Menu

Category Archives: Security

Articles about security

NIST requests ideas for crypto that can survive quantum computers

LinuxSecurity.com: Security fix for CVE-2016-9036, CVE-2016-9037

LinuxSecurity.com: Security fix for CVE-2016-9036, CVE-2016-9037

LinuxSecurity.com: – Fixed crash in auth process when auth-policy was configured and authenticationwas aborted/failed without a username set. – director: If two users haddifferent tags but the same hash, the users may have been redirected to thewrong tag’s hosts. – Index files may have been thought incorrectly lost, causing”Missing middle file seq=..” to be logged […]

LinuxSecurity.com: Security fix for CVE-2016-9036, CVE-2016-9037

LinuxSecurity.com: Security fix for CVE-2016-9036, CVE-2016-9037

Risk Level: Very Low. Type: Trojan, Worm.

OurMine hackers hack Marvel and Netflix Twitter accounts
Don’t pay up to decrypt – cure found for CryptXXX ransomware, again

security update

security update

security update

New Wave of Hailstorm Spam Pelts Inboxes

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: The system could be made to expose sensitive information.

LinuxSecurity.com: The system could be made to expose sensitive information.

Student makes documentary after spying on thief who stole his smartphone

Risk Level: Very Low. Type: Trojan.

VMware removes hard-coded root access key from vSphere Data Protection
Nmap security scanner gets new scripts, performance boosts
Netflix US Twitter account hacked
Beware: Android Super Mario Run is Actually Malware; Don’t Download It

  Did we get you to click? That’s how the bad guys get you, too. One little click on the wrong link and your clients’ businesses could be up the proverbial creek. Theft only comprises one aspect of the activities cybercriminals undertake, but it’s a sizeable chunk of their enterprise. What’s worth noting is what […]

Panasonic, IOActive Clash on Vulnerability Report
Tech companies like Privacy Shield but worry about legal challenges
Congressional report sides with Apple on encryption debate
Home routers under attack in ongoing malvertisement blitz
Op-ed: Why I’m not giving up on PGP
IDG Editors predict tech trends for 2017
Energy firm points to hackers after Kiev power outage
What is cyberbullying and how to defend against it?

Cyberbullying has come to be a huge problem on the internet. Here are some important things to be aware of. The post What is cyberbullying and how to defend against it? appeared first on WeLiveSecurity

LinuxSecurity.com: An update for gstreamer-plugins-bad-free is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for gstreamer-plugins-good is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

Facebook has stopped SHA-ring, a year later than it promised
Strong non-backdoored encryption is vital – but the Feds should totally be able to crack it, say House committees

LinuxSecurity.com: An update for vim is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

Wassenaar weapons pact talks collapse leaving software exploit exports in limbo

Risk Level: Very Low. Type: Trojan.

Pakistani hackers deface Google Bangladesh domain
China gives America its underwater drone back – with a warning
Year-end cybercrime update 2016: an avalanche of good news?

Highlighting 20 success stories in the struggle against cybercrime, from indictments to arrests, extraditions to sentencing. Law enforcement efforts in cyberspace may have borne more fruit in 2016 than in any other year. The post Year-end cybercrime update 2016: an avalanche of good news? appeared first on WeLiveSecurity

Wassenaar Renegotiation Will Be in Trump Administration’s Hands
Testing times: Can your crypto-code survive the Google gauntlet?
Anonymous Shut Down Thai Sites Against Internet Censorship, Surveillance Law

Type: Vulnerability. The Microsoft .NET Framework is prone to an information-disclosure vulnerability; fixes are available.

ShadowBrokers got NSA spy tools from rogue insider
Kingpin in $1m global bank malware ring gets five years in chokey

LinuxSecurity.com: Several security issues were fixed in Samba.

Phishing attack on LA County computers; personal data of 756k people stolen

Risk Level: Very Low.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low.

Hackers suspected of causing power outage in Ukraine
New Decryptor Unlocks CryptXXX v3 Files
5 technologies that will shake things up in 2017
Bad news, fandroids: Mobile banking malware now encrypts files
Hacking airplane entertainment systems
Ukraine Suffers Power Outage Possibly Due to Energy Plant Hack
Christmas pump-and-dump stock spam
Fraudulent Video Ad Bot Rakes in Close to $5 Million Daily
New Linux/Rakos threat: devices and servers under SSH scan (again)

ESET’s Peter Kálnai and Michal Malik report on a new Linux/Rakos threat – devices and servers are under SSH scan again. The post New Linux/Rakos threat: devices and servers under SSH scan (again) appeared first on WeLiveSecurity

In-Flight Entertainment System Flaws Put Passenger Data at Risk
How to get more from your security budget
NCSC boss asked to detail efforts to protect financial services sector against cyberattacks

The head of the UK’s NCSC has been asked to offer more detail into how the financial services sector will be protected from cyberattacks. The post NCSC boss asked to detail efforts to protect financial services sector against cyberattacks appeared first on WeLiveSecurity

This is your captain speaking… or is it?
Box won’t say if it’s giving your secrets to the government
Turkey reportedly blocks Tor network nationwide
Financial Data Worth Millions Unwittingly Exposed In Ameriprise Accounts
7 Linux predictions for 2017
Google open-sources test suite to find crypto bugs
Maybe security isn't going to get better after all

One billion-plus accounts stolen in one online heist. The U.S. presidential election messed with by another country. Corporate secrets stolen and released on the internet on a regular basis. More and more data held hostage by ransomware. Stock markets routinely manipulated by hackers. Denial-of-service attacks whacking websites all over the place. Will computer security ever […]

756,000 individuals at risk after phish of 108 LA County employees
Evolved DNSChanger malware slings evil ads at PCs, hijacks routers

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

Sports blog jocks to crypto-cash nerds – here’s who got pwned

LinuxSecurity.com: Security Report Summary

Cops, Feds spaff $100m on Stingray cellphone snooping gear – and there’s sod all oversight
Protecting Your Online Presence with 3 Simple Tips
ShadowBrokers Dump Came from Internal Code Repository, Insider
Los Angeles to extradite bloke from Nigeria after scores of city workers fall for phish scam
You can now buy hacked NSA tools for Bitcoin 1000
Google Unveils Cryptographic Library Test Suite Wycheproof

Type: Vulnerability. Adobe Flash Player is prone to an unspecified remote code-execution vulnerability; fixes are available.

Stolen Yahoo Data Sold to Spammers, One Government Client
LinkedIn’s Recent Acquisition Lynda.com Suffers Massive Data Breach

LinuxSecurity.com: This update fixes CVE-2016-9580 and CVE-2016-9581.

LinuxSecurity.com: Rebase to upstream 4.4.3: http://www.freeipa.org/page/Releases/4.4.3 —- -Fixes 1395311 – CVE-2016-9575 ipa: Insufficient permission check in certprofile-mod – Fixes 1370493 – CVE-2016-7030 ipa: DoS attack against kerberized servicesby abusing password policy

LinuxSecurity.com: Security fix for CVE-2016-9957, CVE-2016-9958, CVE-2016-9959, CVE-2016-9960,CVE-2016-9961

LinuxSecurity.com: x86 CMPXCHG8B emulation fails to ignore operand size override [XSA-200,CVE-2016-9932] (#1404262) —- ARM guests may induce host asynchronous abort[XSA-201, CVE-2016-9815,

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for BZ#1401985

LinuxSecurity.com: This release fixes CVE-2016-1249 (out-of-bound read when using server-sideprepared statements) and CVE-2016-1251 vulnerability (a use after free whenusing prepared statements).