Menu

Category Archives: Security

Articles about security

Lawmakers Asking What ISPs Can Do About DDoS Attacks
Election hacking FAQ: 2016 US presidential election edition

Stephen Cobb, senior security researcher at ESET answers the 10 most frequently asked questions on election hacking. The post Election hacking FAQ: 2016 US presidential election edition appeared first on WeLiveSecurity.

AT&T Spies on Customer; Sells Data to the Government: Report
Webcam security: Understanding this modern day threat

Who would have thought that webcams could be exploited? Well, they can, and so serious is the issue, that it has the likes of Mark Zuckerberg covering them with up with tape. The post Webcam security: Understanding this modern day threat appeared first on WeLiveSecurity.

Rise of the IoT machines
Major Vulnerability Found In Schneider Electric Unity Pro

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

The Hive Mind: When IoT devices go rogue

IoT devices, while extremely useful for simplifying various mundane aspects of everyday life, also offer criminals a new attack platform: your appliances. The post The Hive Mind: When IoT devices go rogue appeared first on WeLiveSecurity.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise MRG 2.5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

Got Ancient exploit but nowhere to use it? Try the horrid GRX network
No, the Jester didn’t hack the Russian Foreign Ministry website
VXer turns to ancient freemium model to flog keylogger, malware tools
This is not a drill: Hackers pop stock Nexus 6P in five minutes
Microsoft Security Essentials Installer Leads to Support Scam Malware
Asterisk users need to patch DoS bug

security update

LinuxSecurity.com: Security fix for XXE SVG issue.

Hacker Selling Hacked IoT Botnet for DDoS Attacks up to 1Tbps
Dyn DDoS Work of Script Kiddies, Not Politically Motivated Hackers
ARM builds up security in the tiniest IoT chips
Every step your phone tracker takes I’ll be watching you
Following Lull, New Campaigns Pushing Retooled ‘Pumpkin’ Locky
Apple Patches iOS Flaw Exploitable by Malicious JPEG

From: Apple Product SecurityReply to list APPLE-SA-2016-10-24-5 watchOS 3.1 watchOS 3.1 is now available and addresses the following: CoreGraphics Available for: All Apple Watch models Impact: Viewing a maliciously crafted JPEG file may lead to arbitrary code execution Description: A memory corruption issue was addressed through improved […]

From: Apple Product SecurityReply to list APPLE-SA-2016-10-24-4 tvOS 10.0.1 tvOS 10.0.1 is now available and addresses the following: CFNetwork Proxies Available for: Apple TV (4th generation) Impact: An attacker in a privileged network position may be able to leak sensitive user information […]

From: Apple Product SecurityReply to list APPLE-SA-2016-10-24-3 Safari 10.0.1 Safari 10.0.1 is now available and addresses the following: WebKit Available for: OS X Yosemite v10.10.5, OS X El Capitan v10.11.6, and macOS Sierra 10.12 Impact: Processing maliciously crafted web content may lead to arbitrary code execution […]

From: Apple Product SecurityReply to list APPLE-SA-2016-10-24-2 macOS Sierra 10.12.1 macOS Sierra 10.12.1 is now available and addresses the following: AppleGraphicsControl Available for: OS X Yosemite v10.10.5 and OS X El Capitan v10.11.6 Impact: An application may be able to execute arbitrary code with kernel privileges […]

From: Apple Product SecurityReply to list APPLE-SA-2016-10-24-1 iOS 10.1 iOS 10.1 is now available and addresses the following: CFNetwork Proxies Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch 6th generation and later Impact: An attacker in a privileged network position may be able to […]

Millions of Android Devices Vulnerable to DRAMMER Attack
Paging 1994: Crap encryption still rife in devices
Election Leaks Failed to Move Needle on Polls
Find Your Keys, Lose Your Privacy

LinuxSecurity.com: The OpenSSL Project is a collaborative effort to develop a robust, commercial-grade, full-featured Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) protocols as well as a full-strength general purpose cryptography library.

LinuxSecurity.com: Security fix for CVE-2016-3102. Update to 1.651.1. Fix dangling symlink(rhbz#1330472)

LinuxSecurity.com: phpMyAdmin 4.6.4 (2016-08-16) ============================= This releaseincludes many security fixes of various levels of severity. Upstream recommendsall users upgrade to this release immediately. For full information on thevulnerabilities fixed and mitigation factors for users who are unable toupgrade, refer to the ChangeLog file included with this release and the securityannouncements at https://www.phpmyadmin.net/security/ Aside from the […]

LinuxSecurity.com: Security fix for CVE-2016-3102. Update to 1.651.1. Fix dangling symlink(rhbz#1330472)

LinuxSecurity.com: Security fix for CVE-2016-3102. Update to 1.651.1. Fix dangling symlink(rhbz#1330472)

LinuxSecurity.com: Security fix for CVE-2016-3102. Update to 1.651.1. Fix dangling symlink(rhbz#1330472)

LinuxSecurity.com: Security fix for CVE-2016-3102. Update to 1.651.1. Fix dangling symlink(rhbz#1330472)

LinuxSecurity.com: Security fix for CVE-2016-2774

LinuxSecurity.com: New upstream release

LinuxSecurity.com: Security fix for CVE-2016-3102. Update to 1.651.1. Fix dangling symlink(rhbz#1330472)

LinuxSecurity.com: Security fix for CVE-2016-3102. Update to 1.651.1. Fix dangling symlink(rhbz#1330472)

LinuxSecurity.com: Security fix for CVE-2016-4855 (#1373374)

Surveillance by consent: Commissioner launches UK-wide CCTV strategy
Lifting the lid on Sednit: A closer look at the software it uses

ESET’s threat analysts have taken a closer look at the software used by Sednit to spy on its targets and steal confidential information. The post Lifting the lid on Sednit: A closer look at the software it uses appeared first on WeLiveSecurity.

Friday’s IoT-based DDoS attack has security experts worried
VASCO white paper- Strong authentication to solve your everyday banking problems
The only realistic plan to avoid DDoS disaster

Last Friday’s massive DDoS attack against Dyn.com and its DNS services slowed down or knocked out internet connectivity for millions of users for much of the day. Unfortunately, these sorts of attacks cannot be easily mitigated. We have to live with them for now.Huge DDoS attacks that take down entire sites can be accomplished for a […]

Microsoft: Watch out millennials for evil Security Essentials
Graduate recruitment site exposed 50,000 CVs sent to Virgin Media UK
MedSec’s St Jude pacemaker hacks confirmed by pen-tester
Joomla! readies patch for core vulnerability so critical it isn’t talking
Judge orders FBI to reveal whether White House launched ‘Tor pedo’ torpedo exploits

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

LinkedIn, Dropbox hack suspect named as Yevgeniy Nikulin by US prosecutors
It’s nearly 2017 and JPEGs, PDFs, font files can hijack your Apple Mac, iPhone, iPad
St. Jude Faces New Claim Heart Implants are Hackable
A boobytrapped JPEG could infect your iPhone. Upgrade to iOS 10.1 now
Firm recall webcams after confirming involvement in Dyn DDoS attack
Webcam firm recalls hackable devices after mighty Mirai botnet attack

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Chinese Manufacturer Recalls IOT Gear Following Dyn DDoS
App proves Rowhammer can be exploited to root Android phones – and there’s little Google can do to fully kill it
Fake Microsoft Installer Leads to Malware, Support Call Scam

LinuxSecurity.com: Security Report Summary

Risk Level: Very Low. Type: Trojan.

Hacker Who DDoSed Boston Hospital for OpJustina Facing Charges
Know your enemy: Training can help avoid cybersecurity pitfalls

European Cyber Security Month offers a great opportunity to remind people of some of the practices that can boost their cybersecurity skills. The post Know your enemy: Training can help avoid cybersecurity pitfalls appeared first on WeLiveSecurity.

Rowhammer Vulnerability Comes to Android
For rent: An IoT botnet to take down much of the internet
Post-Mirai, how to better protect your IoT devices
Chinese electronics biz recalls webcams at heart of botnet DDoS woes
From There to Here (But Not Back Again)
Crashing a $1,000 Drone by Hacking the 3D Manufacturing System
French surveillance law is unconstitutional after all, highest court says
Chinese firm admits its hacked products were behind Friday’s massive DDOS attack