Menu

Category Archives: Security

Articles about security

Lovely. Now someone’s ported IoT-menacing Mirai to Windows boxes
25% off Kuna Smart Home Security Outdoor Light & Camera – Deal Alert

security update

Run this in April: UPDATE Azure SET SQLthreat_detection = ‘generally available’
Tor and Its 10 Best Alternatives
IDG Contributor Network: Why executive orders aren’t enough to fix cybersecurity
Microsoft unveils a bonanza of security capabilities
Deleted browsing history on safari may not actually be deleted

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Minor upstream release fixing CVE-2016-8610, CVE-2017-3731, CVE-2017-3732.

LinuxSecurity.com: Important change: * most of the utilities were move to the new sub-package”server-utils” Other enhancements: (see changelog) * CVE fixes, SPECfilefixes, patches revision, tests blacklist revisions * Preparation and testing ofthe Cracklib plugin to be added

LinuxSecurity.com: Add upstream patches fixing CVE-2016-9577 and CVE-2016-9578

LinuxSecurity.com: gnome-boxes 3.20.4 release, fixing a possible security issue with storing theexpress installation password in clear text. – Store the user password in thekeyring during an express installation. – Fix typo in debug string. – Fix printfformat strings.

LinuxSecurity.com: Version 1.1.26 (released 24-Jan-2017) * security fix: escape nav_data name toavoid XSS attack Version 1.1.25 (released 15-Sep-2016) * fix _rev2optrevassertion on long input

Recent WordPress vulnerability used to deface 1.5 million pages
Protecting Small Business from Increasing Cyber Attacks
1.5M Unpatched WordPress Sites Hacked Following Vulnerability Disclosure
How to better protect your WhatsApp account with two-step verification (2SV)
Apple iCloud didn’t wipe ‘deleted’ browser histories for over a year

Macros Turn Focus Towards MacOS Researchers have discovered a trend of malicious Microsoft Word documents for MacOS that behave similar to Windows macro infections. The culprits download and execute a malicious payload to a user’s computer. While not particularly sophisticated, the macro-based infections focus on exploiting the users of the computer, rather than a software […]

Crossing border security? Here’s how you protect your data
Apple’s iCloud saved deleted browser records, security company finds
Microsoft lawsuit against indefinite gag orders can proceed
Arby’s Gets Roasted in Breach of 300K Payment Cards
Caution! The cloud’s backdoor is your datacenter

LinuxSecurity.com: Update to 2.1

LinuxSecurity.com: January 2017 security fixes – http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html#AppendixJAVA

LinuxSecurity.com: Security fix for CVE-2017-5884, CVE-2017-5885

LinuxSecurity.com: * various security relevant flaws

After Linux; Mirai Botnet is Available for Windows

LinuxSecurity.com: January 2017 security fixes – http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html#AppendixJAVA

Scottish court issues damages to couple over distress caused by neighbour’s use of CCTV
Explained: Apple iCloud kept ‘deleted’ browser histories for over a year
Russian Authorities Arrest Nine for Stealing $17 Million from Banks
Trump cybersecurity order morphs into 2,200-plus-word extravaganza

security update

security update

Clusters f**ked: Insecure Hadoop file systems wiped by miscreants

LinuxSecurity.com: Several security issues were fixed in the kernel.

Macs don’t get viruses? Hahaha, ha… seriously though, that Word doc could be malware
High Severity BIND Vulnerability Can Lead to A Crash

LinuxSecurity.com: Security Report Summary

InterContinental Hotels Group confirms suspected data breach

The InterContinental Hotels Group has revealed that 12 of its hotels suffered a data breach between August and December last year. The post InterContinental Hotels Group confirms suspected data breach appeared first on WeLiveSecurity

Smashing Security podcast #007: ‘ASCII art attack’
Tried-and-true Triada supplants Hummingbad as top mobile malware
CryptoShield Infections from RIG EK Picking Up
Life after antivirus: Reinventing endpoint security
Dino Dai Zovi on Securing Linux in Modern Workloads
Consortium Publishes Manifesto on Autonomous Vehicle Security
How to create a robust data backup plan (and make sure it works)
French man sues Uber after privacy bug led wife to suspect adultery
Cardiff researchers get £250k to monitor Brexit hate crime on Twitter
US could demand social media passwords of visa applicants
How to Manage the Security Vulnerabilities of Your Open Source Product
The Android Wear 2.0 terror and other fake news
USMC: We want more F-35s per year than you Limeys will get in half a decade

LinuxSecurity.com: Security Report Summary

Is GDPR good or bad news for business?

The General Data Protection Regulation (GDPR), the biggest reform of privacy legislation for 20 years, will come into effect on May 25, 2018, bringing with it major changes to Europe’s privacy laws. The post Is GDPR good or bad news for business? appeared first on WeLiveSecurity

LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary and Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

Mag publisher Future stored your FileSilo passwords in plaintext. Then hackers hit
F5’s Big-IP leaks little chunks of memory, even SSL session IDs

LinuxSecurity.com: Several security issues were fixed in OpenJDK 7.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

security update

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: Version 1.1.26 (released 24-Jan-2017) * security fix: escape nav_data name toavoid XSS attack Version 1.1.25 (released 15-Sep-2016) * fix _rev2optrevassertion on long input

LinuxSecurity.com: Upstream 3.2.7 (important security fix)

Want to come to the US? Be prepared to hand over your passwords if you’re on Trump’s hit list

LinuxSecurity.com: Important change: * Most of the utilities were move to the new sub-package”server-utils” Other enhancements: (see changelog) * CVE fixes, SPECfilefixes, patches revision, tests blacklist revisions * Preparation and testing ofthe Cracklib plugin to be added

LinuxSecurity.com: BitlBee 3.5.1 (30 Jan 2017) =========================== – purple: Fix crash onfile transfer requests from unknown contacts. This was the result of anincomplete fix in the previous release and may result in remote DoS. Read thefull security advisory at: https://bugs.bitlbee.org/ticket/1282 – After someinvestigation we decided to reclassify a crash fix from the previous release asa […]

Ex-NSA contractor Harold Martin indicted: He spent ‘up to 20 years stealing top-secret files’
Revealed: ‘Suicide bomber Barbie’ and other TSA quack science that cost $1.5 billion
Retail Giant Sports Direct Suffered Data Breach Affecting 30,000 Employees
Fileless Memory-Based Malware Plagues 140 Banks, Enterprises

LinuxSecurity.com: Security Report Summary

Pony credential stealer trampling users via Microsoft Publisher documents
Hackers deface thousands of website by exploiting WordPress vulnerability

LinuxSecurity.com: Update to 2.78.0. Fixes bug #1409216

Good guy Logic Supply resolves breach in days, unlike some companies
Mac malware from Iran targeting US defense industry, human rights activist

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Smashing Security podcast: Email attachment malware
Valve Patches Trivial XSS Bug in Steam
Conviction by computer is go, confirms UK Ministry of Justice
Uber Debuts SSH Key Authentication Module
Do you know where that open source came from?
Sports Direct hacked last year, and still hasn’t told its staff of data breach

Throughout 2016, many of the attacks and risks in the world of cybercrime followed “analog” crime: holding something for ransom/extortion, propaganda, theft, and identity scams. You might expect a cybersecurity vendor to see these trends as good for business, but in fact it’s the opposite. The modern world relies heavily on the internet and web […]

XSS marks the spot: Steam vuln dangles potential phishing line
Macro Malware Comes to macOS
Entrust your security secrets to a safe pair of hands

Imagine: your security is flawless. Not a single other person can access your sensitive information or accounts. And then the unthinkable happens – you’re in an accident. How will your loved ones get past your security measures to tend to your affairs? The post Entrust your security secrets to a safe pair of hands appeared […]

Ex-FireEye intern escapes prison sentence after creating and selling Dendroid malware
Revealed: Malware that skulks in memory, invisibly collecting sysadmins’ passwords
Open source users: It’s time for extreme vetting
Sophos to assimilate Invincea’s intelligent machine tech to fight malware