Menu

Category Archives: Security

Articles about security

Insecure IoT gear can help hackers turn your phone into a GPS tracker
VASCO white paper: Why RASP technology is critical for modern app security
<div>No, you still don't need an RFID-blocking wallet</div>

Back in January, I wrote one of my most popular posts ever: “Why you don’t need an RFID-blocking wallet.” As the title suggests, I argued that it’s a waste of money to buy a wallet with special shielding to protect your chipped credit card from RFID scanners wielded by street criminals seeking to snatch your […]

No, you still don’t need an RFID-blocking wallet
Targeted online guessing ‘a major threat to online security’

Targeted online guessing represents a major threat to online security, according to new research. The post Targeted online guessing ‘a major threat to online security’ appeared first on WeLiveSecurity.

LinuxSecurity.com: An update for pacemaker is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

‘Trust it’: Results of Signal’s first formal crypto analysis are in
Google to patch Chrome mobile hole after bank trojan hits 318k users
Netflix flattens bug that allowed account p0wnage via voicemail
Turn off remote admin, SOHOpeless D-Link owners
Ransomware repulsion regimes revealed!
Android’s Hover feature is a data HOOVER

Risk Level: Very Low. Type: Trojan.

China passes new Cybersecurity Law – you have seven months to comply if you wanna do biz in Middle Kingdom
Carriers are going virtual to give enterprises more freedom
Chinese chap in the clink for trying to swap US Navy FPGAs with fakes to beat export ban
Risk of Election Day Cyberattacks Low According To Experts
Tesco Bank Stops Online Transactions After Money Missing from 20K Accounts
Beware; LinkedIn Users Hit with Sophisticated Phishing Campaign
Microsoft Tears off the Band-Aid with EMET

LinuxSecurity.com: Add patch to fix dnf module groupinstall handling —- Update to new ansible2.2 version. For full changes see:https://github.com/ansible/ansible/blob/stable-2.2/CHANGELOG.md

LinuxSecurity.com: This update fixes a rare ocasion where ghostscript would fail when displaying*.ps files. More info can be found[here](http://bugs.ghostscript.com/show_bug.cgi?id=697286). —- This is asecurity update for these CVEs: *[CVE-2016-8602](https://bugzilla.redhat.com/show_bug.cgi?id=1383940) – *checkfor sufficient params in .sethalftone5* *[CVE-2016-7977](https://bugzilla.redhat.com/show_bug.cgi?id=1380415) – *.libfiledoes not honor -dSAFER* [This CVE is now correctly fixed, previous release wasaccidentally missing the fix.]

LinuxSecurity.com: Security fix for CVE-2016-6293

LinuxSecurity.com: The 4.8.6 stable update contains a number of important fixes across the tree.

LinuxSecurity.com: October 2016 CPU fixes: http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html#AppendixJAVA

LinuxSecurity.com: – new upstream version (49.0.2)

LinuxSecurity.com: Bump version to 1.3.5.15-1

LinuxSecurity.com: Security fix for CVE-2016-7035 (improper IPC guarding)

LinuxSecurity.com: – fix cookie injection for other servers (CVE-2016-8615) – compare user/passwdcase-sensitively while reusing connections (CVE-2016-8616) – base64: check forinteger overflow on large input (CVE-2016-8617) – fix double-free in krb5 code(CVE-2016-8619) – fix double-free in curl_maprintf() (CVE-2016-8618) – fix globparser write/read out of bounds (CVE-2016-8620) – fix out-of-bounds read incurl_getdate() (CVE-2016-8621) – fix URL unescape […]

Clever Gmail Hack Let Attackers Take Over Accounts
U.K. bank suspends online payments after fraud hits 20,000 accounts
Cisco’s Mobile Careers Site Exposed Job Seekers Data
Web security still outstandingly mediocre, experts report
Applied for a job at Cisco? Your personal data and passwords could have been stolen
Need to review 650,000 emails in eight days? Easy with a computer
WikiLeaks Releases DNCLeak2; Suffers Massive DDoS Attack
How to do an APK Analysis Using AppMon

There are a great many tools available to help quickly analyze the behavior of mobile malware samples. In the case of Android, one such app is AppMon. The post How to do an APK Analysis Using AppMon appeared first on WeLiveSecurity.

Boffins turn phone into tracker by abusing pairing with – that’s right – IoT kit
Tesco Bank limits online transactions after fraud hits thousands
Microsoft EMET gets end-of-life reprieve
20,000 Tesco Bank accounts raided by hackers, money stolen

LinuxSecurity.com: An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for java-1.6.0-ibm is now available for Red Hat Enterprise Linux 5 Supplementary and Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

Tech support scammers use denial of service bug to hang victims
Cerber ransomware menace now targeting databases
School cyber safety spiel shows smut to ‘Strayan students
China passes controversial, intrusive cybersecurity law
Password reset warrior arrested for popping 1050 student accounts
It’s not just you: Twitter was down everywhere
Apple, Mozilla kill API to deplete W3C battery-snitching standard
User danger declines as two thirds of Chromistas now use HTTPS

LinuxSecurity.com: Security Report Summary

security update

Did the Mirai botnet knock Liberia offline? Not so much
Cisco’s job applications site leaked personal data
Election-themed spam spikes as U.S. presidential race comes to an end
Mark Zuckerberg to be Tried by Munich Court for Tolerating Offending Content
Anonymous Hacks Milwaukee’s Charitable Bradley Foundation Network
After Galaxy Note 7, Samsung Recalls Millions of Washing Machines
10 ways to make sure your remote workers are being safe
Update your Belkin WeMo devices before they become botnet zombies
El Paso city bungs $3.2m to email crooks pretending to be bosses
Inside the RIG Exploit Kit

Computer safety has never been more of a necessity, regardless of your location in the world. This week’s cyber news recap spans from Western Europe to Australia, with a variety of threats that everyday users may face themselves. UK Hospital System Hit with Malware In the last few days, a hospital network in the UK was […]

Commodity ‘Exaspy’ Spyware Found Targeting High-Level Execs

security update

security update

Admins, update your databases to avoid the MySQL bug
Build your own IMSI slurping, phone-stalking Stingray-lite box – using bog-standard Wi-Fi

LinuxSecurity.com: An update for docker is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

Brit cops cuff 14 in £11m money-laundering malware ring sting
Colossal DDoS attack in Liberia wipes majority of country offline

Liberia has been hit with a harmful DDoS attack yet, with most of its residents unable to get online. The Mirai botnet is the cause. The post Colossal DDoS attack in Liberia wipes majority of country offline appeared first on WeLiveSecurity.

Computer forensics defuses FBI’s Clinton email ‘bombshell’ – the math doesn’t add up
Mirai IoT botnet blamed for smashing Liberia off the internet
Anti-ultrasound tech aims to foil the dog-whistle marketeers
Half of Chrome Pageloads are HTTPS
World-leading heart hospital ‘very, very lucky’ to dodge ransomware hit
Test-Run DDoS Attacks Against Liberia Cease
Hacker finds flaw in Gmail allowing anyone to hack any email account
Fake Android Flash Player App Malware Targeting Banks, Social Media
I can see your texts: A deep dive into SMS/messaging clients, security, and privacy

ESET’s Michael Aguilar takes a deep dive into SMS/messaging clients, security, and privacy. The post I can see your texts: A deep dive into SMS/messaging clients, security, and privacy appeared first on WeLiveSecurity.

Another Country is under massive DDoS attacks – Thanks to Mirai Malware
Amazon’s very own Linux now available for download
William Hill website hit with DDoS attack

UK-based bookmaker William Hill has been hit with a DDoS attack, preventing many of its customers from being able to access its main website. The post William Hill website hit with DDoS attack appeared first on WeLiveSecurity.

Tokens of terror spark ‘major security update’ at GitLab
Microsoft extends support for EMET security tool

LinuxSecurity.com: Multiple vulnerabilities have been found in Oracle’s JRE and JDK software suites allowing remote attackers to remotely execute arbitrary code, obtain information, and cause Denial of Service.

LinuxSecurity.com: Multiple vulnerabilities have been found in both LibreOffice and OpenOffice, the worst of which allows for the remote execution of arbitrary code.

Is password security at just $1/month too expensive for most?

LinuxSecurity.com: New curl packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. [More Info…]

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: This update addresses multiple security problems and fixes systemd dependencies.

LinuxSecurity.com: This update addresses multiple security problems and fixes systemd dependencies.

LinuxSecurity.com: the new package fixes the CVE-2016-7966. for more info please take a look athttps://www.kde.org/info/security/advisory-20161006-1.txt

LinuxSecurity.com: This update backports an upstream patch to fix multiple integer overflows(CVE-2016-9085).

DMCA Exemptions Lift Hacking Restrictions