Menu

Latest articles

Facebook crushes 583 million fake accounts in 3 months

LinuxSecurity.com: New upstream bugfix release, includes security fix for CVE-2017-18266

Alexa, Siri and Google can be tricked by commands you can’t hear
StalinLocker ransomware: Put unlock code or say goodbye to your data
Last call for GDPR

With the deadline fast approaching SMBs are reminded of what is required to become compliant The post Last call for GDPR appeared first on WeLiveSecurity

CIA’s “Vault 7” mega-leak was an inside job, claims FBI
Hackers siphon hundreds of millions of pesos out of Mexican banks through shadow transactions
US Government Cybersecurity at a Crossroads
Airports Ill-Equipped to Deal with Major Cyber-Attacks
Blighty’s super-duper F-35B fighter jets are due to arrive in a few weeks
Rail Europe data breach lasted almost three months
Russian malware harvesting Telegram Desktop creds, chats

LinuxSecurity.com: New php packages are available for Slackware 14.0, 14.1, and 14.2 to fix security issues.

LinuxSecurity.com: New curl packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Oh, great, now there’s a SECOND remote Rowhammer exploit
DOJ convicts second bloke for helping malware go undetected

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has three fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Suspected member of The Dark Overlord hacking group arrested
Smashing Security #078: Hounds hunt hackers, too-human Google AI, and ethnic recognition tech – WTF?
Running Cisco DNA Center? Update right now to get rid of the static admin credential

LinuxSecurity.com: OSS-fuzz, assisted by Max Dymond, discovered that cURL, an URL transfer library, could be tricked into reading data beyond the end of a heap based buffer when parsing invalid headers in an RTSP response.

LinuxSecurity.com: It was discovered that there was an issue in the curl a command-line tool for downloading (eg.) data over HTTP. curl could have be tricked into reading data beyond the end of a heap

security update

Lawyers for Marcus Hutchins: His ‘I made malware’ jail phone call isn’t proper evidence
New Cryptominer Distributes XMRig in Aggressive Attacks

LinuxSecurity.com: Several security issues were fixed in PHP.

Former CIA engineer allegedly leaked Vault 7 documents to WikiLeaks
RedHat admins, patch now – don’t let your servers get pwned!
EFAIL Opens Up Encrypted Email to Prying Eyes
Chili’s Doesn’t Leave Data Breach on the Back Burner
Securus lets cops perform real-time cellphone tracking of US Mobile Users
Google to require Android device-makers to roll out OS security patches regularly

The move is intended to help address the mobile platform’s perennial problem – that many manufacturers of Android-powered devices are slow to get software updates out the door The post Google to require Android device-makers to roll out OS security patches regularly appeared first on WeLiveSecurity

WannaCry hero charged with creating Kronos banking malware
Seven out of ten see criminal hacking as big risk to health, safety, prosperity

Recent survey shows that adults in the US view computer hacking as a major threat to their quality of life The post Seven out of ten see criminal hacking as big risk to health, safety, prosperity appeared first on WeLiveSecurity

Chili’s PoS breach: Want some credit card theft with your baby back ribs?
Mexican Banks Lose Millions in SWIFT-like Attacks
Chili’s Suffers Data Breach
Major #eFail Vulnerability Exposes PGP Encrypted Email — UPDATED
What an Apple phishing attack looks like | Salted Hash Ep 32
Four-million Facebook users’ data wide open for anyone to download for years
Facebook can’t wiggle out of facial recognition lawsuit, judge says
Serious XSS vulnerability discovered in Signal
Kaspersky Lab plays Swiss gambit in attempt to assuage Russian spying fears
Mining apps? We’re cool so long as they admit to it, says Canonical
UPnP joins the ‘just turn it off on consumer devices, already’ club
Red Hat admin? Get off Twitter and patch this DHCP client bug
Ex-CIA man named as suspect in Vault 7 leak

security update

Indian Cricket Board Exposes Personal Data of Thousands of Players
Julian Assange said to have racked up $5m security bill for Ecuador

Reading Time: ~2 min.Smartphone apps make life easier, more productive, and more entertaining. But can you trust every app you come across? Malicious mobile apps create easy access to your devices for Android and iOS malware to wreak havoc. And there are many untrusted and potentially dangerous apps lurking around in app stores determined to […]

Sensitive myPersonality App Data of Millions of Facebook Users Exposed
Attackers Use UPnP to Sidestep DDoS Defenses
Adobe Doles Out Second Round of Higher Priority Patches
Researchers reveal flaws that may expose encrypted emails to prying eyes

A team of academics says that, if exploited, the vulnerabilities can reveal the plain text of encrypted emails, including those sent years ago The post Researchers reveal flaws that may expose encrypted emails to prying eyes appeared first on WeLiveSecurity

LinuxSecurity.com: Several security issues were fixed in PHP.

Kaspersky Lab’s move from Russia to Switzerland fails to save it from Dutch oven
Get a hands-on, inside look at the dark web | Salted Hash Ep 25
A tale of two zero-days

Double zero-day vulnerabilities fused into one. A mysterious sample enables attackers to execute arbitrary code with the highest privileges on intended targets The post A tale of two zero-days appeared first on WeLiveSecurity

Facebook app left 3 million users’ data exposed for four years
Police dog sniffs out USB drive to snare school hacker
The next Android version’s killer feature? Security patches
White Hat Spoofs 2FA, Sends User to Phishing Page
NCA: Organized Cybercrime Continues to Rise
The EFAIL vulnerability – why it’s OK to keep on using email
Prison phone service can expose the location of anyone with a phone
Zero arrests, 2 correct matches, no criminals: London cops’ facial recog tech slammed
Can AI help bridge the IT security skills gap? | Salted Hash Ep 27
Wanna break Microsoft’s Edge browser? Google’s explained how
How could the Facebook data slurping scandal get worse? Glad you asked

LinuxSecurity.com: A vulnerability has been found in mpv that may allow a remote attacker to execute arbitrary code.

LinuxSecurity.com: The package firefox before version 60.0-1 is vulnerable to multiple issues including arbitrary code execution, same-origin policy bypass, access restriction bypass, content spoofing, denial of service, information disclosure and sandbox escape.

LinuxSecurity.com: The package webkit2gtk before version 2.20.2-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package llpp before version 27-2 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: Fabian Vogt discovered that incorrect permission handling in the PAM module of the KDE Wallet could allow an unprivileged local user to gain ownership of arbitrary files.

S/MIME artists: EFAIL email app flaws menace PGP-encrypted chats
Bytecoin cryptocurrency mining malware found in Ubuntu Snap Store
GDPR Phishing Scam Targets Apple Accounts, Financial Data
How many ways can a PDF mess up your PC? 47 in this Adobe update alone

LinuxSecurity.com: Security fix for CVE-2018-10380

Samsung Patches Six Critical Bugs in Flagship Handsets

LinuxSecurity.com: Security fix for CVE-2018-10380

Despite Efail, the sky is not falling
Britain to slash F-35 orders? Erm, no, scoffs Lockheed UK boss
Uninstall PGP? PGP and S/MIME protected emails prone to exposure
Navy names new attack sub HMS Agincourt
Wah, encryption makes policing hard, cries UK’s National Crime Agency
Nest turns up the temperature on password reusers
Denmark’s largest train operator hit by service crippling DDoS attack
Is Google’s Duplex AI helpful or plain creepy?
Remote code execution bug found in GPON routers, but how bad is it really?
WannaCryptor: The curious tale of a ravenous cryptoworm

Do you still remember how WannaCryptor ran its – winding – course? It was a tale that revealed a number of intriguing plot lines amid the ransomworm’s numerous twists and turns. The post WannaCryptor: The curious tale of a ravenous cryptoworm appeared first on WeLiveSecurity

FBI: Reported Internet Crimes Topped $1.4 Billion Last Year
Open Source AI For Everyone: Three Projects to Know
2 million lines of source code left exposed by phone company EE
Critical vulnerabilities in PGP/GPG and S/MIME email encryption, warn researchers
PGP and S/MIME decryptors can leak plaintext from emails, says infosec Professor
Family Planning office warns customers private parts may be exposed