Menu

Latest articles

Russia, America dig into tug-of-war over Bitcoin laundering suspect
Will Equifax breach spur real reform? Don’t hold your breath
Report Claims Russia Stole NSA Tools Using Kaspersky Software
‘Dark Overlord’ Hackers Leak Student Data After Sending Death Threats
Latest Intelligence for September 2017
September saw Symantec uncover new activity by the Dragonfly group, and the start of several new Locky spam campaigns. Read More
Apple fixes flaw that displayed actual password rather than password hint
Dnsmasq vulnerability puts home routers and IoT devices at risk
Suspected Dark Web drug dealer undone by his own beard
Update your Androids, the October patches are out
Emergency Apple Patch Fixes High Sierra Password Hint Leak
US Top Law Enforcement Calls Strong Encryption a ‘Serious Problem’

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. Yahoo Breach Expands to All 3 Billion Users In a recent statement, Yahoo announced that its […]

Avast urges devs to secure toolchains after hacked build box led to CCleaner disaster
Another W3C API exposing users to browser snitching
How bad can the new spying legislation be? Exhibit 1: it’s called the USA Liberty Act
Crazy but true – Apple’s “show hint” button reveals your actual password
CloudFlare Boots Off Torrent Site For Using Cryptocurrency Miner
Russian spies used Kaspersky AV to hack NSA contractor, swipe exploit code – new claim

Type: Vulnerability. Adobe Flash Player and AIR are prone to an unspecified integer-overflow vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Adobe Flash Player and AIR are prone to an unspecified memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Adobe Flash Player is prone to an unspecified memory-corruption vulnerability; fixes are available.

Net neutrality becomes a battle of the bots
Dumb bug of the week: Apple’s macOS reveals your encrypted drive’s password in the hint box
Google Timeline – bug or feature? [VIDEO]

Risk Level: Very Low. Type: Trojan.

Hackers pounce on 3 vulnerable WordPress plugins
Hackers can identify if you are using sex toys and exploit them
Sonic publicly confirms payment card breach at drive-in locations
Latin American ATM Thieves Turning to Hacking
Smartphones of NATO Soldiers Compromised By Russian Hackers
Spy vs spy vs hacker vs… who is THAT? Everyone’s hacking each other
Smashing Security podcast #046: Good beard bad beard
How a missing smiley foiled a $70,000 email fraud
Cybersecurity in Asia Pacific

As the Asia Pacific region continues to grow, and adoption of digital technologies – by consumers and businesses – continues, the region is starting to appreciate how attractive it has become to cybercriminals. The post Cybersecurity in Asia Pacific appeared first on WeLiveSecurity

UK cybercops reacted to 590 ‘significant attacks’ over past year – report
Chrome turns the screw ever tighter in Google’s encryption crusade
Bulletproof hosts stay online by operating out of disputed backwaters
Inside the CCleaner Backdoor Attack
India’s national internet registry breached, but says heist was trivial
Chinese Bitcoin exchange denies hacking rumors after theft of $2.5M
Attackers Redefining Objectives, Approaches
RAM, bam, awww … man! Boffins defeat Rowhammer protections

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Open your doors to white hats before black hats blow them off, US deputy AG urges big biz

security update

security update

Chips in iPhone 7s, Androids, smart TVs vulnerable to rogue Wi-Fi
Israeli Firm Offering WiFi Interception Service to Law Enforcement Agencies
Experts Have Sobering Message on Human Rights, Privacy for Security Pros
All 3 Billion Yahoo Users Were Hacked in 2013 Data Breach
Russian suspected of $4bn Bitcoin laundering op to be extradited to US
Costin Raiu and Juan Andres Guerrero-Saade on APT Fourth-Party Collection
DNSSEC master key change delayed after ISPs struggle
Facebook will use facial recognition to unlock your account
Users encounter threats through email twice as often as other infection vectors
The latest ISTR special report, Email Threats 2017, casts a light on a threat landscape where attackers are actively spreading malicious threats, BEC [...]
Cloudflare CTO Goes Inside the Cloudbleed Bug
Email fraudsters foiled by a smiley
It’s time that companies became more cyber-resilient

Cybersecurity is everyone’s responsibility and organisations need to train staff to ensure they have a more empowered and security savvy workforce. The post It’s time that companies became more cyber-resilient appeared first on WeLiveSecurity

2013 Yahoo Breach Affected All 3 Billion Accounts
Oracle wants you to drop a log into its cloud, so it can talk security
Sole Equifax security worker at fault for failed patch, says former CEO
Russian bot-herder and election-fiddling suspect closer to US trial
3 billion Yahoo accounts affected by 2013 breach
The biggest hack in history is actually three times bigger than we feared
Nothing matters any more… Now hapless Equifax bags $7.5m IT contract with US taxmen
Oath-my-God: THREE! BILLION! Yahoo! accounts! hacked! in! 2013! – not! ‘just!’ 1bn!
Patch your WordPress plugins: Scum are right now hijacking blogs
Five Critical Android Bugs Get Patched in October Update

security update

Equifax Says 145.5M Affected by Breach, Ex-CEO Testifies
Chinese Bitcoin Trading Exchange Blames User For Losing $3M

“I use a Mac, so I don’t need to worry about malware, phishing, or viruses.” Many Mac users turn a blind eye to cybersecurity threats, often noting that most scams and attacks occur on PCs. However, within the last few years, there has been a noted uptick in spyware (a type of software that gathers information […]

Google Warns of DoS and RCE Bugs in Dnsmasq
Google makes encryption mandatory for sites on 45 Top-Level Domains
The Google tracking feature you didn’t know you’d switched on
3 vulnerable WordPress plugins affecting 21,000 websites
‘Critical’ zero-day bug found in three popular WordPress plugins
How does Behavioral Biometrics help financial institutions manage fraud risk? Download VASCO’s white paper now
Schrems busts Privacy Shield wide open
How a Twitter troll was slain
MH370 final report: Aussies still don’t know where it crashed or why
How forgetting to renew a domain name cost $3m
‘I don’t need to understand how encryption works,’ admits UK Home Secretary
ESET at Virus Bulletin 2017

The annual Virus Bulletin International Conference takes place in Madrid, Spain this October and ESET will be well represented across the three-day event. The post ESET at Virus Bulletin 2017 appeared first on WeLiveSecurity

Un-Delled SonicWall beefs up firewall to wrestle ransomware
Patch your Android, peeps, it has up to 14 nasty flaws to flog
Equifax couldn’t find or patch vulnerable Struts implementations
Android keyboard app misled 200 million users about how it was collecting data
HPE coughed up source code for Pentagon’s IT defenses to … Russia
Bitcoin’s soft and vulnerable underbelly
Dnsmasq and the seven flaws: Patch these nasty remote-control holes
Netgear Fixes 50 Vulnerabilities in Routers, Switches, NAS Devices
Judge: FBI Can Keep iPhone Crack and Price Secret
3 simple steps to online safety
News in brief: Whole Foods holed; Facebook face lock; Mining malware
Gary McGraw on BSIMM8 and Software Security
UK National Lottery knocked offline by DDoS attack