Menu

Latest articles

News in brief: veterans among S3 leak victims; court rules on email privacy; man jailed for VPN sales
Patch Released for Critical Apache Struts Bug
Four Million Time Warner Cable Records Left on Misconfigured AWS S3
Apache Struts you’re stuffed: Vuln allows hackers to inject evil code into biz servers

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

London police’s use of facial recognition falls flat on its face
Instagram breach deepens with dark web ‘Doxagram’ domain
Military Contractor’s Vendor Leaks Resumes in Misconfigured AWS S3
Spam Campaigns Using Trickbot Banking Trojan Against Cryptocurrencies
Would-be cyberattackers caught by malware with a sting in the tail
Kurat võtku! Estonia identifies security risk in almost 750,000 ID cards
YouTube MP3 Converter Site Shut Down After Labels Win Lawsuit
Yahoo! braces itself for enormous class-action suit over breaches
Bazinga! Social network Taringa ‘fesses up to data breach

LinuxSecurity.com: GD library could be made to crash if it opened a specially crafted file.

LinuxSecurity.com: An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

Chinese cryptocurrency crackdown

China banned the raising of funds using token-based digital currencies and deemed the practice illegal on Monday, in a move seen as an attempt to impose more regulations on the virtual market. The post Chinese cryptocurrency crackdown appeared first on WeLiveSecurity

UK not as keen on mobile wallets as mainland Europe and US
Latin American social media giant Taringa hacked; 28M accounts stolen

LinuxSecurity.com: A vulnerability in MCollective might allow remote attackers to execute arbitrary code.

News in brief: Pratchett’s data steamrollered; WikiLeaks hit by hackers; Instagram details for sale
Lawyer suggests tying access to encryption to verified ID
Leaky S3 bucket sloshes deets of thousands with US security clearance
Trove of Private Military Contractor Job Applicants Exposed Online
Security-focused phone launches crowdfunding drive
Tempted to join the games in the crytpcurrency playground?

LinuxSecurity.com: Several security issues were fixed in FontForge.

LinuxSecurity.com: Libidn2 2.0.4 (released 2017-08-30) integer overflow in bidi.c/_isBidi() * Fix integer overflow in puny_decode.c/decode_digit() * Improve docs * Fix idna_free() to idn_free() * Update fuzzer corpora

LinuxSecurity.com: Qemu: usb: ohci: infinite loop due to incorrect return value [CVE-2017-9330] (#1457698) Qemu: nbd: segmentation fault due to client non-negotiation [CVE-2017-9524] (#1460173) Qemu: qemu-nbd: server breaks with SIGPIPE upon client abort [CVE-2017-10664] (#1466466) Qemu: exec: oob access during dma operation [CVE-2017-11334] (#1471640) revised full fix for XSA-226 (regressed

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available.

Six million Instagram accounts hacked

A hack believed to target only celebrity accounts on Instagram has also accessed millions of users’ private data. The post Six million Instagram accounts hacked appeared first on WeLiveSecurity

LinuxSecurity.com: Several security issues were fixed in Liblouis.

Crypto-busters reverse nearly 320 MEELLION hashed passwords

LinuxSecurity.com: An update that solves 9 vulnerabilities and has two fixes An update that solves 9 vulnerabilities and has two fixes An update that solves 9 vulnerabilities and has two fixes is now available. is now available.

security update

Asterisk RTP bug worse than first thought: think intercepted streams

LinuxSecurity.com: This update fixes CVE-2017-12982.

LinuxSecurity.com: This update fixes CVE-2017-12982.

LinuxSecurity.com: Qemu: usb: ohci: infinite loop due to incorrect return value [CVE-2017-9330] (#1457698) Qemu: nbd: segmentation fault due to client non-negotiation [CVE-2017-9524] (#1460173) Qemu: qemu-nbd: server breaks with SIGPIPE upon client abort [CVE-2017-10664] (#1466466) Qemu: exec: oob access during dma operation [CVE-2017-11334] (#1471640) revised full fix for XSA-226 (regressed

Stolen 6M Celebrities data from Instagram sold on Dark Web

LinuxSecurity.com: Libidn2 2.0.4 (released 2017-08-30) integer overflow in bidi.c/_isBidi() * Fix integer overflow in puny_decode.c/decode_digit() * Improve docs * Fix idna_free() to idn_free() * Update fuzzer corpora

security update

security update

security update

LinuxSecurity.com: Libidn2 2.0.4 (released 2017-08-30) integer overflow in bidi.c/_isBidi() * Fix integer overflow in puny_decode.c/decode_digit() * Improve docs * Fix idna_free() to idn_free() * Update fuzzer corpora

LinuxSecurity.com: **Version 2.2.5** – 2017-08-30 * **Security** – Double-free in gdImagePngPtr(). **CVE-2017-6362** – Buffer over-read into uninitialized memory. **CVE-2017-7890** * **Fixed** – Fix #109: XBM reading fails with printed error – Fix #338: Fatal and normal libjpeg/ibpng errors not distinguishable – Fix #357: 2.2.4: Segfault in test suite – Fix #386:

LinuxSecurity.com: – Update to 2.6.0 Release notes: https://tls.mbed.org/tech- updates/releases/mbedtls-2.6.0-2.1.9-and-1.3.21-released Security Advisory: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security- advisory-2017-02

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has 5 fixes An update that solves three vulnerabilities and has 5 fixes An update that solves three vulnerabilities and has 5 fixes is now available. is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

DailyStormer comes back with Albanian domain; gets booted off

From streaming entertainment to social media to our online bank accounts and software, we are inundated every day with the need to create and remember new passwords. In fact, one study revealed that Americans have an average of 130 online accounts registered to a single email address. And what are the chances that those 130 […]

‘HoeflerText’ Popups Target Browsers With RAT and Locky Ransomware
US cops can’t keep license plate data scans secret without reason
Massive Locky Ransomware Strain Hits US with Over 23 Million Emails
News in brief: Call to link encryption to ID; Facebook maps everyone; Mirai ‘blackmailer’ extradited
Massive Locky ransomware campaign sends out 23 million emails in 24 hours
Online file conversion services – why trust them?
Hacker Charged for Crashing Businesses Using Millions of Mirai botnet
Open source or proprietary: how should we secure voting systems?
‘Independent’ gov law reviewer wants users preemptively identified before they’re ‘allowed’ to use encryption
Threatpost News Wrap, September 1, 2017
Ex-cop who won’t decrypt hard drives still in jail indefinitely
No Fix Planned For LabVIEW Bug, Says National Instruments
US Government Site Was Hosting Ransomware
Insecure Office 365 setups could be a ticking time bomb for your business
Blonde girlfriend’s passport let dark-haired man fly from London to Germany
Twitter struggles to deal with the sock-puppet and bot armies
Snoops ‘n’ snitches auditor IPCO gets up and running
Instagram warns users of API bug on heels of nude Bieber photos leak
China’s cybersecurity law grants government ‘unprecedented’ control over foreign tech
Connect at mine free Wi-Fi! I would knew what I is do! I is cafe boss!
WikiLeaks suffer defacement at the hands of OurMine group

WikiLeaks’ whistleblowing website suffered an attack from the group known as OurMine on Thursday The post WikiLeaks suffer defacement at the hands of OurMine group appeared first on WeLiveSecurity

IRS-Themed Ransomware Using Old-School Tactics Over the past week, researchers have discovered a new ransomware variant that attempts to impersonate both the IRS and the FBI, similar to the FBI lockscreen malware that was popular several years ago. By tricking the victim into opening a link to a fake FBI questionnaire, the ransomware is downloaded […]

Asterisk bugs make a right mess of RTP
AT&T customers with Arris modems at risk, claim infosec bods
Robocall scumbags already target Hurricane Harvey victims
Malware writer offers free trojan to hackers … with one small drawback
Instagram hacked; data of top celebrities stolen and traded
Session Hijacking Bug Exposed GitLab Users Private Tokens
When uploading comments to the FCC, you can now include malware
Bugs in Arris Modems Distributed by AT&T Vulnerable to Trivial Attacks
Angelfire: CIA’ Undetectable Implants Infect Windows Boot Sector
Polyinstantiating /tmp and /var/tmp directories
FDA Recalls 465K Pacemakers Tied to MedSec Research
Pacemaker gets firmware update – go and see your doctor
Beware scammers phishing for disaster charity – or anything else
WikiLeaks official website hacked by OurMine hacking group
Instagram confirms hack against high-profile users’ account info
Reflected XSS Bug Patched in Popular WooCommerce WordPress Plugin
Machine learning for malware: what could possibly go wrong?
UK council fined £70k for leaving vulnerable people’s data open to world+dog
Is your email in the latest cache of 711 million pwnd addresses?
Google removes 300 Android apps following DDoS attack

Google has been forced to remove almost 300 apps from its Play Store after learning that apps were being hijacked for DDoS attacks. The post Google removes 300 Android apps following DDoS attack appeared first on WeLiveSecurity

Patchy PCI compliance putting consumer credit card data at risk
People-rating app Sarahah slurps up contacts for feature that doesn’t exist
Mystery surrounds malware attack that forced German state parliament offline
CyberRehab’s mission? To clean up the internet, one ASN block at a time
No razzle-dazzle here! Hackers target Zazzle with run-of-the-mill brute-force attack