Menu

Category Archives: Security

Articles about security

DROWN-ing Xcode developer? Apple’s thrown you a lifebelt
US Voter Data Leaked Again; This Time Multiple States are Involved
AtomBombing; An Injection Code that Infects Multiple Processes in Windows
Electronic Arts, EA Servers Down Again (Updated)
As the clocks go back, UK Apple users targeted by smishing campaign
HackForums delete “Server Stress Testing” amidst links with Dyn DDoS Attack
Hardware Firewall: Choosing the Right Firewall Distribution
Google to Make Certificate Transparency Mandatory By 2017
‘Hacker’ accused of idiotic plan to defraud bank out of $1.5 million
Australian Red Cross apologizes for largest Aussie data breach to date
DMCA updated – toaster penetration testing gets green light in America
Red Cross Data Leak; Personal Data of 550,000 Blood Donors Stolen
Lad cuffed after iOS call exploit knocks out Arizona 911 center
Florida man ran $1.35m hack-and-spam racket with 50m-plus addresses
Danish Payment Processing Firm Suffers Breach 100k Credit Cards Stolen
Mirai Vulnerability Disclosed, But Exploits May Constitute Hacking Back

LinuxSecurity.com: An update for nodejs-tough-cookie and nodejs is now available for Red Hat OpenShift Container Platform 3.1, 3.2, and 3.3. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support and Red Hat Enterprise Linux 6.5 Telco Extended Update Support. [More…]

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 5 Supplementary and Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for openstack-manila-ui is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for openstack-manila-ui is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for openstack-manila-ui is now available for Red Hat OpenStack Platform 9.0 (Mitaka). Red Hat Product Security has rated this update as having a security impact [More…]

Fake BSOD Lock Screens Popping Up Again In a nod to screen-locking malware from past years, a new variant has arrived that now requests a simple call to support for assistance. Rather than demand a ransom to remove the fake screen, it provides a number to a fake tech support line and suggests calling them. […]

From: Apple Product SecurityReply to list APPLE-SA-2016-10-27-3 iTunes 12.5.2 for Windows iTunes 12.5.2 for Windows is now available and addresses the following: WebKit Available for: Windows 7 and later Impact: Processing maliciously crafted web content may result in the disclosure of user information […]

From: Apple Product SecurityReply to list APPLE-SA-2016-10-27-2 iCloud for Windows v6.0.1 iCloud for Windows v6.0.1 is now available and addresses the following: WebKit Available for: Windows 7 and later Impact: Processing maliciously crafted web content may result in the disclosure of user information […]

From: Apple Product SecurityReply to list APPLE-SA-2016-10-27-1 Xcode 8.1 Xcode 8.1 is now available and addresses the following: IDE Xcode Server Available for: OS X El Capitan v10.11.5 and later Impact: A remote attacker may be able to cause unexpected application termination or arbitrary code execution […]

Apple Patches iTunes, iCloud for Windows, Xcode Server
Ukrainian Hackers Expose 2,337 Emails from Putin’s Most Trusted Advisor
550,000 Australian Red Cross blood donor details leaked

The personal details of 550,000 Australian Red Cross blood donors have been leaked in an event being described as Australia’s largest ever security breach. The post 550,000 Australian Red Cross blood donor details leaked appeared first on WeLiveSecurity.

Threatpost News Wrap, October 28, 2016
Researchers expose Mirai vuln that could be used to hack back against botnet
This IoT Scanner Shows if Your Device is Vulnerable to be used in DDoS Attacks
Alleged ISIS member ‘wore USB cufflink and trained terrorists in encryption’
International Internet Day: A great network targeted by cybercriminals

As the world celebrates International Internet Day, we take a look at how cybercriminal activity has evolved online. The post International Internet Day: A great network targeted by cybercriminals appeared first on WeLiveSecurity.

Search engine results increasingly poisoned with malicious links
Nude celebrity photo hacker sentenced to 18 months in prison
Researchers exploit unencrypted radio to hack wireless mice, keyboards
Windows Atom Tables popped by security researchers

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

Researchers tag new brace of bugs in NTP, but they’re fixable
‘Fappening’ hacker gets 18 months in US federal clapper
Bitcoin exchange boss going down for washing ransomware cash
Blood donors’ privacy anaemic after Red Cross data breach

LinuxSecurity.com: Security Report Summary

Dan Kaminsky calls for a few good hackers to secure the web
Scare tactics! Tech support scam claims your hard drive will be deleted

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

IDG Contributor Network: Cybersecurity Awareness Month: Shedding light on application security
Hackers Earn $215,000 for Hacking Nexus 6P, iPhone 6S
Cisco Patches Critical Vulnerability in Facility Events Response System

LinuxSecurity.com: New version of jasper is available (jasper-1.900.13). Security fix forCVE-2016-8690, CVE-2016-8691, CVE-2016-8692, CVE-2016-8693.

Datto launches backup and disaster recovery technology to combat ransomware

LinuxSecurity.com: Fixes CVE-2016-7969, CVE-2016-7970 and CVE-2016-7972 —- Update to 0.13.3.Contains various bugfixes.

Microsoft Extends Malicious Macro Protection to Office 2013
DDoS Attack on Dyn: Largest of Its Kind Involving 100,000 Mirai Botnets
Dyn DDoS Could Have Topped 1 Tbps
Keen Lab Takes Down iPhone 6S, Nexus 6P at Mobile Pwn2Own

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Locky Ransomware in Action: Real-World Attack Description
Phishing fraudsters pose as UK bank social media types
Windows Atom Tables Can Be Abused for Code Injection Attacks
Belgian court fines Skype for failing to intercept criminals’ calls in 2012
How to fight macro malware in Office 2016 and 2013
Schneider Electric plugs gaping hole in industrial control kit
Conspiracy or cockup? Google hid ProtonMail’s encrypted email service from search results
How Google’s Project Zero made Apple refactor its kernel
PayPal patches bone-headed two factor authentication bypass
Good luck securing ‘things’ when users assume ‘stuff just works’
Hacker’s Icarus machine steals drones midflight
Internet of S**t things claims another scalp: DNS DDoS smashes StarHub
Three LibTIFF bugs found, only two patched
How many Internet of S**t devices knocked out Dyn? Fewer than you may expect
Joomla! squashes critical privileged account creation holes

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Patch Flash NOW
Blue screen of death with a support number? Beware the malware scam

security update

security update

end-of-life

Adobe emits emergency patch for Flash hole malware is exploiting right this minute
Cybercriminals in the health sector put under the microscope
Joomla Update Fixes Two Critical Issues, 2FA Error

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for XXE SVG issue.

LinuxSecurity.com: Security Report Summary

Arrested LinkedIn Hacker Accused of Hacking DropBox, Stealing Bitcoins
Remote Code Execution Vulnerabilities Plague LibTIFF Library
Password1? You’re so random. By which we mean not random at all – UK.gov
Adobe Patches Flash Zero Day Under Attack
Lawmakers Asking What ISPs Can Do About DDoS Attacks
Election hacking FAQ: 2016 US presidential election edition

Stephen Cobb, senior security researcher at ESET answers the 10 most frequently asked questions on election hacking. The post Election hacking FAQ: 2016 US presidential election edition appeared first on WeLiveSecurity.

AT&T Spies on Customer; Sells Data to the Government: Report
Webcam security: Understanding this modern day threat

Who would have thought that webcams could be exploited? Well, they can, and so serious is the issue, that it has the likes of Mark Zuckerberg covering them with up with tape. The post Webcam security: Understanding this modern day threat appeared first on WeLiveSecurity.

Rise of the IoT machines
Major Vulnerability Found In Schneider Electric Unity Pro