Menu

Category Archives: Security

Articles about security

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

27,000 MongoDB servers have their data wiped, receive ransom demand for its safe return
MongoDB Attacks Jump From Hundreds to 28,000 In Just Days
St. Jude Medical Patches Vulnerable Cardiac Devices
iCloud Glitch? Woman buys iPhone, finds contact details of top celebs
Hello Kitty Database of 3.3 Million Breached Credentials Surfaces
Following Extortion Attempt, Gaming Network ESEA Breached, 1.5M Profiles Leaked
Prison librarian swaps books for bars after dark-web gun buy caper

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: MinGW cross compiled libpng 1.6.27 release, fixing a potential security issue.For details, see https://sourceforge.net/p/png-mng/mailman/message/35575076/

LinuxSecurity.com: This update fixes an old NULL pointer dereference bug in png_set_text_2()discovered and patched by Patrick Keshishian (CVE-2016-10087). The potential”NULL dereference” bug has existed in libpng since version 0.71 of June 26,1995. To be vulnerable, an application has to load a text chunk into the pngstructure, then delete all text, then add another text chunk […]

LinuxSecurity.com: Update —- Update to 0.11 —- Update —- Update. **WARNING:** if youare using your own config file, add “` include /etc/sway/config.d/* “` Atthe end of it, otherwise nothing will work on Wayland

LinuxSecurity.com: MinGW cross compiled libpng 1.6.27 release, fixing a potential security issue.For details, see https://sourceforge.net/p/png-mng/mailman/message/35575076/

LinuxSecurity.com: This update fixes an old NULL pointer dereference bug in png_set_text_2()discovered and patched by Patrick Keshishian (CVE-2016-10087). The potential”NULL dereference” bug has existed in libpng since version 0.71 of June 26,1995. To be vulnerable, an application has to load a text chunk into the pngstructure, then delete all text, then add another text chunk […]

Hackers Leak 1.5 Million ESEA Player Records after Demanding $50k as Ransom
Man pleads guilty to role in harassment scheme against senior US government officials

Justin Liverman, a student from North Carolina, has admitted collaborating in a harassment scheme targeting US officials and their families. The post Man pleads guilty to role in harassment scheme against senior US government officials appeared first on WeLiveSecurity

US Voting Systems Deemed Critical Infrastructure
This tool can help weed out hard-coded keys from software projects
Top cop: Strap Wi-Fi jammers to teen web crims as punishment
Drug Trade on Dark Web Lands Two Men into Jail
Connected car hacking: Who’s to blame?

ESET’s Cameron Camp just about recovered from the sensory overload that is CES to gather his thoughts on what was another fascinating event. The post Connected car hacking: Who’s to blame? appeared first on WeLiveSecurity

What a Locky Ransomware attack looks like
How to recover your system from a Ransomware attack
The Impact of British IP Bill on Technological Awareness and the Dark Web
MongoDB ransomware attacks sign criminals are going after servers, applications
Open source server simplifies HTTPS, security certificates
Hacker publishes GitHub secret key hunter
Google caps punch-yourself-in-the-face malicious charger hack
VNC server library gets security fix
MongoDB ransom attacks soar, body count hits 27,000 in hours

Risk Level: Very Low. Type: Trojan.

security update

Twitter suspends ‘Pharma bro’ Martin Shkreli’ account for harassment
TV News anchor says ‘Alexa, buy me a dollhouse’ with predictable results…

LinuxSecurity.com: Security Report Summary

How to respond to a ransomware infection

LinuxSecurity.com: Update to Samba 4.4.9 —- Security fix for CVE-2016-2125, CVE-2016-2126

LinuxSecurity.com: For changes see: https://www.mozilla.org/en-US/thunderbird/45.6.0/releasenotes/

LinuxSecurity.com: **Version 5.4.5** (2016-12-29) * SECURITY FIX: fixed CVE-2016-10074 bydisallowing potentially unsafe shell characters Prior to 5.4.5, the mailtransport (Swift_Transport_MailTransport) was vulnerable to passing arbitraryshell arguments if the “From”, “ReturnPath” or “Sender” header came from anon-trusted source, potentially allowing Remote Code Execution * deprecatedthe mail transport

Super Mario Run for Android? No, it’s malware

LinuxSecurity.com: **Version 5.4.5** (2016-12-29) * SECURITY FIX: fixed CVE-2016-10074 bydisallowing potentially unsafe shell characters Prior to 5.4.5, the mailtransport (Swift_Transport_MailTransport) was vulnerable to passing arbitraryshell arguments if the “From”, “ReturnPath” or “Sender” header came from anon-trusted source, potentially allowing Remote Code Execution * deprecatedthe mail transport

Unprotected MongoDB: Medical Data of Veterans affected by sleep disorders leaked

security update

security update

How to use “Find my iPhone” app to locate your smartphone
Now hiring: 1 million cybersecurity job openings in 2017
UK’s Largest Hosting firm 123-Reg ‘Pounded’ by DDoS Attack
FTC IoT privacy and security push points out D-Link router and webcam flaws

The US Federal Trade Commission has again acted on its serious concerns about data privacy and security in the Internet of Things (IoT). This time D-Link webcams and routers are the focus. Stephen Cobb puts this latest FTC move in context. The post FTC IoT privacy and security push points out D-Link router and webcam […]

Wikileaks Support Account Deletes Tweet about Making Database of Verified Accounts
Bank robber reveals identity – by using his debit card during crime
FBI let alleged pedo walk free rather than explain how they snared him
Brazil’s largest news portals UOL and Folha hacked; redirected to RedTube

security update

CIA director AOL email hacker coughs to crime
More than 10,000 exposed MongoDB databases deleted by ransomware groups

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Symantec’s First Ever Hardware Device Protects Network and IoT Devices

  FireCrypt Ransomware Builder Found in Wild Researchers have discovered a new ransomware variant that uses “.firecrypt” as its amended extension once encryption has taken place. FireCrypt is compiled using a command line builder software that allows varying inputs and outputs to be determined by the author for a unique hash, as this allows for […]

Ransomware sleazeballs target UK schools
Children in a digital world ‘need lessons in online safety’

More needs to be done to better equip children for life in a digital world, according to a new report from England’s children’s commissioner. The post Children in a digital world ‘need lessons in online safety’ appeared first on WeLiveSecurity

Hacker Claims Breach of FBI’s Webserver; Plone CMS Calls It a Hoax
MongoDB Databases being Targeted by Cyber-criminals for Ransom
3… 2…1… and 123-Reg hit by DDoSers. Again
Dodgy dealer on Amazon lures marks towards phishing site
D-Link sucks so much at Internet of Suckage security – US watchdog
Insane blackhats behind world’s most expensive ransomware ‘forget’ to backup crypto keys
Netgear unveils world’s easiest bug bounty

LinuxSecurity.com: New upstream release

LinuxSecurity.com: Update to the latest upstream release

LinuxSecurity.com: This update includes the latest stable release of _Apache Subversion_, version**1.9.5**. #### Client-side bugfixes: * fix accessing non-existent paths duringreintegrate merge * fix handling of newly secured subdirectories in workingcopy * info: remove trailing whitespace in –show-item=revision ([issue4660](http://subversion.tigris.org/issues/show_bug.cgi?id=4660)) * fix recordingwrong revisions for tree conflicts * gpg-agent: improve discovery of gpg-agentsockets * gpg-agent: fix […]

LinuxSecurity.com: Update to 4.5.1.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: For changes see: https://www.mozilla.org/en-US/thunderbird/45.6.0/releasenotes/

LinuxSecurity.com: **Version 5.2.21** (December 28th 2016) * Fix missed number update in versionfile – no functional changes —- **Version 5.2.20** (December 28th 2016) ***SECURITY** Critical security update for CVE-2016-10045 please update now!Thanks to [Dawid Golunski](https://legalhackers.com) and Paul Buonopane(Zenexer). —- ** Version 5.2.19** (December 26th 2016) * Minor cleanup** Version 5.2.18** (December 24th 2016) * **SECURITY** […]

KillDisk Ransomware Now Targets Linux, Prevents Boot-Up, Has Faulty Encryption
Tech Support Scammers Targeting Mac Users with DoS attacks
Smashing Security #002: ‘Invest in carrier pigeons’

security update

LinuxSecurity.com: An update for puppet-tripleo is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact [More…]

Netgear launches Bug Bounty program; offering lucrative rewards

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: CVE-2016-3189 bzip2: heap use after free in bzip2recover

LinuxSecurity.com: libpng 1.6.27 release, fixing a potential security issue. For details, seehttps://sourceforge.net/p/png-mng/mailman/message/35575076/

LinuxSecurity.com: Update to 2.46 Fixes various security issues, seehttp://www.mozilla.org/security/known-vulnerabilities/seamonkey.html for moreinfo. No more includes Chatzilla and DOM Inspector in the package — installthem yourself now (as usual other addons) from https://addons.mozilla.org

LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla Firefox and Thunderbird the worst of which could lead to the execution of arbitrary code.

Spy code dormant for three years resurfaces in two new variants
Ex-soldier pleads guilty to terror crime after not revealing iPhone PIN
Man sues Verizon for $72 million, says negligence allowed him to commit ID theft
KillDisk now targeting Linux: Demands $250K ransom, but can’t decrypt

ESET has discovered a Linux variant of the KillDisk component that renders Linux machines unbootable, while encrypting files and requesting a large ransom at the same time. The post KillDisk now targeting Linux: Demands $250K ransom, but can’t decrypt appeared first on WeLiveSecurity

  By now, everybody has probably heard of CryptoLocker. It makes sense that CryptoLocker would get a fair amount of media attention, since it’s been involved in several high-profile hacks, but there are a number of other players on the ransomware stage that deserve a place of distinction among the list of players. Managed service […]

Schools warned about cold-calling ransomware attacks
British military laser death ray cannon contract still awarded, MoD confirms
Windows exploitation in 2016

We are pleased to present our annual report Windows exploitation in 2016. In this latest version of our report, we offer a fresh look at modern security features in Windows 10. The post Windows exploitation in 2016 appeared first on WeLiveSecurity

Security expert: Ransomware took in $1 billion in 2016
Security-Oriented Kodachi 3.6 Linux OS Improves VPN and Tor Connectivity, More
LG threatens to put Wi-Fi in every appliance it releases in 2017