Menu

Latest articles

LinuxSecurity.com: An update that solves 10 vulnerabilities and has two fixes is now available.

Emirates dinged for slipshod online data privacy practices
What to Do When Msvcp140.dll Goes Missing in Windows
Cryptocurrency miners go nuclear, RSA blunder, Winner back in court, and plenty more
Hackers crack Final Fantasy XV Windows edition before its launch
Brit semiconductor tech ended up in Chinese naval railgun – report
GitHub was hit by the most powerful DDoS attack in history
The Pirate Bay suffers 40% traffic drop after domain ban in Netherlands
Global police test their cyber-chops in simulated IoT attack

More than three dozen cybercrime and digital forensics experts from 23 countries have investigated a simulated attack on a bank that had been carried out through an IoT device. The post Global police test their cyber-chops in simulated IoT attack appeared first on WeLiveSecurity

Terrorist social media posts should be removed within an hour, says EC
World’s largest DDoS attack thwarted in minutes
Bill Gates: Cryptocurrencies killing people in “fairly direct way”
Web Application Firewalls: Choosing the Right WAF for Server Security
Signal and Telegram messaging services offline for some hours
A Sneak Peek at the New NIST Cybersecurity Framework
Scammers spoof Office 365, DocuSign and others | Salted Hash Ep 21
Spring break! Critical vuln in Pivotal framework’s Data parts plugged
Cryptomining Gold Rush: One Gang Rakes In $7M Over 6 Months

LinuxSecurity.com: The package mkinitcpio-busybox before version 1.28.1-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package busybox before version 1.28.1-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: It was discovered that there was a potential XML External Entity (XXE) attack in libjgraphx-java, a diagramming library for Java applications. For Debian 7 “Wheezy”, this issue has been fixed in libjgraphx-java version

Biohacking your body can be really painful… and not hugely useful
Stolen: 600 Bitcoin Mining Computers in Iceland & 153 from Malaysia

security update

security update

security update

security update

security update

LinuxSecurity.com: Fix: Multiple vulnerabilities in RubyGems https://www.ruby- lang.org/en/news/2018/02/17/multiple-vulnerabilities-in-rubygems/

US Air Force Hacked for Good at HackerOne’s Bug Bounty Event
DDoS Attacks Now Launched with Monero Ransom Notes
Mozilla Firefox 59 Web Browser Promises New Privacy and Security Features
5 Linux Tools to Help Recover Data from Corrupted Drives

LinuxSecurity.com: The security update announced as DSA-4120-1 caused regressions on the powerpc kernel architecture (random programs segfault, data corruption). Updated packages are now available to correct this issue.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

42 Android Models infected with data stealing banking trojan

LinuxSecurity.com: Several vulnerabilities have been discovered in the Dovecot email server. The Common Vulnerabilities and Exposures project identifies the following issues:

LinuxSecurity.com: Multiple heap buffer over reads were discovered in freexl, a library to read Microsoft Excel spreadsheets, which could result in denial of service.

Equifax Adds 2.4 Million More People to List of Those Impacted By 2017 Breach
In Wake of ‘Biggest-Ever’ DDoS Attack, Experts Say Brace For More
Malware steals data directly from the device to hack Facebook account
RedDrop nasty infects Androids via adult links, records sound, and fires off premium-rate texts
US Navy gives Lockheed Martin $150m big frickin’ laser cannon contract
GitHub knocked briefly offline by biggest DDoS attack ever

At its peak, inbound traffic reached a staggering 1.35 terabits per second (Tbps), outflanking the previously record-setting assault of 1 Tbps at French web hosting provider OVH in September 2016. The post GitHub knocked briefly offline by biggest DDoS attack ever appeared first on WeLiveSecurity

Beware; rTorrent Client Exploited to Mine Monero Cryptocurrency
Chi*a ce*sors the letter ‘N’ from the i*ter*et for a day
20,000 web certificate private keys outed in “business tiff”
Facebook’s see yourself bald app: extreme hackers or extreme hoax?
The rise of AI needs to be controlled, report warns

The experts urge policy-makers to work closely with technical researchers, computer scientists and the cybersecurity community to investigate, understand and prepare for possible malicious uses of AI. The post The rise of AI needs to be controlled, report warns appeared first on WeLiveSecurity

LinuxSecurity.com: Several vulnerabilities have been discovered in SimpleSAMLphp, a framework for authentication, primarily via the SAML protocol. CVE-2016-9814 & CVE-2016-9955

Apple issues advice on how to spot App Store and iTunes phishing scams
Can emojis save you from a terrible password?
Don’t fall for fake iTunes and App Store messages
Memcached servers can be hijacked for massive DDoS attacks
How to start analyzing the security of your IoT devices

The big challenge with IoT devices is that they are all different: Each manufacturer has its own firmware, uses different protocols, and designs its own architecture. So, the first step before carrying out any analysis is to understand the architecture, find out what components are involved, and how they interact and communicate among themselves. The […]

Train to become an expert cyber crime fighter

The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Thanatos Ransomware Causing Major Damage for Victims A new ransomware variant has recently appeared and is proving […]

Github hit by 1.35 Tbps DDoS attack; the largest ever

security update

LinuxSecurity.com: New ntp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Microsoft lobs Skylake Spectre microcode fixes out through its Windows

LinuxSecurity.com: New dhcp packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues.

Bug in HP Remote Management Tool Leaves Servers Open to Attack
HTTPS cert flingers Trustico, SSL Direct go TITSUP after website security blunder blabbed

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Equifax reveals additional 2.4 million users impacted from 2017 breach
Machine learning self defence: how to not shoot yourself in the foot
Sophisticated RedDrop Malware Targets Android Phones

LinuxSecurity.com: An update for quagga is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: This is the One-Year notification for the retirement of Red Hat Enterprise Linux 6.4 Advanced Mission Critical (AMC). This notification applies only to those customers subscribed to the Advanced Mission Critical (AMC) channel for Red Hat Enterprise Linux 6.4.

LinuxSecurity.com: – Update to 2.7.0 Release notes: https://tls.mbed.org/tech- updates/releases/mbedtls-2.7.0-2.1.10-and-1.3.22-released Security Advisory: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security- advisory-2018-01

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Hackers can compromise Memcached Servers for DDoS attacks
Ad Network Circumvents Ad-Blocking Tools To Run In-Browser Cryptojacker Scripts
Smashing Security #067: Cyber stalking and gun control
Equifax finds ANOTHER 2.4 million Americans hit by breach
Personal Data of 21,426 US Marine Force Reserve Personnel Leaked
Equifax peeks under couch, finds 2.4 million more folk hit by breach
Mobile World Congress: Introducing 5G

If we look back at previous incarnations of mobile networks, 1G, 2G and so on, there have been major changes to the technology. The next generation, 5G, delivers, greater speed and lower latency, but also has the advantage of being able to connect many more devices concurrently. The post Mobile World Congress: Introducing 5G appeared […]

1 in 50 publicly readable Amazon buckets are also writable – and that’s a data disaster waiting to happen
27% of under-18s have been sexted, and it’s on the rise
Russia behind compromise of seven states’ voter registration systems
Microsoft still refusing to hand over private email data stored in Ireland
Why Blockchain Will Serve New IT Purposes in 2018
Right to be Forgotten requests stagnate, Google refuses most anyway