Menu

Latest articles

BazarLoader Malware Abuses Slack, BaseCamp Clouds
iOS Kids Game Morphs into Underground Crypto Casino
NSA: 5 Security Bugs Under Active Nation-State Cyberattack
Russian infosec firm Positive Technologies trying to stay positive after US sanctions
One in six people use pet’s name as password

Other common and easily hackable password choices include the names of relatives and sports teams, a UK study reveals The post One in six people use pet’s name as password appeared first on WeLiveSecurity

Microsoft received almost 25,000 requests for consumer data from law enforcement over the last six months
Mandiant Front Lines: How to Tackle Exchange Exploits
S3 Ep28.5: Hacking back – is attack an acceptable form of defence? [Podcast]
Google Project Zero Cuts Bug Disclosure Timeline to a 30-Day Grace Period
Watchdog thinks Google tricked Australians into giving up data, sues. Judge semi-agrees
Top Tips for Securing Your Linux System in 2021>
A Call to Action: Recent PHP Hack Highlights the Need for Better Security>
Linux Lite 5.4 Released With Bug Fixes And UI Enhancements>
Red Hat Launches RHEL Stream to Compete With the Rising Popularity of CentOS Stream>
Spring cleaning? Don’t forget about your digital footprint

Here are some quick and easy tips to help you clean up your cyber-clutter and keep your digital footprint tidy The post Spring cleaning? Don’t forget about your digital footprint appeared first on WeLiveSecurity

At Webroot, we could go on and on about user experience (UX) design. The study of the way we interact with the tools we use has spawned entire industries, university programs and professions. A Google Scholar search of the term returns over 300 thousand results. Feng Shui, Leonardo Davinci and Walt Disney are all described […]

Pen testing is the art of attempting to breach an organization’s network, computers and systems to identify possible means of bypassing their defenses. It’s an “art” because there is no one-size-fits-all method or process. Testers need a variety of skills, knowledge and tools to make the attempt. Most testers are hackers trying to use their […]

Mobile app security standard for IoT, VPNs proposed by group backed by Big Tech

security update

Biden Races to Shore Up Power Grid Against Hacks
FBI removes web shells from compromised Exchange servers

Authorities step in to thwart attacks leveraging the recently-disclosed Microsoft Exchange Server vulnerabilities The post FBI removes web shells from compromised Exchange servers appeared first on WeLiveSecurity

Gafgyt Botnet Lifts DDoS Tricks from Mirai
It was Russia wot did it: SolarWinds hack was done by Kremlin’s APT29 crew, say UK and US
University of Hertfordshire pulls the plug on, well, everything after cyber attack
White House launches plan to protect US critical infrastructure against cyber attacks
Attackers Target ProxyLogon Exploit to Install Cryptojacker
S3 Ep28: Pwn2Own hacks, dark web hitmen and COVID-19 privacy [Podcast]

Appled all the changes from the upstream 2.53.7.1 update. Fixed tab opening in background and tab choosing on a tab close. —- Fix updating and support of legacy javascript extensions. —- Update to 2.53.7 Enable support for module scripts. (To turn it off, toggle “dom.moduleScripts.enabled” in about:config). For sending mail, now “Thunderbird” is advertised in […]

Upstream release, security fix for CVE-2021-20307

This is the ninth maintenance release of Python 3.8. [Changelog](https://docs.py thon.org/release/3.8.9/whatsnew/changelog.html#python-3-8-9). Contains a security fix for CVE-2021-3426.

Upstream release, security fix for CVE-2021-20307

An update that solves three vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

Is it still possible to run malware in a browser using JavaScript and Rowhammer? Yes, yes it is (slowly)
Smashing Security podcast #223: Booze, nudes, and insurance dudes
Nigerian email scammer sent down for 40 months in the US, ordered to pay back $2.7m to victims
Report: Aussie biz Azimuth cracked San Bernardino shooter’s iPhone, ending Apple-FBI privacy standoff

In the United States, there are approximately 350,000 companies contracting for the Department of Defense. Each of these companies have to meet varying degrees of compliance and are now subject to the Cybersecurity Maturity Model Certification (CMMC). Effectively, CMMC means that before a DoD contractor can execute on their contract, they have to receive an […]

Security Bug Allows Attackers to Brick Kubernetes Clusters
Ransomware Attack Creates Cheese Shortages in Netherlands
What the FLoC? Browser makers queue up to decry Google’s latest ad-targeting initiative as invasive tracking
School janitor says she was fired for not installing smartphone tracking app
FBI Clears ProxyLogon Web Shells from Hundreds of Orgs
A Post-Data Privacy World and Data-Rights Management
Chrome and Chromium updated after yet another exploit is found in browser’s V8 JavaScript engine
100,000 Google Sites Used to Install SolarMarket RAT
Microsoft Has Busy April Patch Tuesday with Zero-Days, Exchange Fixes
FBI hacks into hundreds of infected US servers (and disinfects them)
Is Linux Mint Turning Into Windows?>
New Linux, macOS malware hidden in fake Browserify NPM package>

An update for libldb is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Apache SpamAssassin 3.4.6 Release Fixes Two Potentially Aggravating Bugs>

Updated Red Hat JBoss Web Server 5.4.2 packages are now available for Red Hat Enterprise Linux 7, and Red Hat Enterprise Linux 8. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The 5.11.13 stable kernel update contains a number of important fixes across the tree.

The 5.11.13 stable kernel update contains a number of important fixes across the tree.

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Red Hat JBoss Web Server 5.4.2 zip release is now available for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8 and Windows. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Spy agency GCHQ told me Gmail’s more secure than Microsoft 365, insists British MP as facepalming security bods tell him to zip it
FBI deletes web shells from hundreds of compromised Microsoft Exchange servers before alerting admins
Google Sites blight: Over 100,000 web pages for business form searches overrun with backdoor RATs

“It is a nightmare. Do all you can to prevent ransomware.” – A survey respondent Many businesses are hesitant to talk about their experiences with ransomware. It can be uncomfortable to cop being hit. Whether it’s shame at not doing more to prevent it, the risk of additional bad publicity from discussing it or some other […]

How the NAME:WRECK Bugs Impact Consumers, Businesses
1Password targets developers with Secrets Automation, acquisition of SecretHub
COVID-Related Threats, PowerShell Attacks Lead Malware Surge
NSA helps out Microsoft with critical Exchange Server vulnerability disclosures in an April shower of patches

Ransomware attacks generate big headlines when the targets are government entities, universities and healthcare organizations. But there’s one increasingly frequent target of ransomware attacks that tends to slip under the radar. Small and midsize businesses (SMBs) have become bigger financial targets for hackers. As Webroot Senior Threat Researcher Kelvin Murray points out in a recent […]

Ransomware attack causes supermarket cheese shortage in the Netherlands
IoT bug report claims “at least 100M devices” may be impacted
Tax Phish Swims Past Google Workspace Email Security
A helpful reminder about just how much Facebook stalks you on the internet
Cracked copies of Microsoft Office and Adobe Photoshop steal your session cookies, browser history, crypto-coins
Adobe Patches Slew of Critical Security Bugs in Bridge, Photoshop
WhatsApp flaw lets anyone lock you out of your account

An attacker can lock you out of the app using just your phone number and without requiring any action on your part The post WhatsApp flaw lets anyone lock you out of your account appeared first on WeLiveSecurity

Chrome Zero-Day Exploit Posted on Twitter
Average convicted British computer criminal is young, male, not highly skilled, researcher finds
Want to turbo-charge your cybersec skills? It’s time to put yourself on the SPOT
1.3M Clubhouse Users’ Data Dumped in Hacker Forum for Free
Man Arrested for AWS Bomb Plot
Apple and Google block official UK COVID-19 app update
Zero Trust: The Mobile Dimension
Upstox warns of serious data breach, resets passwords
Mike Lynch-backed Darktrace to file for London IPO in aftermath of Deliveroo flop
Clubhouse in the spotlight after user records posted online

Reports of another trove of scraped user data add to the recent woes of popular social media platforms The post Clubhouse in the spotlight after user records posted online appeared first on WeLiveSecurity

Is Linux A More Secure Option Than Windows For Businesses? >
Naked Security Live – How to spot “government” scammers
Stuxnet sibling theory surges after Iran says nuke facility shut down by electrical fault
United States’ plan to beat China includes dominating tech standards groups – especially for 5G

security update

security update

security update

Texan’s alleged Amazon bombing effort fizzles: Militia man wanted to take out ‘about 70 per cent of the internet’
Pwn2Own 2021: Zoom, Teams, Exchange, Chrome and Edge “fully owned”
UK’s National Cyber Security Centre recommends password generation idea suggested by El Reg commenter
CyberBattleSim: Microsoft’s open-source Holodeck in which autonomous attackers, defenders battle it out
How do we stamp out the ransomware business model? Ban insurance payouts for one, says ex-GCHQ director
India uses controversial Aadhaar facial biometrics to identify COVID vaccination recipients
Combating security challenges with cloud-native AI-driven architecture
Italian charged with hiring “dark web hitman” to murder his ex-girlfriend
S3 Ep27: Census scammers, beg bounties and data breach fines [Podcast]
Belgian police seize 28 tons of cocaine after ‘cracking’ Sky ECC’s chat app encryption