Menu

Category Archives: Security

Articles about security

Telemarketing firm leaks 17,000 recorded calls, many containing credit card details
Nicolas Brulez on Malware Reverse Engineering Tips and Tricks
Another Radio Station Transmission hacked with F*** Donald Trump Songs
Privacy worries are on the rise, new U.S. poll shows
Cybersecurity: 5 basic lessons for everyone

A new way of looking at cybersecurity, no longer viewing it as a goal in itself, but instead something that is directly connected to business needs. The post Cybersecurity: 5 basic lessons for everyone appeared first on WeLiveSecurity

Facebook, GitHub teams up to make password resets more secure
NATO Members Targeted by Unique Macro Malware
We see you, ransomware flingers, testing out your baddest stuff on… Germany?
MongoDB ransom attacks continue to plague administrators
Better security through obscurity? Think again

When attackers look for vulnerabilities, they target popular software. Why bother chasing flaws in applications that few people use? That’s why one of my best friends runs a third-party application instead of Adobe Acrobat Reader to open and read PDF documents. Another friend runs the Maxthon browser to stay out of the way of exploits […]

Ransomware: Key insights from infosec experts

Ransomware is not going anywhere. Here, we’ve rounded up vital tips and advice from three ESET experts: Lysa Myers, Stephen Cobb and David Harley. The post Ransomware: Key insights from infosec experts appeared first on WeLiveSecurity

Want to bring down that pesky drone? Try the power of sound

LinuxSecurity.com: Multiple vulnerabilities have been found in HarfBuzz, the worst of which could allow remote attackers to cause a Denial of Service condition.

We don’t want to alarm you, but PostScript makes your printer an attack vector
Google’s Chrome is about to get rather in-your-face about HTTPS
VMware’s enterprise mobility management tool can p0wn itself
OpenSSL pushes trio of DoS-busting patches
Apple kills activation lock check, possible dirty stolen device hack
Infosec industry to drive machine learning spend surge says analyst
You’re taking the p… Linux encryption app Cryptkeeper has universal password: ‘p’
WTF is your problem, Netgear? Another hijack hole found in its routers

LinuxSecurity.com: An update for nagios is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for nagios is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for nagios is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for nagios is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

With net neutrality pretty much dead in the US, your privacy is next

security update

Forgot your GitHub password? Facebook cooks up spec to reset logins via social network
Hundreds of Thousands of Netgear Routers Vulnerable to Password Bypass

LinuxSecurity.com: Security Report Summary

Fake Netflix, WhatsApp, Facebook Android Apps Contain SpyNote RAT
Facebook Tackles Account Recovery with Delegated Recovery Protocol

security update

Telemarketing Firm Leaks 400,000 Recorded Calls
Ransomware avalanche at Alpine hotel puts room keycards on ice
Ransomware attack impacted 70% of Washington DC police surveillance cameras

LinuxSecurity.com: Update to 6.2.4

LinuxSecurity.com: Update to Firefox 51.0.1. —- – new upstream version (51.0.1)

LinuxSecurity.com: Security fix for CVE-2016-10164

LinuxSecurity.com: This is a security update for these CVEs: *[CVE-2016-9601](https://bugzilla.redhat.com/show_bug.cgi?id=1410021) – *Heap-buffer overflow in jbig2_image_new function* This update also solves possiblelicensing issues with ghostscritpt’s source code.

LinuxSecurity.com: Update to 7.0.4

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: A null pointer dereference in libpng might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in SQUASHFS, the worst of which may allow execution of arbitrary code

LinuxSecurity.com: An integer overflow in libXpm might allow remote attackers to execute arbitrary code or cause a Denial of Service Condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in FFmpeg, the worst of which may allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: A vulnerability in Firewalld allows firewall configurations to be modified by unauthenticated users.

Ransomware disrupts Washington DC’s CCTV system
Many Android VPN Apps Breaking Privacy Promises
70% of DC Police CCTV cameras were hacked before presidential inauguration
How a single SMS can break your Samsung Galaxy Android phone
Hackers Infect Hotel Door Lock System with Ransomware
Barclays warns customers of the risks of business email compromise
Has President Trump’s executive order on ‘Public Safety’ killed off Privacy Shield?
Questions to ask your recovery vendor before you buy
Managing risk by understanding attack surfaces
How most hackers get into systems
Some examples of vulnerable code and how to find them

“When looking for vulnerabilities in open-source code, it is advisable to check portions of code that is prone to errors”: Useful tips from one of ESET’s malware analysts, Matías Porolli, on how to spot vulnerable code. The post Some examples of vulnerable code and how to find them appeared first on WeLiveSecurity

UK Cybersecurity: Permanent job salaries growing faster than contractor pay rises
Google moves into the Certificate Authority business
Big Blue’s BigInsights has big-ish bugs
Marketing company leaks 17,000 recorded phone calls, many with credit card numbers
Hotel guests locked in their rooms by ransomware? It doesn’t make sense
Ransomware killed 70% of Washington DC CCTV ahead of inauguration
WordPress slips out three quick patches
Cisco TelePresence control software had remote-exploitable bug
Linux devices with standard settings infected by Linux.Proxy.10 malware

LinuxSecurity.com: Multiple vulnerabilities have been found in Perl, the worst of which could allow remote attackers to execute arbitrary code.

security update

security update

38% of Android VPN Apps on Google Play Store Plagued with Malware

LinuxSecurity.com: Update to the latest stable version. See https://ikiwiki.info/news/ for the listof changes. Security fix for CVE-2016-10026, CVE-2016-9646, CVE-2017-0356.

LinuxSecurity.com: Fix validation logic in the base consumer The base consumer is intended to onlyderive its validation switch from the on-disk configuration if the child classdoesn’t override the validate_signatures switch. There was a bug here where thedefault value provided in the base class made it appear as if *all* childconsumers had turned *off* validation, which […]

LinuxSecurity.com: Update to the latest stable version. See https://ikiwiki.info/news/ for the listof changes. Security fix for CVE-2016-10026, CVE-2016-9646, CVE-2017-0356.

LinuxSecurity.com: New mozilla-thunderbird packages are available for Slackware 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for puppet-swift is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

Facebook Launches “Security Key” Feature to Protect User Accounts
Cisco Warns of Critical Flaw in Teleconferencing Gear
VPN on Android means ‘Voyeuristic Peeper Network’ in many cases

security update

Wow, look out, hackers: Trump to order 60-day cybersecurity probe
WordPress 4.7.2 Update Fixes XSS, SQL Injection Bugs
OpenSSL issues new patches as Heartbleed still lurks
LeakedSource data breach website goes offline following alleged police raid
Dridex Returns With Windows UAC Bypass Method

Major Dark Web Marketplace Hacked Recently, a hacker using the alias cypher0007 reached out to AtlasBay, a large dark web market, with information on two significant vulnerabilities that allowed him to access over 200,000 private messages, names, and addresses. Along with retrieving a good amount of buyer and seller information, the hacker also revealed that […]

Threatpost News Wrap, January 27, 2017
Google to Operate its Own Root CA
Texas cops lose evidence going back eight years in ransomware attack
National Audit Office: UK’s military is buying more than it can afford
Google launches root certificate authority
US and Russia engaged in legal tug of war over LinkedIn hack suspect
That Hearbleed problem may be more pervasive than you think
Securing MySQL DBMS
Breach Notification Website LeakedSource Allegedly Raided, Shut Down
Smashing Security podcast #005: ‘Upskirt insecurity’
218,000 private unencrypted AlphaBay dark web messages exposed
An introduction to private browsing

Privacy and security fears are driving many people to look into the possibilities of private browsing. We investigate what it is and how you stay anonymous online The post An introduction to private browsing appeared first on WeLiveSecurity