Menu

Monthly Archives: July 2017

Type: Vulnerability. Microsoft Edge is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge and Internet Explorer are prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Explorer is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Micro Market Vendor Warns of Bankcard And Biometric Data Breach

security update

Telcos Singled Out for Prioritizing Government Requests for Data Over Privacy

LinuxSecurity.com: New rpcbind packages are available for Slackware 14.2 and -current to fix a security issue.

LinuxSecurity.com: New libtirpc packages are available for Slackware 14.2 and -current to fix a security issue.

Energy, Nuclear Targeted with Template Injection Attacks
Google to Fully Distrust WoSign/StartCom SSL Certs in Chrome 61
Smart Home Device Calls Police Amid Domestic Dispute
News in brief: NATO backs Kiev over cyber-attacks; China cracks down on VPNs; Somalia knocked offline

LinuxSecurity.com: Multiple vulnerabilities have been found in libcroco, the worst of which may have unspecified impacts.

LinuxSecurity.com: Two security issues have been discovered in the X.org X server, which may lead to privilege escalation or an information leak. For the oldstable distribution (jessie), these problems have been fixed

LinuxSecurity.com: A vulnerability in MAN DB allows local users to gain root privileges.

International Investigatory Group Also Target of Government Spyware
LeakerLocker ransomware threatens to dox Android users as extortion
Tendulkar wants your number on Twitter, what do you do?
Satellite Communication Can Now Be Cracked In Seconds
FTC slaps $104m judgment on loan application firm
Jayden K Smith’s Facebook friendship request – not a hacker, it’s a hoax
Apps that are a matter of life, death and data win $75,000 prizes
Supermarkets and fishy perfumes

Recently I’ve been seeing lightly-revised versions of a longstanding hoax, says David Harley. Read more on supermarkets and fish perfumes. The post Supermarkets and fishy perfumes appeared first on WeLiveSecurity

Three million wrestling fans at risk after WWE leaves database unprotected
When ex-workers attack (again): man used Trojan to cause havoc
Petya ransomware developer releases master decryption key, giving hope for victims

security update

LinuxSecurity.com: A vulnerability in Gajim might allow remote attackers to intercept encrypted communications.

LinuxSecurity.com: New irssi packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: update

LinuxSecurity.com: A vulnerability in RoundCube may allow authenticated users to bypass security restrictions.

LinuxSecurity.com: Multiple vulnerabilities have been found in VLC, the worst of which may allow remote attackers to execute arbitrary code.

SpyDealer Rooting Malware Steals Data From Android Devices

LinuxSecurity.com: Update to new ISC supported version 9.9.10.

LinuxSecurity.com: Update to new ISC supported version 9.9.10.

LinuxSecurity.com: update

LinuxSecurity.com: Update to latest upstream release in order to fix CVE-2017-9735

LinuxSecurity.com: Update to latest upstream release in order to fix CVE-2017-9735

LinuxSecurity.com: Update to latest upstream release in order to fix CVE-2017-9735

LinuxSecurity.com: This is new version with security fixes for CVE-2017-9468, CVE-2017-9469.

Prisoner Uses Drones and Cell Phones to Escape
CIA Implants Steal SSH Credentials From Linux & Windows Devices: WikiLeaks

LinuxSecurity.com: New stable upstream release, primarily includes security fixes for CVE-2017-10794, CVE-2017-10799, CVE-2017-10800 See also http://www.graphicsmagick.org/NEWS.html#july-4-2017

LinuxSecurity.com: Update to new ISC supported version 9.9.10-P2 including security fixes.

LinuxSecurity.com: Update to new ISC supported version 9.9.10-P2 including security fixes.

LinuxSecurity.com: Update to annulen-branch of qt5-qtwebkit, which contains a lot of security fixes. Drop-in replacement for the old unmaintained qt5-qtwebkit

Black Hat Survey: Security Pros Expect Major Breaches in Next Two Years

LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available. An update that fixes 11 vulnerabilities is now available. An update that fixes 11 vulnerabilities is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has 14 fixes An update that solves two vulnerabilities and has 14 fixes An update that solves two vulnerabilities and has 14 fixes is now available. is now available.

LinuxSecurity.com: Clément Berthaux from Synaktiv discovered two vulnerabilities in BIND, a DNS server implementation. They allow an attacker to bypass TSIG authentication by sending crafted DNS packets to a server.

LinuxSecurity.com: A vulnerability has been found in GNOME applet for NetworkManager allowing local attackers to access the local filesystem.

LinuxSecurity.com: A vulnerability in feh might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in JasPer, the worst of which could could allow an attacker to execute arbitrary code.

LinuxSecurity.com: A vulnerability in phpMyAdmin might allow remote attackers to bypass authentication.

LinuxSecurity.com: Multiple vulnerabilities have been found in virglrenderer, the worst of which could allow local guest OS users to cause a Denial of Service condition. [More…]

AA apologises, and confirms customers’ partial credit card data *was* exposed
Hard Rock, Loews Hotels Among Sabre Corp Hospitality Breach Victims
Authorities Shut Down Major Dark Web Child Porn Platform
Update your Android now – many holes fixed including ‘BroadPwn’ Wi-Fi bug
News in brief: fears as online bazaar goes dark; Tesla to build biggest battery; EU move on right to repair

Risk Level: Very Low. Type: Trojan, Worm.

Organisations count the cost of Petya as the storm abates
EPIC files restraining order to block voter fraud commission’s data swoop
Leaky WWE Database Exposes Personal Data of 3M Wrestling Fans
CopyCat Malware Made $1.5M by Infecting 14M Android Devices
Decryption Key to Original Petya Ransomware Released
Two suspects arrested in connection with WannaCry Android lookalikes
Massive WWE Database with 3 Million Records Exposed Online
Cloud computing security: This is where you’ll be spending the money
How to Achieve an Optimal Security Posture

LinuxSecurity.com: poppler could be made to crash or run programs as your login if it opened a specially crafted file.

LinuxSecurity.com: An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now available. errata is now available.

LinuxSecurity.com: An update that solves 17 vulnerabilities and has one errata An update that solves 17 vulnerabilities and has one errata An update that solves 17 vulnerabilities and has one errata is now available. is now available.

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. British Lawmakers’ Logins Targeted Over the last week, multiple parliament members and other lawmakers in the […]

Risk Level: Very Low. Type: Trojan.

security update

security update

Let’s Encrypt to Offer Wildcard Certificates in 2018

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the libtiff library and the included tools, which may result in denial of service or the execution of arbitrary code.

LinuxSecurity.com: Several security issues were fixed in Thunderbird.

LinuxSecurity.com: It was discovered that jabberd2, a Jabber instant messenger server, allowed anonymous SASL connections, even if disabled in the configuration.

News in brief: Parliament hack ‘amateur attack’; ‘Humpty Dumpty’ in great fall; Google faces more EU fines
CopyCat Malware Infected 14M Android Devices, Rooted 8M, in 2016
Encryption thwarting investigators as federal government taps increase