Menu

Latest articles

US-CERT Warns of ASLR Implementation Flaw In Windows
It was El Reg wot won it: Bing banishes bogus Brit bank banner ad
Amazon Echo and Google Home patched against BlueBorne threat
US intelligence can’t break vulnerability hoarding habit
CENTCOM Says Massive Data Cache Found on Leaky Server is Benign
Germany slaps ban on kids’ smartwatches for being ‘secret spyware’
FCC: robocalls can go get BLOCKED
Android Flaw Lets Attackers Capture Screen and Record Audio
Android malware found in hundreds of music player apps on Play Store
Amazon to fix Key home security vulnerability
Kids’ smartwatches banned in Germany over spying concerns

German parents are being told to destroy smartwatches they have bought for their children after the country’s telecoms regulator put a blanket ban in place to prevent sale of the devices, amid growing privacy concerns. The post Kids’ smartwatches banned in Germany over spying concerns appeared first on WeLiveSecurity

Matrix Banker malware spreads to multiple industries | Salted Hash Ep 7
The First Threatpost Alumni Podcast
UK’s ICO issues stark reminder of backlash for privacy invasion

The Information Commissioner’s Office (ICO) in the United Kingdom has issued a stark reminder and straight-to-the-point warning for all employees who might be tempted to snoop on others’ personal data. The post UK’s ICO issues stark reminder of backlash for privacy invasion appeared first on WeLiveSecurity

LinuxSecurity.com: A security update for .NET Core on RHEL is now available. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Container ship loading plans are ‘easily hackable’
Is your business ready for the Holiday Season?

Unfortunately, as with every opportunity, there are people who want to benefit from your success without putting in the hard work. Cybercriminals will view the increase in traffic and spending as opportunities to make extra money. The post Is your business ready for the Holiday Season? appeared first on WeLiveSecurity

It’s 2017, and command injection is still the top threat to web apps
DNS resolver 9.9.9.9 will check requests against IBM threat database
F5 DROWNing, not waving, in crypto fail
User experience test tools: a privacy accident waiting to happen
Some ‘security people are f*cking morons’ says Linus Torvalds
A banking trojan that steals Gmail, Facebook, Twitter and Yahoo Password

LinuxSecurity.com: A use-after-free vulnerability was discovered in XML::LibXML, a Perl interface to the libxml2 library, allowing an attacker to execute arbitrary code by controlling the arguments to a replaceChild() call.

LinuxSecurity.com: Jakub Wilk reported a heap-based buffer overflow vulnerability in procmail’s formail utility when processing specially-crafted email headers. A remote attacker could use this flaw to cause formail to crash, resulting in a denial of service or data loss.

security update

security update

security update

YouTube terminated its own channel “Citizentube” for multiple or severe violations
Misconfigured Amazon S3 Buckets Exposed US Military’s Social Media Spying Campaign
Researchers demonstrate Amazon Key system can be hacked
Multiple Vulnerabilities in LibXL Library Open Door to RCE Attacks
Germany bans kids smartwatches, asks parents to destroy them

security update

security update

Massive US military social media spying archive left wide open in AWS S3 buckets
Amazon Promises Fix to Stop Key Service Hack
Skype faces fine after refusing to allow eavesdropping
Digital certs authority StartCom to shut up shop

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Twitter gets tough on white supremacists with new policy
For goodness sake, stop the plod using facial recog, London mayor told
McAfee’s ClickProtect Apparently Infected Devices with Banking Malware
Lloyds’ Avios Reward credit cardholders report fraudulent activity
Kaspersky Investigators Reveal How NSA Hacking Tools Were Stolen
Bug that deleted $300m could have been fixed months ago
KeePass – a password manager that’s cloud-less (but complex)
One-third of internet pounded by DoS attacks

Simple DoS attacks, which are a one-on-one affair, have been all but supplanted by DDoS attacks. The latter involve concerted campaigns from armies of devices conscripted into botnets which, as if lined up and marching in lockstep, aim to knock the unlucky target offline. The post One-third of internet pounded by DoS attacks appeared first […]

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. Brothers Printers Vulnerable to Major Exploit Researchers have discovered an exploit in several Brothers printer models […]

Fake news ‘as a service’ booming among cybercrooks

LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.

LinuxSecurity.com: New libplist packages are available for Slackware 14.2 and -current to fix security issues.

Mr. Robot eps3.5_kill-process.inc – the security review

LinuxSecurity.com: An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Kaspersky: Clumsy NSA leak snoop’s PC was packed with malware
Parity: The bug that put $169m of Ethereum on ice? Yeah, it was on the todo list for months
Oracle Issues Emergency Patches for ‘JoltandBleed’ Vulnerabilities

LinuxSecurity.com: Rod Widdowson of Steading System Software LLP discovered a coding error in the OpenSAML library, causing the DynamicMetadataProvider class to fail configuring itself with the filters provided and omitting whatever checks they are intended to perform.

LinuxSecurity.com: Rod Widdowson of Steading System Software LLP discovered a coding error in the “Dynamic” metadata plugin of the Shibboleth Service Provider, causing the plugin to fail configuring itself with the filters provided and omitting whatever checks they are intended to perform.

security update

security update

Oracle scrambles to sew up horrid security holes in PeopleSoft’s Tuxedo
Another preinstalled app found on OnePlus that could collect user data
Drone maker DJI left its private SSL, firmware keys open to world+dog on GitHub FOR YEARS
White House Releases VEP Disclosure Rules
Ransomware via RDP – how to stay safe! [VIDEO]
A Boeing 757 was hacked remotely while it sat on the runway
Pawnbroker pwnd: Cash Converters says hacker slurped customer data
Forever 21 clothing stores hit by credit card data breach after encryption failure
Security is from Mars, Developers are from Venus……or ARE they?
New, revamped Terdot Trojan: It’s so 2017, it even fake-posts to Twitter
Woman scammed for $60,000 through fake Police website
Think you deleted that embarrassing WhatsApp message you sent? Think again

LinuxSecurity.com: It was discovered that jackson-databind, a Java library used to parse JSON and other data formats, improperly validated user input prior to deserializing: following DSA-4004-1 for CVE-2017-7525, an additional set of classes was identified as unsafe for deserialization.

DJI bug bounty NDA is ‘not signable’, say irate infosec researchers
YASAT – A Simple Security Auditing Tool
After a year of intensely investigating password theft, here’s what Google found
Deleted WhatsApp sent messages might not be gone forever
Homeland Security team remotely hacked a Boeing 757
Forever 21 informs customers of a potential data breach
Apple’s Face ID security fooled by simple face mask
Does UK high street banks’ crappy crypto actually matter?
Smashing Security podcast #052: Facebook tackles vengeful scumbags, and a sex toy privacy boob

LinuxSecurity.com: An update for openstack-aodh is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Q: Why are you running in the office? A: This is my password for El Reg

security update

The four problems with the US government’s latest rulebook on security bug disclosures
Cisco Warns of Critical Flaw in Voice OS-based Products
Crouching cyber Hidden Cobra: US warns Nork hackers are at it again with new software nasty
US govt’s ‘foreign’ spy program that can snoop on Americans at home. Sure, let’s reauth that…
Amazon Echo and Google Home Devices Vulnerable to BlueBorne Attack

Type: Vulnerability. Microsoft Office is prone to a cross-site request-forgery vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a memory-corruption vulnerability; fixes are available.