Menu

Category Archives: Security

Articles about security

Honeypots: Free psy-ops weapons that can protect your network before defences fail
Sloppy iOS apps expose ‘encrypted’ user traffic
Smashing Security podcast: Passwords
100,000+ WordPress webpages defaced as recently patched vulnerability is exploited
Attackers Capitalizing on Unpatched WordPress Sites

LinuxSecurity.com: gnome-boxes 3.22.4 release, fixing a possible security issue with storing theexpress installation password in clear text. – Store the user password in thekeyring during an express installation. – Fix typo in debug string in vm-configurator. – Fix printf format strings in the selectiontoolbar.

LinuxSecurity.com: Minor upstream release fixing CVE-2016-8610, CVE-2017-3731, CVE-2017-3732.

LinuxSecurity.com: Update to 2.78.0. Fixes bug #1409216

Feds snooping on your email without a warrant? US lawmakers are on a war path to stop that
Popular iOS Apps Vulnerable to TLS Interception Attacks
Smart TV Manufacturer Vizio Fined $2.2M for Tracking Customers
St. Jude Patches Additional Cardiac Device

LinuxSecurity.com: An update for ntp is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for spice is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for spice-server is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in RTMPDump, the worst of which could lead to arbitrary code execution.

LinuxSecurity.com: Update to 3.22.6: * Fix minor memory leak[(#682723)](https://bugzilla.gnome.org/show_bug.cgi?id=682723) * Fix seriouspassword extraction sweep attack on password manager[(#752738)](https://bugzilla.gnome.org/show_bug.cgi?id=752738) * Fix adblockerblocking too much stuff, breaking Twitter[(#777714)](https://bugzilla.gnome.org/show_bug.cgi?id=777714)

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: For changes see: https://www.mozilla.org/en-US/thunderbird/45.7.0/releasenotes/

Indian hackers hack Facebook groups for posting teen, revenge porn images
Laptop-light GoCardless says customers’ personal data may have been lifted
Polish banks hit by malware seemingly spread by government website
Phishing: Another thing we can blame on Brexit
Ransomware soars in 2016, while malware declines
76 Famous iOS Apps Vulnerable to Silent Data Interception
IRS-related phishing scams seen running rampant
76 popular iPhone apps found wide open to data interception attacks
Dozens of iOS apps fail to secure users’ data, researcher says
US House approves new privacy protections for email and the cloud
Kali Linux on the Raspberry Pi: 3, 2, 1, and Zero
Fretting over fake news? It's only going to get worse

If you’re worried about fake news, you ain’t seen nothing yet. Soon we may not be able to tell the difference between a fake video and a real one, even forensically. What we are seeing today is the tip of the iceberg. Fake news has already altered the world forever. It’s always been a huge […]

FTC vs. VIZIO: Getting smart about TV data collection and sharing

Is your smart TV selling data about what you watch, without asking? As the US FTC goes after one TV maker, it may be time to check. The post FTC vs. VIZIO: Getting smart about TV data collection and sharing appeared first on WeLiveSecurity

Darkode VXer handed three years’ probation
Trump’s cybersecurity strategy kinda makes sense, so why delay?
Got an OpenBSD Web server? Better patch it

Risk Level: Very Low.

Web banking malware slurps $1.2m for crooks, now kingpin ‘fesses up
Went out boozing in SF during Dreamforce or Oracle OpenWorld? Malware may have slurped your bank card
Vizio coughs up $2.2m after its smart TVs spied on millions of families
Hacker: I made 160,000 printers spew out ASCII art around the world

security update

LinuxSecurity.com: The 4.9.7 update contains a number of important fixes across the tree

LinuxSecurity.com: Welcome to **phpMyAdmin 4.6.6**, a release containing security and bug fixes.This release includes many security fixes of various levels of severity. Werecommend all users upgrade to this release immediately. For full information onthe vulnerabilities fixed and mitigation factors for users who are unable toupgrade, refer to the ChangeLog file included with this release and […]

InterContinental Hotels Confirms Credit Card Breach

LinuxSecurity.com: The 4.9.7 update contains a number of important fixes across the tree

LinuxSecurity.com: 3.1.4

LinuxSecurity.com: Welcome to **phpMyAdmin 4.6.6**, a release containing security and bug fixes.This release includes many security fixes of various levels of severity. Werecommend all users upgrade to this release immediately. For full information onthe vulnerabilities fixed and mitigation factors for users who are unable toupgrade, refer to the ChangeLog file included with this release and […]

ICS, SCADA Security Woes Linger On
Banking chiefs ‘lack confidence to identify data breaches’

Just over one in five banks and insurers are confident in their ability to identify data breaches, according to a new global survey from Capgemini Consulting. The post Banking chiefs ‘lack confidence to identify data breaches’ appeared first on WeLiveSecurity

Anonymous shut down thousands of Dark Web sites for hosting child porn
Why does it cost 20 times as much to protect Mark Zuckerberg as Tim Cook?
Hacker hijacks thousands of publicly exposed printers to warn owners
Hacker takes over thousands of Printers; sends alerts to users
Anonymous hacker took down 10,000+ dark web sites, including child abuse content
Hacker blackmails David Beckham following email leak
Security Sessions: The CSO’s role in active shooter planning
Polish banks hit by malware sent through hacked financial regulator
Security firms need to stop exaggerating hacker’s abilities to hype their products
Google ordered by U.S. court to produce emails stored abroad

The benefits of adopting the managed service provider (MSP) business model are compelling. After all, predictable, recurring revenue; deeper engagement with clients; and a trusted advisor relationship that generates further business opportunities all sound like everything a successful services business could want. However, for some, it still means braving uncharted territory. Important Considerations IT solutions […]

The best security solutions of the year
Microsoft’s DRM can expose Windows-on-Tor users’ IP address
Hello? Police? My darknet drug market was just hacked by criminals
“This is you?” message is the latest scam to be distributed via Facebook

Risk Level: Very Low. Type: Trojan.

Slammer worm slithers back online to attack ancient SQL servers
Why You Should Use These 5 VPN Services
Twitter Users Hit with Blue Badge Verification Phishing Scam
Hacker Dumps Hacking Tools Allegedly Stolen from Cellebrite
Privacy-Focused Tails 2.10 Linux Includes Security Updates, New Tools
Linux: The 10 best privacy and security distributions
AI isn’t for the good guys alone anymore
Thought your data was safe outside America after the Microsoft ruling? Think again
New SMB bug: How to crash Windows system with a ‘link of death’
Hacking the 2016 election: A timeline

Hotel Doors Locked By Ransomware A prestigious hotel in Austria was the target of a ransomware attack that left their electronic door locking systems inoperable for several hours. The hack only stopped hotel personnel from activating new keycards due to system is capabilities allowing the functionality without power. Unfortunately, the hotel did pay a ransom […]

PayPal Users Hit with Account Limited Phishing Scam
Honeywell SCADA Controllers Exposed Passwords in Clear Text
Locky Ransomware, Kovter Click-Fraud Malware Spreading in Same Campaigns

LinuxSecurity.com: This release turns on HTTPS encyption all over the publishing plugins. Usersusing Tumblr and Yandex.Fotki publishing are strongly advised to change theirpasswords and reauthenticate Shotwell to those services after upgrade. Users ofPicasa and Youtube publishing are strongly advised to reauthenticate (Log outand back in) Shotwell to those services after upgrade. Changes in shotwell0.24.5 release: […]

LinuxSecurity.com: This release turns on HTTPS encyption all over the publishing plugins. Usersusing Tumblr and Yandex.Fotki publishing are strongly advised to change theirpasswords and reauthenticate Shotwell to those services after upgrade. Users ofPicasa and Youtube publishing are strongly advised to reauthenticate (Log outand back in) Shotwell to those services after upgrade. Changes in shotwell0.24.5 release: […]

LinuxSecurity.com: This update should make OpenLDAP up to date with latest NSS, notably: – fixolcTLSProtocolMin handling – fix TLS_CIPHER_SUITE parsing – update a list ofciphers to fit latest NSS development – make use of NSS global settings for`DEFAULTS’ TLS_CIPHER_SUITE keyword Additionaly, slapd should start correctlyafter network is online, now.

LinuxSecurity.com: Update wavpack to 5.1.0

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for rabbitmq-server is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…]

Risk Level: Very Low. Type: Trojan.

Palestinian Engineer Jailed for Hacking Israeli CCTVs & Drones
Scammers target firms with W-2 phishing/CEO fraud blend
Sophos update borks systems at London NHS trust
Threatpost News Wrap, February 3, 2017
0-Day Security Flaw Could Lead Windows Devices to BSOD
Cisco Patches Authentication Bypass in Cisco Prime Home
Chinese hackers switch tactics for spying on Russian jet makers
Critical Cisco security hole could lead to hackers seizing control of thousands of home routers
Microsoft Waits for Patch Tuesday to Fix SMB Zero Day
How AI is stopping criminal hacking in real time
Vulnerability in Microsoft SMBv3 protocol crashes Windows PCs
UK defence secretary: Russian hacks are destabilising Western democracy
UK.gov slammed by Parliamentary types for ‘dysfunctional’ infosec
GCHQ cyber-chief slams security outfits peddling ‘medieval witchcraft’