Menu

Category Archives: Security

Articles about security

IDG Contributor Network: Holiday shopping season and fraud: Not one without the other
Bug Hunters Prefer Communication Over Compensation
Ashley Madison slammed with $1.6 million fine for devastating data breach
Code Reuse a Peril for Secure Software Development
Evernote users threaten to quit over new privacy policy – but have already agreed to staff reading their notes
StormCloud 2017 – See me speaking in London, January 2017
ESET Trends for 2017: Holding security ransom

ESET’s Trends for 2017: Security Held Ransom report includes a review of the most important events of last year and outlines trends in cybercriminal activity and cyberthreats for 2017. The post ESET Trends for 2017: Holding security ransom appeared first on WeLiveSecurity

Yahoo breach means hackers had three years to abuse user accounts
Here’s some questions Congress should ask about the election-related hacks
Yahoo data breach: What you can do

Yahoo has announced that one billion of its user accounts has been affected by a data breach. ESET’s Mark James offers some informative security advice. The post Yahoo data breach: What you can do appeared first on WeLiveSecurity

Yahoo experiences biggest data breach in history: 1 billion affected

Yahoo has experienced the biggest data breach in history, with up to one billion user accounts thought to have been affected by a historic security incident. The post Yahoo experiences biggest data breach in history: 1 billion affected appeared first on WeLiveSecurity

Yahoo hack – a billion reasons to change your email account
Security! experts! slam! Yahoo! management! for! using! old! crypto!
Bluetooth-enabled safe lock popped after attackers win PINs
BlackEnergy power plant hackers target Ukrainian banks
Yahoo Discloses Data From 1 Billion Accounts Stolen in 2013

security update

Yahoo reports massive data breach involving 1 billion accounts
Yahoo hacked; More than 1 billion user accounts impacted
Yahoo! says! hackers! stole! ONE! BEELLION! user! accounts!
Give us encrypted camera storage, please – filmmakers, journos
Bye, privacy: Evernote will let its employees read your notes

security update

LinuxSecurity.com: This updates includes a rebase from tomcat 8.0.38 up to 8.0.39 which resolvesmultiple CVEs: * #1397493 – CVE-2016-6816 CVE-2016-6817 CVE-2016-8735 tomcat:various flaws

These 26 brand new Android smartphones come with malware pre-installed
FBI Bust Indian Student for Conducting DDoS Attacks on a Chat Site

Type: Vulnerability. Microsoft Office is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Infosec bods: This is a backdoor in Skype for Macs. Microsoft: No.
Mirai Giving DDoS-as-a-Service Industry a Boost
Google Discloses Contents of Eight National Security Letters

LinuxSecurity.com: Security Report Summary

Apple Fixes 97 Vulnerabilities Across macOS, iTunes, Safari, iCloud
Flash Player Bug An Eavesdropper’s Delight
Meet “Legion Hacking Group” Hacking Bigwigs of India
Millions of websites at risk, as Joomla high level security flaw discovered. Update now
Pythonic code review
Low-cost Android Smartphones Shipped with Malicious Firmware
Ray-Bans out, Uggs in: Holiday season scam plagues social media

A new holiday season scam campaign is plaguing social media – and this time it’s pretending to sell heavily discounted Uggs, reports ESET’s Ondrej Kubovič. The post Ray-Bans out, Uggs in: Holiday season scam plagues social media appeared first on WeLiveSecurity

TalkTalk’s hacker (and blackmailer) pleads guilty
Law Enforcement Targets Users of DDoS-For-Hire Services
Google publishes national security letters for the first time
Teenager’s phone confiscated for TalkTalk cyberattack offenses

A 17-year-old who pleaded guilty to offenses relating to 2015’s TalkTalk cyberattack has had his iPhone confiscated and been sentenced to a 12-month rehabilitation order. The post Teenager’s phone confiscated for TalkTalk cyberattack offenses appeared first on WeLiveSecurity

Windows 10 Creators Update steps up your security response
Uber ‘God View’ allowed staff to spy on high-profile politicians, ex-partners and Beyoncé, court hears
Persistent ad and dialler trojans found on 28 Android phones
A single typo may have tipped US election Trump’s way
Uber-creepy: Dial-a-ride devs accused of stalking pop diva Beyonce
Reschedule the holiday party, Patch Tuesday is here and it’s a big one
Zcash Spurs Rash of Malicious Mining Software
Pre-rolled stripped, hardened Copperhead Androids hit Oz, NZ
Snowden: Donald Trump could get pal Putin to kick me out of Russia
Beta Firmware Updates Available for Vulnerable Netgear Routers
Facebook tool helps find malicious SSL certificates
Microsoft Patches Publicly Disclosed IE, Edge Vulnerabilities
KFC’s Colonel’s Club card Scheme Hacked, 1.2million Members Impacted
Adobe Patches 31 Vulnerabilities, Flash Zero-Day Under Attack
Leading Clinical Laboratory Services Provider Suffers Massive Data Breach
KFC Warns 1.2 Million UK Customers of Colonel’s Club Breach
The rise of TeleBots: Analyzing disruptive KillDisk attacks

ESET’s Anton Cherepanov analyzes the work of TeleBots, a malicious toolset that was used in focused cyberattacks against targets in Ukraine’s financial sector. The post The rise of TeleBots: Analyzing disruptive KillDisk attacks appeared first on WeLiveSecurity

Netgear starts patching routers affected by a critical flaw
Don’t let your former IT staff sabotage your company
DDoS-for-hire takedown! 34 arrests made by Europol, FBI, and others
TalkTalk hacker gets iPhone taken away by Norwich Youth Court
US-CERT warns Netgear routers can be easily exploited

It has not been a good year for the internet of things, security-wise. The latest IoT devices found vulnerable to trivial exploitation? Netgear routers. The post US-CERT warns Netgear routers can be easily exploited appeared first on WeLiveSecurity

Facebook Releases Free Certificate Transparency Monitoring Tool

  Managed service providers are tasked with serving a broad range of markets, from construction to healthcare; accounting to legal; staffing firms to manufacturing; media and advertising to technology. But the day-to-day MSP challenges, even across so many diverse verticals, remain the same. Let’s break it down: modern technology changes fast and keeps gaining momentum, […]

NWH Hacker Steals 30,000 Passport Records from Russian Consulate Website
Nearly half of all websites pose security risks
Distributed Guessing Attack can ‘compromise Visa cards in just six seconds’

A new study from Newcastle University in the UK suggests that cybercriminals can access online banking details of any Visa card through a so-called Distributed Guessing Attack. The post Distributed Guessing Attack can ‘compromise Visa cards in just six seconds’ appeared first on WeLiveSecurity

Despite costly attacks, 85% of business leaders confident in preparedness
Cybersecurity skills aren’t being taught in college
Politics bog down US response to election hacks
Op-ed: I’m throwing in the towel on PGP, and I work in security
Dozens arrested in international DDoS-for-hire crackdown
Three serious Linux kernel security holes patched
Security by design for mobile device manufacturers

ESET’s Cameron Camp takes a closer look at security by design for mobile device manufacturers, assessing where we are and where we are heading. The post Security by design for mobile device manufacturers appeared first on WeLiveSecurity

Too many contractors spoil the business

As a traveling computer security consultant for over 20 years, I’ve had the chance to visit a lot of different operations and see what works and doesn’t work. I’m always looking for common denominators for successes and failures, and I share these lessons as I learn them. But I realize I’ve unconsciously absorbed one home […]

LinuxSecurity.com: Multiple vulnerabilities have been found in Node.js, the worst of which can allow remote attackers to cause Denial of Service conditions.

LinuxSecurity.com: Multiple vulnerabilities have been found in WebKitGTK+, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Zabbix, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in WebKitGTK+, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Multiple vulnerabilities have been found in Botan, the worst of which allows remote attackers to execute arbitrary code.

P0wnographer finds remote code exec bug in McAfee enterprise

LinuxSecurity.com: Multiple vulnerabilities have been found in SQUASHFS, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: A vulnerability in Bash could potentially lead to arbitrary code execution.

LinuxSecurity.com: A buffer overflow in Pixman might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: An integer overflow in TigerVNC might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability in XStream may allow remote attackers to execute arbitrary code.