Menu

Latest articles

News in brief: Virginia greenlights delivery bots; Line to launch AI assistant; Uber seeks licence

LinuxSecurity.com: An update for python-oslo-middleware is now available for Red Hat OpenStack Platform 9.0 (Mitaka). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for ipa is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

HackerOne Offers Open Source Projects Free Access to Platform
Amazon mega-outage caused by single command line error
Google to Protect Mac Chrome Users with Additional “Safe Browsing” Alerts
Secrets of the Filecode ransomware revealed
Cybersecurity rules toughened up for NY financial firms

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. Boeing Informs Workers of Data Breach Am I surprised there’s another data breach in the news […]

Apple pushing two-factor authentication for iOS 10.3 users
Threatpost News Wrap, March 3, 2017
Slack quick to whack account hijack crack
Yahoo CEO forgoes annual bonus, worth millions, over security breaches

Yahoo’s Marissa Mayer has missed out on $2m from her annual bonus due to her management of security breaches affecting billions of users. The post Yahoo CEO forgoes annual bonus, worth millions, over security breaches appeared first on WeLiveSecurity

Researcher uses Google’s speech tools to skewer Google reCAPTCHA
Mike Pence used personal AOL account for government business as Indiana governor
RAF pilot awaits sentence for digicam-induced airliner dive
Bletchley Park: Training the next the generation of cybersecurity codebreakers

Bletchley Park, considered to be the birthplace of modern computing, is to train the generation of cybersecurity codebreakers. The post Bletchley Park: Training the next the generation of cybersecurity codebreakers appeared first on WeLiveSecurity

A Minor Typo Brought the Entire Internet Network of Amazon Down
UK’s first Investigatory Powers Commissioner: Lord Justice Fulford
Howard Schmidt’s Legacy of Service Remembered
MWC: These might be the droids you are looking for
Awkward. Investigatory Powers Act could prove hurdle to UK-EU Privacy Shield following Brexit
Pence used private mail for state work as governor, and account was hacked
Free decryption tools now available for Dharma ransomware
Howard A Schmidt remembered as a ‘humble’ industry giant
Nearly 1m Coachella user details potentially accessed in breach
This old ransomware variant is back – with sneaky new tricks
Three Years after Heartbleed, How Vulnerable Are You?
9 secrets to cyberattack survival
132 Android apps found in the Google Play Store exploiting malicious iFrames

Locky (.osiris) O Locky, Locky! Wherefore art thou, Locky? Alas, could Locky be no more? At the beginning of 2017, data from the field suggested potential Locky infections had decreased dramatically, so we were hoping it was on its way out. Unfortunately, Locky returned with a vengeance, though it had changed its methods somewhat. Upon […]

SHA-1 crack just got real: System Center uses it to talk to Linux

Don’t Let Tax Season Scammers Steal Your Refund! This time of year, most of us are probably still dreading the moment we have to quit procrastinating, buckle down, and file our income taxes. Coincidentally, it’s also a time that cybercriminals are working overtime to scam home users into giving over their financial data, and even […]

LinuxSecurity.com: Security fix for CVE-2017-2625

LinuxSecurity.com: The 4.9.13 update contains a number of important fixes across the tree

LinuxSecurity.com: The 4.9.13 update contains a number of important fixes across the tree.

LinuxSecurity.com: WARNING: Please note that this update comes with a slightly different syntax ofsesman.ini file, so if you edited this file by hand, you may need to look at the.rpmnew file and merge any required changes by hand. This release also createsthree files in /etc/xrdp directory if they don’t already exist or are empty: -rsakeys.ini […]

Hundreds of Android Apps on Google Play Store Infected with Windows Malware
DDoS attack pummels Luxembourg state servers
How Threat Modeling Helps Discover Security Vulnerabilities

security update

Cisco Warns of High Severity Bug in NetFlow Appliance
WordPress Plugin NextGEN Gallery Vulnerable to SQL Injection Attack

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability.

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support and Red Hat Enterprise Linux 6.5 Telco Extended Update Support. [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.2 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

132 Google Play Apps Booted For Malicious IFrames
News in brief: AI boost to video streaming; Mayer loses bonus; move to tackle comment trolls
Ransomware roundtable: Is this the new spam?
Cloudflare chief pledges third-party review of code
Keys for Dharma Ransomware Released
Cloudbleed Triggered 1.2M Times, Damage Kept to Minimum
Poor robot security could lead to ‘Skynet’ nightmare, warn researchers
Chrome for MacOS to block rogue ad injections and settings changes
Yahoo Tells SEC Executives Failed to Act on Breach
Android Password Manager You Trust Could be Exposing Login Data
We found a hidden backdoor in Chinese Internet of Things devices – researchers
FCC halts data security regulations for broadband providers
Why Internet of Things is the world’s greatest cyber security threat
Yahoo execs botched its response to 2014 breach, investigation finds
Google reCaptcha Bypass Technique Uses Google’s Own Tools
Twitter scrambles those anonymous account eggs
Smashing Security #010: The dolls must be destroyed
Famed Hacker Kevin Mitnick Shows You How to Go Invisible Online
Researchers find “severe” flaw in WordPress plugin with 1 million installs
Over a million websites could be at risk from critical WordPress gallery plugin flaw
Dark net webmail provider Sigaint still in the, er, dark
Major internet safety strategy to ‘bolster online safety’ for children in the UK

The UK is developing an internet safety strategy in an attempt to secure a position as “the safest place in the world for young people to go online”. The post Major internet safety strategy to ‘bolster online safety’ for children in the UK appeared first on WeLiveSecurity

Chatting with David Dufour, senior director of engineering, Webroot, is always interesting. Quite frankly, so is pinning him down for a short Q+A  about his experience at RSA 2017. One thing I could be sure of, though, was David having an opinion and being a straight shooter. As a first time attendee, I was curious […]

LinuxSecurity.com: Security Report Summary

Yahoo! dysfunction! meant! security! warnings! were! ignored!
Slack only took five hours to fix bug that could have allowed hackers to hijack your account

LinuxSecurity.com: Security Report Summary

Yahoo CEO Marissa Mayer will miss out on cash bonus after security breaches

security update

Come see me speaking at The Shard in London about security
Online shops plundered by bank card-stealing malware after bungling backend Aptos hacked
US-Europe Privacy Shield not worth the paper it’s printed on – civil liberties groups
Old Windows malware may have tampered with 132 Android apps
WordPress photo plugin opens ‘a million sites’ to SQLi database feasting
CloudPets Notifies California AG of Data Breach

security update

LinuxSecurity.com: The newest upstream commit, CVE-2017-6350 vim: Integer overflow at anunserialize_uep memory allocation site, CVE-2017-6349 vim: Integer overflow at au_read_undo memory allocation site

LinuxSecurity.com: fix CVE-2017-3156 (rhbz#1425455,1425458)

Slack Fixes Cross-Origin Token Theft Bug

LinuxSecurity.com: Security fix for CVE-2017-2586, CVE-2017-2587 and CVE-2017-5849, —- Addlicense information file copyright_summary —- New version of netpbm isavailable (10.77.00) —- add missing directives about bundled librariesjasper and jbigkit —- New version of netpbm is available (10.76.00)

LinuxSecurity.com: An update for openstack-puppet-modules is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for openstack-puppet-modules is now available for Red Hat OpenStack Platform 9.0 (Mitaka). Red Hat Product Security has rated this update as having a security impact [More…]

News in brief: AWS fail hits services; YouTube launches streaming service; Windows gets ‘walled garden’ option

LinuxSecurity.com: Security Report Summary

Unholy trinity of AKBuilder, Dyzap and Betabot used in new malware campaigns
Robots Rife With Cybersecurity Holes
Software engineer detained at JFK airport; forced to prove he is really an engineer
Is E2EMail a new beginning or the end for Google’s End-to-End?