Menu

Latest articles

Starbucks Wi-Fi hijacked customers’ laptops to mine cryptocoins
Permissions Flaw Found on Azure AD Connect

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

85 Credential-Stealing Apps Found on Google Play Store
19-Year-Old ROBOT Flaw Resurfaces to Haunt Popular Websites
Mr. Robot season 3 finale: shutdown -r
Fox-IT reveals hackers hijacked its DNS records, spied on clients’ files
Mirai botnet authors plead guilty
Cybersecurity Trends 2018: The costs of connection

To help the reader navigate through the maze of such threats, ESET’s thought leaders have zeroed in on several areas that top the priority list in our exercise in looking forward. The post Cybersecurity Trends 2018: The costs of connection appeared first on WeLiveSecurity

Bitfinex cryptocurrency exchange is back up after repeated DDoS
The Mirai botnet: three men plead guilty after weaponizing the Internet of Things

LinuxSecurity.com: An update for go-toolset-7 and go-toolset-7-golang is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

UK.gov delays biometrics strategy again – but cops will STILL USE the tech
NIST Releases New Cybersecurity Framework Draft
Smashing Security podcast #057: Mikko – live from the sauna – talks Bitcoin security

LinuxSecurity.com: The package quagga before version 1.2.2-1 is vulnerable to denial of service.

LinuxSecurity.com: The package qt5-webengine before version 5.10.0-1 is vulnerable to multiple issues including arbitrary code execution, cross-site scripting, access restriction bypass, content spoofing and information disclosure.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

OK, OK, MIRA-I DID IT: Botnet-building compsci kid comes clean

LinuxSecurity.com: An update that solves three vulnerabilities and has three An update that solves three vulnerabilities and has three An update that solves three vulnerabilities and has three fixes is now available. fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

Hackers behind Mirai botnet & DYN DDoS attacks plead guilty
19-Year-Old TLS Vulnerability Weakens Modern Website Crypto

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer are prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office Outlook is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to an information-disclosure vulnerability; fixes are available.

LinuxSecurity.com: An update for eap7-jboss-ec2-eap is now available for Red Hat JBoss Enterprise Application Platform 7.1 for Red Hat Enterprise Linux 6 and Red Hat JBoss Enterprise Application Platform 7.1 for Red Hat Enterprise Linux 7.

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 7.1 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 7.1 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: A regression was added by the patch introduced in version 0.5.0-2+deb7u2 to fix CVE-2017-16927: xrdp-sesman started to segfault in libscp. For Debian 7 “Wheezy”, these problems have been fixed in version

LinuxSecurity.com: An update for rh-java-common-lucene5 is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for rh-java-common-lucene is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Fix to directory traversal attacks (CVE-2017-17042).

LinuxSecurity.com: Update to 2.1 —- Update to 2.0, Initial support for aarch64 images and associated SBCs

Break the Internet: a last ditch attempt to save net neutrality
Banker jailed for helping criminals who stole millions using Dridex malware
Netflix sparks privacy row after making fun of users of Twitter
Barclays employee sentenced for aiding Dridex money launderers
Massive Uber data scraping and secret servers exposed in Waymo suit
Memes: the explanation of nearly everything – including computer viruses

We still don’t have a solid scientific theory of memes; nonetheless, they already allow us to understand why certain things happen the way they do. Memes are “alive”; they reproduce, mutate, and evolve according to Darwinian laws. The post Memes: the explanation of nearly everything – including computer viruses appeared first on WeLiveSecurity

Apple plugs IoT HomeKit hole
File with 1.4 Billion Hacked and Leaked Passwords Found on the Dark Web
Newly Revealed Flaw in Intel Processors Allows Undetectable Malware
Australian airport hack was ‘a near miss’ says government’s cybersecurity expert
One per cent of all websites probably p0wned each year, say boffins
Up to ‘ONE BEEELLION’ vid-stream gawpers toil in crypto-coin mines
Put down the eggnog, it’s Patch Tuesday: Fix Windows boxes ASAP
Intel to slap hardware lock on Management Engine code to thwart downgrade attacks
I, Robot? Aiiiee, ROBOT! RSA TLS crypto attack pwns Facebook, PayPal, 27 of 100 top domains

Risk Level: Very Low. Type: Trojan.

Tenable’s response to folks upset at AWOL features: A 150-emails-a-minute spam storm
It’s time to patch your Microsoft and Adobe software again against vulnerabilities
What is the cyber kill chain?
Kaspersky dragged into US govt’s trashcan as weaponized blockchain agile devops mulled
Microsoft December Patch Tuesday Update Fixes 34 Bugs
Argy-bargy Argies barge into Starbucks Wi-Fi with alt-coin discharges

security update

Sophisticated ‘MoneyTaker’ group stole millions from Russian & US banks
New Spider Ransomware Comes With 96-Hour Deadline

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2017:3402

iOS jailbreak exploit published by Google
Bitfinex cryptocurrency exchange hit by massive DDoS attacks​
Ransom email scam from ‘hitman’ demands: pay up or die
Man apologizes after photo of ‘racist’ woman goes viral
Brrr! It’s a snow day and someone has pwned the chuffin’ school heating
Cryptocurrency in kilowatt hours: Counting the costs of anonymous transactions

The energy costs are not the only charges in a transaction: the bitcoin network itself levies a charge which, according to a blog from Valve, the gaming provider behind the Steam network, has skyrocketed from $0.20 in 2016 to $20 per transaction today The post Cryptocurrency in kilowatt hours: Counting the costs of anonymous transactions […]

Coinbase: don’t expect to trade your cryptocurrency at busy times
This Fidget spinner app is sending other apps data to Chinese server

It has been a turbulent year of devastating ransomware attacks (e.g. NotPetya) and gut-wrenching breaches (e.g. Equifax). Undoubtedly, the question on everyone’s mind is, “what’s in store for us in the New Year?” Webroot’s top 10 cybersecurity predictions for 2018 covers everything from ransomware and breaches to mobile, cryptocurrency, and government.We’ve grouped our predictions to […]

Spies are watching… on LinkedIn
Watch: How to Pick a Lock
Dyn Inc. DDoS anniversary, and the truth about the Reaper botnet

LinuxSecurity.com: New release (1:12.2.2-1), security fix for CVE-2017-16818

LinuxSecurity.com: Fix omapi SD leak (#1523547)

LinuxSecurity.com: * CVE-2017-1000256: libvirt: TLS certificate verification disabled for clients (bz #1503687) * Fix qemu image locking with shared disks (bz #1513447)

LinuxSecurity.com: Fix to directory traversal attacks (CVE-2017-17042).

LinuxSecurity.com: This is an update fixing denial of service (CVE-2017-16944). —- This is an update fixing use-after-free (CVE-2017-16943).

LinuxSecurity.com: Upstream annoucement: [WordPress 4.9.1 Security and Maintenance Release](https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and- maintenance-release/)

LinuxSecurity.com: Update to latest version. Contains security fixes for CVE-2017-15090, CVE-2017-15092, CVE-2017-15093 and CVE-2017-15094

LinuxSecurity.com: * Ver. 19.3.6.4

LinuxSecurity.com: The simplesamlphp package in wheezy is vulnerable to multiple attacks on authentication-related code, leading to unauthorized access and information disclosure.

LinuxSecurity.com: Several vulnerabilities have been discovered in the chromium web browser. CVE-2017-15407

Why bother cracking PCs? Spot o’ malware on PLCs… Done. Industrial control network pwned