Menu

Latest articles

Police mull gathering crime evidence from smart home devices
PHPMailer could put your website at risk: here’s what you need to know

Risk Level: Very Low. Type: Trojan.

If you’re anything like me, you probably make a bunch of lofty resolutions every year that you probably won’t, or even can’t, achieve. (For instance, I’ve been promising to hit the gym a little harder for about 6 years now.) But enough is enough. Here are 5 completely achievable resolutions to help keep you and […]

CNN Report Shows Fallout 4 Screenshots to Explain Russian Hacking Scheme
New Android-infecting malware brew hijacks devices. Why, you ask? Your router
How to remove ransomware from your LG Smart TV
Apple sued over fatal FaceTime car crash
Deprecation of Insecure Algorithms and Protocols in RHEL 6.9
Data breaches through wearables put target squarely on IoT in 2017
Claims that Russia hacked the US election and power grid are ‘overblown’
Weekly review – the hot 13 stories of the week
How to tell if your Snapchat has been hacked, and how to get it back
Army social media psyops bods struggling to attract fresh blood
Better authentication: Go get 'em, FIDO

Only a handful of industry associations accomplish what they set out to do. In the security realm, I’ve always been a huge fan of the Trusted Computing Group. It’s one of the few vendor organizations that truly makes computers more secure in a holistic manner. The Fast Identity Online (FIDO) Alliance is another group with lots […]

LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla Firefox, SeaMonkey, and Thunderbird the worst of which could lead to the execution of arbitrary code.

Programmer finds way to liberate ransomware’d Google Smart TVs
Libpng library gets fix for truly ancient bug
Hate ‘contact us’ forms? This PHPmailer zero day will drop shell in sender
Android tops 2016 vuln list, with 523 bugs
Russian ‘grid attack’ turns out to be a damp squib
Top Secret -cleared SOCOM staff in 11GB Govt contractor breach

security update

5 Premium VPN Services To Access HULU Outside The US
Philippine Military Website Hacked and Defaced
Latest iMessage Hack Crashes iPhone within Minutes
A lesson from network outages: Redundancy matters
Cyber-savvy New Year’s resolutions you’ll want to keep

Put cyber security at the top of your New Year’s resolution list for 2017, implementing a digital detox and improving your online behaviors. The post Cyber-savvy New Year’s resolutions you’ll want to keep appeared first on WeLiveSecurity

Russian Malware Found in Vermont Electricity Department Laptop
Anonymous Hacks, Defaces Bilderberg Group Website Against World Crisis

security update

OurMine Group Hacks Nat Geo Photography’s Twitter Account
New Malware Poses as Android Client to Infect Wi-Fi Networks and Hijack DNS
FBI-DHS Report Links Fancy Bear Gang to Election Hacks
News in brief: US raps Russian hacking; internet clampdowns ‘cost $2.4bn’; AR move to track lost items
Pakistan automotive giant PakWheels Hacked, 700k accounts stolen
Uber, Apple Maps and location tracking: what’s really going on?
Hedge fund turns to AI to navigate through the maze
Lithuania says Russian spyware infected government computers

  Ransomware “Star” Shines on LG Smart TV As ransomware continues to steal the malware stage, its authors have widened their target audience to include smart devices, such as TVs. Since a number of smart TVs use Android® operating systems, they can be susceptible to the same Android malware that usually strikes mobile devices. Recently, […]

The 10 biggest security incidents of 2016

In 2016, companies have had their security solutions tested by increasingly sophisticated cybercriminals. We look at the year’s biggest security incidents. The post The 10 biggest security incidents of 2016 appeared first on WeLiveSecurity

In deep: the internet’s underwater weak links
What 2017 has in store for cybersecurity
The shocking failure in how the FBI warned the DNC that it had been hacked
Obama expels 35 Russian spies over election hacking
Who helped Russia “hack” the US election? It might have been you…
Beware: Facebook collects data about your offline life through data brokers

Why wait for news on the next big thing in technology, when you can get a sneak peek at the hottest, up-and-coming consumer tech and innovations at CES 2017? For the last 50 years, the yearly CES event has served as a showcase and springboard for the latest advancements in tech as they enter the […]

Anonymous Hacks Thai LA Consulate to Protest Arrests and Cyber Law

LinuxSecurity.com: A vulnerability in mod_wsgi could lead to privilege escalation.

Retailers! Avoid getting hacked during the holiday season (or any other time of the year)

Tips for cash-strapped retailers looking to avoid getting hacked, during the holiday shopping season, or any other season. The post Retailers! Avoid getting hacked during the holiday season (or any other time of the year) appeared first on WeLiveSecurity

PHPMailer, SwiftMailer Updates Resolve Critical Remote Code Execution Vulnerabilities
Microsoft May Stop Forcing You to Upgrade to Windows 10
News in brief: marijuana breach; Amazon moots airships; Firefox winds down for XP, Vista
Threatpost 2016 Year in Review
Your new year’s resolution: get ready for GDPR
Meet the Leet DDoS Botnet, Just as Powerful as Mirai
Sultry Sextortion Sisters Meet Their Match In Nigerian Oil Billionaire
Welcome to America. Now, what’s your Twitter handle?
Guest post: Whose genes are they anyway?
5 signs we’re finally getting our act together on security
5 key technologies to double down on now

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: New python packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: New samba packages are available for Slackware 14.2 and -current to fix security issues. [More Info…]

LinuxSecurity.com: Update to 2.2.4 with backport for XSS vulnerability.

LinuxSecurity.com: Update to latest jquery1 stable, with backport fix for XSS vulnerability.)

LinuxSecurity.com: This update adds security sandboxing to tracker-extract.

LinuxSecurity.com: Update to latest jquery1 stable, with backport fix for XSS vulnerability.)

LinuxSecurity.com: fix for “TLS SecurityMode.required bypass via StripTLS attack”(rhbz#1406703,1406704)

security update

LG Smart TV Screen Bricked After Android Ransomware Infection
How to Choose the Perfect Laptop for Online Study
Someone DDoSed ExtraTorrent Domain while ThePirateBay suffered downtime

LinuxSecurity.com: * Mon Dec 12 2016 Norvald H. Ryeng – 5.7.17-1 -Update to MySQL 5.7.17, for various fixes described athttps://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-17.html – Add newplugin: connnection_control.so – Add MySQL Group Replication:group_replication.so – Add numactl-devel to buildreq and enable NUMA support (ifavailable) – Simplify boost path – Build compat-openssl10 in rawhide for now -Reqs. in -devel packages was […]

LinuxSecurity.com: Updated to 2.1.4

LinuxSecurity.com: This update contains a **SECURITY** fix for an issue with potentially seriousconsequences but very limited scope. If an administrator of a wiki you talked tousing python-wikitcms were malicious, they could cause arbitrary code executionas the user running wikitcms. No-one besides a wiki administrator could do this,as it requires crafting the wiki’s response to an […]

LinuxSecurity.com: Updated to 2.1.4

LinuxSecurity.com: This update contains a **SECURITY** fix for an issue with potentially seriousconsequences but very limited scope. If an administrator of a wiki you talked tousing python-wikitcms were malicious, they could cause arbitrary code executionas the user running wikitcms. No-one besides a wiki administrator could do this,as it requires crafting the wiki’s response to an […]

LinuxSecurity.com: Update to 2.2.4 with backport for XSS vulnerability.

LinuxSecurity.com: Security fix for CVE-2016-4330, CVE-2016-4331, CVE-2016-4332, CVE-2016-4333

LinuxSecurity.com: two security flaws (#1406840) x86 PV guests may be able to mask interrupts[XSA-202, CVE-2016-10024] x86: missing NULL pointer check in VMFUNC emulation[XSA-203, CVE-2016-10025] x86: Mishandling of SYSCALL singlestep duringemulation [XSA-204, CVE-2016-10013] (#1406260)

LinuxSecurity.com: * Mon Dec 12 2016 Norvald H. Ryeng – 5.7.17-1 -Update to MySQL 5.7.17, for various fixes described athttps://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-17.html – Add newplugin: connnection_control.so – Add MySQL Group Replication:group_replication.so – Add numactl-devel to buildreq and enable NUMA support (ifavailable) – Simplify boost path – Build compat-openssl10 in rawhide for now -Reqs. in -devel packages was […]

LinuxSecurity.com: – fix floating point buffer overflow issues (CVE-2016-9586)

News in brief: Amazon asked for Echo data; Facebook in new fake news row; airline systems ‘insecure’
Three Chinese Hackers Made Millions by Hacking American Law Firms
Mixing biology with technology: what could possibly go wrong?
‘Meltdown’ over international cybersecurity agreement
Leaked info confirms in-house hacking capabilities of Israeli firm Cellebrite
Thai Police Arrest 9 Suspects Behind Cyber Attacks on Gov’t Sites
US Immigration asking foreign travelers for their social media account details
Four New Normals for 2017
Weekly review – the hot 28 stories of the past week
Trio charged with $4m insider trading by hacking merger lawyers
How Microsoft will drive enterprise IT in 2017
Encryption in 2016: Small victories add up
Android Trojan Switcher Infects Routers via DNS Hijacking
What is encryption and how does it work?

It has become one of the most topical and discussed topics in information security in recent times. In this video we outline some of the key aspects of encryption. The post What is encryption and how does it work? appeared first on WeLiveSecurity

security update

PHPMailer Bug Leaves Millions of Websites Open to Attack