Menu

Latest articles

Scammy and spammy harassers are chasing veteran pros off crypto-collab platform Keybase
Feds Offer $5M Reward to Nab ‘Evil Corp’ Dridex Hacker
Cookie-stealing malware wants to know your Facebook ad budget
Chinese DDoS tool Great Cannon resurfaces to target Hong Kong protestors
iCloud-hacking politician to be sentenced on Christmas eve
Machine-raiding Python libraries squashed by community
Feds slap $5m bounty on ‘Evil Corp’ Russian duo accused of running ZeuS, Dridex banking trojans
HackerOne Breach Leads to $20,000 Bounty Reward
Critical DoS messaging flaw fixed in December Android update
Microsoft readies new language for safe programming
OpenBSD Hit with Authentication, LPE Bugs
How to fool infosec wonks into pinning a cyber attack on China, Russia, Iran, whomever
Yodel parcel tracking app blabs about other people’s parcels
80% of all Android apps encrypt traffic by default

Google keeps pushing in its mission for broader encryption adoption The post 80% of all Android apps encrypt traffic by default appeared first on WeLiveSecurity

Major data center provider hit by ransomware attack, claims report
Oil be damned: Iran-based crooks flinging malware at Middle Eastern energy plants again – research
‘Ultimate’ MiTM Attack Steals $1M from Israeli Startup

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Snake bites: Beware malicious Python libraries

RabbitMQ could be made to execute arbitrary code if it received a specially crafted input.

Face scanning – privacy concern or identity protection?

What issues would face scanning attached to a mobile device resolve and, if used correctly, would it make the incursion into my privacy acceptable? The post Face scanning – privacy concern or identity protection? appeared first on WeLiveSecurity

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Atlassian scrambles to fix zero-day security hole accidentally disclosed on Twitter
Lazarus group goes back to the Apple orchard with new macOS trojan
Smashing Security #157: A biometric knuckle duster

Type: Vulnerability. Symantec Norton Password Manager is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Symantec Norton Password Manager is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Symantec Norton Password Manager is prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to multiple denial-of-service vulnerabilities; fixes are available.

ThreatList: 1 in 9 SMBs Believe Nation-State Actors Are Targeting Them
Cut-and-paste goof reveals HackerOne session cookie, and earns bug hunter $20,000
Flawed Implementation of RCS Standard putting data of millions at risk
Nebraska Medicine Breached By Rogue Employee
‘Highly Competitive’ Buer Loader Emerges in Underground Markets
Iran Targets Mideast Oil with ZeroCleare Wiper Malware
3 arrested, 30,000+ piracy sites shut down in global operation IOSX
EFF Talks the Corporate Surveillance of Consumers
Dutch Politician Could Get Three Years in Prison for Hacking iCloud Accounts
Steam players – beware of fake skins as phishers try to hijack accounts
Facebook made to ‘correct’ user’s post as Singapore flexes fake-news muscle
Microsoft looks to Rust language to beat memory vulnerabilities
10 Key Tips for Hiring a Web Design Company
FBI: Russia-based FaceApp is a ‘potential counterintelligence threat’
Mozilla locks nosy Avast, AVG extensions out of Firefox store amid row over web privacy
This Smartwatch is exposing real-time location data of thousands of kids
DHS Plans to Expand Facial Recognition Border Checks

Reading Time: ~ 2 min. Have you noticed a decrease in your child’s happiness or an increase in their anxiety? Cyberbullying might be the cause to these behavioral changes. Bullying is no longer confined to school playgrounds and neighborhood alleys. It has long moved into the online world, thanks to the easy access to technology. […]

ThreatList: A Third of Biometric Systems Targeted by Malware in Q3

Type: Vulnerability. Qualcomm Closed-Source Components are prone to multiple unspecified vulnerabilities; fixes are available.

Type: Vulnerability. IBM Cloud Pak System is prone to an unspecified cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Moodle is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Multiple Kaspersky Products are prone to an arbitrary code-execution vulnerability; fixes are available.

Type: Vulnerability. Linux kernel is prone to a denial-of-service vulnerability.

Type: Vulnerability. Apache cordova-plugin-inappbrowser is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Redhat KeyCloak is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Multiple Trend Micro Products are prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Django is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel 2016 is prone to an information-disclosure vulnerability.

Android Ups the Mobile Security Ante with Default TLS Encryption
Critical Android Flaw Leads to ‘Permanent DoS’
Notorious spy tool taken down in global operation

IM-RAT, which could be had for as little as US$25, was bought by nearly 15,000 people The post Notorious spy tool taken down in global operation appeared first on WeLiveSecurity

SMS and personal data of millions of Americans leaked online
Supply Chain Account Takeover: How Criminals Exploit Third-Party Access
‘StrandHogg’ Vulnerability Allows Malware to Pose as Legitimate Android Apps
Step-by-Step Guide to Creating the Best Web Pages
AWS has new tool for those leaky S3 buckets so, yeah, you might need to reconfigure a few things
SMS company exposes millions of text messages, credentials online
Mixcloud user accounts up for sale on dark web
IM RAT spy tool seller raided, busted, kicked offline
Ad fraud: Fake local news sites are rolling in the dough
Jail for bomb hoaxer who targeted Super Bowl, Houses of Parliament, and schools for Jewish children
UK parcel firm Yodel plugs tracking app’s random yaps about where on map to snap up strangers’ tat
Russian FaceApp selfie-slurper poses ‘potential counterintelligence threat’, FBI warns
Welcome back from the holiday, Americans! Here’s who leaked data while you were away
Microsoft OAuth Flaw Opens Azure Accounts to Takeover
Europol wipes out 30,000+ piracy sites, three suspects cuffed to walk the legal plank

Type: Vulnerability. Linux kernel is prone to a denial-of-service vulnerability.

Type: Vulnerability. Multiple F5 BIG-IP Products are prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. PHP is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. PHP is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. PHP is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. PHP is prone to a heap-based memory-corruption vulnerability; fixes are available.

Type: Vulnerability. PHP is prone to a memory-corruption vulnerability; fixes are available.

Type: Vulnerability. PHP is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. PHP is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. PHP is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. PHP is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. PHP is prone to a remote stack-based buffer-overflow vulnerability; fixes are available.

Type: Vulnerability. PHP is prone to a denial-of-service vulnerability; fixes are available.

Authorities Break Up Imminent Monitor Spyware Organization
CISA Pushing U.S. Agencies to Adopt Vulnerability Disclosure Policies
Smart TVs: The Cyberthreat Lurking in Your Living Room, Feds Warn
Judge to interview Assange over claims Spanish security firm snooped on him during Ecuador embassy stint
Insecure Database Exposes Millions of Private SMS Messages

A security update is now available for Red Hat Single Sign-On 7.3 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

New Red Hat Single Sign-On 7.3.5 packages are now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

New Red Hat Single Sign-On 7.3.5 packages are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,