Menu

Category Archives: Security

Articles about security

Twitter hack sees New York Times warn of Russian missile strike against USA
Protected US military server poked via army recruitment website
It’s 2017 and 200,000 services still have unpatched Heartbleeds
Go dark with the flow: Lavabit lives again
Satan enters roll-your-own ransomware game
Symantec carpeted over dodgy certificates, again
Mozilla wants infosec activism to be the next green movement

LinuxSecurity.com: Multiple vulnerabilities have been found in zlib, the worst of which could allow attackers to cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in DirectFB, all of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A buffer overflow in DCRaw might allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: A buffer overflow in Lua might allow context-dependent attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in libupnp, the worst of which could lead to the execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in DBD::mysql, the worst of which might allow an attacker to execute arbitrary code.

LinuxSecurity.com: A buffer overflow in PPP might allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in QEMU, the worst of which could cause a Denial of Service condition.

Employment scam targets college students and their bank accounts

LinuxSecurity.com: check valid input arguments for nla_reserve() (rh #1414305, CVE-2017-0386)

security update

security update

security update

Radio Station Transmission Hacked with F*** Donald Trump Song
Researchers condemn unsubstantiated WhatsApp “Backdoor” story by Guardian
Mozilla’s First Internet Health Report Tackles Security, Privacy
India’s Famous Horse Racing Site Hacked with Dharma Ransomware
Protesters Called To Join Inauguration Day DDoS Attack
Rsync errors lead to data breach at Canadian ISP, KWIC Internet
Encrypted email service ProtonMail opens door for Tor users
7 (more) security TED Talks you can’t miss
350,000 Twitter bot sleeper cell betrayed by love of Star Wars and Windows Phone
Researcher claims to expose identity of Mirai Botnet Author
Coalition of Cryptographers, Researchers Urge Guardian to Retract WhatsApp Story

security update

Rap for crap WhatsApp trap flap: Yack yack app claptrap slapped
Hadoop, CouchDB Next Targets in Wave of Database Attacks

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Multiple vulnerabilities have been found in cURL, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in NSS, the worst of which could allow remote attackers to obtain access to private key information.

LinuxSecurity.com: Multiple vulnerabilities have been found in irssi, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A heap-based buffer overflow in CVS might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in IcedTea allowing remote attackers to affect confidentiality, integrity, and availability through various vectors.

LinuxSecurity.com: An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

Hack the Army Bounty Pays Out $100,000; 118 Flaws Fixed
General Electrics plays down industrial control plant vulnerabilities
Ransomware attack hits St Louis Public library
Threatpost News Wrap, January 20, 2017
Trump’s ‘cyber tsar’ Giuliani among creds leaked in mass hacks
Google pushed developers to fix security flaws in 275,000 Android apps
Email Encryption Service Provider ‘ProtonMail’ Now on Tor

MongoDB Hacks Spreading Fast In the past few weeks, researchers have been monitoring the steady rise of hacked MongoDB installations, now surpassing over 28,000 individual systems. While the attacks started with ransoming back the stolen data, the attackers have now begun simply deleting the information from the database and leaving the ransom note for payment […]

Attackers start wiping data from CouchDB and Hadoop databases
How to wake the enterprise from IoT security nightmares
Microsoft’s standing to sue over secret US data requests in question
Fake news alert! Internet breaches are not cloud breaches
Unbreakable Locky ransomware is on the march again
Shocking crime surge – THE TRUTH: England, Wales stats now include hacking and fraud

LinuxSecurity.com: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

Viral Chinese selfie app Meitu phones home with personal data
Operator of DDoS protection service named as Mirai author
Smashing Security #004: ‘You don’t mess with Brian Krebs’
Bring down the White House’s website for Trump’s inauguration, urges software engineer
The Changing Face of Carbanak
Google Maps Will Soon Find Parking Spot for You

LinuxSecurity.com: An update for python-XStatic-jquery-ui is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for openstack-cinder is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Updated openstack-cinder packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. [More…]

LinuxSecurity.com: An update for openstack-cinder is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

ProtonMail Gets Own Tor-Accessible .Onion Hidden Service
Locky Limps Back into Action After Lull

Ransomware as a Service (RaaS) has been growing steadily since it made its debut in 2015 with Tox. With the new Satan service, it’s easier than ever. The idea is to use this web portal to contract threat actors to create new ransomware samples for distribution via the desired attack vector. This allows any potential […]

Cybersecurity skills shortage ‘still a global problem’

There are signs of improvement in the global cybersecurity skills gap, but serious problems still remain, a new report finds. The post Cybersecurity skills shortage ‘still a global problem’ appeared first on WeLiveSecurity

Risk Level: Very Low. Type: Trojan.

Samsung SmartCam owners warned of hacker hijack vulnerability
Quimitchin Malware Targeting Mac Users also Compatible with Linux
‘Beeeellion-dollar’ mastercrooks in hotel, restaurant blitzkrieg
Facebook, Researcher at Odds Over Messenger Issue
Android Scoring System Roots Out Malicious, Harmful Apps
Justine Bone on St. Jude Vulnerabilities and Medical Device Security
Adobe Acrobat auto-installed a vulnerable Chrome extension on Windows PCs
Trump inauguration DDoS protest is ‘illegal’, warn securobods
How to Keep Hackers out of Your Linux Machine Part 1: Top Two Security Tips
Google Infrastructure Security Design Overview
Oracle to Java devs: Stop signing JAR files with MD5
ProtonMail launches Tor hidden service to dodge totalitarian censorship
What’s the biggest danger to the power grid? Hackers? Terrorists? Er, squirrels
Chrome dev explains how modern browsers make secure UI just about impossible
Insecure Hadoop installs next in ‘net scum crosshairs
Adobe’s naughty Chrome telemetry code had XSS problem

Risk Level: Very Low.

Risk Level: Very Low. Type: Trojan.

security update

Silence is golden: How Google hunts Android malware in the wild
Hacker Exploits Remote Code Execution Bug to Breach Facebook Security
Carbanak Using Google Services for Command and Control
Skills gap could hold back blockchain, AI, IoT advancements in 2017
College fires IT admin, loses access to Google email, successfully sues IT admin for $250,000
Docker Patches Container Escape Vulnerability
Oracle Patches 270 Vulnerabilities in Year’s First Critical Patch Update

“Highest average score for ease of use, quality of support, and […] requirements in endpoint protection.” That’s how Marty Duffy, Director of Research at G2 Crowd, describes Webroot after seeing the results of this year’s G2 Crowd survey on Best Software for IT Teams 2017. We’d be lying if we said we weren’t over the […]

LinuxSecurity.com: **Version 5.2.22** (January 5th 2017) * **SECURITY** Fix[CVE-2017-5223](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-5223),local file disclosure vulnerability if content passed to `msgHTML()` is sourcedfrom unfiltered user input. Reported by Yongxiang Li of Asiasecurity. The fixfor this means that calls to `msgHTML()` without a `$basedir` will not importimages with relative URLs, and relative URLs containing `..` will be ignored. *Add simple […]

LinuxSecurity.com: This new point release fixes a security vulnerability in wrestool. For furtherdetails see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850017