Menu

Category Archives: Security

Articles about security

New wave of cyberattacks against Ukrainian power industry

ESET has discovered a new wave of cyberattacks attacks against Ukraine’s electric power industry. Interesting, the malware that was used is not BlackEnergy. The post New wave of cyberattacks against Ukrainian power industry appeared first on We Live Security.

LinuxSecurity.com: Update to 2.10.4. Major new features: * New HTTP disk cache for the NetworkProcess. * IndexedDB support. * New Web Inspector UI. * AutomaticScreenServer inhibition when playing fullscreen videos. * Initial Editor API.* Performance improvements. This update addresses the followingvulnerabilities: * CVE-2015-1122 * CVE-2015-1152 * CVE-2015-1155 *CVE-2015-3660 * CVE-2015-3730 * CVE-2015-3738 * CVE-2015-3740 *CVE-2015-3742 […]

LinuxSecurity.com: Sync with latest openssh package.

LinuxSecurity.com: Security update.

LinuxSecurity.com: PV superpage functionality missing sanity checks [XSA-167, CVE-2016-1570] VMX:intercept issue with INVLPG on non-canonical address [XSA-168, CVE-2016-1571]Qemu: pci: null pointer dereference issue CVE-2015-7549 qemu: DoS by infiniteloop in ehci_advance_state CVE-2015-8558 qemu: Heap-based buffer overrun duringVM migration CVE-2015-8666 Qemu: net: vmxnet3: incorrect l2 header validationleads to a crash via assert(2) call CVE-2015-8744 qemu: Support reading […]

LinuxSecurity.com: Patches for CVE-2016-1982,3

LinuxSecurity.com: Update to latest upstream stable release, Linux v4.3.4. Elan touchpad fixes.—- Update to 4.3.y stable series. Fixes across the tree.

LinuxSecurity.com: System administrators are aware as how important their systems security is, not just the runtime of their servers. Intruders, spammers, DDOS attack, crackers, are all out there trying to get into people’s computers, servers and everywhere they can lay hands on and interrupt the normal runtime of services.

LinuxSecurity.com: Thanks so much to Peter Smith for announcing on linuxsecurity.com the release of his Linux Network Security book available free online. “In 2005 I wrote a book on Linux security. 8 years later and the publisher has gone out of business. Now that I’m free from restrictions on reproducing material from the book, I […]

security update

security update

security update

security update

security update

security update

security update

security update

security update

security update

Risk Level: Very Low. Type: Trojan.

Type: Vulnerability. Adobe Flash Player is prone to an unspecified heap-based buffer-overflow vulnerability; fixes are available.

Americans ‘worry more about online privacy than losing main income”

American consumers are more concerned about not knowing how their personal data is collected online than they are about losing their main source of income, new research has found. The post Americans ‘worry more about online privacy than losing main income” appeared first on We Live Security.

The security review: Windows exploitation 2015 and Bayrob trojan

Highlights from the past seven days in information security include ESET’s annual Windows exploitation report, analysis of the Bayrob trojan and beating tax identity fraud. The post The security review: Windows exploitation 2015 and Bayrob trojan appeared first on We Live Security.

LinuxSecurity.com: AMERICAN AND BRITISH INTELLIGENCE secretly tapped into live video feeds from Israeli drones and fighter jets, monitoring military operations in Gaza, watching for a potential strike against Iran, and keeping tabs on the drone technology Israel exports around the world.

LinuxSecurity.com: Mike Mimoso talks to privacy and security veteran Jon Callas of Silent Circle about the digital footprint businesses and consumers leave, how to secure our private data, and how a new documentary sponsored by Silent Circle called “Power of Privacy” helps visualize how personal information is shared-and abused-online.

LinuxSecurity.com: It was the talk most anticipated at this year’s inaugural Usenix Enigma security conference in San Francisco and one that even the other speakers were eager to hear.

LinuxSecurity.com: The OpenSSL project has patched a problem in the cryptographic library but one that likely does not affect many popular applications. OpenSSL enables SSL (Secure Sockets Layer) or TLS (Transport Layer Security) encryption. Most websites use it, which is indicated in Web browsers with a padlock symbol.

LinuxSecurity.com: A year after Google’s Chromium Security team proposed marking all HTTP sites which are non-secure, the company is preparing to implement the policy in Chrome.

security update

security update

security update

security update

security update

A lot happens in the security world, some big and some small, and many stories get lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot ThreatBrief, highlighting 5 major security news stories of the week. Indian Banks Hit with Ransomware Recently, several Indian banks were infiltrated […]

HSBC’s online banking services hit with cyberattack

HSBC in the UK has revealed via Twitter that its internet banking services were targeted by cybercriminals this morning (January 29th), which it has “successfully defended”. The post HSBC’s online banking services hit with cyberattack appeared first on We Live Security.

Businesses ‘still naïve to the risks of cybercrime’

Close to half all businesses in the UK are of the opinion that they are safe from cybercrime, according to new research. They believe the risks are minute. The post Businesses ‘still naïve to the risks of cybercrime’ appeared first on We Live Security.

This Facebook bug could have allowed hackers to take over your account
Sysadmin held at gunpoint by man demanding he fix his computer
Dad found not guilty for taking away his daughter’s iPhone
FDA releases draft guidelines to improve cybersecurity in medical devices
APPLE-SA-2016-01-25-1 tvOS 9.1.1

From: Apple Product SecurityReply to list APPLE-SA-2016-01-25-1 tvOS 9.1.1 tvOS 9.1.1 is now available and addresses the following: Disk Images Available for: Apple TV (4th generation) Impact: A local user may be able to execute arbitrary code with kernel privileges Description: A memory corruption issue existed in the parsing of […]

APPLE-SA-2016-01-19-3 Safari 9.0.3

From: Apple Product SecurityReply to list APPLE-SA-2016-01-19-3 Safari 9.0.3 Safari 9.0.3 is now available and addresses the following: WebKit Available for: OS X Mavericks v10.9.5, OS X Yosemite v10.10.5, OS X El Capitan v10.11 to v10.11.2 Impact: Visiting a maliciously crafted website may lead to arbitrary code execution […]

APPLE-SA-2016-01-19-2 OS X El Capitan 10.11.3 and Security Update 2016-001

From: Apple Product SecurityReply to list APPLE-SA-2016-01-19-2 OS X El Capitan 10.11.3 and Security Update 2016-001 OS X El Capitan 10.11.3 and Security Update 2016-001 is now available and addresses the following: AppleGraphicsPowerManagement Available for: OS X El Capitan v10.11 to v10.11. […]

APPLE-SA-2016-01-19-1 iOS 9.2.1

From: Apple Product SecurityReply to list APPLE-SA-2016-01-19-1 iOS 9.2.1 iOS 9.2.1 is now available and addresses the following: Disk Images Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later Impact: A local user may be able to execute arbitrary code with kernel privileges […]

APPLE-SA-2016-01-07-1 QuickTime 7.7.9

From: Apple Product SecurityReply to list APPLE-SA-2016-01-07-1 QuickTime 7.7.9 [Re-sending with a valid signature] QuickTime 7.7.9 is now available and addresses the following: QuickTime Available for: Windows 7 and Windows Vista Impact: Viewing a maliciously crafted movie file may lead to an […]

Scammers peddle adult dating, webcam spam through legitimate email notifications
Scammers peddle adult dating, webcam spam through legitimate email notifications
Waledac takes pot shot with pump and dump stock spam
Waledac takes pot shot with pump and dump stock spam
Indian, US, UK finance department employees targeted with remote access Trojans
Indian, US, UK finance department employees targeted with remote access Trojans
Scammers impersonate India's Income Tax Department to deliver malware
Scammers impersonate India's Income Tax Department to deliver malware
Worst Passwords of 2015, Best Passwords of 2016
Webroot’s Acceleration with Advancement of IoT
Google Glass for the masses, king of computerized headgear, is dead
1 tip to make your home safer on Data Privacy Day
Police destroy evidence with 10 failed passcode attempts on iPhone
What do you think of trying Tor today?
Your kids: more time online, less time watching TV… so let’s keep them safe
Major TeslaCrypt ransomware offensive underway
Major TeslaCrypt ransomware offensive underway
Threat Recap: Week of January 17th
As tax season approaches, beware of tax related scams
Crypto-ransomware – still a real worry
KB 2881029, 3039794, 2920727 throw spurious VBA, 'Office Automation' errors
New Android ransomware uses clickjacking to gain admin privileges
Protect yourself against DNS tunneling
Oracle hops on the bandwagon to dump Java browser plug-in
OpenSSL patches two vulnerabilities in cryptographic library

NMAP Scanning – Idle Scan An unusual scan which is available for NMAP is the Idle Scan. To start, the Port Scan requires an idle system to be used as a “zombie”. The “zombie” is used to scan for open ports on a Target system. Results are sent from the “zombie” system to the Source […]

NMAP TCP/IP Basics Before getting too far into Network Mapping (NMAP) everyone should have an understanding of the Transmission Control Protocol Internet Protocol (TCP/IP). By knowing the basics of TCP/IP, you will have a better understanding of what NMAP is doing. To help back up the underlying workings, I will try to include packet captures […]

All computer systems can suffer from malware and viruses, including Linux. Thankfully, very few viruses exist for Linux, so users typically do not install antivirus software. It is still recommended that Linux users have antivirus software installed on Linux systems that are on a network or that have files being transferred to the device. Some […]

Firefox is a popular web-browser according to W3Schools (http://www.w3schools.com/browsers/browsers_stats.asp). A popular web-browser may be at risk for security and privacy issues because malicious hackers will want to target such a browser. Also, a security or privacy issue in a popular browser will affect numerous people. Obviously, some users of Firefox may want to use plugins […]

NMAP TCP Scanning When using NMAP, there are basic scans which are used to find specific information. There are four basic scans used the most by NMAP and can be handy depending on what you need to discover on a system or a network. Let’s start by listing the basic scans. The four basic scans […]

LinuxSecurity.com: Criminals flexing their technical muscles was the biggest motivation last year behind distributed denial-of-service attacks (DDoS), which involve flooding a target’s web servers with junk traffic, according to an analysis by Arbor Networks.

LinuxSecurity.com: As an active member of our digital-first society, there is almost nothing more demoralizing than trying to track down coherent technology policies from our top ten candidates for the 2016 presidential race.

LinuxSecurity.com: Millions of online merchants are at risk of hijacking attacks made possible by a just-patched vulnerability in the Magento e-commerce platform.

LinuxSecurity.com: Shodan, a search engine for the Internet of Things (IoT), recently launched a new section that lets users easily browse vulnerable webcams.

LinuxSecurity.com: An Israeli security research firm has come forward with a troubling discovery. A zero-day vulnerability in the Linux kernel has left “tens of millions” of Linux PCs and servers exposed, along with 66 percent of Android phones and tablets. And it’s been there for nearly three years.

Wendy’s launches investigation into possible data breach

The fast food chain Wendy’s may have been the victim of a data breach, the security expert Brian Krebs has revealed. Unusual activity has been reported. The post Wendy’s launches investigation into possible data breach appeared first on We Live Security.

The IoT (Internet of Things) as a concept has been with us since the late 1990’s and has evolved from simple M2M (Machine-to-Machine) connectivity into a vision for Operational Productivity enabled by Interoperability.  Innovation and investment in new IoT technology and business models are driven by the pursuit of key operational benefits such as Provisioning […]

Belong to the ‘selfie’ generation? You are probably oversharing

The ‘Selfie Generation’, which shares every detail of their lives online, doesn’t realize that giving away too much information can have serious consequences. The post Belong to the ‘selfie’ generation? You are probably oversharing appeared first on We Live Security.

‘Application not compatible': Bayrob may be stealing your info

In this post, ESET’s Josep Albors analyzes Bayrob, a trojan that has been intensely targeting users across the world since mid-December, 2015. The post ‘Application not compatible’: Bayrob may be stealing your info appeared first on We Live Security.

security update

When it comes to digital security, little is as important as knowing how to create a strong password. An ideal password is easy enough to remember so that it doesn’t need to be written down, yet complex enough to prevent someone else from guessing it. For many, this is a challenging and even frustrating experience, […]

Businesses increasingly targeted with ransomware

Cybercriminals are increasingly targeting businesses with ransomware, according to a new report by the Online Trust Alliance. The post Businesses increasingly targeted with ransomware appeared first on We Live Security.

Will your Swiss email account stay private (or can the govt take a look)?

A referendum is to be held on Switzerland’s proposed surveillance law, a decision lauded by supporters of privacy. ESET’s Cameron Camp discusses further. The post Will your Swiss email account stay private (or can the govt take a look)? appeared first on We Live Security.

security update

security update

security update

security update

Why patching is still a problem — and how to fix it
Despite warnings from people like me, unpatched software is the top reason computers get exploited. People aren’t too dumb or lazy to install [...]
Why you don't need an RFID-blocking wallet
Because I’m a computer security guy, I have friends who like to show off their new RFID-blocking wallets and purses. “Look what I got for [...]
Train your users to beat phone scams
As I landed in Dallas returning from my recent visit to China, I picked up my cellphone voicemails. One of them was from my bank, telling me my personal [...]

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

A better way to move past insecure SHA-1 certs
I’ve written a few times about the pending mini-Y2K issue that is SHA-1 deprecation. In a nutshell, all digital certificates are signed by a hashing [...]

Type: Vulnerability. Adobe Flash Player and AIR are prone to an unspecified integer-overflow vulnerability; fixes are available.

How computer security changed in 2015
You can call me a pundit, I guess, but I don’t like making predictions. Most industry forecasts are horribly inaccurate and miss the stuff people [...]

Type: Vulnerability. Adobe Flash Player and AIR are prone to multiple unspecified memory-corruption vulnerabilities; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.