbian Messages
Operation BugDrop – hackers steal gigabytes of data from organisations, record conversations
Sunny with a chance of stolen credentials: Malicious weather app found on Google Play

ESET has spotted a new banking malware on Google Play. Disguised as a weather forecast app, it steals banking credentials and locks screens. The post Sunny with a chance of stolen credentials: Malicious weather app found on Google Play appeared first on WeLiveSecurity

Infosec firm NCC Group launches review over crap financials
New crypto-ransomware hits macOS

This last month we have seen a new ransomware for Mac. Written in Swift, it is distributed on BitTorrent distribution site as “Patcher” for pirating popular software. The post New crypto-ransomware hits macOS appeared first on WeLiveSecurity

7 Wi-Fi vulnerabilities beyond weak passwords
Why you need a bug bounty program
“Secure” Trump website defaced by hacker claiming to be from Iraq

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

Netflix treats security ills with Stethoscope: Open-source self-probing tool
How’s your online bank security looking? The Dutch studied theirs and… yeah, not great
DomainMonster mash: Hundreds of websites vandalized after Brit web host server hacked

LinuxSecurity.com: Ruby Archive::Tar::Minitar is vulnerable to a directory traversal attack.

LinuxSecurity.com: Multiple vulnerabilities have been found in GPL Ghostscript, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

Talos opens box, three Aerospike vulns fly out
Researchers offer simple scheme to stop the next Stuxnet
Smashing Security podcast: Macs and malware
Tiny “Spyslide Webcam Cover” Protects Your Privacy From Hackers, Spies
Microsoft rolls out KB 4010250 Flash Player update for Windows 8.1 and 10
US Homeland Security is so secure even its own staff can’t log in
Check How Facebook AI Monitors Your Activities with this Crazy Chrome Extension
The real problem with the security industry
Data Stealing Malware TeamSpy Resurfaces in Spam Campaign
OpenSSL Update Fixes High-Severity DoS Vulnerability
‘Hey, Homeland Security. Don’t you dare demand Twitter, Facebook passwords at the border’

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

You are not alone; YouTube is down for everyone (Updated)
Java and Python FTP attacks can punch holes through firewalls
TeamSpy malware targeting users through malicious TeamViewer app
Google Discloses Unpatched Microsoft Vulnerability
Verizon knocks off $350M from Yahoo deal after breaches
Rook Security on Online Extortion
Windows Botnet Spreading Mirai Variant
Hacking group RTM able to divert bulk financial transfers with malware
Healthcare data breaches reach a ‘sizeable number of US consumers’

Approximately 26% of Americans have been compromised by healthcare data breaches, according to a new survey from Accenture. The post Healthcare data breaches reach a ‘sizeable number of US consumers’ appeared first on WeLiveSecurity

Surprise! Microsoft issues Flash patches for Internet Explorer, Edge
Prison for former sysadmin who hacked industrial facility and caused a million dollars worth of damage
How to protect your Microsoft account with two-step verification (2SV)
RTM: Stealthy group targeting remote banking system

Today, ESET has released a white paper on RTM, a cybercrime group that has been relentlessly targeting businesses in Russia and neighboring countries. The post RTM: Stealthy group targeting remote banking system appeared first on WeLiveSecurity

TeamSpy hackers get the crew back together after four-year hiatus
Kaspersky: No whiff of Linux in our OS because we need new start to secure IoT
Intent-Based Security Gains Momentum at RSA
Would killing Bitcoin end ransomware?
12 steps to small business security
The 7 security threats to technology that scare experts the most
RSA: Elite cryptographers scoff at idea that law enforcement can ‘overcome’ encryption
Build your security defense on data, not guesswork

One of the biggest problems with security defenses is the lack of concrete data to measure the effectiveness of mitigations against threats. In almost any other industry, the dearth of data would be embarrassing. As I’ve noted before, every organization needs to develop a data-driven security defense. Such a defense uses a company’s own threat intelligence to […]

Java and Python have unpatched firewall-crossing FTP SNAFU
EA Servers Go Down; Battlefield 1 Servers Facing Outage

LinuxSecurity.com: Multiple vulnerabilities have been found in tcpdump, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in PHP, the worst of which could lead to arbitrary code execution or cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in Xen, the worst of which could lead to the execution of arbitrary code on the host system.

LinuxSecurity.com: Multiple vulnerabilities have been found in Nagios, the worst of which could lead to privilege escalation.

LinuxSecurity.com: Multiple vulnerabilities have been found in QEMU, the worst of which could lead to the execution of arbitrary code on the host system.

LinuxSecurity.com: Multiple vulnerabilities have been found in libass, the worst of which have unknown impacts.

LinuxSecurity.com: Multiple vulnerabilities have been found in LibVNCServer/LibVNCClient, the worst of which allows remote attackers to execute arbitrary code when connecting to a malicious server.

LinuxSecurity.com: Multiple vulnerabilities have been found in Dropbear, the worst of which allows remote attackers to execute arbitrary code.

Gun Retailer Airsoft GI’s Forum Hacked; 65,000 User Accounts Leaked

LinuxSecurity.com: A vulnerability in Opus could cause memory corruption.

LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: A buffer overflow in TigerVNC might allow remote attackers to execute arbitrary code.

Hacker defaces Donald Trump fundraising site via subdomain takeover attack

LinuxSecurity.com: Security fix for CVE-2017-3135

LinuxSecurity.com: Multiple vulnerabilities have been found in MuPDF, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in the GNU C Library, the worst of which allows context-dependent attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability in NTFS-3G allows local users to gain root privileges.

LinuxSecurity.com: Security fix for CVE-2017-5595