Menu

Latest articles

What is Cyber Deception?
Revealed: Web servers used by disk-nuking Shamoon cyberweapon
Organizations ‘concerned by cybersecurity skills gap’

The ongoing cybersecurity skills gap is dealing a significant blow to the confidence of organizations looking to defend themselves against potential attacks. The post Organizations ‘concerned by cybersecurity skills gap’ appeared first on WeLiveSecurity

Crypto-curious? Wickr’s opened its kimono for code review
ITU ponders whether blockchain belongs in its security standards
As Microsoft touts Windows Insider for biz, let’s take a look at W10’s broken 2FA logins
Setting Expectations Between States on Cyberwar
Republicans send anti-Signal signal to US EPA
OK, it’s time to talk mass spying again: America’s Section 702 powers are up for renewal
Cerber ransomware takes special care not to encrypt security product files
World’s Sturdiest Phone Nokia 3310 To Be Relaunched this Year
Rasputin whips out large intimidating tool, penetrates uni, city, govt databases – new claim
Verizon! surprisingly! OK! with! Yahoo! despite! mega-hack!

The City of San Diego is the 8th largest city in the US and has over 12,000 employees, numerous vendor partnerships, as well as a vast array of diverse systems and devices to protect. In addition to more traditional endpoints and data centers, the City must protect each new piece of smart technology it implements. These […]

News in brief: Nokia to reboot iconic phone; AI assistants set to do voice calls; Yahoo, Verizon ‘agree price’

LinuxSecurity.com: Qemu: net: mcf_fec: infinite loop while receiving data in mcf_fec_receive[CVE-2016-9776] Qemu: audio: memory leakage in ac97 [CVE-2017-5525] Qemu: audio:memory leakage in es1370 device [CVE-2017-5526] oob access in cirrus bitblt copy[XSA-208, CVE-2017-2615]

LinuxSecurity.com: – update to the latest upstream pre-release (fixes CVE-2016-9179)

LinuxSecurity.com: The newest upstream commit, fixing CVE-2017-5953 vim: Tree length values notvalidated properly when handling a spell file

LinuxSecurity.com: Security fix for CVE-2016-7922, CVE-2016-7923, CVE-2016-7924, CVE-2016-7925,CVE-2016-7926, CVE-2016-7927, CVE-2016-7928, CVE-2016-7929, CVE-2016-7930,CVE-2016-7931, CVE-2016-7932, CVE-2016-7933, CVE-2016-7934, CVE-2016-7935,CVE-2016-7936, CVE-2016-7937, CVE-2016-7938, CVE-2016-7939, CVE-2016-7940,CVE-2016-7973, CVE-2016-7974, CVE-2016-7975, CVE-2016-7983, CVE-2016-7984,CVE-2016-7985, CVE-2016-7986, CVE-2016-7992, CVE-2016-7993, CVE-2016-8574,CVE-2016-8575, CVE-2017-5202, CVE-2017-5203, CVE-2017-5204, CVE-2017-5205,CVE-2017-5341, CVE-2017-5342, CVE-2017-5482, CVE-2017-5483, CVE-2017-5484,CVE-2017-5485, CVE-2017-5486

LinuxSecurity.com: Security fix for CVE-2017-3135

LinuxSecurity.com: The 4.9.9 update contains a number of important fixes across the tree

LinuxSecurity.com: Security fix for CVE-2017-2586, CVE-2017-2587 and CVE-2017-5849, —- Addlicense information file copyright_summary —- New version of netpbm isavailable (10.77.00)

LinuxSecurity.com: Rebase to latest upstream gitrev 20161120

Government focuses on young people to tackle cyberskills shortage

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Fake news: what can we all do to play our part in combating it?
Turning Tables on Nigerian Business Email Scammers
UK credit broker fined £120k for spamming folk with five million texts
Security researchers trick ‘CEO’ email scammer into giving up identity
Google Touts Progress in Android Security in 2016
‘World’s eighth-worst spammer sent more than a million emails’
Man sues Uber after privacy flaws ‘led to his divorce’
Pwnd Android conference phone exposes risk of spies in the boardroom
Proof-of-concept ransomware to poison the water supply
Kremlin-linked hackers believed to be behind Mac spyware Xagent
No Firewalls, No Problem for Google
RSA 2017: Deconstructing macOS ransomware

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

Forget quantum and AI security hype, just write bug-free code, dammit
New Chinese Cybersecurity Threats

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

Google claims ‘massive’ Stagefright Android bug had ‘sod all effect’

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

Meet LogicLocker: Boffin-built SCADA ransomware
Inside Confide, the chat app ‘secretly used by Trump aides’: OpenPGP, OpenSSL, and more
DHS Chairman Paints Bleak US Cybersecurity Picture
Schneier Brings Campaign for IoT Regulation to RSA
ASLR-security-busting JavaScript hack demo’d by university boffins
Apple: Don’t panic, but your Mac can be pwned via GarageBand .bands
PayPal users hit with “Payment Successfully Made Via Ali Express” Phishing Scam
‘We need a new Geneva Convention to protect all citizens from snoops’
Bruce Schneier: The US government is coming for YOUR code, techies
Cryptographers Dismiss AI, Quantum Computing Threats
No crypto backdoors, more immigration … says Republican head of House Committee on Homeland Security

security update

security update

security update

Roses are red, bugs make you blue, Patch Tuesday is late, because Microsoft loves you
News in brief: flying cabs for Dubai; UK hit by cyberattacks; Googlers quit after earning too much money
Someone DDoSed A University Server By Hacking Its Vending Machines
Microsoft’s president wants a Geneva Convention for cyberwar
Adobe Patches 13 Code Execution Vulnerabilities in Flash
Sage 2.0 ransomware wants to be just like Cerber when it grows up
No, you can’t get Verizon Unlimited free for 12 months
Nation States Distancing Themselves from APTs
IBM’s Watson teams up with its SIEM platform for smarter, faster event detection
65% of IT professionals feel Shadow IT is compromising cloud security
Battle of the botnets: My zombie horde’s bigger than yours
Ransomware attackers shift focus and resources to high-value sectors
Twitter stumbles on safety feature as users push back
The Rise of Fileless Malware: Over 100 Telecoms, Banks, Gov’t Orgs Under Attack
Researcher develops ransomware attack that targets water supply
CrowdStrike attempts to sue NSS Labs to prevent test release, court denies request

We’re not telling you anything new when we say that malware continues to pose a major challenge for businesses of all sizes. Polymorphism, in particular, is especially dangerous. Polymorphic executables constantly mutate without changing their original algorithm, meaning the code can change itself each time it replicates, even though its function never changes at all. […]

Worried about hacks, senators want info on Trump’s personal phone
New Android trojan mimics user clicks to download dangerous malware

Android users are exposed to a new malicious app imitating Adobe Flash Player and serving as an entrance gate for potentially any kind of dangerous malware The post New Android trojan mimics user clicks to download dangerous malware appeared first on WeLiveSecurity

Google search results are falling foul of scammers spoofing well-known sites
UK website data insecurity worries: Users in bits over car break-up emails
ILOVEYOU: The wrong kind of LoveLetter

A game with love: How the LoveLetter virus corrupted our tech by playing on our emotions. The post ILOVEYOU: The wrong kind of LoveLetter appeared first on WeLiveSecurity

Border guards force US citizen to unlock his NASA-owned work phone
Newly discovered flaw undermines HTTPS connections for almost 1,000 sites
Infrastructure under attack: The next ransomware wave
Prepare for the smart bot invasion

For most of my professional life, the term “bot” has been associated with badness. As a computer security professional, whenever I saw bots involved, they were usually committing malicious acts and harnessing hundreds or thousands of otherwise innocent devices and computers to engage in harmful deeds.But that will change as good bots become more common, […]

Android Banking Trojan Marcher Infects Devices to Steal Payment Cards
Valentine’s day: what’s your secret technology crush?
The Register’s guide to protecting your data when visiting the US
SaaS-y security outfit CrowdStrike falls out of love with test lab
Senators raise concerns over Donald Trump’s smartphone security
Roses are red, you’re over the moon, ‘cos you work in infosec, and you’re retiring soon
Explain! yourself! US! senators! yell! at! Yahoo!
Infosec pros aren’t too bothered by Trump – it’s his cabinet sidekicks you need to worry about
WTF is up with the W3C, DRM and security bods threatened – we explain
IT bosses: Get budgets for better security by rating threats on a scale of zero to Yahoo!
Smashing Security podcast: Using public Wi-Fi
Teacher Being Investigated for Exposing 7th Graders to Porn
Lazarus mob possibly behind malware attacks against Polish banks
Mozilla says Firefox Klar does not Collect User Data from iOS Devices
News in brief: Cook hits out at ‘fake news’; Trump under fire; flying cars on the runway