Menu

Latest articles

Risk Level: Very Low. Type: Trojan, Worm.

Blockchain Wallet CoinPouch Hacked; Verge Coins Stolen
SAML Post-Intrusion Attack Mirrors ‘Golden Ticket’
3 simple tips to stay off the hook this phishing season
Seek ‘passion’ and tech skills will follow, say recruiting security chiefs
New reality in European banking looming large: the lowdown

At the heart of the regulation is the requirement for banks to allow licensed third-party providers (TPPs) of financial services to access securely their customer-account data, as long as the customer has given their prior consent. The post New reality in European banking looming large: the lowdown appeared first on WeLiveSecurity

UK emergency crews get 4G smartmobes as monkeys attempt to emerge from Reg’s butt
EU’s data protection bods join the party to investigate Uber breach
Cloud storage for password managers – are you for or against?
‘Treat infosec fails like plane crashes’ – but hopefully with less death and twisted metal
Busy Browsers attract Black Friday Burglars

Just as in past decades when cash drawers and bank vaults were targeted for theft, today’s e-shops and online banks have fallen under the scope of cybercriminals. Their “digital-focus” is just an evolutionary step beyond robbing stagecoaches in the Wild West, and banks in the 20th century. The post Busy Browsers attract Black Friday Burglars […]

Linus Torvalds on security: ‘Do no harm, don’t break users’
Firefox to warn users who visit p0wned sites

LinuxSecurity.com: An update that solves three vulnerabilities and has two An update that solves three vulnerabilities and has two An update that solves three vulnerabilities and has two fixes is now available. fixes is now available.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in impersonation of Kerberos services, denial of service, sandbox bypass or HTTP header injection.

LinuxSecurity.com: Two vulnerabilities were discovered in the Open Ticket Request System which could result in disclosure of database credentials or the execution of arbitrary shell commands by logged-in agents.

Alleged HBO hacker identified, charged and indicted

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available.

security update

Firefox to collaborate with HaveIBeenPwned to alert users on data breach

LinuxSecurity.com: **Update** – Fixed chain-build – Remove hard dependency of bash-completion from fedpkg **rpkg** – Ignore TestModulesCli if openidc-client is unavailable (cqi) – Port mbs-build to rpkg (mprahl) – Add .vscode to .gitignore (mprahl) – Fix TestPatch.test_rediff in order to run with old version of mock (cqi) – Allow to specify alternative Copr config file […]

LinuxSecurity.com: **Update** – Fixed chain-build – Remove hard dependency of bash-completion from fedpkg **rpkg** – Ignore TestModulesCli if openidc-client is unavailable (cqi) – Port mbs-build to rpkg (mprahl) – Add .vscode to .gitignore (mprahl) – Fix TestPatch.test_rediff in order to run with old version of mock (cqi) – Allow to specify alternative Copr config file […]

Tether hits back after $31m cryptocurrency hack

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: update to 9.5.10, per release notes http://www.postgresql.org/docs/9.5/static/release-9-5-10.html

LinuxSecurity.com: Tobias Schneider discovered that libspring-ldap-java, a Java library for Spring-based applications using the Lightweight Directory Access Protocol, would under some circumstances allow authentication with a correct username but an arbitrary password.

LinuxSecurity.com: update to 9.6.6 per release notes: https://www.postgresql.org/docs/9.6/static/release-9-6-6.html

LinuxSecurity.com: An update that solves three vulnerabilities and has two An update that solves three vulnerabilities and has two An update that solves three vulnerabilities and has two fixes is now available. fixes is now available.

Tips for Making Your Business Secure from Digital Crimes
Royal Navy destroyer leaves Middle East due to propeller problems
‘Data is the new oil’: F-Secure man on cartels, disinformation and IoT
Worries over Intel’s Mangement Engine grow after new flaws found
Androids caught secretly reporting location data regardless of opt-out
World’s top websites record all your browsing movements
Mr. Robot eps3.6_fredrick+tanya.chk – the security review
Smartphone adoption among older Americans continues growth spurt

Some three-quarters of users up to 34 years of age reported that they “definitely” or “probably” use their phone too much. Almost half (47 percent) of all ages said they make a conscious effort to pare back their mobile phone time, most commonly by keeping their devices in their bag or pocket or by switching […]

US indicts alleged culprit of HBO hack-and-extort campaign

Between approximately July 23 and 29, Mesri reportedly engaged in his blackmail campaign. After the TV network didn’t pay the required $6 million in digital cryptocurrency, he began leaking portions of the stolen data on July 30. The post US indicts alleged culprit of HBO hack-and-extort campaign appeared first on WeLiveSecurity

To fix Intel’s firmware fiasco, wait for Christmas Eve or 2018
Samba needs two patches, unless you’re happy for SMB servers to dance for evildoers
Devs working to stop Go math error bugging crypto software
Smashing Security podcast #053: Game of Thrones, a major Amazon cloud leak, and web tracking gone crazy

LinuxSecurity.com: An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

security update

security update

3 Cybersecurity Predictions for 2018
What we know about Uber (so far, anyway) [VIDEO]
HP to Patch Bug Impacting 50 Enterprise Printer Models

Risk Level: Very Low. Type: Trojan.

Black Friday shopping? “A little delay goes a long way!”
Permissionless data slurping: Why Google’s latest bombshell matters
You’re such a goober, Uber: UK regulators blast hushed breach
Google and Twitter turn their backs on Russian media over fake news
Uber Paid Hackers $100k to Hide Massive Theft of 75M Accounts
Possible cut to British F-35 order considered before Parliament
Girls Inc. in the spotlight: Nonprofit Pitch Fest contest grand prize winner

Girls Inc. of San Diego County was founded 50 years ago as a local affiliate of the national Girls Inc. The national organization was started as the Girls Club of America more than 150 years ago, to help young women who had migrated from rural communities in search of job opportunities. The post Girls Inc. […]

Chromebook exploit earns researcher second $100k bounty
Apple served with warrant for Texas mass killer’s iCloud data
Loake Shoes admits: We’ve fallen victim to cybercrims
Once more unto the breach: El Reg has a go at crisis management
Crypto-jackers enlist Google Tag Manager to smuggle alt-coin miners
Apple: Sure, we banned VPN iOS apps in China, but, um, er, art!
Uber Reveals 2016 Breach of 57 Million User Accounts

LinuxSecurity.com: Change default COPR URL route from http://copr.fedoraproject.org to https://copr.fedorainfracloud.org

LinuxSecurity.com: Fixes a command injection vulnerability (CVE-2008-7319)

Iranian military hacker fingered for ‘Game of p0wns’ HBO leak
Microsoft says Win 8/10’s weak randomisation is ‘working as intended’
Wait, did Oracle tip off world to Google’s creepy always-on location tracking in Android?
Uber suffered massive data breach, then paid hackers to keep quiet
Google collects Android location data even if location service is off
Uber: Hackers stole 57m passengers, drivers’ info. We also bribed the thieves $100k to STFU
Uber paid hackers $100,000 to keep data breach quiet
Sacramento Regional Transit System in California Held for $7,000 Ransom
Intel Patches CPU Bugs Impacting Millions of PCs, Servers
Ex-Facebook privacy manager dishes the dirt on your data
US Senate takes aim at “warrantless surveillance”
GitHub starts scanning millions of projects for insecure components
Hackers steal $30 million worth of cryptocurrency in Tether hack
New campaigns spread banking malware through Google Play

For a user, it can be difficult to figure out whether an app is malicious. First off it is always good only to install applications from the Google Play store, since most malware is still mainly spread through alternative stores. The post New campaigns spread banking malware through Google Play appeared first on WeLiveSecurity

Germany bans sale, distribution and possession of kids’ smartwatches
National Cyber Security Centre boss: For the love of $DEITY, use 2FA on your emails, peeps
Cybersecurity for journalists and the news media

In journalism, having good contacts is key and this is true when it comes to defending your digital assets. The following are some sources – of information and, possibly, assistance – that you might want to cultivate. The post Cybersecurity for journalists and the news media appeared first on WeLiveSecurity

Scammed via Western Union? Claim your share of a $586 million refund now!
Linus Torvalds: ‘I don’t trust security people to do sane things’
White House Releases New Charter for Using, Disclosing Security Vulnerabilities
Captain Crunch aka John Draper banned from DefCon for sexual misconduct
Only…zero days left until the holiday shopping season!

The holidays are a time when people purchase gifts for their friends, families, and yes, even for themselves. Increasingly, children are using and accessing more and more digital devices — making it important for everyone to work together to secure these devices. The post Only…zero days left until the holiday shopping season! appeared first on […]

Working remotely? It only takes a moment on a free WiFi connection for a hacker to access to your personal accounts. While complimentary WiFi is convenient, protecting your connection with a VPN is the best way stay safe on public networks, keeping your data and browsing history secure.   What is a VPN? VPN stands for […]

Vigilante or bug hunter?
Patch on way ‘this week’ for HP printer vulns

LinuxSecurity.com: New libtiff packages are available for Slackware 14.2 and -current to fix security issues.

Windows 8 broke Microsoft’s memory randomisation

security update

Intel finds critical holes in secret Management Engine hidden in tons of desktop, server chipsets
BankBot banking malware found in flashlight and solitaire apps
Cops jam a warrant into Apple to make it cough up Texas mass killer’s iPhone, iCloud files