Menu

Latest articles

Poison .JPG spreading ransomware through Facebook Messenger

LinuxSecurity.com: – update to 1.8.18p1 – fixes CVE-2016-7076

Mozilla hackers audit cURL file transfer toolkit, give it a tick for security

Risk Level: Very Low. Type: Trojan.

Melbourne man arrested for broadcasting fake messages to pilots
Don’t be a security turkey this Thanksgiving!
‘Compromised’ laptop implicated in US Navy breach of 130,000 records
Facebook ‘quietly developing censorship tool’ for China
New decryption tool for Crysis ransomware

ESET has developed a free tool to decrypt files and recover the information that might have been compromised by Crysis. The post New decryption tool for Crysis ransomware appeared first on WeLiveSecurity.

Are your headphones spying on you?
So, just how were those MailChimp accounts hacked?
Google secures five-year access to health data of 1.6m people
How your speakers could be turned into eavesdropping microphones
Historic Black Friday online safely advice

If you are getting ready to hunt for online deals this Black Friday, here are a few tips that will help you keep attackers away from your hard earned money. The post Historic Black Friday online safely advice appeared first on WeLiveSecurity.

The First Ransomware to Exploit Telegram Cracked and Decryptor Published
U.S. says cybersecurity skills shortage is a myth
8 Books Security Pros Should Read
Organizations ‘not doing enough’ to prevent data breaches

Organizations need to do more to prevent themselves from experiencing data breaches, as many people are of the opinion that not enough is currently being done. The post Organizations ‘not doing enough’ to prevent data breaches appeared first on WeLiveSecurity.

CERT tells Microsoft to keep EMET alive because it’s better than Win 10’s own security
CompSci boffins offer new bug-rating system to get you home on time
Vicinity of obscurity! Fareit trojan spread via uncommon file type
Attackers use ancient zero-day to pop Asian banks, govts
CompSci Prof raises ballot hacking fears over strange pro-Trump voting patterns
Men overboard! US Navy spills data on 134k sailors

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

security update

  For many years now, Microsoft has offered a system with Windows that allows you to take control of another machine. This has been invaluable for system admins that need to control servers and other Windows machines, without having to run around from office to office or site to site. Easy takeover of machines does […]

Black Friday Scams: Shop Safely with These Tips
NTP fixes denial-of-service flaws
Stop wasting time making the wrong passwords stronger
Cyber Monday: What to watch out for when you hit the web
Visa cries foul over Euro regulator’s stronger authentication demands

LinuxSecurity.com: Several security issues were fixed in Python.

LinuxSecurity.com: Security Report Summary

It’s Google.com not ɢoogle.com; beware of the pro-Trump spam domain

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Sorry, iPhone fans – only Fandroids get Barclays’ tap-to-withdraw
MailChimp accounts hacked to spam out malicious emails

Hackers broke into the MailChimp accounts of some businesses, and send out malicious invoice emails to subscribers… but that doesn’t mean that MailChimp suffered a serious security breach. Once again, two-factor authentication could have saved users’ bacon. The post MailChimp accounts hacked to spam out malicious emails appeared first on WeLiveSecurity.

FBI hacked 8K computers in 120 countries against child pornography site
Uber Portal Leaked Names, Phone Numbers, Email Addresses, Unique Identifiers
Comcast is the honey badger of ISPs – injects pop-ups into browsers, doesn’t give a fsck
Fake news still rattling cages, from Facebook to Google to China
InPage Zero Day Used in Attacks Against Banks
It’s the final countdown for SHA-1 SSL certificates
Deliver-oops! Takeaway pusher’s customers burger-ed by hijackers
A Hacker Took Over Tel Aviv’s Public Wi-Fi Network to Prove That He Could
38 Percent of Mobile Professionals Have Never Used a VPN
DoD, HackerOne kick off Hack the Army bug bounty challenge
Best smaller cities to land a cybersecurity job
Every move you make, every click you take, we’ll be watching you
Telegram API ransomware wrecked three weeks after launch
It’s time: Patch Network Time Protocol before it loses track of time
Signal security revealed: A triple-Diffie-Hellman with a double ratchet

LinuxSecurity.com: An update for memcached is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for memcached is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

Credit cards ripped from Madison Square Garden venues in year-long op
Snail mail thieves feed international identity theft rings say Oz cops
FYI: The FBI is being awfully evasive about its fresh cyber-spy powers
WordPress auto-update server had flaw allowing anyone to add anything to websites worldwide

Risk Level: Very Low. Type: Worm.

$55 surveillance camera hacked by Mirai botnet within 98 seconds
Users Reporting Electronic Arts and PlayStation Servers are Down

security update

security update

Hospital info thief malware puts itself into a coma to avoid IT bods
Despite DDoS attack, Dyn Clinches Acquisition Deal with Oracle
Microsoft Cutting Off SHA-1 Support in February for Edge, IE 11
Black Friday: What to watch out for when you hit the stores

LinuxSecurity.com: New ntp packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

Michigan State University experiences data breach

Michigan State University has experienced a data breach, which it said took place on November 13th. The post Michigan State University experiences data breach appeared first on WeLiveSecurity.

Exploit Code Released for NTP Vulnerability
Scammers Using Images on Facebook Messenger to Drop Locky Ransomware
WordPress Plugins Leave Black Friday Shoppers Vulnerable
Hack the Army: US military begs white hats to sweep it for bugs
DoD Publishes Vulnerability Disclosure Policy
Get Safe Online warns of Amazon email scam

Amazon customers are the latest victims of an email scam, warns Get Safe Online. The post Get Safe Online warns of Amazon email scam appeared first on WeLiveSecurity.

178 arrested in pan-European money mule crackdown
Merkel calls for balanced approach to data protection
Is encrypted e-mail a must in the Trump presidential era?
Your car will be recalled in 2017 thanks to poor open-source security
Siemens-branded CCTV cameras vulnerable to hacking, require urgent firmware patch
Time’s almost out for websites to abandon SHA-1
Moment of truth: Web browsers and the SHA-1 switch

The long-awaited SHA-1 deprecation deadline of Jan. 1, 2017, is almost here. At that point, we’ll all be expected to use SHA-2 instead. So the question is: What is your browser going to do when it encounters a SHA-1 signed digital certificate? We’ll delve into the answers in a minute. But first, let’s review what […]

Siemens-branded CCTV webcams require urgent firmware patch

Your business’s CCTV camera could be coughing up your admin passwords. Patch now, or regret later. The post Siemens-branded CCTV webcams require urgent firmware patch appeared first on WeLiveSecurity.

Irish eyes are crying: Tens of thousands of broadband modems wide open to hijacking

LinuxSecurity.com: A buffer overflow in TestDisk might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A path traversal attack in Tar may lead to the remote execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: A buffer overflow in RPCBind might allow remote attackers to cause a Denial of Service.