Menu

Monthly Archives: September 2017

How SS7 Flaw Can Be Used to Hack Gmail ID and Bitcoin Wallet
Equifax’s disastrous Struts patching blunder: THOUSANDS of other orgs did it too
Cloud Security Error Exposes Half a Million Voters’ Personal Information
“Admin from Hell” holds company to ransom with porn makeover
Critical VMware vulnerability, patch and update now
You lost your ballpoint pen, Slack? Why’s your Linux version unsigned?
Night Vision Enabled Security Cameras Secretly Transfer Your Data

LinuxSecurity.com: An update that solves four vulnerabilities and has two An update that solves four vulnerabilities and has two An update that solves four vulnerabilities and has two fixes is now available. fixes is now available.

CCleaner targeted top tech companies in attempt to lift IP

security update

Risk Level: Very Low. Type: Trojan.

Smashing Security podcast #043: Backups – a necessary evil?
Orland-whoa! Chap cops to masterminding $100m Microsoft piracy racket

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

security update

FedEx: TNT NotPetya infection blew a $300m hole in our numbers

LinuxSecurity.com: Update to upstream release 1.25.6

More than three dozen schools call off classes after ‘cyber terrorist’ threat
Viacom cloud config goof exposed Paramount Pictures, Comedy Central, MTV, and more
Human failings undermine security – but who’s failing who?
What Triggers HTTPS Chrome Browser Warnings?
The Apache “Optionsbleed” security hole explained [VIDEO]
Malware Steals Data From Air-Gapped Network via Security Cameras

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

News in brief: Twitter stops terrorists; WhatsApp stops UK gov; Russia stops Dark Web drugs
Deep-Learning PassGAN Tool Improves Password Guessing
Pirate Bay hits users’ CPUs with secret cryptocurrency mining

With global ransomware attacks, such as WannaCry and not-Petya, making big headlines this year, it seems the unwelcomed scourge of ransomware isn’t going away any time soon. While large-scale attacks like these are most known for their ability to devastate companies and even whole countries, the often under-reported victim is the average home user. We […]

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

Why SMS two-factor authentication puts your bitcoins at risk
The laws that are ruining the Internet
Pirate Bay digs itself a new hole: Mining alt-coin in slurper browsers
5 Ways to Secure Wi-Fi Networks
First ever crypto-mining Chrome extension discovered
Cloud-Focused Firms Earn High Marks for Software Security in BSIMM8 Report
Manage access control using Redis Bitfields

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

security update

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

iOS 11 Update includes Patches for Eight Vulnerabilities

security update

security update

LinuxSecurity.com: Rebase to the latest upstream version 2.0.14. This update contains security fix for CVS -2017-1000050.

LinuxSecurity.com: new upstream release —- * heap overflow in libwpd

LinuxSecurity.com: Security fix for CVE-2017-13735

LinuxSecurity.com: Update to version 1.3.0, see https://nih.at/libzip/NEWS.html for details. —- This update backports security fix for CVE-2017-14107.

Equifax Suffered Earlier Breach in March
Apache “Optionsbleed” vulnerability – what you need to know
News in brief: Linux advice for Equifax; fired over phish; Security.txt standard proposed
Red Alert 2.0: New Android banking trojan can block and log incoming calls from banks

As a CISO, I think the cybersecurity community is beginning to realize that the threats we face as security professionals are consistently evolving, and, more importantly, that we must evolve just as quickly to combat them. Recent data collected by the Webroot® Threat Intelligence Platform on the acceleration of phishing attacks and the maturation of new, […]

Risks Limited With Latest Apache Bug, Optionsbleed

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

Apple’s new tracking protection is “sabotage”, claims ad industry
Misleading headlines about Equifax’s *earlier* hack
APNIC-sponsored proposal could vastly improve DNS resilience against DDoS
The Pirate Bay hijacked users’ CPU power to secretly mine cryptocurrency Monero
PyPI Python repository hit by typosquatting sneak attack
Safer but not immune: Cloud lessons from the Equifax breach
Heads roll, as it’s revealed Equifax’s IT team knew about web app vulnerability

Risk Level: Very Low. Type: Trojan.

Attackers Use Undocumented MS Office Feature to Leak System Profile Data

security update

DOJ lets itself off the privacy hook
Pirate Bay Spotted Hosting Monero Cryptocurrency Miner

LinuxSecurity.com: Multiple vulnerabilities have been found in cURL, the worst of which may allow attackers to bypass intended restrictions.

LinuxSecurity.com: A vulnerability in SquirrelMail might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability in module File::Path for Perl allows local attackers to set arbitrary mode values on arbitrary files bypassing security restrictions. [More…]

LinuxSecurity.com: Gentoo’s GIMPS ebuilds are vulnerable to privilege escalation due to improper permissions. A local attacker could use it to gain root privileges. [More…]

LinuxSecurity.com: A command injection vulnerability in Git may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A command injection vulnerability in Subversion may allow remote attackers to execute arbitrary code.

Google Chrome Will Mark FTP Resources As “Not Secure”
Chrome to brand FTP as “not secure”
IDG Contributor Network: From equanimity to Equifax
CCleaner Software Hacked with Backdoor; 2 Million Users Infected
The Pirate Bay website quietly runs a cryptocurrency miner on visitors’ PCs, gobbling up CPU cycles

LinuxSecurity.com: GDK-PixBuf could be made to crash or run programs as your login if it opened a specially crafted file.

CCleaner, distributed by anti-virus firm Avast, contained malicious backdoor

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

security update

The Pirate Bay Caught Running Cryptocurrency Mining Script
Vevo hacked, 3.12 TB of data leaked

LinuxSecurity.com: Multiple vulnerabilities have been found in GDK-PixBuf, the worst of which could result in the execution of arbitrary code.

LinuxSecurity.com: A vulnerability in Kpathsea allows remote attackers to execute arbitrary commands by manipulating the -tex option from mpost program.

LinuxSecurity.com: A vulnerability in Supervisor might allow remote attackers to execute arbitrary code. [More…]

LinuxSecurity.com: A vulnerability in chkrootkit may allow local users to gain root privileges.