Menu

Latest articles

How a hacked phone number cost Jered Kenna millions in bitcoins
Panasonic, IOActive Clash on Vulnerability Report
Tech companies like Privacy Shield but worry about legal challenges
Congressional report sides with Apple on encryption debate
Porn block on new PCs to ‘fight trafficking’ – unless you pay $20
Home routers under attack in ongoing malvertisement blitz
Op-ed: Why I’m not giving up on PGP
IDG Editors predict tech trends for 2017
Energy firm points to hackers after Kiev power outage
What is cyberbullying and how to defend against it?

Cyberbullying has come to be a huge problem on the internet. Here are some important things to be aware of. The post What is cyberbullying and how to defend against it? appeared first on WeLiveSecurity

LinuxSecurity.com: An update for gstreamer-plugins-good is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for gstreamer-plugins-bad-free is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

Facebook has stopped SHA-ring, a year later than it promised
Strong non-backdoored encryption is vital – but the Feds should totally be able to crack it, say House committees

LinuxSecurity.com: An update for vim is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

Wassenaar weapons pact talks collapse leaving software exploit exports in limbo

Risk Level: Very Low. Type: Trojan.

Pakistani hackers deface Google Bangladesh domain
China gives America its underwater drone back – with a warning
Year-end cybercrime update 2016: an avalanche of good news?

Highlighting 20 success stories in the struggle against cybercrime, from indictments to arrests, extraditions to sentencing. Law enforcement efforts in cyberspace may have borne more fruit in 2016 than in any other year. The post Year-end cybercrime update 2016: an avalanche of good news? appeared first on WeLiveSecurity

Wassenaar Renegotiation Will Be in Trump Administration’s Hands
Testing times: Can your crypto-code survive the Google gauntlet?
Anonymous Shut Down Thai Sites Against Internet Censorship, Surveillance Law

Type: Vulnerability. The Microsoft .NET Framework is prone to an information-disclosure vulnerability; fixes are available.

ShadowBrokers got NSA spy tools from rogue insider
Kingpin in $1m global bank malware ring gets five years in chokey
When a Russian-speaking hacker cracks a US Election website…
News in brief: inflight systems ‘can be hacked’; LA seeks extradition of ‘cyberattacker’; Uber safety fears grow

LinuxSecurity.com: Several security issues were fixed in Samba.

Phishing attack on LA County computers; personal data of 756k people stolen

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low.

Risk Level: Very Low.

Hackers suspected of causing power outage in Ukraine
New Decryptor Unlocks CryptXXX v3 Files
Shadow Brokers are back with ‘stolen NSA cyberweapons’, now 99.9% off
5 technologies that will shake things up in 2017
Yahoo breach: your account is selling for pennies on the dark web
Bad news, fandroids: Mobile banking malware now encrypts files
Hacking airplane entertainment systems
Ukraine Suffers Power Outage Possibly Due to Energy Plant Hack
Christmas pump-and-dump stock spam
Fraudulent Video Ad Bot Rakes in Close to $5 Million Daily
New Linux/Rakos threat: devices and servers under SSH scan (again)

ESET’s Peter Kálnai and Michal Malik report on a new Linux/Rakos threat – devices and servers are under SSH scan again. The post New Linux/Rakos threat: devices and servers under SSH scan (again) appeared first on WeLiveSecurity

Google using Project Wycheproof to scan crypto software for security holes
In-Flight Entertainment System Flaws Put Passenger Data at Risk
How to get more from your security budget
NCSC boss asked to detail efforts to protect financial services sector against cyberattacks

The head of the UK’s NCSC has been asked to offer more detail into how the financial services sector will be protected from cyberattacks. The post NCSC boss asked to detail efforts to protect financial services sector against cyberattacks appeared first on WeLiveSecurity

This is your captain speaking… or is it?
Box won’t say if it’s giving your secrets to the government
Turkey reportedly blocks Tor network nationwide
Financial Data Worth Millions Unwittingly Exposed In Ameriprise Accounts
7 Linux predictions for 2017
Google open-sources test suite to find crypto bugs
Maybe security isn't going to get better after all

One billion-plus accounts stolen in one online heist. The U.S. presidential election messed with by another country. Corporate secrets stolen and released on the internet on a regular basis. More and more data held hostage by ransomware. Stock markets routinely manipulated by hackers. Denial-of-service attacks whacking websites all over the place. Will computer security ever […]

Lawmaker urges regulating Facebook and Google’s algorithms
756,000 individuals at risk after phish of 108 LA County employees
Evolved DNSChanger malware slings evil ads at PCs, hijacks routers

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

Sports blog jocks to crypto-cash nerds – here’s who got pwned

LinuxSecurity.com: Security Report Summary

Cops, Feds spaff $100m on Stingray cellphone snooping gear – and there’s sod all oversight
Protecting Your Online Presence with 3 Simple Tips
ShadowBrokers Dump Came from Internal Code Repository, Insider
Los Angeles to extradite bloke from Nigeria after scores of city workers fall for phish scam
You can now buy hacked NSA tools for Bitcoin 1000
Google Unveils Cryptographic Library Test Suite Wycheproof

Type: Vulnerability. Adobe Flash Player is prone to an unspecified remote code-execution vulnerability; fixes are available.

News in brief: Obama warns Putin on hacking; China to return US drone; lynda.com hacked
Stolen Yahoo Data Sold to Spammers, One Government Client
LinkedIn’s Recent Acquisition Lynda.com Suffers Massive Data Breach

LinuxSecurity.com: This update fixes CVE-2016-9580 and CVE-2016-9581.

LinuxSecurity.com: Rebase to upstream 4.4.3: http://www.freeipa.org/page/Releases/4.4.3 —- -Fixes 1395311 – CVE-2016-9575 ipa: Insufficient permission check in certprofile-mod – Fixes 1370493 – CVE-2016-7030 ipa: DoS attack against kerberized servicesby abusing password policy

LinuxSecurity.com: Security fix for CVE-2016-9957, CVE-2016-9958, CVE-2016-9959, CVE-2016-9960,CVE-2016-9961

LinuxSecurity.com: x86 CMPXCHG8B emulation fails to ignore operand size override [XSA-200,CVE-2016-9932] (#1404262) —- ARM guests may induce host asynchronous abort[XSA-201, CVE-2016-9815,

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for BZ#1401985

LinuxSecurity.com: This release fixes CVE-2016-1249 (out-of-bound read when using server-sideprepared statements) and CVE-2016-1251 vulnerability (a use after free whenusing prepared statements).

LinuxSecurity.com: Security fix for CVE-2016-9844

LinuxSecurity.com: The 4.8.14 stable kernel update contains a number of important fixes across thetree.

LinuxSecurity.com: – Security fix for CVE-2016-8670 – Security fix for CVE-2016-6911 – Security fixfor CVE-2016-7568 – For Fedora 26 disabled two tests – they are failing becauseof freetype 2.7 (https://github.com/libgd/libgd/issues/302,https://github.com/libgd/libgd/issues/217)

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for CVE-2016-9844

Risk Level: Very Low. Type: Trojan.

Insecure NAS Device Exposes 350 Ameriprise Investment Accounts
Germany threatens Facebook with €500,000 fine per fake news post
Cyber insurance brokers: If it makes you feel any better, 2016 was not our year either
US government eyes car-to-car data sharing to improve safety
Akamai buys bot-sniffing startup Cyberfend
Ransomware payouts ‘heading for $1bn a year’
Yahoo’s billion account database for sale on the black market
IoT attacks: 10 things you need to know

IoT attacks are on the rise. As the technology becomes more relevant to our lives, we take a look at what the state of play is. The post IoT attacks: 10 things you need to know appeared first on WeLiveSecurity

PayAsUGym breach exposes passwords
Review: Threat hunting turns the tables on attackers
10 biggest hacks of user data in 2016
Legion’s high-profile Twitter hacks have us looking the wrong way