Menu

Latest articles

LinuxSecurity.com: * [7.x-1.21](https://www.drupal.org/project/metatag/releases/7.x-1.21) *[Moderately Critical – Information disclosure – SA-CONTRIB-2017-019](https://www.drupal.org/node/2852937)

LinuxSecurity.com: – Update to 1.0.4 Release notes: http://www.cacti.net/release_notes_1_0_0.phphttp://www.cacti.net/release_notes_1_0_1.phphttp://www.cacti.net/release_notes_1_0_2.phphttp://www.cacti.net/release_notes_1_0_3.phphttp://www.cacti.net/release_notes_1_0_4.php

LinuxSecurity.com: cirrus_bitblt_cputovideo does not check if memory region is safe [XSA-209,CVE-2017-2620] (#1425420)

LinuxSecurity.com: This is a new upstream feature and security release. Improvements include:bypass; pre-filter — fast packet keywords; TLS improvements; ICS protocoladditions: DNP3 CIP/ENIP; SHA1/SHA256 for file matching, logging & extraction;NIC offloading disabled by default; unix socket enabled by default; and AppLayer stats. Documentation: http://suricata.readthedocs.io/en/suricata-3.2/

LinuxSecurity.com: Security fix for CVE-2017-5884, CVE-2017-5885

That CIA exploit list in full: The good, the bad, and the very ugly
Top tip: Unplug your WD My Cloud boxen – now

LinuxSecurity.com: Security Report Summary

Dahua video kit left user credentials in plain sight
Is the CIA’s Weeping Angel spying on TV viewers?
US Senator snaps on glove, probes insecure IoT toymaker CloudPets

LinuxSecurity.com: New mozilla-thunderbird packages are available for Slackware 14.1, 14.2, and -current to fix security issues. [More Info…]

Firefox 52 warns when you try to enter passwords on non-encrypted websites
Ohi-D’oh! US prison hands inmates’ SSNs over to… an identity thief
Hacking the hackers: Draft US bill would allow hacking victims to hack back

security update

WikiLeaks dump shows CIA can use IoT to hack ‘anything, anywhere’

As if the job market isn’t hard enough to break into, rising seniors and recent college graduates are employment scam targets. In January, the FBI issued a warning that employment scams targeting college students are still alive and well. Employment Scams – A Public Service Announcement According to the FBI, scammers advertise phony job opportunities […]

Windows snooping patches KB 2952664, KB 2976978 are back (again)
WikiLeaks Reveals CIA’s Hacking Capabilities in ‘Vault 7’ series documents
WordPress 4.7.3 Patches Half-Dozen Vulnerabilities
Spies do spying, part 97: Shock horror as CIA turn phones, TVs, computers into surveillance bugs
Unpatched Western Digital Bugs Leave NAS Boxes Open to Attack
News in brief: Kodi streaming ‘not illegal’; whistleblower movie planned; robots on the rise
Dahua Patching Backdoor in DVRs, IP Cameras

LinuxSecurity.com: An update for ansible and openshift-ansible is now available for Red Hat OpenShift Container Platform 3.2, Red Hat OpenShift Container Platform 3.3, and Red Hat OpenShift Container Platform 3.4. [More…]

WordPress fixes XSS, CSRF flaws in latest core update
WikiLeaks drops huge cache of confidential CIA documents
Google leads ‘guerilla patching’ of big vulnerability in open source projects
City planners use mobile data to track congestion in tourist hot spots
Android gets patches for critical OpenSSL, mediaserver, and kernel driver flaws
Satan ransomware: old name, new business model
Why email is safer in Office 365 than on your Exchange server
Google Increases its Bug Bounty Program Reward Money
Cybercrooks charging more than the price of a new car for undetectable Mac malware
Say goodbye to enhanced data privacy, US web surfers
Active Defense Bill Raises Concerns Of Potential Consequences
Facebook shopped BBC hacks to National Crime Agency over child abuse images probe
Scammers hired hundreds of ‘staff’ to defraud TalkTalk customers
WordPress webmasters urged to upgrade to version 4.73 to patch six security holes
HackerOne offers bug bounty service for free to open-source projects
The Border Patrol can take your password. Now what?
4 strategies to root out your security risks

You’ll never reduce your security risk if you can’t identify and mitigate the root causes of those vulnerabilities. It isn’t enough to have a list of malware programs that your antimalware has detected. You need to to determine how viruses and hackers have penetrated your environment in the past. In the vast majority of organizations, […]

LinuxSecurity.com: Security fix for CVE-2017-6060 CVE-2017-5896 —- Add comment with explanationof disabled debuginfo

LinuxSecurity.com: – Update to 1.0.4 Release notes: http://www.cacti.net/release_notes_1_0_0.phphttp://www.cacti.net/release_notes_1_0_1.phphttp://www.cacti.net/release_notes_1_0_2.phphttp://www.cacti.net/release_notes_1_0_3.phphttp://www.cacti.net/release_notes_1_0_4.php

Boffins show Intel’s SGX can leak crypto keys
That big scary 1.4bn leak was basically nothing but email addresses
Shamoon malware spawns even nastier ‘StoneDrill’
Put down the coffee, stop slacking your app chaps or whatever – and patch WordPress
Wow, did you see what happened to Veracode? Oh no, no, it’s not dead. It’s been bought by CA
Don’t worry, slowpoke Microsoft, we patched Windows bug for you, brags security biz

Risk Level: Very Low. Type: Worm.

Western Australia’s Web votes have security worries, say ‘white hat’ mathematicians
US Marines seek a few supposedly good men … who leaked naked pics of a few good women
DOJ Dismisses Playpen Case to Keep Tor Hack Private

security update

Spammer’s Leaky Backup Exposes Massive Empire

LinuxSecurity.com: Security fix in CA certificate chain verification (better check untrusted CAcertificates from peer, more strict error handling).

Destructive StoneDrill Wiper Malware On The Loose
Meet StoneDrill Malware Destroying Everything on Infected Computers

Talks of integration are often met with audible sighs of displeasure. It’s a lot of work. You have to combine various platforms, software, and the list goes on. At Webroot, we decided to take some of the pain out of this process by partnering with Kaseya to deliver a fully integrated endpoint security solution for […]

‘Dozens’ of police departments maintain private DNA databases

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for CVE-2017-3135 (unaffected), fixes regression made byCVE-2016-8864

LinuxSecurity.com: Security fix for CVE-2017-2626

LinuxSecurity.com: Security fix for CVE-2017-2625

LinuxSecurity.com: Security fix for CVE-2017-5884, CVE-2017-5885

LinuxSecurity.com: Security fix for CVE-2016-9299

LinuxSecurity.com: Security fix for CVE-2016-9299

LinuxSecurity.com: Security fix for CVE-2017-6410

LinuxSecurity.com: Security fix for CVE-2017-6410

LinuxSecurity.com: Security fix for CVE-2017-3135 (unaffected), fixes regression made byCVE-2016-8864

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: new upstream release 2.5.3, fixing leaks

News in brief: Facebook tags ‘disputed’ news; products to be judged on security; smart meters snafu
Hackers could bypass protective measures to gain access to locked Twitter accounts
Uber under fire for ‘Greyball’ program used to dodge enforcement officials
Microsoft Bug Bounty Program: Report Vulnerabilities, Get up to $30,000
Bruce Schneier on IoT Regulation
Third party patch released for Microsoft zero-day that Google made public
10 ways to ruin a cybercriminal’s day

Technology is affecting our relationships and changing our lives, but are we taking the necessary measures to protect ourselves online? Here’s how to outsmart cybercriminals. The post 10 ways to ruin a cybercriminal’s day appeared first on WeLiveSecurity

Ex penetrated us almost 700 times through secret backdoor, biz alleges
Realistic crisis simulations are the backbone of cyber preparedness – ENISA plays a role in EU cyber preparedness
Google, Microsoft bump bug bounties
1.37bn records from somewhere to leak on Monday
Is Obama planning a coup? Yes, says Google Home
1 Million Decrypted Gmail and Yahoo Accounts Being Sold on Dark Web
Hackers Using Unmonitored System Tools, Protocols for Malicious Goals
Telegram lets scammers connect directly with potential victims by way of stored contacts
Someone hacked this billboard in Mexico and defaced with porn video

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Worm.

IoT of toys stranger than fiction: cybersecurity and data privacy update

The Internet of Stranger Things came to life in the recent case of a cuddly connected toy, raising wider and deeper questions about cybersecurity, privacy, and the future of digital technology. The post IoT of toys stranger than fiction: cybersecurity and data privacy update appeared first on WeLiveSecurity

South Korean Retail Giant Lotte’s Website Hacked After US Military Deal
New Fileless Attack Using DNS Queries to Carry Out PowerShell Commands

security update

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Robots can be hacked, exploit to kill people, spy on military secrets: Researchers
Pence v Clinton: Both used private email for work, one hacked, one accused of hypocrisy