Menu

Latest articles

Twitter Flaw Could Have Allowed Attacker to Tweet From Any Account
Police swoop on gang that planted banking Trojan on 1m phones
WannaCryptor, aka WannaCry interview with Stephen Cobb and Marc Saltzman

Stephen Cobb, a senior security researcher at ESET, talks about one of the biggest cyberattacks of 2017 – WannaCryptor, aka WannaCry with radio and TV personality Marc Saltzman. The post WannaCryptor, aka WannaCry interview with Stephen Cobb and Marc Saltzman appeared first on WeLiveSecurity

386 WannaCry Ransomware and 26 EternalRocks Samples Discovered
Malware Network Communication Provides Better Early Warning Signal
LastPass’s new cloud backup option – sunny skies or a brewing storm?
Hacked Twitter account spits out poison – make sure yours isn’t next
Sn1per – Penetration Testing Automation Scanner
Hackers Unlock Samsung Galaxy S8 With Fake Iris

LinuxSecurity.com: MiniUPnP could be made to crash or run programs if it received specially crafted network traffic.

LinuxSecurity.com: Several security issues were fixed in jbig2dec.

LinuxSecurity.com: Samba could be made to run programs as an administrator.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update for samba3x is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for samba is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for samba4 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: Jakub Jirasek of Secunia Research discovered that libtasn1, a library used to handle Abstract Syntax Notation One structures, did not properly validate its input. This would allow an attacker to cause a crash by denial-of-service, or potentially execute arbitrary code, by

LinuxSecurity.com: steelo discovered a remote code execution vulnerability in Samba, a SMB/CIFS file, print, and login server for Unix. A malicious client with access to a writable share, can take advantage of this flaw by uploading a shared library and then cause the server to load and execute it.

LinuxSecurity.com: This updates fixes a security bug in the route manager, to prevent it from overwriting arbitrary files (CVE-2017-8921)

security update

security update

Risk Level: Very Low. Type: Worm.

Subtitle Hack Leaves 200 Million Vulnerable to Remote Code Execution
Google Elevates Security in Android O
Yahoo Retires ImageMagick After Bugs Leak Server Memory
Indian hacker pwned Air India, SpiceJet & Cleartrip; booked free flights
News in brief: Dubai launches its first robocops; Samsung woes over iris recognition; IoT security criticised
Hackers Claim Leaking Thousands of Spotify Login Credentials
Apple Receives First National Security Letter, Reports Spike in Requests for Data
XData ransomware making rounds amid global WannaCryptor scare

A week after the global outbreak of WannaCryptor, also known as WannaCry, another ransomware, known as XData, has been making rounds. The post XData ransomware making rounds amid global WannaCryptor scare appeared first on WeLiveSecurity

Digital watermark leads police straight to Bollywood pirates
Man jailed for stealing images and details from more than 50 women
Top 3 Chrome VPN Extensions for Maximum Online Privacy
Is the world ready for GDPR? Privacy and cybersecurity impacts are far-reaching

Enforcement of GDPR, the General Data Protection Regulation, begins in May of 2018, imposing data privacy and security requirements on many organizations in the US and other countries. Are you impacted? The post Is the world ready for GDPR? Privacy and cybersecurity impacts are far-reaching appeared first on WeLiveSecurity

Yahoo retires ImageMagick library after 18-byte exploit leaks user email content
Ashley Madison claims to be gaining 500,000 new members each month
Warning after WannaCry sets off fake BT phishing attack
How to remove all your cookies, cached data, and browsing history from Safari

LinuxSecurity.com: An update for rpcbind is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for libtirpc is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

US politicians think companies should be allowed to ‘hack back’ after WannaCry

LinuxSecurity.com: Update to chromium 58. Move chrome-remote-desktop to user systemd service. Security fixes for CVE-2017-5068, CVE-2017-5057, CVE-2017-5058, CVE-2017-5059, CVE-2017-5060, CVE-2017-5061, CVE-2017-5062, CVE-2017-5063, CVE-2017-5064, CVE-2017-5065, CVE-2017-5066, CVE-2017-5067, CVE-2017-5069

LinuxSecurity.com: Update to chromium 58. Move chrome-remote-desktop to user systemd service. Security fixes for CVE-2017-5068, CVE-2017-5057, CVE-2017-5058, CVE-2017-5059, CVE-2017-5060, CVE-2017-5061, CVE-2017-5062, CVE-2017-5063, CVE-2017-5064, CVE-2017-5065, CVE-2017-5066, CVE-2017-5067, CVE-2017-5069

LinuxSecurity.com: The 4.10.16 stable kernel update contains a number of important fixes across the tree.

LinuxSecurity.com: The 4.10.16 stable kernel update contains a number of important fixes across the tree.

Trump’s Cybersecurity Boss Talks Priorities

LinuxSecurity.com: Update to chromium 58. Move chrome-remote-desktop to user systemd service. Security fixes for CVE-2017-5068, CVE-2017-5057, CVE-2017-5058, CVE-2017-5059, CVE-2017-5060, CVE-2017-5061, CVE-2017-5062, CVE-2017-5063, CVE-2017-5064, CVE-2017-5065, CVE-2017-5066, CVE-2017-5067, CVE-2017-5069

LinuxSecurity.com: Update to chromium 58. Move chrome-remote-desktop to user systemd service. Security fixes for CVE-2017-5068, CVE-2017-5057, CVE-2017-5058, CVE-2017-5059, CVE-2017-5060, CVE-2017-5061, CVE-2017-5062, CVE-2017-5063, CVE-2017-5064, CVE-2017-5065, CVE-2017-5066, CVE-2017-5067, CVE-2017-5069

LinuxSecurity.com: The 4.10.16 stable kernel update contains a number of important fixes across the tree.

LinuxSecurity.com: The 4.10.16 stable kernel update contains a number of important fixes across the tree.

Verizon Patches XSS Issues in its Messaging Client
Facebook guidelines give discomforting insight into moderation policy

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

News in brief: Bitcoin price bubbles up; Uber uses AI to boost its take; WannaCry ‘hero’ censures tabloids

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

IDG Contributor Network: What’s all the chatter about chatbots
EternalRocks Worm Spreads Seven NSA SMB Exploits
Yes, Geek Squad can search your files and hand you over to the police
Zomato working with ‘ethical hacker’ to improve security

Zomato has confirmed that it has been communicating with the hacker responsible for stealing the data of around 17 million of its customers. The post Zomato working with ‘ethical hacker’ to improve security appeared first on WeLiveSecurity

Hackers trying to bring back WannaCry attacks by DDoSing its KillSwitch
After WannaCry, EternalRocks digs deeper into the NSA’s exploit toolbox
Judge demands cellphone passwords from social media star
North Korea denies link to WannaCry ransomware attack
GDPR is just a year away: here’s what you need to know
EternalRocks Worm Uses Same SMB Flaw in Windows like WannaCry
Jaya Baloo on WannaCry and Defending Against Advanced Attacks
What does Twitter think you’re interested in? Now you can find out
Keys for Crysis released, as decryption efforts of WannaCryptor files continue

ESET have prepared a new Crysis decrypting tool. Victims who still have their encrypted files can now download the decryptor from its utilities page. The post Keys for Crysis released, as decryption efforts of WannaCryptor files continue appeared first on WeLiveSecurity

Rogues reset ‘passwords’, steal W-2 info from Equifax subsidiary customer employees
ATM heists: 27 arrested as police move against ‘black box’ attacks

LinuxSecurity.com: Fix for CVE-2017-6949, also bump to 4.12.0

LinuxSecurity.com: Fix for CVE-2017-6949, also bump to 4.12.0

LinuxSecurity.com: Security fix for CVE-2017-8849. https://www.kde.org/info/security/advisory-20170510-2.txt

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Worm.

How To Prevent Growing Issue of Encryption Based Malware (Ransomware)

security update

security update

HSBC voice recognition security system spoofed by BBC
Proposed PATCH Act forces US snoops to quit hoarding code exploits
Twitter abandons ‘Do Not Track’ privacy protection

security update

security update

security update

Terror Exploit Kit Evolves Into Larger Threat

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for openstack-heat is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Updated atomic-openshift-utils and openshift-ansible packages that fix two security issues and several bugs are now available for OpenShift Container Platform 3.5, 3.4, 3.3, and 3.2. [More…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: New kdelibs packages are available for Slackware 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. [More Info…]

LinuxSecurity.com: New freetype packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. [More Info…]

News in brief: twins fox bank’s voice security; FCC moves on net neutrality; torrent site closes