Menu

Category Archives: Security

Articles about security

Donald Trump finally believes Russia hacked the DNC
Google Cloud unlocks key achievement

LinuxSecurity.com: fix CVE-2016-8741 (rhbz#1409836,1409835)

LinuxSecurity.com: update to 3.2.10.RELEASE, fix CVE-2016-9879

LinuxSecurity.com: Update to the latest upstream release 1.3.2, also with some security fixes (seebug #1193445 from the native flac package).

LinuxSecurity.com: Security fix for CVE-2016-8605

security update

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Professionally designed ransomware Spora might be the next big thing
Buggy Domain Validation Forces GoDaddy to Revoke Certs
Hacker siblings arrested for targeting Italian elite – infecting 20k emails
Cloudflare Shares National Security Letter It Received in 2013
ShadowBrokers Selling Windows Exploits, Attack Tools
How Blockchain Can Revolutionize Personal Data Storage?
Second Try at Windows LSASS Patch Addresses Vulnerability
Spammers Revive Hancitor Downloader Campaigns
Trump: It was probably Russia that hacked the DNC, Clinton campaign
Notorious Shadow Brokers’ Group Now Selling Windows Hacking Tools
Digital video recorder installers master password list ‘leaked’ – claims
Airline passengers’ bookings and info leaked by boarding gate displays
GoDaddy revokes digital certificates improperly validated due to bug
Debugging a kernel in QEMU/libvirt
Hello Kitty, Goodbye database containing 3.3 million users credentials
GCHQ feeds first crop of infosec startups to Cyber Accelerator
LA College Hit By Ransomware: Pays $28,000 to Unlock Files
US Navy runs into snags with aircraft carrier’s electric plane-slingshot
CES: IoT security comes of age

For years, IoT security seemed like solving a problem that didn’t exist. Not anymore says ESET’s Cameron Camp, who was at this year’s CES. The post CES: IoT security comes of age appeared first on WeLiveSecurity

How White Hat hackers do bad things for good reasons
Families of ISIS victims sue Twitter for being ‘weapon for terrorism’
Oh Britain. Worried your routers will be hacked, but won’t touch the admin settings
How to secure MongoDB – because it isn’t by default and thousands of DBs are being hacked
Pay the ransom? You won’t get your data back
British Hadoop security startup expands to New York to land big investor

LinuxSecurity.com: Multiple vulnerabilities have been found in phpMyAdmin, the worst of which could lead to arbitrary code execution.

LinuxSecurity.com: Flex might generate code with a buffer overflow making applications using such scanners vulnerable to the execution of arbitrary code.

LinuxSecurity.com: A vulnerability has been found in Vim and gVim concerning how certain modeline options are treated.

LinuxSecurity.com: A vulnerability in vzctl might allow attackers to gain control over ploop containers.

LinuxSecurity.com: A heap-based buffer overflow in c-ares might allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in 7-Zip, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: A vulnerability in BIND might allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in phpBB, the worst of which may allow remote attackers to inject arbitrary web script or HTML.

LinuxSecurity.com: Multiple vulnerabilities have been found in PgBouncer, the worst of which may allow an attacker to bypass authentication.

LinuxSecurity.com: Multiple vulnerabilities have been found in Botan, the worst of which might allow remote attackers to obtain ECDSA secret keys.

New Windows 10 privacy controls: Just a little snooping – or the max

LinuxSecurity.com: Gentoo’s NGINX ebuilds are vulnerable to privilege escalation due to the way log files are handled.

LinuxSecurity.com: Multiple vulnerabilities have been found in Expat, the worst of which may allow execution of arbitrary code.

Sundown exploit kit weaves Edge hack hole
Ansible patches ‘own the farm’ vulnerability
EMC slings patch at remote hack nonce-nse
Juniper warns: Borked upgrade opens root on firewalls

Risk Level: Very Low. Type: Trojan.

Brazilian Gov’t Twitter account mistakenly posts social media passwords
US Intel: Russia hacked Republican groups during election
Adobe patches critical flaws in Flash Player, Reader, and Acrobat
Netflix users targeted by credit card phishing scheme
Microsoft Issues Record Low Number of Patch Tuesday Bulletins
It’s now 2017, and your Windows PC can still be pwned by a Word file
Amazon Echo and the Alexa dollhouses: Security tips and takeaways

Tips on securing the Alexa service on Amazon Echo devices, notably voice purchasing, a topic brought into focus by the recent “San Diego dollhouse TV story”. The post Amazon Echo and the Alexa dollhouses: Security tips and takeaways appeared first on WeLiveSecurity

Anonymous hacks Thai Gov’t job portal; leaks a trove of data
Netflix Phishing Campaign Targeted User Information, Credit Card Data

LinuxSecurity.com: Multiple vulnerabilities have been found in libTIFF, the worst of which may allow execution of arbitrary code.

Adobe Patches Code Execution Flaws in Flash, Reader, Acrobat
Cybercriminals ‘should be punished with Wi-Fi jammers’

A senior UK police officer has suggested that offenders of cybercrime should be penalized by being made to wear Wi-Fi jammers rather than being sent to prison. The post Cybercriminals ‘should be punished with Wi-Fi jammers’ appeared first on WeLiveSecurity

Disk-wiping malware Shamoon targets virtual desktop infrastructure
Lawmakers Reintroduce Popular Email Privacy Act
Two New Edge Exploits Integrated into Sundown Exploit Kit
Security scare over hackable heart implants

A US government probe into claims that certain heart implants are vulnerable to hacking attacks, has resulted in emergency security patches being issued for devices that cardiac patients have in their homes. The post Security scare over hackable heart implants appeared first on WeLiveSecurity

EU tosses Europe’s cookies… popups
UK Parliament suddenly remembers it wants to bone up cyber security *cough* Russia *cough*
Someone stole $3.6M from a Miami bank; officials oblivious for 6 months
Google Patches Android Custom Boot Mode Vulnerability
Experts Warn of Novel PDF-Based Phishing Scam
Threatpost News Wrap, January 6, 2017
Attacks On MongoDB Rise As Hijackings Continue
FTC: D-Link Failed to Secure Routers, IP Cameras
Ransomware extorts Los Angeles school to the tune of $28,000
Dangerous assumptions that put enterprises at risk
Former DHS head urges Trump to see economic dangers from cyberattacks
Privacy legislation reintroduced for mail older than 180 days
Because I’m bad, I’m bad, Shamoon: PC wiper tried to shut down Saudi snapshot defences
What do you call a firm that leaves customer financials unencrypted on a hard drive? RSA
MongoDB ransacked: Now 27,000 databases hit in mass ransom attacks
GitHub secret key finder released to public
Trump Plans To Build Anti-Hacking Team
Hacker: Lol, I pwned FBI.gov! Web devs: Nuh-uh, no you didn’t
Q&A: RSA crypto pioneer Adleman keeps pushing the limits

I recently had the pleasure of interviewing Dr. Leonard Adleman — the “A” in the very popular public cryptographic algorithm RSA — as part of the Association for Computing Machinery’s 50th anniversary celebration of the Turing Award. In 2002, Adleman himself won the Turing Award, often referred to at the Nobel Prize of the computing […]

Git Hound, Truffle Hog root out GitHub leaks
Rethink on bank cybersecurity rules might only follow major bank breach, says expert

LinuxSecurity.com: Multiple vulnerabilities have been found in Python, the worst of which could lead to arbitrary code execution.

LinuxSecurity.com: Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.

Like stealing data from a kid: LA school pays web scum US$28,000 ransom
Autocomplete a novel phishing hole for Chrome, Safari crims
St Jude patching Merlin@home heart kit
Two years on, thousands of unpatched Magento shops still being carded
Onion Browser goes free for privacy-conscious iOS users, citing ‘recent events’

Type: Vulnerability. Microsoft Windows LSASS is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

27,000 MongoDB servers have their data wiped, receive ransom demand for its safe return