Menu

Latest articles

Flaw spotted in North Korea’s Red Star operating system
New Botnet is Attacking the US West Coast with Huge DDoS Attacks
Nintendo targets 3DS vulnerabilities in new bug bounty
Hackers Gamify DDoS Attacks With Collaborative Platform
Malicious online ads expose millions to possible hack
Crims using anti-virus exclusion lists to send malware to where it can do most damage
Uber is watching your smartphone’s battery charge

LinuxSecurity.com: Multiple vulnerabilities have been found in Mercurial, the worst of which could lead to the remote execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in OpenSSH, the worst of which allows remote attackers to cause Denial of Service.

LinuxSecurity.com: A buffer overflow in PECL HTTP might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in OpenSSL, the worst of which allows attackers to conduct a time based side-channel attack.

Android, Qualcomm move on insecure GPS almanac downloads
Open source Roundcube webmail can be attacked … by sending it an e-mail

Risk Level: Very Low. Type: Trojan.

After IoTs, it is the IMDs that are Most Vulnerable to Hacking
IBM Watson steps into real-world cybersecurity

LinuxSecurity.com: New upstream version 2.50. – Fixes serious DLL hijacking attack:https://sourceforge.net/p/nsis/bugs/1125/

Flash Exploit Found in Seven Exploit Kits
DailyMotion Hack Leaks Emails, Passwords of 87M Users
News in brief: smart toys ‘threaten kids’ security’; Samsung battery teardown; HP turns off Telnet

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Nghttp2 is vulnerable to a Denial of Service attack.

LinuxSecurity.com: Patch is vulnerable to a locally generated Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in the Chromium web browser, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Security fix for CVE-2016-9296

LinuxSecurity.com: phpMyAdmin 4.6.5.1 (2016-11-26) =============================== A patch-levelrelease fixing two small issues: * an issue affecting a small number of usersusing $cfg[‘Servers’][$i][‘hide_db’] or $cfg[‘Servers’][$i][‘only_db’]. * anissue affecting the create table dialog where the partition selection tool wasoverzealous and made it difficult to create a new table. There are also minorimprovements to the Czech language file. phpMyAdmin […]

LinuxSecurity.com: Update to 1.10.1

LinuxSecurity.com: Add fix for gstreamer FLIC decoder vulnerability

LinuxSecurity.com: xen : various security flaws (#1397383) x86 null segments not always treated asunusable [XSA-191, CVE-2016-9386] x86 task switch to VM86 mode mis-handled[XSA-192, CVE-2016-9382] x86 segment base write emulation lacking canonicaladdress checks [XSA-193, CVE-2016-9385] guest 32-bit ELF symbol table loadleaking host data [XSA-194, CVE-2016-9384] x86 64-bit bit test instructionemulation broken [XSA-195, CVE-2016-9383] x86 software interrupt […]

LinuxSecurity.com: Libvirt is vulnerable to directory traversal when using Access Control Lists (ACL).

LinuxSecurity.com: Multiple vulnerabilities have been found in GD, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability in LinuxCIFS utils’ “cifscreds” PAM module might allow remote attackers to have an unspecified impact via unknown vectors.

DarkWeb Website Asking for Funds to Assassinate Donald Trump and Mike Pence
Putin moves to step up Russia’s cyberdefenses
App developers not ready for iOS transport security requirements
Sony Closes Backdoors in IP-Enabled Cameras
Daily Motion video sharing service named in breach claim of 80M accounts
‘Rich irony’ as Facebook blocks extension to highlight fake news
Lock suspect in stolen car to bust him? There’s an app for that…
Dailymotion hacked, millions of user accounts exposed
Hackers actively stealing Wi-Fi keys from vulnerable routers
Rogue admin jailed after taking down former employer’s network
Hacking is legal again finally (sometimes)

Go ahead and hack your car, that’s fine now. Go ahead and hack the Department of Defense, that’s okay too under new policies. It wasn’t always this way. The post Hacking is legal again finally (sometimes) appeared first on WeLiveSecurity.

4 top disaster recovery packages compared
Are you human or a bot? Google’s invisible reCAPTCHA will decide
Obama’s cybersecurity plan faces uncertainty with Trump
Own goal for Scottish Football Association as fans sent phishy emails
Sony kills off secret backdoor in 80 internet-connected CCTV models
The cloud storage security gap — and how to close it
Why it’s so hard to prosecute cyber criminals
<div>Why it's so hard to prosecute cyber criminals</div>

We live in a world where internet crime is rampant. Cyber criminals steal hundreds of millions of dollars each year with near impunity. For every 1 that gets caught, 10,000 go free — maybe more. For every 1 successfully prosecuted in a court of law, 100 get off scot-free or with a warning. Why is […]

The UK’s Investigatory Powers Act allows the State to tell lies in court
Facebook, Microsoft, Twitter and YouTube team to ID terror content
In the three years since IETF said pervasive monitoring is an attack, what’s changed?
Standards body warned SMS 2FA is insecure and nobody listened
Printer security is so bad HP Inc will sell you services to fix it
Arista CloudVision Portal bug revealed, plus evidence it’s been used
1.4bn records from HaveIBeenPwned offered for your analytical pleasure
Video-sharing Website Dailymotion Hacked; 87 Million Accounts Leaked
CloudFlare warns of another massive botnet, er, flaring up
Credit Cards can be Hacked in Just 6 Seconds—Reveals New Study
Dirty Cow Vulnerability Patched in Android Security Bulletin
Google Debuts Continuous Fuzzer for Open Source Software
Distributed Guessing Attack Reels in Payment Card Data
Toyota dealer sued for stealing intimate photo off couple’s smartphone
New Large-Scale DDoS Attacks Follow Schedule
How to guess credit card security codes
News in brief: porn database hacked; Obama call to Trump; MPs move on Snooper’s Charter
Chrome bug triggered errors on websites using Symantec SSL certificates
Facebook reportedly looking at curating news (again)
Be Prepared for Jail Time if You Post Fake News on Social Media in Saudi Arabia
Amazon Launches AWS Shield DDoS Protection Service
Saudi Arabian Central Bank Systems Targeted with Shamoon Malware
Website leaves 43,000 sensitive medical records exposed
Yorkshire cyber security biz ECSC Group to debut on AIM exchange
EFF Blasts DEA in Ongoing Secret ‘Super Search Engine’ Lawsuit
Five new malware programs are discovered every second
How to survive the death of Flash
Apple set to deploy drones to boost Maps accuracy
Take care copy-and-pasting that code from Stack Overflow
Android ransomware spreads further, with new methods in its toolbox

ESET lifts the lid on Android ransomware – the picture doesn’t look good. It’s on the increase and extremely sophisticated. The post Android ransomware spreads further, with new methods in its toolbox appeared first on WeLiveSecurity.

Child safety: An unexpected radio interview

David Harley, talking about child safety and security in (and yet not in) the South Atlantic. The post Child safety: An unexpected radio interview appeared first on WeLiveSecurity.

Guessing valid credit card numbers in six seconds? Priceless
IoT camera crew Titathink tells Reg it’ll patch GET bug in a week
U.K. Police don’t pay to unlock iPhones, they mug you while phone is unlocked
Vendor claims to sell millions of Experian and Whois accounts on Dark Web
Hackers steal $31 million from Russia’s central bank, as FSB warns of foreign plot
New anti-Facial Recognition Glasses Protect Users’ Privacy From CCTV Cameras

LinuxSecurity.com: A vulnerability in DavFS2 allows local users to gain root privileges.

LinuxSecurity.com: Due to a design flaw, the output of GnuPG’s Random Number Generator (RNG) is predictable.

LinuxSecurity.com: Security fix for CVE-2016-7504, CVE-2016-7505, CVE-2016-7506, CVE-2016-9017,CVE-2016-9108, CVE-2016-9109, CVE-2016-9294

LinuxSecurity.com: Security fix for CVE-2016-7504, CVE-2016-7505, CVE-2016-7506, CVE-2016-9017,CVE-2016-9108, CVE-2016-9109, CVE-2016-9294

LinuxSecurity.com: Update to 1.9.9 (bugfix release for CVE-2016-7146, CVE-2016-7148)

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: A security update that fixes Calamares bug CAL-405:https://calamares.io/bugs/browse/CAL-405 When installing with a LUKS-encrypted`/` partition, Calamares was always creating a keyfile to decode `/` and storingit in the initramfs. It did that even with an unencrypted separate `/boot`partition. As a result, the keyfile would be stored in cleartext on the `/boot`partition, and it was possible […]

LinuxSecurity.com: Update to 1.9.9 (bugfix release for CVE-2016-7146, CVE-2016-7148)

LinuxSecurity.com: A security update that fixes Calamares bug CAL-405:https://calamares.io/bugs/browse/CAL-405 When installing with a LUKS-encrypted`/` partition, Calamares was always creating a keyfile to decode `/` and storingit in the initramfs. It did that even with an unencrypted separate `/boot`partition. As a result, the keyfile would be stored in cleartext on the `/boot`partition, and it was possible […]

LinuxSecurity.com: Security fix for CVE-2016-9299

LinuxSecurity.com: Security fix for CVE-2016-9299

LinuxSecurity.com: Update to 1.9.9 (bugfix release for CVE-2016-7146, CVE-2016-7148)