Menu

Category Archives: Security

Articles about security

US government subcontractor leaks confidential military personnel data
Why companies offer a hacking bounty — and why there are challenges
Ransomware offers free decryption if you learn about cybersecurity
Federal Trade Commission launches $25,000 IoT security competition

The Federal Trade Commission have launched a competition to encourage the public to devise a technical solution to protect IoT devices from security threats. The post Federal Trade Commission launches $25,000 IoT security competition appeared first on WeLiveSecurity

Linux 2017: With great power comes great responsibility
Ransomware Has Evolved, And Its Name Is Doxware
8 Docker security rules to live by

LinuxSecurity.com: Security Report Summary

Researchers work to save trusted computing apps from keyloggers

LinuxSecurity.com: An update for gstreamer1-plugins-bad-free is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for gstreamer-plugins-good is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for gstreamer1-plugins-good is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for gstreamer-plugins-bad-free is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

Put walls around home Things, win $25k from US government
Hacker claims FBI CMS zero day hack, dumps 155 purported logins
Ransomware scum: ‘I believe I’m a good fit. See attachments’
Florida Man sues Verizon for $72m – for letting him commit identity theft
French Businessman Spared Jail Time for Involvement in Child Porn Scheme
Hot Desk? Sec-tech firm LANDESK to be forged together with HEAT

LinuxSecurity.com: upstream version 1.0.9 (BZ#1406277)

LinuxSecurity.com: – Fixes 1395311 – CVE-2016-9575 ipa: Insufficient permission check incertprofile-mod – Fixes 1370493 – CVE-2016-7030 ipa: DoS attack againstkerberized services by abusing password policy —- – Fixes 1395311 -CVE-2016-9575 ipa: Insufficient permission check in certprofile-mod – Fixes1370493 – CVE-2016-7030 ipa: DoS attack against kerberized services by abusingpassword policy

LinuxSecurity.com: upstream version 1.0.9 (BZ#1406277)

LinuxSecurity.com: An update for systemd is now available for Red Hat Enterprise Linux 7.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

The year in security: Trends 2017

In this feature, we capture some of the key ideas discussed in ESET’s latest trends paper for 2017, Security Held Ransom. The post The year in security: Trends 2017 appeared first on WeLiveSecurity

TCL targets Apple, Samsung with new BlackBerry handset
IoT devices could help authorities solve criminal cases
Travel booking systems ‘wide open’ to abuse – report
Exposed MongoDB installs being erased, held for ransom
FTC sets $25,000 prize for automatic IoT patching
Obama’s Russian Hacking Retaliation Is Biggest “Since the Cold War”
White Hat Hacker Launches Public Support Site
Hackers could explode horribly insecure smart meters, pwn home IoT

LinuxSecurity.com: An update for ghostscript is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for ghostscript is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

Boffins bag side-channel bugs before they bite
Kaspersky fixing serious certificate slip
Web-exposed MongoDB installs wiped by bitcoin ransoming script scum
Lone Hacker Defaces Google Brazil Domain
Washington Post backtracks on frenzied reporting of Russian hack attack against power grid
Latest WhatsApp Scam Infects Users with Banking Malware
Box.com Plugs Account Data Leakage Flaw
Vermont Grid ‘Hack’ Latest Tumble Down Attribution Rabbit Hole
Pentagon Subcontractor Inadvertently Leaks 11 Gigs of Sensitive Data
Review: Microsoft Windows Defender comes up short

LinuxSecurity.com: CVE-2016-3189 bzip2: heap use after free in bzip2recover

LinuxSecurity.com: Update to 2.46 Fixes various security issues, seehttp://www.mozilla.org/security/known-vulnerabilities/seamonkey.html for moreinfo. No more includes Chatzilla and DOM Inspector in the package — installthem yourself now (as usual other addons) from https://addons.mozilla.org

LinuxSecurity.com: – Fixed crash in auth process when auth-policy was configured and authenticationwas aborted/failed without a username set. – director: If two users haddifferent tags but the same hash, the users may have been redirected to thewrong tag’s hosts. – Index files may have been thought incorrectly lost, causing”Missing middle file seq=..” to be logged […]

LinuxSecurity.com: An integer overflow in LZO might allow remote attackers to execute arbitrary code or cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in HDF5 which could lead to the arbitrary execution of code.

LinuxSecurity.com: Multiple vulnerabilities have been found in memcached which could lead to the remote execution of arbitrary code.

LinuxSecurity.com: An integer overflow in musl might allow an attacker to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in libotr and Pidgin OTR, allowing remote attackers to execute arbitrary code.

LinuxSecurity.com: An update for ipa is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: This update fixes CVE-2016-9580 and CVE-2016-9581. —- This update adds apatch to fix CVE-2016-9573 and CVE-2016-9572.

LinuxSecurity.com: This update fixes CVE-2016-9580 and CVE-2016-9581.

Risk Level: Very Low. Type: Trojan.

If you’re anything like me, you probably make a bunch of lofty resolutions every year that you probably won’t, or even can’t, achieve. (For instance, I’ve been promising to hit the gym a little harder for about 6 years now.) But enough is enough. Here are 5 completely achievable resolutions to help keep you and […]

CNN Report Shows Fallout 4 Screenshots to Explain Russian Hacking Scheme
New Android-infecting malware brew hijacks devices. Why, you ask? Your router
How to remove ransomware from your LG Smart TV
Apple sued over fatal FaceTime car crash
Deprecation of Insecure Algorithms and Protocols in RHEL 6.9
Data breaches through wearables put target squarely on IoT in 2017
How to tell if your Snapchat has been hacked, and how to get it back
Army social media psyops bods struggling to attract fresh blood
Better authentication: Go get 'em, FIDO

Only a handful of industry associations accomplish what they set out to do. In the security realm, I’ve always been a huge fan of the Trusted Computing Group. It’s one of the few vendor organizations that truly makes computers more secure in a holistic manner. The Fast Identity Online (FIDO) Alliance is another group with lots […]

LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla Firefox, SeaMonkey, and Thunderbird the worst of which could lead to the execution of arbitrary code.

Programmer finds way to liberate ransomware’d Google Smart TVs
Libpng library gets fix for truly ancient bug
Hate ‘contact us’ forms? This PHPmailer zero day will drop shell in sender
Android tops 2016 vuln list, with 523 bugs
Russian ‘grid attack’ turns out to be a damp squib
Top Secret -cleared SOCOM staff in 11GB Govt contractor breach

security update

5 Premium VPN Services To Access HULU Outside The US
Philippine Military Website Hacked and Defaced
Latest iMessage Hack Crashes iPhone within Minutes
A lesson from network outages: Redundancy matters
Cyber-savvy New Year’s resolutions you’ll want to keep

Put cyber security at the top of your New Year’s resolution list for 2017, implementing a digital detox and improving your online behaviors. The post Cyber-savvy New Year’s resolutions you’ll want to keep appeared first on WeLiveSecurity

Russian Malware Found in Vermont Electricity Department Laptop
Anonymous Hacks, Defaces Bilderberg Group Website Against World Crisis

security update

OurMine Group Hacks Nat Geo Photography’s Twitter Account
New Malware Poses as Android Client to Infect Wi-Fi Networks and Hijack DNS
FBI-DHS Report Links Fancy Bear Gang to Election Hacks
Pakistan automotive giant PakWheels Hacked, 700k accounts stolen
Lithuania says Russian spyware infected government computers

  Ransomware “Star” Shines on LG Smart TV As ransomware continues to steal the malware stage, its authors have widened their target audience to include smart devices, such as TVs. Since a number of smart TVs use Android® operating systems, they can be susceptible to the same Android malware that usually strikes mobile devices. Recently, […]

The 10 biggest security incidents of 2016

In 2016, companies have had their security solutions tested by increasingly sophisticated cybercriminals. We look at the year’s biggest security incidents. The post The 10 biggest security incidents of 2016 appeared first on WeLiveSecurity

What 2017 has in store for cybersecurity
The shocking failure in how the FBI warned the DNC that it had been hacked
Obama expels 35 Russian spies over election hacking
Who helped Russia “hack” the US election? It might have been you…
Beware: Facebook collects data about your offline life through data brokers

Why wait for news on the next big thing in technology, when you can get a sneak peek at the hottest, up-and-coming consumer tech and innovations at CES 2017? For the last 50 years, the yearly CES event has served as a showcase and springboard for the latest advancements in tech as they enter the […]

Anonymous Hacks Thai LA Consulate to Protest Arrests and Cyber Law

LinuxSecurity.com: A vulnerability in mod_wsgi could lead to privilege escalation.

Retailers! Avoid getting hacked during the holiday season (or any other time of the year)

Tips for cash-strapped retailers looking to avoid getting hacked, during the holiday shopping season, or any other season. The post Retailers! Avoid getting hacked during the holiday season (or any other time of the year) appeared first on WeLiveSecurity