Menu

Latest articles

Pro-ISIS hackers deface Ohio government websites
Basic Security Testing with Kali Linux

LinuxSecurity.com: An update that solves one vulnerability and has 27 fixes is An update that solves one vulnerability and has 27 fixes is An update that solves one vulnerability and has 27 fixes is now available. now available.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available.

Google strips private medical data from searches

LinuxSecurity.com: An update that fixes 50 vulnerabilities is now available. An update that fixes 50 vulnerabilities is now available. An update that fixes 50 vulnerabilities is now available.

Risk Level: Very Low. Type: Trojan.

security update

Fake Pornography App Infecting Devices with Android Ransomware
Google to stop scanning user emails for Gmail ads
Hackers attempt to break into UK MPs’ email accounts, as Houses of Parliament targeted by cyber attack
UK Parliament Under “Sustained and Determined” Cyber Attack
Facebook’s new feature to prevent misuse of profile pics

security update

800,000 Virgin Media customer urged to change their router passwords
Someone leaked 32TB of Windows 10 internal builds and source code

security update

security update

security update

WikiLeaks’ Latest Dump Exposes CIA Hacking Tools for air-gapped PCs
Siemens Patches Vulnerabilities in SIMATIC CP, XHQ

LinuxSecurity.com: Several vulnerabilities have been found in the Apache HTTPD server. CVE-2017-3167

LinuxSecurity.com: Multiple vulnerabilities have been found in Vim and gVim, the worst of which might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: An out-of-bounds write in Graphite might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in jbig2dec, the worst of which might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Several security issues were fixed in OpenVPN.

LinuxSecurity.com: Multiple vulnerabilities have been found in Urban Terror, the worst of which allows for the remote execution of arbitrary code.

LinuxSecurity.com: It was discovered that Flatpak, an application deployment framework for desktop apps insufficiently restricted file permissinons in third-party repositories, which could result in privilege escalation.

LinuxSecurity.com: Multiple vulnerabilities have been found in libksba which might allow remote attackers to obtain sensitive information or crash an libksba-based application. [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in the Graphite font rendering engine which might result in denial of service or the execution of arbitrary code if a malformed font file is processed.

Few Victims Reporting Ransomware Attacks to FBI
News in brief: drone chiefs urge regulation; Microsoft drops SMB1; Virgin router warning
Threatpost News Wrap, June 23, 2017
Virgin Media to 800,000 Hub 2 users: Change Your Password Now
NSA Advocates Data Sharing Framework
Russia ‘targeted 21 states’ during US election campaign, says official
Millennials: Meet the next generation of cybersecurity

As baby boomers retire and the employment gap in cybersecurity is plugged by generation x, we look at how millennials are set to shape the industry. The post Millennials: Meet the next generation of cybersecurity appeared first on WeLiveSecurity

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. WannaCry Shuts Down Honda Production Plant Over the last few days, Honda officials have discovered a […]

If these universities had run an ad blocker they might have been saved from ransomware attack
Ransomware revisited – is it really the worst sort of malware? [Security SOS Week]
Dating app boss sees ‘no problem’ on face-matching without consent
Police cancel 590 speeding fines after WannaCry hits traffic cameras

LinuxSecurity.com: An update that fixes 12 vulnerabilities is now available. An update that fixes 12 vulnerabilities is now available. An update that fixes 12 vulnerabilities is now available.

Ouch! UK Govt’s Cyber Essentials scheme suffers data breach due to configuration error

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: This update addresses CVE-2017-1000366, a vulnerability in the dynamic linker allowing local privilege escalation.

LinuxSecurity.com: For changes see https://www.mozilla.org/en-US/thunderbird/52.2.0/releasenotes/

Textalyzer Device Tells Police Everything Users Do on Their Smartphone

security update

Cisco Patches XXE, DOS, Code Execution Vulnerabilities
Cybereason snags $100m from Softbank to mount distribution, tech offensive
Breach at UK.gov’s Cyber Essentials scheme exposes users to phishing attacks
Honda plant in Japan briefly stops making cars after fresh WannaCrypt outbreak
Ad ‘urgently’ seeks company to build national e-ID system
Microsoft admits to disabling third-party antivirus code if Win 10 doesn’t like it
US is Number One! In sales register hacking attacks, at least
Hacker exposed bank loophole to buy luxury cars and a face tattoo
NSA had NFI about opsec: 2016 audit found laughably bad security
South Korean hosting co. pays $1m ransom to end eight-day outage
Stack Clash flaws blow local root holes in loads of top Linux programs
Mexican government accused of illegal phone hacking of citizens
US voter info stored on wide-open cloud box, thanks to bungling Republican contractor
Fancy buying our aircraft carrier satnav, Raytheon asks UK
It’s 2017, and UPnP is helping black-hats run banking malware
Worried about election hacking? There’s a technology fix – Helios
FOIA documents show the Kafkaesque state of US mass surveillance

LinuxSecurity.com: New openvpn packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: Emeric Boit of ANSSI reported that SPIP, a website engine for publishing, insufficiently sanitises the value from the X-Forwarded-Host HTTP header field. An unauthenticated attacker can take advantage of this flaw to cause remote code execution.

LinuxSecurity.com: The system could be made to run programs as an administrator.

Average Cost of Breach Goes Down For the First Time Ever
News in brief: AI comes to Mars; WannaCry hits speed cameras; Edge bounty program extended

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Microsoft Says Fireball Threat ‘Overblown’
What does looking under the hood of your browser reveal about you?
Microsoft PatchGuard flaw could let hackers plant rootkits on x64 Windows 10 boxen
Phishing campaign spoofs online auto brand, exposes stolen passwords
Two Brits nabbed in connection with global plot to hack Microsoft network
Birthday Reminder looks benign but the devil’s in the details: Hooks DNS, serves dodgy ads

The strange behavior of a simple Windows application caught our attention and sparked the analysis by ESET of a previously undocumented malware. The post Birthday Reminder looks benign but the devil’s in the details: Hooks DNS, serves dodgy ads appeared first on WeLiveSecurity

UCL ransomware attack traced to malvertising campaign
WannaCry Ransomware Hits Traffic Cameras in Australia
Coming soon (maybe) to toyshops – AI doll that can read kids’ emotions
Botnets – malware that makes you part of the problem [Security SOS Week]
Honeypots and the Internet of Things
WannaCry ransomware infects Australian traffic cameras, human error blamed
‘No decision’ on Raytheon GPS landing system aboard Brit aircraft carriers
Deep Root: what can we learn from the GOP’s data leak?

LinuxSecurity.com: Disable executable stack for aarch64 builds.

NSA-Backed OpenC2.org Aims to Defend Systems at Machine Speed

LinuxSecurity.com: CVE-2017-1000381: c-ares NAPTR parser out of bounds access

LinuxSecurity.com: This update addresses CVE-2017-1000366, a vulnerability in the dynamic linker allowing local privilege escalation.

LinuxSecurity.com: Update to .104. Fix mp3 playback. Security fix for CVE-2017-5087, CVE-2017-5088, CVE-2017-5089

LinuxSecurity.com: Rebuild for new luajit

Smashing Security #030: GDPR – The good and the bad

LinuxSecurity.com: Alvaro Munoz and Christian Schneider discovered that jython, an implementation of the Python language seamlessly integrated with Java, is prone to arbitrary code execution triggered when sending a serialized function to the deserializer.

LinuxSecurity.com: Aniket Nandkishor Kulkarni discovered that in tomcat7, a servlet and JSP engine, static error pages used the original request’s HTTP method to serve content, instead of systematically using the GET method. This could under certain conditions result in undesirable results,

LinuxSecurity.com: Aniket Nandkishor Kulkarni discovered that in tomcat8, a servlet and JSP engine, static error pages used the original request’s HTTP method to serve content, instead of systematically using the GET method. This could under certain conditions result in undesirable results,

LinuxSecurity.com: Several security issues were fixed in the kernel.

Researcher calls the fuzz on OpenVPN, uncovers crashy vulns
Homeland Security: Putin’s hackers tried to crack electoral networks in 21 US states

security update