Menu

Latest articles

Malware infecting Androids somewhere in the supply chain
Celebrity Websites Hacked with Messages Against ISIS and Turkey
WikiLeaks says it will work with software vendors to fix CIA zero-day exploits… but when?
Security Flaws in MAC Address Randomization Technique makes iOS, Android Devices Vulnerable to Tracking
#OpBlueWhale: “Anonymous” Urges Teens to Quit Playing Suicide Game
Spy satellite scientist sent down for a year for stowing secrets at home
The Best Alternatives Operating Systems
‘Password rules are bullsh*t!’ Stackoverflow Jeff’s rage overflows
Official: America auto-scanned visitors’ social media profiles. Also: It didn’t work properly
New Linux malware hijacks one vendor’s IoT devices by exploiting CGI bug
FCC under fire for trying to ditch cybersecurity
IDG Contributor Network: Mobile devices: The ‘last mile’ to enterprise biometrics

security update

Wikileaks says CIA does CYA, reinvents the ‘Boss’ key from 1992
How online gamers use malware to cheat
Home Depot agrees to $25 million settlement for data breach

US retail giant Home Depot is set to pay a $25 million settlement in relation to a data breach suffered in 2014. The post Home Depot agrees to $25 million settlement for data breach appeared first on WeLiveSecurity

Endangered animals at growing risk from GPS ‘cyber-poachers’

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. Microsoft Services Go Offline Was I the only one who wasn’t able to access my Xbox […]

Google Chrome 57 Browser Update Patches ‘High’ Severity Flaws
Threatpost News Wrap, March 10, 2017
Apache Attack Traffic Dropping, Limited to Few Sources
Payments Giant Verifone Suffers Data Breach
Privilege Escalation Flaw Patched in Schneider Wonderware
Police warn on keeping kids safe as Justin Bieber impersonator charged
TeamViewer stopped working? Let me guess, your ISP is TalkTalk…
Mobile security: The reality of malware … augmented

What awaits us in terms of mobile security trends? Throughout this article, we will discuss how risks might develop in the near future. The post Mobile security: The reality of malware … augmented appeared first on WeLiveSecurity

The perils of working from home with young children
WikiLeaks will share CIA hacking details with companies, but can they use it?
Zero Days Have Staying Power
WikiLeaks promises to supply CIA’s hacking tool code to vendors
Hacktivist or script kiddy? Know your 10 types of hacker
Google tries to beat AWS at cloud security
Android YouTube download apps flood devices with ads to secure high ratings for droppers
‘Nigerian princes’ snatch billions from Western biz via fake email – Interpol
MAC randomization: A massive failure that leaves iPhones, Android mobes open to tracking

security update

What a Flake: Congress mulls trashing privacy rules, letting ISPs go to town on your data
Want a Career in Cybersecurity? Find Out Which Degrees Can Get You There
Hundreds of Thousands of Vulnerable IP Cameras Easy Target for Botnet, Researcher Says
640,000 Decrypted PlayStation Accounts Being Sold on DarkWeb

security update

The convenience of having some kind of internet connection on more and more of the devices we use each day is undeniable. However, without proper security vetting, this convenience may come at a hefty price. In the past year alone, we’ve seen millions of routers, DVRs, IP cameras, cars, and more get hacked and either […]

Zero-days? Sexy, sure, but crap passwords and phishing are probably more pressing
Are you customer of a firm that’s been breached? Look out for more attacks

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Attacks Heating Up Against Apache Struts 2 Vulnerability
Consumer Reports launches new privacy and data security standard

The US-based nonprofit organization Consumer Reports has come up with a new standard that aims to boost consumer confidence in privacy and data security. The post Consumer Reports launches new privacy and data security standard appeared first on WeLiveSecurity

Instagram phishing apps pulled from Google Play
Brit ISP TalkTalk blocks control tool TeamViewer
Google Patched Hundreds of Android Security Flaws in March Update
Apache Struts bug is under attack, patch now
China mulls national cryptocurrency in race to digital money
New Instagram credential stealers discovered on Google Play

ESET researchers discovered 13 new Instagram credential stealers on Google play and looked into the motivations behind their fraudulent schemes. The post New Instagram credential stealers discovered on Google Play appeared first on WeLiveSecurity

Royal Navy’s newest ship formally named in Glasgow yard
Facebook to listen out for posts from people vulnerable to suicide
Smashing Security #011: WikiLeaks and the CIA
Bots: Biggest player on the cybercrime block
Hackers exploit Apache Struts vulnerability to compromise corporate web servers
WikiLeaks publishes docs from what it says is trove of CIA hacking tools
Google’s ‘SHA-1 Countdown Clock’ Could Undermine Enterprise Security
Ways in which to plug the infosec talent gap

ESET’s Lysa Myers looks at the shortage of qualified information security talent to fill positions, discussing ways in which to plug the infosec talent gap. The post Ways in which to plug the infosec talent gap appeared first on WeLiveSecurity

Oops! 185,000-plus Wi-Fi cameras on the web with insecure admin panels

In honor of International Women’s Day, we hosted our quarterly Women of Webroot meeting this afternoon at our World Headquarters in Broomfield. Women of Webroot brings together women from all parts of our business to celebrate wins and provide support for issues women in tech may face. Although there are more women in technology-related positions […]

Apache Struts 2 needs patching, without delay. It’s under attack now
Buggy backups! Unplug your WD My Cloud until these flaws are fixed

Risk Level: Very Low. Type: Trojan.

FBI boss: ‘Memories are not absolutely private in America’
Senator Demands Answers About CloudPets Breach
Dark Web Suffers After Anonymous Hacked Firm Hosting Child Porn Sites
Leaked docs suggest NSA and CIA behind Equation cyberespionage group
CIA hacking dossier leak reignites debate over vulnerability disclosure
Confide Updates App After Critical Security Issues Are Raised
What WikiLeaks’ massive CIA leak tells us about cybersecurity
News in brief: Firefox drops XP, Vista support; CloudPets boss pressed; judge rules on streaming
Facebook Call Cops on BBC for Exposing Child Abuse Content
Apple has already fixed most of the iOS exploits the CIA used
Firefox 52 Expands Non-Secure HTTP Warnings, Enables SHA-1 Deprecation
Dad ruled liable and fined for his son’s illegal download
Good Weather App radio interview with Alexis Dorais-Joncas and Marc Saltzman

A full radio interview with ESET’s Alexis Dorais-Joncas and radio and TV personality Marc Saltzman – on NewsTalk 1010 – talking about a malicious weather app that was found on Google Play. The post Good Weather App radio interview with Alexis Dorais-Joncas and Marc Saltzman appeared first on WeLiveSecurity

Verifone downplays impact of recent breach
Why is Windows malware cropping up in Android apps?
Comey Talks Strong Crypto, Silent on WikiLeaks
Alleged spammer leaks 1.37bn email addresses after backup catastrophe
Wikileaks Vault 7: CIA hacked Smart TVs, Phones, Trucks and Computers
CIA false flag team repurposed Shamoon data wiper, other malware
Messaging app used by Trump aides ‘riddled with security bugs’
Amazon fight to keep Echo recording out of murder trial now moot
Dahua security camera owners urged to update firmware after vulnerability found
Rate this as five stars or we’ll bombard you with pop-up ads
Aggressive ad-displaying Google Play app tricks users into leaving high ratings

ESET researchers have observed an increased number of apps on Google Play using social engineering techniques to boost their ratings, ranging from legitimate apps, through adware to malware. The post Aggressive ad-displaying Google Play app tricks users into leaving high ratings appeared first on WeLiveSecurity

Lame comment spam campaign attempts to promote iPhone app
Wikileaks Just Dumped a Cache of Information on Alleged CIA Hacking Tools
Next Generation Security: No, Dorothy, there is no magic wand

LinuxSecurity.com: Fixed CVE 2017-2590: freeipa: ipa: Insufficient permission check for ca-del, ca-disable and ca-enable commands [fedora-all]

LinuxSecurity.com: * [7.x-1.21](https://www.drupal.org/project/metatag/releases/7.x-1.21) *[Moderately Critical – Information disclosure – SA-CONTRIB-2017-019](https://www.drupal.org/node/2852937)

LinuxSecurity.com: This is a new upstream feature and security release. Improvements include:bypass; pre-filter — fast packet keywords; TLS improvements; ICS protocoladditions: DNP3 CIP/ENIP; SHA1/SHA256 for file matching, logging & extraction;NIC offloading disabled by default; unix socket enabled by default; and AppLayer stats. Documentation: http://suricata.readthedocs.io/en/suricata-3.2/

LinuxSecurity.com: Security fix for CVE-2017-5884, CVE-2017-5885

Time’s up for SHA-1 hash algo, but one in five websites still use it

LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary and Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]