Menu

Monthly Archives: June 2017

Europol arrest 6 over malware crypter and counter anti-virus platform

security update

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Mozilla Fixes 32 Vulnerabilities in Firefox 54
Decryption Utility Unlocks Files Encrypted by Jaff Ransomware
News in brief: Hollywood fights piracy; Covfefe not a typo; Kim Dotcom loses

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: Multiple security vulnerabilities have been found in oSIP, a library implementing the Session Initiation Protocol, which might result in denial of service through malformed SIP messages.

Blast from the past – Patch Tuesday updates for Windows XP
DHS, FBI Warn of North Korea ‘Hidden Cobra’ Strikes Against US Assets
Abuse of Apple Search Ads Feature Leading to Fraud
Criminals snatching iPhones to scam users twice
Infection by mouseover – what you need to know about PowerPoint spam
A Dark Web service claims to track any phone and read text messages
Post-WannaCry, 5.5 Million Devices Still Expose SMB Port
Rare XP Patches Fix Three Remaining Leaked NSA Exploits
Employees have “low cyber IQ” despite high corporate confidence

Businesses are confident that they have sufficient cybersecurity systems in place to protect them, but in reality the weak link may be their employees, who lack basic skills and knowledge. The post Employees have “low cyber IQ” despite high corporate confidence appeared first on WeLiveSecurity

Is it time for cash for medical “Clunkers”?
Pirates dance around AACS 2 encryption to offer UHD Blu-Ray movies online
Raspberry Pi sours thanks to mining malware

LinuxSecurity.com: It was discovered that a side channel attack in the EdDSA session key handling in Libgcrypt may result in information disclosure. For the stable distribution (jessie), this problem has been fixed in

security update

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

security update

Microsoft Patches Two Critical Vulnerabilities Under Attack
Risk of ‘Destructive Cyber Attacks’ Prompts Microsoft to Update XP Again
Mazda cars hacked with just a USB
Adobe Fixes 21 Critical Vulnerabilities with June Patch Tuesday Update

LinuxSecurity.com: fixes buffer overflows for flac and pcm

LinuxSecurity.com: Security fix for CVE-2017-5645

LinuxSecurity.com: Security fix for CVE-2017-5645

LinuxSecurity.com: Per release notes: http://www.postgresql.org/docs/9.5/static/release-9-5-7.html

LinuxSecurity.com: Agostino Sarubbo discovered multiple vulnerabilities in zziplib, a library to access Zip archives, which could result in denial of service and potentially the execution of arbitrary code if a malformed archive is processed.

News in brief: Update Flash now; Heartbleed fine; the $1.9m email
Crash Override – The 2nd industrial malware to target Ukraine’s power supply
Virgin Super Hub 2 serious security bug – act now to close the hole

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Microsoft’s radical idea for dishing out cyberblame
Indian soldier in hot water after playing porn instead of presentation
Patrick Wardle on MacRansom Ransomware-as-a-Service
The Xavier info-stealing ad library lurks within over 800 Android apps in the Google Play store
How a single email stole $1.9 million from Southern Oregon University
Heartbleed still hurting hard. UK council fined £100,000 after data breach
Xavier Malware Infects Hundreds of Android Apps on Google Play Store
Latest Intelligence for May 2017
The WannaCry outbreak dominated the news cycle, while the phishing rate reached a high for 2017. Read More
Distributor caught selling Apple customers’ data
When sysadmins attack: how to delete an entire company
Pump-and-dump pot stock spam
Docker Aims to Improve Linux Kernel Security With LinuxKit
pymultitor – Python Multi Threaded Tor Proxy
FIN7 Hitting Restaurants with Fileless Malware

LinuxSecurity.com: https://lists.gnupg.org/pipermail/gnutls-devel/2017-June/008446.html

LinuxSecurity.com: Gajim 0.16.8 * Fix rejoining MUCs after connection loss * Fix Groupchat invites * Fix encoding problems with newer GnuPG versions * Fix old messages randomly reappearing in the chat window * Fix some problems with IBB filetransfer * Make XEP-0146 Commands opt-in * Improve sending messages to your own resources * Improve reliability […]

Type: Vulnerability. Microsoft Office is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Outlook is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft PowerPoint is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Uniscribe is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Outlook for Mac is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Skype for Business and Lync Server are prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Microsoft Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Uniscribe is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Uniscribe is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Uniscribe is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Uniscribe is prone to an information-disclosure vulnerability; fixes are available.