Menu

Monthly Archives: September 2017

LinuxSecurity.com: A vulnerability in mod_gnutls allows remote attackers to spoof clients via crafted certificates.

LinuxSecurity.com: Multiple vulnerabilities have been found in WebkitGTK+, the worst of which may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Binutils, the worst of which may allow remote attackers to cause a Denial of Service condition. [More…]

Equifax confirms up to 400,000 UK consumers at risk after data breach
Alaska Voter Database Exposed Online
Guess what happened after VEVO told its hackers to ‘f**k off’…

security update

Fitbit’ Fitness Tracker Devices Leak Personal Data: Researchers
Android Apps Infected with ExpensiveWall Malware Downloaded 21M Times
OurMine hacks video hosting service Vevo; leaks 3.12TB data online
LinkedIn Phishing Scam Steals Gmail Credentials Through Google Docs

security update

Rogue WordPress Plugin Allowed Spam Injection

German Voting Software Raises Concerns With German elections only a couple weeks away, researchers have been working to determine how secure the voting systems really are. Per a recent study, the software being used contains multiple vulnerabilities that could lead to devastating results if the election is compromised. Meanwhile, the software creator maintains there is […]

Chrome will automatically block annoying autoplay videos
VMware Patches Bug That Allows Guest to Execute Code on Host
India’s Aadhaar digital ID scheme: what could possibly go wrong?
Linux 4.13 Kernel Launches With Accelerated Security Feature
Linus Torvalds Wants Attackers to Join Linux Kernel Development
Poisoned WordPress ‘Display Widgets’ plugin finally purged
Facebook’s Crisis Response hub centralizes help for disaster victims
$1M bounty offered for zero-day exploits targeting Tor Browser
Open Source Summit: Securing IoT is About Avoiding Anti-Patterns
How network automation can speed deployments and improve security
How many people outside the U.S. are affected by the Equifax breach?

In the recent Equifax breach you may have noticed that people in the UK and Canada are also affected but there has been little clarification as to how many. The post How many people outside the U.S. are affected by the Equifax breach? appeared first on WeLiveSecurity

Equifax Confirms March Struts Vulnerability Behind Breach
Premium SMS Malware ‘ExpensiveWall’ Infects Millions of Android Devices
News in brief: FTC to probe Equifax; Bitcoin price falls on China move; HBO teases GoT finale news
Disguised as Citrix Utility, Kedi RAT Exploits Gmail to Transfer Data
Equifax: researchers find leaky customer help portal in Argentina
4,000 ElasticSearch servers found hosting PoS malware
Microsoft patches second FinSpy zero-day exploit this year
Equifax felled by a months-old Apache Struts vulnerability
Poisoned plugin allowed hackers to post spammy content on up to 200,000 WordPress websites
Firm offers up to $1 million for Tor zero-day exploits – but who will they sell them to?
Cryptocurrency web mining: In union there is profit

Cryptocurrency mining has been used by cybercriminals to make a quick and easy profit while corrupting the victim’s machine in the process. The post Cryptocurrency web mining: In union there is profit appeared first on WeLiveSecurity

Equifax: four simple steps to secure yourself
DHS faces lawsuit over legality of forced warrantless device searches
Next US Elections: Open Source vs. Commercial Software?
Windows 10’s Subsystem for Linux: Here’s how hackers could use it to hide malware
Startup That Sells Zero-Days to Governments Is Offering $1 Million For Tor Hacks
Smashing Security podcast #042: Equifax, BlueBorne, and the iPhone X

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Get $1M for reporting zero-day flaws in Tor to “help Govt fight crime”

LinuxSecurity.com: Several security issues were fixed in tcpdump

LinuxSecurity.com: Several security issues were fixed in tcpdump.

security update

security update

Thousands of Elasticsearch Servers Hijacked to Host PoS Malware

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Remote Desktop Virtual Host is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office Publisher is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Shell is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a security-bypass vulnerability.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a security-bypass vulnerability.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Uniscribe is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.