Menu

Latest articles

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Ethical hacker may get 8 years in prison for reporting flaws in Magyar Telekom
Three UK customer details exposed in homepage blunder

Reading Time: ~2 min. Facebook Research App Removed from App Store After seeing their Onavo VPN application removed from the Apple App Store last year, Facebook has re-branded the service as a “research” app and made it available through non-Apple testing services. The app itself requires users download and install a Facebook Enterprise Developer Certificate […]

Threatpost News Wrap Podcast For Feb. 1
FaceTime bug, eavesdropping and digital snooping – what to do? [VIDEO]
Cybercriminals Aim for the Super Bowl Goal Posts
Hackers used Karma tool to hack iPhones of prominent Govt officials
Four new caches of stolen logins put Collection #1 in the shade

The recently discovered tranches of stolen login credentials freely floating around the internet total 2.2 billion records The post Four new caches of stolen logins put Collection #1 in the shade appeared first on WeLiveSecurity

Linux user? Check those patches! Public exploit published for systemd security holes…
Credential dump contains another 2.2 billion pwned accounts
UK spy overseer: Snooper’s Charter cockups are still getting innocents arrested
Hacker talks to baby through Nest security cam, jacks up thermostat
Microsoft Azure data deleted because of DNS outage
Google says sorry for pulling a Facebook with monitoring program
Bringing the Houzz down: Home design website tells users to reset passwords after copping to breach
You got a smart speaker but you’re worried about privacy. First off, why’d you buy one? Secondly, check out Project Alias

LinuxSecurity.com: Several issues have been discovered in the MariaDB database server. The vulnerabilities are addressed by upgrading MariaDB to the new upstream version 10.0.38. Please see the MariaDB 10.0 Release Notes for further details:

Twitter follow bots cut off from API, as accounts disabled for spreading misinformation from Iran and elsewhere

LinuxSecurity.com: The 4.20.5 stable kernel update contains a number of important fixes across the tree.

Apple yoinks enterprise certs from Facebook, Google, killing internal apps, to show its power

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Facebook Boots Hundreds of Iran-Linked Accounts For Spreading Misinformation
TheMoon Rises Again, With a Botnet-as-a-Service Threat

Reading Time: ~5 min. This is the second of a three-part report on the state of three malware categories: miners, ransomware, and information stealers.  As noted in the last blog, mining malware is on a decline, partly due to turmoil affecting cryptocurrencies. Ransomware is also on a decline (albeit a slower one). These dips are at […]

security update

security update

security update

Prepare to Defend Your Network Against Swarm-as-a-Service
2019 Already Marred By Slew of Data Breach Incidents
Airbus Data Takes Flight; and Billions of Credentials Dumped on Dark Web
U.S. Government Goes After North Korea’s Joanap Botnet
Kwik-Fit hit by MOT fail, that’s Malware On Target
Japan to probe citizens’ IoT devices in the name of security

Smart devices were targeted by more than one-half of cyberattacks detected in the country in 2017 The post Japan to probe citizens’ IoT devices in the name of security appeared first on WeLiveSecurity

Hackers hit Airbus, steal personal details of employees
Texas lawyer suing Apple over FaceTime bug claims it was used to snoop on a meeting
Google Pulls Data-Chugging App From iOS Devices
Mac “CookieMiner” Malware Aims to Gobble Crypto Funds
Update now! Chrome and Firefox patch security flaws
14k HIV+ records leaked, Singapore says sorry
Personal data slurped in Airbus hack – but firm’s industrial smarts could be what crooks are after
Phone cloner gets 65 months in jail
Cybercrime black markets: Dark web services and their prices

A closer look at cybercrime as a service on the dark web The post Cybercrime black markets: Dark web services and their prices appeared first on WeLiveSecurity

LinuxSecurity.com: Several security issues were fixed in Avahi.

Apple kicks Facebook’s snoopy Research app out of the App Store

LinuxSecurity.com: The package ghostscript before version 9.26-2 is vulnerable to sandbox escape.

What’s Farsi for ‘as subtle as a nuke through a window’? Foreign diplomats in Iran hit by renewed Remexi nasty
The D in SystemD stands for Danger, Will Robinson! Defanged exploit code for security holes now out in the wild
Smashing Security #113: FaceTime, Facebook, faceplant
Team America tries to crash Little Rocket Man’s Joanap botnet from within, warns owners of infected boxes
Attackers Can Track Kids’ Locations via Connected Watches

security update

Furious Apple revokes Facebook’s enty app cert after Zuck’s crew abused it to slurp private data
Stealthy Malware Disguises Itself as a WordPress License Key
Apple Blasts Facebook Over Data-Sucking ‘Research’ App
‘We’re coming for you’, global police tell DDoS attack buyers

First closing in on operators, now on users, as the hunt continues and law enforcement in many countries is about to swoop on people who bought DDoS attacks on WebStresser The post ‘We’re coming for you’, global police tell DDoS attack buyers appeared first on WeLiveSecurity

Matrix under the microscope: what a niche ransomware can teach us
Researchers Allege ‘Systemic’ Privacy, Security Flaws in Popular IoT Devices
“Love you” malspam gets a makeover for massive Japan-targeted campaign

ESET researchers have detected a substantial new wave of the “Love you” malspam campaign, updated to target Japan and spread GandCrab 5.1 The post “Love you” malspam gets a makeover for massive Japan-targeted campaign appeared first on WeLiveSecurity

Exposed! Facebook pays teenagers to install app that harvests personal data

Reading Time: ~4 min. Like many technology companies, Webroot is constantly on the hunt for a diverse pool of engineering and technical cybersecurity talent. According to Jon Oltsik, senior principal analyst with Enterprise Security Group, a cybersecurity skills deficit holds the top position for problematic skills in ESG’s annual survey of IT professionals. In fact, the […]

Privilege escalation vulnerability uncovered in Microsoft Exchange
Firefox makes it easier for users to dodge ad-trackers
It’s mop-up time for WebStresser DDoS-for-hire users
Scammers steal social media videos to wring hearts and wallets

LinuxSecurity.com: New mozilla-firefox packages are available for 14.2 and -current to fix security issues.

LinuxSecurity.com: Security fix for CVE-2019-6706.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

You think election meddling is bad now? Buckle up for 2020, US intel chief tells Congress
And it’s go, go, go for class-action lawsuits against Equifax after 148m personal records spilled in that mega-hack
Japan to Hunt Down Citizens’ Insecure IoT Devices
2019 and Beyond: The (Expanded) RSAC Advisory Board Weighs in on What’s Next: Pt. 2
Judge! snuffs! Yahoo!’s attempt! to! settle! 2013! megahack! class-action!
Feds Dismantle Dark Web Credentials Market
Mozilla Firefox 65 Ups the Ante on Privacy with Anti-Tracking Efforts

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Apple takes Group FaceTime offline after discovery of spying bug

The company is rushing to fix a glitch that may let other iPhone users hear and see you – before you answer the call The post Apple takes Group FaceTime offline after discovery of spying bug appeared first on WeLiveSecurity

Hey boffin, take a walk on the wild side: Stuffy academics need to let out their inner black hat
Apple Disables Group FaceTime Following Major Privacy Glitch
Apple scrambles to fix FaceTime eavesdropping bug
Singapore fingers deported fraudster for leak of list of thousands of HIV+ people

Reading Time: ~4 min. It’ll cost you a buck. Just like everyone else’s. The use of a Social Security Number (SSN) as unique identifiers has long been a contentious subject. SSNs were never intended to be used for identification, and their ubiquitous abuse for identification and authentication has lead me to call them “Social Insecurity […]

Hear me out! Thousands tell UK taxman to wipe their voice IDs

Even so, the database has grown to seven million voiceprints amid a controversy that puts the spotlight on the privacy implications of the collection of biometric information The post Hear me out! Thousands tell UK taxman to wipe their voice IDs appeared first on WeLiveSecurity

Japanese government will try to hack its citizens’ IOT devices