Menu

Category Archives: Security

Articles about security

French spies warn politicians of hack risk as election draws near
Google Cloud Platform finally offers key management service
Windows 10 Anniversary Update crushed exploits without need of patches
Google reveals its servers all contain custom security silicon
Brilliant phishing attack probes sent mail, sends fake attachments
Just give up: 123456 is still the world’s most popular password

Risk Level: Very Low. Type: Trojan.

Netflix Users Targeted with yet another sophisticated Phishing Scam
Meet Spora, a ransomware that infects users in good faith – Literally

security update

security update

security update

Student Arrested for Selling Keylogger that Infected thousands of devices
WhatsApp vulnerability could allow Facebook and others to read messages
Facebook users hit with “You are in this video?” malware scam
Just in Time for Trump, the NSA Loosens Its Privacy Rules
First came mass MongoDB ransacking: Now copycat ransoms hit Elasticsearch
Guccifer 2.0, alleged Russian cyberspy, returns to deride U.S.
Suspected NSA tool hackers dump more cyberweapons in farewell
How to set up your Android phone for ultimate privacy
Promising compsci student sold key-logger, infects 16,000 machines, pleads guilty, faces jail
US Marines seek more than a few good men (3,000 men and women, actually) for cyber-war

security update

Playpen child sex abuse archive admin gets 20 years in the Big House

security update

Researchers Warn Against “free internet without Wi-Fi” WhatsApp Scam
Adobe’s Latest Security Patch Installs Chrome Extension to Collect Data
WhatsApp Says ‘Backdoor’ Claim Bogus
Adobe Acrobat Reader DC security update installs Chrome spyware
Google’s Key Transparency Simplifies Public Key Lookups
UK’s largest hospital trust battles Friday 13th malware outbreak

LinuxSecurity.com: A vulnerability in runC could lead to privilege escalation.

LinuxSecurity.com: Multiple vulnerabilities have been found in PostgreSQL, the worst of which could result in execution of arbitrary code or privilege escalation.

LinuxSecurity.com: Security Report Summary

Google floats prototype Key Transparency in bid to tackle secure swap woes
Pirates, pirates, whatchu gonna do? Advertisers cop a visit from PIPCU
Windows 10 anniversary update: Security and privacy, hope and change?

With analysts predicting a big shift to Windows 10 in the enterprise in 2017, a new ESET white paper looks at security and privacy changes in Windows 10 Anniversary Update, the build that Microsoft expects its business customers to run on the majority of their desktop computers. The post Windows 10 anniversary update: Security and […]

After MongoDB, ransomware groups hit exposed Elasticsearch clusters
Oh, for F…acebook: Critics bash WhatsApp encryption ‘backdoor’
WhatsApp bug: Messages ‘can be intercepted and read’

A WhatsApp ‘security issue’ has been identified, meaning third parties may be able to both intercept and read encrypted messages, according to new research. The post WhatsApp bug: Messages ‘can be intercepted and read’ appeared first on WeLiveSecurity

Threatpost News Wrap, January 13, 2017
Don’t follow the example of Donald Trump’s choice for cybersecurity czar
Podcast on ransomware’s threat to the healthcare industry
Forensic analysis techniques for digital imaging

ESET’s Miguel Ángel Mendoza looks at a range of forensic analysis techniques that are used to examine digital images. The post Forensic analysis techniques for digital imaging appeared first on WeLiveSecurity

Suspected NSA tool hackers dump more cyberweapons
GoDaddy revokes nearly 9,000 SSL certificates issued without proper validation
Trump’s CIA nominee grilled on his advocacy of surveillance database
Microsoft sued over forcing employees to watch child porn for online safety
UK launches major cybersecurity inquiry

The UK parliament has launched an inquiry into its cybersecurity defense measures, describing cyberthreats as a “major security challenge”. The post UK launches major cybersecurity inquiry appeared first on WeLiveSecurity

5 data breach predictions for 2017

LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla SeaMonkey, the worst of which could lead to the remote execution of arbitrary code.

EU policy makers consider FRAND licensing of machine-generated data
WordPress plugs eight holes in latest release

LinuxSecurity.com: Security Report Summary

MongoDB hackers now sacking ElasticSearch

LinuxSecurity.com: An update for java-1.6.0-openjdk is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Update to 0.24.6

LinuxSecurity.com: New upstream release

Trump’s cyber-guru Giuliani runs ancient ‘easily hackable website’
ISC squishes BIND packet-of-death bugs

security update

Shadow Brokers quit operation; giving away free Windows hacking tools
Donald Trump will take cybersecurity advice from, um, Rudy Giuliani
Smashing Security #003: ‘Alexa! Get me an axe!’

LinuxSecurity.com: Fix [CVE-2016-9962] Insecure opening of file-descriptor allows privilege FixBZ#1412148 – containerd: container did not start before the specified timeout—- use container-selinux >= 2:2.0-2

Israeli Phone Hacking Firm Cellebrite Hacked; 900 GB data stolen
Security Sessions: Will security budgets go up in 2017?
Thanks, Obama: NSA to stream raw intelligence into FBI, DEA and pals

security update

security update

Shadow Brokers spew Windows hack tools after exploit auction flop

Type: Vulnerability. Microsoft Windows LSASS is prone to a denial-of-service vulnerability; fixes are available.

iPhone hacking biz Cellebrite hacked
Marie Moe on Medical Device Security
ShadowBrokers Bid Farewell, Close Doors
Hamas Compromised Dozens of IDF Soldiers’ Phones Using Seductive Female Images

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

WordPress 4.7.1 Fixes CSRF, XSS, PHPMailer Vulnerabilities

Risk Level: Very Low. Type: Worm.

Risk Level: Very Low. Type: Trojan.

Security hardened, pah! Expert doubts Kaymera’s mighty Google’s Pixel
Beware new WhatsApp scam offering “free internet without Wi-Fi”

The number of scams spreading through the messaging app WhatsApp keeps on increasing, reports Lucas Paus. And there’s already a new one in 2017. The post Beware new WhatsApp scam offering “free internet without Wi-Fi” appeared first on WeLiveSecurity

Brother-and-sister duo arrested over hacking campaign targeting Italy’s bigwigs
43% off Microsoft Wireless Desktop 900 Keyboard and Mouse Bundle – Deal Alert
Vawtrak malware spread via toxic Word documents is still a thing apparently
Flashing a peace sign in selfies could lead to identity theft, scientists warn
Honeytraps used to infect Israeli soldiers’ smartphones with spyware
Users reporting Electronic Arts (EA) servers are doing
Fast Flux networks: What are they and how do they work?

The term Fast Flux can refer to networks used by several botnets to hide the domains used to download malware or host phishing websites, says Josep Albors. The post Fast Flux networks: What are they and how do they work? appeared first on WeLiveSecurity

Hacker Steals 900 GB of Cellebrite Data
Exitmap – Tor Exit Relay Scanner
Peace-sign selfie fools menaced by fingerprint-harvesting tech
Crims shut off Ukraine power in wide-ranging anniversary hacks

LinuxSecurity.com: New gnutls packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: New irssi packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. [More Info…]

Docker swings door shut on privilege escalation bug

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for CVE-2016-8605