Menu

Latest articles

Apple kills activation lock check, possible dirty stolen device hack
Infosec industry to drive machine learning spend surge says analyst
You’re taking the p… Linux encryption app Cryptkeeper has universal password: ‘p’
WTF is your problem, Netgear? Another hijack hole found in its routers

LinuxSecurity.com: An update for nagios is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for nagios is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for nagios is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for nagios is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

With net neutrality pretty much dead in the US, your privacy is next

security update

Forgot your GitHub password? Facebook cooks up spec to reset logins via social network
Hundreds of Thousands of Netgear Routers Vulnerable to Password Bypass

LinuxSecurity.com: Security Report Summary

Fake Netflix, WhatsApp, Facebook Android Apps Contain SpyNote RAT
Facebook Tackles Account Recovery with Delegated Recovery Protocol

security update

Telemarketing Firm Leaks 400,000 Recorded Calls
Ransomware avalanche at Alpine hotel puts room keycards on ice
News in brief: DC cameras hacked; Trump ‘unprepared’ for Russian cyberattacks; fake news probed
Ransomware attack impacted 70% of Washington DC police surveillance cameras

LinuxSecurity.com: Update to 6.2.4

LinuxSecurity.com: Update to Firefox 51.0.1. —- – new upstream version (51.0.1)

LinuxSecurity.com: Security fix for CVE-2016-10164

LinuxSecurity.com: This is a security update for these CVEs: *[CVE-2016-9601](https://bugzilla.redhat.com/show_bug.cgi?id=1410021) – *Heap-buffer overflow in jbig2_image_new function* This update also solves possiblelicensing issues with ghostscritpt’s source code.

LinuxSecurity.com: Update to 7.0.4

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: A null pointer dereference in libpng might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in SQUASHFS, the worst of which may allow execution of arbitrary code

LinuxSecurity.com: An integer overflow in libXpm might allow remote attackers to execute arbitrary code or cause a Denial of Service Condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in FFmpeg, the worst of which may allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: A vulnerability in Firewalld allows firewall configurations to be modified by unauthenticated users.

GDPR is just over a year away – and many firms are nowhere near ready
Ransomware disrupts Washington DC’s CCTV system
Many Android VPN Apps Breaking Privacy Promises
Sex club for women exposes members’ private photographs
70% of DC Police CCTV cameras were hacked before presidential inauguration
How a single SMS can break your Samsung Galaxy Android phone
Hackers Infect Hotel Door Lock System with Ransomware
Barclays warns customers of the risks of business email compromise
Has President Trump’s executive order on ‘Public Safety’ killed off Privacy Shield?
Questions to ask your recovery vendor before you buy
How most hackers get into systems
Managing risk by understanding attack surfaces
Trump’s immigration move sparks fears for Privacy Shield protections
Some examples of vulnerable code and how to find them

“When looking for vulnerabilities in open-source code, it is advisable to check portions of code that is prone to errors”: Useful tips from one of ESET’s malware analysts, Matías Porolli, on how to spot vulnerable code. The post Some examples of vulnerable code and how to find them appeared first on WeLiveSecurity

UK Cybersecurity: Permanent job salaries growing faster than contractor pay rises
Man logs into Facebook account of the woman using his stolen laptop
Google moves into the Certificate Authority business
Big Blue’s BigInsights has big-ish bugs
Marketing company leaks 17,000 recorded phone calls, many with credit card numbers
Hotel guests locked in their rooms by ransomware? It doesn’t make sense
Ransomware killed 70% of Washington DC CCTV ahead of inauguration
WordPress slips out three quick patches
Cisco TelePresence control software had remote-exploitable bug
Linux devices with standard settings infected by Linux.Proxy.10 malware

LinuxSecurity.com: Multiple vulnerabilities have been found in Perl, the worst of which could allow remote attackers to execute arbitrary code.

security update

security update

38% of Android VPN Apps on Google Play Store Plagued with Malware

LinuxSecurity.com: Update to the latest stable version. See https://ikiwiki.info/news/ for the listof changes. Security fix for CVE-2016-10026, CVE-2016-9646, CVE-2017-0356.

LinuxSecurity.com: Fix validation logic in the base consumer The base consumer is intended to onlyderive its validation switch from the on-disk configuration if the child classdoesn’t override the validate_signatures switch. There was a bug here where thedefault value provided in the base class made it appear as if *all* childconsumers had turned *off* validation, which […]

LinuxSecurity.com: Update to the latest stable version. See https://ikiwiki.info/news/ for the listof changes. Security fix for CVE-2016-10026, CVE-2016-9646, CVE-2017-0356.

LinuxSecurity.com: New mozilla-thunderbird packages are available for Slackware 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for puppet-swift is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

Facebook Launches “Security Key” Feature to Protect User Accounts
Cisco Warns of Critical Flaw in Teleconferencing Gear
VPN on Android means ‘Voyeuristic Peeper Network’ in many cases

security update

Wow, look out, hackers: Trump to order 60-day cybersecurity probe
WordPress 4.7.2 Update Fixes XSS, SQL Injection Bugs
OpenSSL issues new patches as Heartbleed still lurks
LeakedSource data breach website goes offline following alleged police raid
Dridex Returns With Windows UAC Bypass Method

Major Dark Web Marketplace Hacked Recently, a hacker using the alias cypher0007 reached out to AtlasBay, a large dark web market, with information on two significant vulnerabilities that allowed him to access over 200,000 private messages, names, and addresses. Along with retrieving a good amount of buyer and seller information, the hacker also revealed that […]

News in brief: Fancy Bear ‘attacked TV network’; Lavabit comes back to life; museum does geek history
Raise your glasses! Wine is 2.0!
Threatpost News Wrap, January 27, 2017
Google to Operate its Own Root CA
Texas cops lose evidence going back eight years in ransomware attack
National Audit Office: UK’s military is buying more than it can afford
Trump’s attorney-general choice wants to ‘overcome encryption’
Google launches root certificate authority
US and Russia engaged in legal tug of war over LinkedIn hack suspect
Pay for experts to rise as cybercrime ‘to cost $6tn a year by 2021’
That Hearbleed problem may be more pervasive than you think
Securing MySQL DBMS
Breach Notification Website LeakedSource Allegedly Raided, Shut Down
Smashing Security podcast #005: ‘Upskirt insecurity’
218,000 private unencrypted AlphaBay dark web messages exposed
Celebgate hacker who stole nude photos gets nine months in jail
An introduction to private browsing

Privacy and security fears are driving many people to look into the possibilities of private browsing. We investigate what it is and how you stay anonymous online The post An introduction to private browsing appeared first on WeLiveSecurity

Sednit: How this notorious cyberespionage group operates

Take a closer look at the cyberespionage group Sednit, which has targeted over 1000 high-profile individuals and organizations with phishing attacks and zero-day exploits. The post Sednit: How this notorious cyberespionage group operates appeared first on WeLiveSecurity

No, disabling your anti-virus software does not make security sense
Trump administration is giving us a good lesson on Twitter security
Data Privacy Day: know the risks of Amazon Alexa and Google Home
Facebook taps FIDO U2F for stronger login security
Worrying about data privacy isn’t enough: Here’s how to own your online presence

ESET’s Ondrej Kubovič: “Worrying about privacy isn’t enough” – here’s how to control your data privacy and online presence. The post Worrying about data privacy isn’t enough: Here’s how to own your online presence appeared first on WeLiveSecurity

PayPal users targeted in sophisticated new phishing campaign

Recent phishing scams targeted both Gmail and Yahoo, and now attackers have their sights set on PayPal with some very convincing bait. The post PayPal users targeted in sophisticated new phishing campaign appeared first on WeLiveSecurity