Menu

Latest articles

Why we need to encrypt everything

If you’ve been paying attention lately, you’ve likely noticed that more of your everyday websites are going HTTPS by default: Twitter, Facebook, LinkedIn, and even your favorite search engine.This is a good development. For years, critics have derided default, widespread HTTPS encryption and authentication as unnecessary and performance-wasting. But now that we’ve seen most of […]

LinuxSecurity.com: An update for 389-ds-base is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: Security Report Summary

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Outlook for Mac is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Outlook is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

This Ransomware tells users to play a popular Japanese game – That’s all
Wonga database hacked: Nearly 270,000 customers could be affected
ShadowBrokers Dump More Equation Group Hacks, Auction File Password
Travel Routers, NAS Devices Among Easily Hacked IoT Devices
Hackers are Exploiting New Microsoft Office Vulnerability to Drop Malware

LinuxSecurity.com: New libtiff packages are available for Slackware 14.2 and -current to fix security issues. [More Info…]

LinuxSecurity.com: Security Report Summary

News in brief: Dallas sirens ‘hacked’; Livejournal cracks down; Russian man arrested in Spain

Risk Level: Very Low. Type: Trojan.

Microsoft Office zero-day being exploited to spread malware, but no patch available… yet
Shadow Brokers return with a password and message for Trump
Mounties admit to using cellphone-snooping ‘stingrays’
Riverbed Patches Vulnerabilities in Application Monitoring Portal
Angry Shadow Brokers release password for suspected NSA hacking tools
BrickerBot malware zeroes in on Linux-based IoT devices
Hackers set off Dallas emergency sirens more than a dozen times in a few hours
Payday loan company Wonga breached – what you need to know
Word zero-day affects all versions of Office and Windows
Hard-coded passwords put industrial systems at risk
Spanish Harmada: More on tech support scams

David Harley and Josep Albors on the evolution of tech support scams and why the current high incidence of reports in Spain are significant. The post Spanish Harmada: More on tech support scams appeared first on WeLiveSecurity

Ghost in the Shell: Fantasy meets reality with cybersecurity themes

With the recent big screen adaptation of Ghost in the Shell, we thought it would be a good idea to review some of the cybersecurity themes it explores. The post Ghost in the Shell: Fantasy meets reality with cybersecurity themes appeared first on WeLiveSecurity

Uber ‘showing drivers and riders different fare estimates’, says lawsuit

Risk Level: Very Low. Type: Trojan.

Wonga data breach puts up to 245,000 UK current and former customers at risk
Malvertising campaign pushes data-collecting VPN on iOS users
Malicious torrent file conducts distributed WordPress password attack

security update

Help prevent a breach in your organisation by watching these Microsoft Office webcasts
Someone hacked every single tornado emergency siren in Dallas
Hackers Leak Passwords to NSA’s “Top Secret Arsenal” against Trump’s Policies
Gaming giant GameStop’ website hacked; credit card data stolen
Trump Is About to Find Out What Happens When You Mess With the Open Internet
Android devices can be fatally hacked by malicious Wi-Fi networks
Researcher Warns SIEMs Are Weak Link In Network Security Chain
Baseband Zero Day Exposes Millions of Mobile Phones to Attack
Creating a More Altruistic Bug Bounty Program
That ‘iPhone Wi-Fi bug’ isn’t just for Apple users – here’s a rundown
News in brief: Twitter sues US government; Google launches Fact Check; cybersecurity apprenticeship launched

Risk Level: Very Low. Type: Trojan.

Apache Struts 2 Exploits Installing Cerber Ransomware
Forget Mirai, IoT Devices are being Destroyed by Brickerbot Attacks
Mastodon: new beast to challenge Big Social, or another white elephant?
Samsung Tizen Security ‘Feels like 2005’
ISP privacy – how much should it cost?

ISPs have started to monetize customer information quietly while selling them bandwidth. The temptation is strong, as that kind of aggregate data has real value on the secondary market, but what about the customers’ privacy? The post ISP privacy – how much should it cost? appeared first on WeLiveSecurity

Why isn’t US military email protected by standard encryption tech?
Healthcare challenges: Ransomware and the Internet of Things are the tip of the iceberg

ESET’s Lysa Myers discusses the challenges facing healthcare technology, medical and fitness devices and highlights the need to secure medical devices The post Healthcare challenges: Ransomware and the Internet of Things are the tip of the iceberg appeared first on WeLiveSecurity

WiFi-enabled adult toy comes up short on security
Linux File Encryption By Jetico Cares For Ultimate User Privacy
Fake News Site Targeting Android, Windows Users with Malware Scam
It’s time to finally say goodbye to Windows XP. And Vista. Again

Three years ago, Microsoft ended its extended support for Windows XP. Today, almost 8% of desktop users worldwide are still run the operating system. The post It’s time to finally say goodbye to Windows XP. And Vista. Again appeared first on WeLiveSecurity

IDG Contributor Network: Can you trust Linux-based Tizen OS?
IoT company disabled customer’s device remotely over bad review
Chrome Security Team Tackles ‘Friendly Fire’ To Keep Browser Safe
News in brief: NASA to crash probe into Saturn; laptop ban might widen; Facebook tool to spot fake news

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Samsung, Nexus, iPhone Devices can be Compromised Due to WiFi Flaws
Bill would block warrantless searches of Americans’ phones at borders
Triada Android spyware evades anti-virus detection by using DroidPlugin sandbox

Email attacks are the most common methods for initiating ransomware and phishing scams. Attackers want you to open an infected attachment or click a malicious link, and unwittingly download malware to your machine. But you can avoid such attacks by being patient, checking email addresses, and being cautious of sketchy-sounding subject lines. 7 dangerous subject […]

Samsung’ Tizen OS Contains Tons of Critical Security Flaws
Sathurbot: Distributed WordPress password attack

This article sheds light on the current ecosystem of the Sathurbot backdoor trojan, in particular exposing its use of torrents as a delivery medium and its distributed brute-forcing of weak WordPress administrator accounts. The post Sathurbot: Distributed WordPress password attack appeared first on WeLiveSecurity

Tax identity fraud: Bringing the fight to this menace

Tax identity fraud is a multibillion dollar industry for criminals. ESET’s Lysa Myers explores new measures and offers some top tips on how to tackle this menace. The post Tax identity fraud: Bringing the fight to this menace appeared first on WeLiveSecurity