Menu

Latest articles

The essential guide to MongoDB security
How to predict the next major hack
Netherlands reverts to hand-counted votes to quell security fears
Wanna protect your data center? Take tips from the US Secret Service
Bring out your dead! Firm wants to pay big bucks for old bugs
WordPress fixed god-mode zero day without disclosing the problem

Twitter is buzzing with chatter about the RSA Conference 2017 (RSAC). Attendees, vendors, and speakers alike are anxiously awaiting the opportunity to discuss information security and the latest technology at the largest security conference in the world. Attending RSAC? Here’s what you should know about Webroot. What’s new with Webroot in 2017 Today, we announced […]

Home-pwners: Cisco’s Prime Home lets hackers hijack people’s routers, no questions asked
WordPress Websites Exposed to Severe Content Injection Vulnerability

security update

security update

Fear not, Europe’s Privacy Shield is Trump-proof – ex-FTC bigwig
HTTPS Hits 50 Percent Traffic Milestone
New security flaws can turn Netgear Routers into army of botnets
Latest Ubuntu Update Includes OpenSSL Fixes

Type: Vulnerability. Microsoft SQL Server is prone to a privilege-escalation vulnerability; fixes are available.

GitLab database goes out after spam attack
Google upgrades G Suite with tools for IT pros
Easing of security checks at remote Scottish airports ‘a risk’

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: A vulnerability in Ansible may allow rogue clients to execute commands on the Ansible controller.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.2 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. [More…]

Federal Reserve staffer caught mining bitcoins at work fined $5,000
Over half of US citizens ‘have experienced a data breach’

A significant number of US citizens have experienced a data breach and are concerned over the security of their personal information, a study reveals. The post Over half of US citizens ‘have experienced a data breach’ appeared first on WeLiveSecurity

News in brief: 2.5m gamers’ details stolen; Google chokes on NHS traffic; Facebook moves on fake news

Risk Level: Very Low. Type: Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

PSP and Xbox Forums Hacked; 2.5 Million User Accounts Stolen
Draft of Trump’s cybersecurity plan emerges. Here’s what experts think
Eight years’ worth of police evidence wiped out in ransomware attack
Zimperium Program Buys Exploits for Patched Mobile Vulnerabilities
Why you shouldn’t trust baby health monitors
Nested, Targeted Attacks Built for Reconnaissance
Reports claim Spanish police have arrested hacker Phineas Fisher
Trump Cyber Executive Order Calls for 60-Day Review
Facebook takes steps to boost password recovery security
New malware stealing login data, bitcoin from cryptocurrency wallets
Google mistakes the entire NHS for massive cyber-attacking botnet
Half the Web Is Now Encrypted. That Makes Everyone Safer
Sniff out and kick out Windows malware for free

LinuxSecurity.com: Security Report Summary

Cyber-spying, leaking to meddle in foreign politics is the New Normal
What’s the difference between you and a sea slug? When it comes to IT security, nothing
Cerber tops Windows 10 ransomware charts
We need to talk about Granny: She’s way more likely to fall for phishing

LinuxSecurity.com: An update for libtiff is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

Dark web hubs paying workers to leak corporate secrets

security update

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Conflicting Reports Suggest Phineas Fisher (HackBack) Arrested in Spain
Trump stresses cybersecurity but postpones executive order
Trump hits control-Z on cybersecurity order: No reason given for delay

LinuxSecurity.com: Multiple vulnerabilities have been found in PCSC-Lite, the worst of which could lead to privilege escalation.

Flaws Found in Popular Printer Models
Human memory, or the lack of it, is the biggest security bug on the ‘net
Password-stealing security hole discovered in many Netgear routers

LinuxSecurity.com: flatpak 0.8.2 release, fixing a security issue that could lead to sandboxescaping. For details, see https://github.com/flatpak/flatpak/releases/tag/0.8.2

LinuxSecurity.com: The 4.9.6 stable kernel update contains a number of important fixes across thetree.

LinuxSecurity.com: This is an security update fixing CVE-2017-5193, CVE-2017-5194, CVE-2017-5195,CVE-2017-5196, CVE-2017-5356.

LinuxSecurity.com: A heap-buffer overflow vulnerability was discovered in pycrypto leading toarbitrary code execution. All users of pycrypto’s AES module that allow the modeof operation to be specified by an attacker, check for ECB explicitly and createthe objects without specifying an IV are vulnerable to this issue. This isCVE-2013-7459.

LinuxSecurity.com: The 4.9.6 stable kernel update contains a number of important fixes across thetree.

LinuxSecurity.com: This is an security update fixing CVE-2017-5193, CVE-2017-5194, CVE-2017-5195,CVE-2017-5196, CVE-2017-5356.

Ugly Password Gaffe Plagues Cryptkeeper Encryption App
Cocker Hill’s PD held to ransom by hackers; crucial digital evidence lost
Facebook steps up security by allowing physical keys for log-in
News in brief: Witcher user details stolen; email chain generated 500m messages; Russians face treason charges
Trump to sign cybersecurity order calling for government-wide review
Suffered a breach? Expect to lose cash, opportunities, and customers – report
Austrian hotel experiences ‘ransomware of things attack’

Only one month into the new year, it appears that we may well have our first example jackware in 2017 with a ransomware of things attack on an Austrian hotel. The post Austrian hotel experiences ‘ransomware of things attack’ appeared first on WeLiveSecurity

Security professionals shortage in UK ‘increasing competition among companies for talent’

IT security professionals are at the forefront of the demand from companies across the UK, many of whom have placed greater demand on tech skills. The post Security professionals shortage in UK ‘increasing competition among companies for talent’ appeared first on WeLiveSecurity

Security execs voice concern over Trump travel ban
Telemarketing firm leaks 17,000 recorded calls, many containing credit card details
Nicolas Brulez on Malware Reverse Engineering Tips and Tricks
Another Radio Station Transmission hacked with F*** Donald Trump Songs
‘I’m not a robot’ verification test beaten by … a robot
Privacy worries are on the rise, new U.S. poll shows
Cybersecurity: 5 basic lessons for everyone

A new way of looking at cybersecurity, no longer viewing it as a goal in itself, but instead something that is directly connected to business needs. The post Cybersecurity: 5 basic lessons for everyone appeared first on WeLiveSecurity

Facebook, GitHub teams up to make password resets more secure
NATO Members Targeted by Unique Macro Malware
We see you, ransomware flingers, testing out your baddest stuff on… Germany?
Do I have to hand over bank and social media details at the US border?
MongoDB ransom attacks continue to plague administrators
Better security through obscurity? Think again

When attackers look for vulnerabilities, they target popular software. Why bother chasing flaws in applications that few people use? That’s why one of my best friends runs a third-party application instead of Adobe Acrobat Reader to open and read PDF documents. Another friend runs the Maxthon browser to stay out of the way of exploits […]

Ransomware: Key insights from infosec experts

Ransomware is not going anywhere. Here, we’ve rounded up vital tips and advice from three ESET experts: Lysa Myers, Stephen Cobb and David Harley. The post Ransomware: Key insights from infosec experts appeared first on WeLiveSecurity

Want to bring down that pesky drone? Try the power of sound

LinuxSecurity.com: Multiple vulnerabilities have been found in HarfBuzz, the worst of which could allow remote attackers to cause a Denial of Service condition.

We don’t want to alarm you, but PostScript makes your printer an attack vector
Google’s Chrome is about to get rather in-your-face about HTTPS
VMware’s enterprise mobility management tool can p0wn itself
OpenSSL pushes trio of DoS-busting patches