Menu

Category Archives: Security

Articles about security

What’s the biggest danger to the power grid? Hackers? Terrorists? Er, squirrels
Chrome dev explains how modern browsers make secure UI just about impossible
Insecure Hadoop installs next in ‘net scum crosshairs
Adobe’s naughty Chrome telemetry code had XSS problem

Risk Level: Very Low.

Risk Level: Very Low. Type: Trojan.

security update

Silence is golden: How Google hunts Android malware in the wild
Hacker Exploits Remote Code Execution Bug to Breach Facebook Security
Carbanak Using Google Services for Command and Control
Skills gap could hold back blockchain, AI, IoT advancements in 2017
College fires IT admin, loses access to Google email, successfully sues IT admin for $250,000
Docker Patches Container Escape Vulnerability
Oracle Patches 270 Vulnerabilities in Year’s First Critical Patch Update

“Highest average score for ease of use, quality of support, and […] requirements in endpoint protection.” That’s how Marty Duffy, Director of Research at G2 Crowd, describes Webroot after seeing the results of this year’s G2 Crowd survey on Best Software for IT Teams 2017. We’d be lying if we said we weren’t over the […]

LinuxSecurity.com: **Version 5.2.22** (January 5th 2017) * **SECURITY** Fix[CVE-2017-5223](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-5223),local file disclosure vulnerability if content passed to `msgHTML()` is sourcedfrom unfiltered user input. Reported by Yongxiang Li of Asiasecurity. The fixfor this means that calls to `msgHTML()` without a `$basedir` will not importimages with relative URLs, and relative URLs containing `..` will be ignored. *Add simple […]

LinuxSecurity.com: This new point release fixes a security vulnerability in wrestool. For furtherdetails see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850017

LinuxSecurity.com: Security fix for CVE-2016-9888

LinuxSecurity.com: This new point release fixes a security vulnerability in wrestool. For furtherdetails see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850017

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise MRG 2.5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

UK’s ICO releases new guidelines for becoming GDPR ready

The UK’s ICO has released a new set of guidelines aimed at ensuring companies are adequately prepared for the introduction of the GDPR. The post UK’s ICO releases new guidelines for becoming GDPR ready appeared first on WeLiveSecurity

Cyber Criminals Held Cancer Services Computers for Ransom

Risk Level: Very Low. Type: Trojan.

Remote code execution vulnerability affecting Facebook’s servers earns researcher $40,000
Oracle patches raft of vulnerabilities in business applications
‘Ancient’ Mac backdoor discovered that targets medical research firms
Clash of Clans’ Developer “Supercell” Hacked; 1.1 Million Accounts Stolen
Not lovin’ it! Researcher finds way to steal McDonald’s users’ passwords
Hacker claims our private cell number on Facebook may not be so private
How—and why—you should use a VPN any time you hop on the internet
If you’re going to use Windows, it makes security sense to use Windows 10
Passwords: A long goodbye
Ooooh, that’s NASty. Security-watchers warn over man-in-the-middle risk
Flashback Wednesday: Pakistani Brain

This month’s Flashback Wednesday takes us back to the beginning. Pakistani Brain, discovered on January 19th, is considered to be the first-ever PC virus. The post Flashback Wednesday: Pakistani Brain appeared first on WeLiveSecurity

WikiLeaks’ Assange confident of winning ‘any fair trial’ in the US
Can a DDoS attack on Whitehouse.gov be a valid protest?
Spora Ransomware Offers Victims Unique Payment Options
Understanding The Basics Of Two-Factor Authentication
Advances in SSL: 5 Strategies For Secure, High-Performance Load Balancers
Hacker cracks Facebook with remote code execution bug
Ransomware scum infect cancer non-profit
SOHOpeless routers offer hard-coded credentials and command injection bugs

LinuxSecurity.com: An update for runc is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for docker is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for docker-latest is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact [More…]

Kill it with fire: US-CERT urges admins to firewall off Windows SMB
Thanks to Obama: Chelsea Manning will be out in May 2017
New RCE Flaws Found in Samsung Smartcam
Gmail Phishing Scam Stealing Credentials Through Infected Attachment
Vulnerabilities Leave iTunes, App Store Open to Script Injection
Sensitive access tokens and keys found in hundreds of Android apps

LinuxSecurity.com: NVIDIA graphics drivers could be made to crash under certain conditions.

The unseemly world of Darkweb marketplaces

LinuxSecurity.com: Multiple vulnerabilities have been found in libxml2, the worst of which could lead to the execution of arbitrary code.

LinuxSecurity.com: Security fix for CVE-2016-9131, CVE-2016-9147, CVE-2016-9444

LinuxSecurity.com: Security fix for CVE-2016-9131, CVE-2016-9147, CVE-2016-9444

LinuxSecurity.com: This update avoids a malicious repository writing to files outside the localstorage root.

LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for bind97 is now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

Terrorists are winning the digital arms race
Router Vulnerabilities Disclosed in July Remain Unpatched
Credential-stuffers enjoy up to 2% attack success rate – report
Mega UK hospitals trust Barts says IT borkage was due to trojan – not ransomware
SHA-1 End Times Have Arrived
Why WhatsApp’s ‘Backdoor’ Isn’t a Backdoor
It makes good security sense to change Alexa’s name – here’s how
Andrew Macpherson on Intelligence Gathering with Maltego
Facebook took two weeks to remove video of 12-year-old girl that livestreamed her suicide
Ransomware: Should you pay up?

ESET’s Cameron Camp provides valuable insight into what you should do if you’re a victim of ransomware. The post Ransomware: Should you pay up? appeared first on WeLiveSecurity

The war for cybersecurity talent hits the Hill
Ransomware brutes smacked 1 in 3 NHS trusts last year
Got microservices? You'd better secure them

One of the toughest parts of being a computer security pro is trying to figure out what to hang your career on every two to five years. Which new buzzwords will stick to become a new paradigms, and which will disappear into the ether? Keeping up with the latest and greatest enterprise tech is part […]

Google ventures into public key encryption
Is your IP security camera making you less secure?
Devs reverse-engineer 16,000 Android apps, find secrets and keys to AWS accounts
Dodgy Dutch developer built backdoors into thousands of sites

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in file, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A buffer overflow in MiniUPnPc might allow remote attackers to cause a Denial of Service condition.

911 app is a joke, says security researcher Randy Westergren
Dovecot mailserver graded ‘nearly impenetrable’
Top tips (not including anti-virus) for protecting your Android from malware

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: A buffer overflow in xdelta might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A buffer overflow in VLC might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Pidgin, the worst of which could lead to execution of arbitrary code.

Researchers Expose Fake Android Apps Stealing Instagram Passwords

Type: Vulnerability. Microsoft Identity Model Extensions is prone to a privilege-escalation vulnerability; fixes are available.

I love podcasts so much, I took a deep breath and made one…
White House Approves New Rules for Sharing of Raw Intelligence Data
Botnet of things: Samsung SmartCams vulnerable to hackers
Invest in encryption and get it right

The heavy ICO fine against Royal & Sun Alliance Insurance PLC has highlighted a shortcoming with encryption. The post Invest in encryption and get it right appeared first on WeLiveSecurity

Facebook’s new public Wi-Fi locator is raising privacy concerns
Free IoT Vulnerability Scanner Hunts Enterprise Threats
The CSO guide to top security conferences
IHOP’s Twitter account hacked; retweets a tweet against Hillary clinton
Wandera has uncovered severe mobile data exposures that affect a high proportion of enterprises. Try it now for free.