Menu

Latest articles

Hacker leaks Snapchat’s source code on Github
Anonymous hackers vow to expose Q-Anon
How SELinux helps mitigate risk while facilitating compliance
“Attack” on FCC over net neutrality was legitimate traffic, report says

LinuxSecurity.com: The following vulnerability was discovered in wpa_supplicant. CVE-2018-14526: | An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0

DARPA takes aim at deepfake forgeries
Google Bug Hunter Urges Apple to Change its iOS Security Culture
Fortnite for Android goes “off market” – is that good or bad? [VIDEO]
IT Leaders Believe AI is a ‘Silver Bullet’ for Threats
Healthcare Firm Exposes Data on 2m+ Mexicans
26.5 million Comcast Xfinity customers had their partial home addresses and SSNs exposed by sloppy security
How evil JavaScript helps attackers tag possible victims – and gives away their intent
WhatsApp security snafu ‘could allow message manipulation’
Should I infect this PC, wonders malware. Let me ask my neural net…
Revealed: El Reg blew lid off Meltdown CPU bug before Intel told US govt – and how bitter tech rivals teamed up
If for some reason you’re still using TKIP crypto on your Wi-Fi, ditch it – Linux, Android world bug collides with it
Microsoft to hackers: Finding Hyper-V bugs is hard. Change my mind. PS: Here’s a head start…

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that solves two vulnerabilities and has two fixes is now available.

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

Stress, bad workplace cultures are still driving security folk to drink
Smashing Security #090: Fortnite for Android, and the FCC’s DDoS BS
Google Project Zero boss: Blockchain won’t solve your security woes – but partying just might
Black Hat 2018: Mixed Signal Microcontrollers Open to Side-Channel Attacks
Black Hat 2018: Google’s Tabriz Talks Complex Security Landscapes

LinuxSecurity.com: The package linux-hardened before version 4.17.11.a-1 is vulnerable to denial of service.

LinuxSecurity.com: The package linux-zen before version 4.17.11-1 is vulnerable to denial of service.

LinuxSecurity.com: The package linux-lts before version 4.14.59-1 is vulnerable to denial of service.

LinuxSecurity.com: The package linux before version 4.17.11-1 is vulnerable to denial of service.

LinuxSecurity.com: Henning Westerholt discovered a flaw related to the To header processing in kamailio, a very fast, dynamic and configurable SIP server. Missing input validation in the build_res_buf_from_sip_req function could result in denial of service and potentially the execution of arbitrary code.

My Little Pony animator jailed for possessing 60k child abuse images
‘Chaff Bug’ Defense Rolls Out Shiny Objects for Attackers to Find

LinuxSecurity.com: New upstream version 0.7alpha. Fixes CVE-2018-14679 libmspack: off-by-one error in the CHM PMGI/PMGL chunk number validity checks

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Threatlist: Manufacturing, a Top Target for Espionage
Japanese dark-web drug dealers are so polite, they’ll offer ‘a refund’ if you’re not satisfied
Interviewing ESET’s experts about the Web’s journey so far – part 3

All good things come to an end, and we’re rounding off our series of interviews to mark the 27th anniversary since computer scientist Tim Berners-Lee publicly announced the World Wide Web project The post Interviewing ESET’s experts about the Web’s journey so far – part 3 appeared first on WeLiveSecurity

Facebook wants to be the future of online banking
5 Ways the Cloud is Beneficial to Businesses
iPhone Chip Maker Firm Attacked with Computer Virus
Windows 10 May Not Be Free for Businesses Anymore
iKeyMonitor: A parental control app ensuring safety of your child
Safe as houses: 5 security measures adopted by cryptocurrency exchanges
HP Bug Bounty Program: Hack HP Printers & Earn Up To $10,000
Snapchat’s source code leaked out, and was published on GitHub
Patrick Wardle on Breaking and Bypassing MacOS Firewalls
Software bugs put nearly 100 million health records at risk of exposure

The slew of vulnerabilities – since patched – were found without the use of automated testing tools The post Software bugs put nearly 100 million health records at risk of exposure appeared first on WeLiveSecurity

Could deliberately adding security bugs make software more secure?

LinuxSecurity.com: The security update for slurm-llnl introduced a regression in the fix for CVE-2018-10995 which broke accounting. For Debian 8 “Jessie”, this problem has been fixed in version

Profit-strapped Symantec pulls employee share scheme
SingHealth Attack Potentially State-Linked
Linux kernel bug: TCP flaw lets remote attackers stall devices with tiny DoS attack
Update Mechanism Flaws Allow Remote Attacks on UEFI Firmware
Twitter CEO says they’re taking no action against InfoWars and Alex Jones
Podcast: enSilo CEO on Black Hat USA 2018 Top Trends
An inside look at hybrid Office 365 phishing attacks | Salted Hash Ep 41
Hey, you know what a popular medical record system doesn’t need? 23 security vulnerabilities
Funnily enough, no, infosec bods aren’t mad keen on W. Virginia’s vote-by-phone-app plan
Fresh Approach to WiFi Cracking Uses Packet-Sniffing

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves 5 vulnerabilities and has two fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

security update

Cybersecurity Certifications: Why They Matter and How to Know Which Ones To Pursue
Cracking the passwords of some WPA2 Wi-Fi networks just got easier
Microsoft Adds Direct Trust for Let’s Encrypt
Pentagon Bans Soldiers from Using GPS Apps and Devices
Batten down the ports: Linux networking bug SegmentSmack could remotely crash systems
Update MikroTik routers – 170,000 devices hit by cryptocurrency malware
Interviewing ESET’s experts about the Web’s journey so far – part 2

Today, we continue with our series of conversations with ESET’s security pros to hear what they have to say about the evolution of the World Wide Web since it was publicly announced 27 years ago The post Interviewing ESET’s experts about the Web’s journey so far – part 2 appeared first on WeLiveSecurity

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Apple chip supplier blames WannaCryptor variant for plant shutdowns

The malware outbreak has even prompted concerns of delays in the shipments of the next wave of iPhones The post Apple chip supplier blames WannaCryptor variant for plant shutdowns appeared first on WeLiveSecurity

Threatlist: Financial Services Firms Lag in Patching Habits
How Bitcoin and the Dark Web hide SamSam in plain sight
iPhone chipmaker blames ransomware for factory shutdowns
Rights groups challenge UK cops over refusal to hand over info on IMSI catchers
Mozilla faces resistance over DNS privacy test
Fortnite ditches Google Play – will it undermine Android security?
Bank on it: It’s either legal to port-scan someone without consent or it’s not, fumes researcher
Chipmaker TSMC Hit by Virus Outbreak
Privacy International Takes Police Phone ‘Hacking’ Case to IPC
Podcast: Black Hat USA 2018 Preview
No, Michael J Fox isn’t dead
What is a phishing kit? Watch this in-depth explainer | Salted Hash Ep 39
Top tip? Sprinkle bugs into your code to throw off robo-vuln scanners
Battle lines drawn over US mass surveillance as senators probe NSA’s bonfire of phone records
IBM, ATMs – WTF? Big Blue to probe cash machines, IoT, vehicles, etc in new security labs

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

BlackBerry claims it can do to ransomware what Apple did to its phones
Cracking the passwords of some WPA/WPA2 W-Fi networks just got easier
Fortnite Skips Google Play For Android Apps, Irking Security Experts
Ramnit Changes Shape with Widespread Black Botnet
Chip flinger TSMC warns ‘WannaCry’ outbreak will sting biz for $250m
Facebook cracks opens its bottle of Fizz – a carbonated TLS 1.3 lib

Reading Time: ~4 min.This week, I’ll be at Black Hat USA 2018 in Las Vegas. If you’ve ever been to Black Hat, then you know all about the flood of information and how hard it can be to take it all in. This year’s presentations will range from the newest trends in browser exploits, bots, […]