Menu

Category Archives: Security

Articles about security

Sednit: How this notorious cyberespionage group operates

Take a closer look at the cyberespionage group Sednit, which has targeted over 1000 high-profile individuals and organizations with phishing attacks and zero-day exploits. The post Sednit: How this notorious cyberespionage group operates appeared first on WeLiveSecurity

No, disabling your anti-virus software does not make security sense
Trump administration is giving us a good lesson on Twitter security
Facebook taps FIDO U2F for stronger login security
Worrying about data privacy isn’t enough: Here’s how to own your online presence

ESET’s Ondrej Kubovič: “Worrying about privacy isn’t enough” – here’s how to control your data privacy and online presence. The post Worrying about data privacy isn’t enough: Here’s how to own your online presence appeared first on WeLiveSecurity

PayPal users targeted in sophisticated new phishing campaign

Recent phishing scams targeted both Gmail and Yahoo, and now attackers have their sights set on PayPal with some very convincing bait. The post PayPal users targeted in sophisticated new phishing campaign appeared first on WeLiveSecurity

LeakedSource website goes dark amid claims of police raid
Bookish hacker finds holes in Amazon, Apple, Google epub services
Uber pays hacker US$9,000 for partner firm’s bug
Former Mozilla dev joins chorus roasting antivirus, says ‘It’s poison!’
Americans fear their data isn’t safe, yet do little to defend it
The security of President Trump’s Android smartphone
Malicious “Charger Ransomware” App Discovered on Google Play Store
Trump signs ‘no privacy for non-Americans’ order – what does that mean for rest of us?

security update

More mobe malware creeps into Google Play – this time, ransomware
Your Facebook account is now more secure than your bank’s (probably)
Facebook Touts ‘Safer’ Security Key Login
Machine behaviors that threaten enterprise security
Bill Calls for Study of Cybersecurity Standards for Cars

LinuxSecurity.com: An update for ansible is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: – new upstream (51.0)

LinuxSecurity.com: * CVE-2016-6836: vmxnet: Information leakage in vmxnet3_complete_packet (bz#1366370) * CVE-2016-7909: pcnet: Infinite loop in pcnet_rdra_addr (bz #1381196)* CVE-2016-7994: virtio-gpu: memory leak in resource_create_2d (bz #1382667) *CVE-2016-8577: 9pfs: host memory leakage in v9fs_read (bz #1383286) *CVE-2016-8578: 9pfs: potential NULL dereferencein 9pfs routines (bz #1383292) *CVE-2016-8668: OOB buffer access in rocker switch emulation (bz #1384898) *CVE-2016-8669: […]

LinuxSecurity.com: Update to ansible 2.2.1. Fixes several CVEs as well as a number of otherbugfixes. See: https://github.com/ansible/ansible/blob/stable-2.2/CHANGELOG.mdfor full changes.

LinuxSecurity.com: Update to ansible 2.2.1. Fixes several CVEs as well as a number of otherbugfixes. See: https://github.com/ansible/ansible/blob/stable-2.2/CHANGELOG.mdfor full changes.

Firefox flags Web of Trust add-on as suspicious, blocks by default
Voyeur adult website hacked; 180k members data leaked
Uber.com Backup Bug Nets Researcher $9K
Google to Block .js Attachments in Gmail
President Trump tweets from insecure Android, security boffins roll eyes
High-Severity Chrome Vulnerabilities Earn Researcher $32K in Rewards
Dark Web’ Largest Trading Platform AlphaBay Hacked; 200k Messages Leaked
Desperately seeking cybersecurity skills

Cybercrime is victimizing US companies and consumers, but a gap in cybersecurity skills presents a problem for the federal government. ESET’s Stephen Cobb investigates. The post Desperately seeking cybersecurity skills appeared first on WeLiveSecurity

10 questions to ask IDaaS vendors before you buy
In real life, Q is a woman! Head of MI6 calls for more female techies at SIS
Half of Ransomware Victims Pay Criminals’ Demands to Recover Data
Firefox 51 delivers a mix of security, performance and reliability tweaks, implements FLAC audio sup
Self-protection is key to Linux kernel security

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

Disk-nuking malware takes out Saudi Arabian gear. Yeah, wipe that smirk off your face, Iran
‘Celebgate’ nudes thief gets just nine months of porridge
Get 72% off NordVPN Virtual Private Network Service For a Limited Time – Deal Alert
HummingWhale Malware infected Android Apps Downloaded Millions of Times
Trump lieutenants ‘use private email’ for govt work… but who’d make a big deal out of that?
Hacker Selling 126 Million Cell Phone Details of “U.S. Cellular” Customers
Shamoon malware revisiting Saudi Arabia; cyberinfrastructure on high alert
Default Credentials Found in Schneider Electric Wonderware Historian
Firefox 51 Begins Warning Users of Insecure HTTP Connections
Linux nasty kicks weak, hacked gadgets when they’re already down
Penguins force-fed root: Cruel security flaw found in systemd v228
Kaspersky cybercrime investigator cuffed in Russian treason probe

To address the need for application security in the digital transformation era, F5 is releasing a new host of products and services. “The digital transformation has really changed security as a whole,” says Preston Hogue, Director of Security Marketing and Competitive Intelligence. What he means is that everything—EVERYTHING—is moving to the cloud. Think about the […]

Lloyds Banking Group hit with distributed denial of service attack

Lloyds Banking Group fell victim to an attempted cyberattack earlier this month, which saw cybercriminals attempt to crash the online banking service over a two day period. The post Lloyds Banking Group hit with distributed denial of service attack appeared first on WeLiveSecurity

41% off Netgear Arlo Security System Wireless HD Camera, Indoor/Outdoor, Night Vision – Deal Alert
It’s that time of the year again: Texas school district blabs staff tax documents to phishers
Corporations at risk of malware attack via Cisco’s WebEx Chrome extension
Cisco scrambling to fix a remote code execution problem in WebEx
RoT: Ransomware of Things

Could the Internet of Things spark the Ransomware of Things? ESET’s Stephen Cobb examines how ransomware and jackware are evolving. The post RoT: Ransomware of Things appeared first on WeLiveSecurity

Charger Mobile Ransomware Removed from Google Play
Charger Android ransomware spread via the official Google Play app store
Yahoo faces SEC probe into its two record-breaking data breaches

The US Securities and Exchange Commission is looking into whether Yahoo could have been quicker to tell investors about two record-breaking data breaches. The post Yahoo faces SEC probe into its two record-breaking data breaches appeared first on WeLiveSecurity

This new ransomware ‘bluff’ trick is costing victims big, even though their files are never really i
InfoWorld’s 2017 Technology of the Year Award winners
Identify and escape: A two-part ransomware plan
Technology of the Year 2017: The best hardware, software, and cloud services
Boffins break Samsung Galaxies with one SMS carrying WAP crap

LinuxSecurity.com: Multiple vulnerabilities have been found in Oracle’s JRE and JDK software suites, the worst of which may allow execution of arbitrary code

LinuxSecurity.com: Multiple vulnerabilities have been found in X.Org X Server, the worst of which may allow authenticated attackers to read from or send information to arbitrary X11 clients.

Firefox bares teeth, attacks sites that collect personal data
Western Digital fixes remote execution bug in My Cloud Mirror
Human bot hybrid finds LinkedIn email, phone number-filching holes
Graham Cluley nominated for most entertaining security blog. Please vote!
Trump’s FBI boss, Attorney General picks reckon your encryption’s getting backdoored
Internet gang claims it caused Lloyds Bank outage via a DDoS attack
Hacker Selling 1 Billion user accounts stolen from Chinese Internet Giants
US govt can’t stop Microsoft taking its Irish email seizure fight to the Supreme Court
SpyNote RAT Now Disguised As Netflix App

LinuxSecurity.com: Security fix for CVE-2016-2120, CVE-2016-7068, CVE-2016-7072, CVE-2016-7073,CVE-2016-7074

LinuxSecurity.com: Security fix for console video game music emu vulnerability in the fullyoptional audacious-plugins-exotic subpackage: CVE-2016-9957, CVE-2016-9958,CVE-2016-9959, CVE-2016-9960, CVE-2016-9961

LinuxSecurity.com: Security fix for CVE-2016-6814

LinuxSecurity.com: Update to 0.8.0-6.git97f52c1

LinuxSecurity.com: Rebase to latest upstream gitrev 20161120

LinuxSecurity.com: Update from 3.8.1 to 3.8.2. Also fixes console video game music emuvulnerability in the fully optional audacious-plugins-exotic subpackage:CVE-2016-9957, CVE-2016-9958, CVE-2016-9959, CVE-2016-9960, CVE-2016-9961

LinuxSecurity.com: Update from 3.8.1 to 3.8.2. Also fixes console video game music emuvulnerability in the fully optional audacious-plugins-exotic subpackage:CVE-2016-9957, CVE-2016-9958, CVE-2016-9959, CVE-2016-9960, CVE-2016-9961

LinuxSecurity.com: Security fix for CVE-2016-2120, CVE-2016-7068, CVE-2016-7072, CVE-2016-7073,CVE-2016-7074

LinuxSecurity.com: Fix validation logic in the base consumer The base consumer is intended to onlyderive its validation switch from the on-disk configuration if the child classdoesn’t override the validate_signatures switch. There was a bug here where thedefault value provided in the base class made it appear as if *all* childconsumers had turned *off* validation, which […]

LinuxSecurity.com: This update fixes a security problem with the EDE package.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

AG Nominee Backs Law Enforcement’s Ability to ‘Overcome’ Encryption
St. Louis Public Library Recovers from Ransomware Attack
UK courts experiencing surge in cyber-crime case load
Study: 62% of security pros don’t know where their sensitive data is
Penguins force-fed root. Cruel flaw found in systemd v228
Yahoo sale to Verizon delayed, following revelation of massive security breaches
DDoSing has evolved in the vacuum left by IoT’s total absence of security
Cisco Patches Critical Flaw in WebEx Chrome Plugin
Apple quashes bugs in iOS, MacOS, and Safari
The essential guide to anti-malware tools