Menu

Monthly Archives: October 2017

LinuxSecurity.com: Multiple vulnerabilities have been found in Xen, the worst of which may allow local attackers to escalate privileges.

Domino’s Pizza delivers user details to spammers

LinuxSecurity.com: Several vulnerabilities have been discovered in the X.Org X server. An attacker who’s able to connect to an X server could cause a denial of service or potentially the execution of arbitrary code.

uBlock Origin ad-blocker knocked for blocking hack attack squawking
Watch out for Microsoft Word DDE nasties: Now Freddie Mac menaced
Oracle Patches 250 Bugs in Quarterly Critical Patch Update

LinuxSecurity.com: An update for wpa_supplicant is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available.

Flaw in Adobe Flash Player Used to Install FinFisher Spyware

LinuxSecurity.com: An update for rh-sso7-keycloak is now available for Red Hat Single Sign-On 7.1 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for rh-sso7-keycloak is now available for Red Hat Single Sign-On 7.1 for RHEL 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Red Hat Single Sign-On 7.1.3 is now available for download from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Vulnerability in WPA2 Protocol Allows Attackers to Intercept and Decrypt Encrypted Data Traffic

Type: Vulnerability. Adobe Flash Player is prone to a remote code-execution vulnerability; fixes are available.

LinuxSecurity.com: More info: https://koji.fedoraproject.org/koji/buildinfo?buildID=982578

KRACK Wi-Fi attack – the rules haven’t changed
Microsoft bug-tracking database was ‘hacked by Wild Neutron gang’
Google Home Mini glitch triggers secret recordings
Lenovo Quietly Patches Massive Bug Impacting Its Android Tablets and Zuk, Vibe Phones
NHS: Remember those patient records we didn’t deliver? Well, we found another 162,000
RAT flies under the radar with exploit-laden file downloaded by decoy Word document
The fix is in for hackable voting machines: use paper
Severe flaw in WPA2 protocol leaves Wi-Fi traffic open to eavesdropping
Linux vulnerable to privilege escalation

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

Devsecops: Add security to complete your devops process
Securing printed data in the ‘paperless’ office

Just as there are ways to audit, manage and protect electronic documents, there are ways to manage printed documents, too. The post Securing printed data in the ‘paperless’ office appeared first on WeLiveSecurity

Release the KRACKen patches: The good, the bad, and the ugly on this WPA2 Wi-Fi drama
Flash 0-day in the wild – patch now!
Crypto-coin miners caught toiling away in hacked cloud boxes
Russia tweaks Telegram with tiny fine for decryption denial

LinuxSecurity.com: Fix the for the Key Reinstallation Attacks in FT handshake (CVE-2017-13082) – Fix PTK rekeying to generate a new ANonce – Prevent reinstallation of an already in-use group key and extend protection of GTK/IGTK reinstallation of WNM-Sleep Mode cases (CVE-2017-13078,

LinuxSecurity.com: New upstream version

LinuxSecurity.com: Fix the for the Key Reinstallation Attacks in FT handshake (CVE-2017-13082) – Fix PTK rekeying to generate a new ANonce – Prevent reinstallation of an already in-use group key and extend protection of GTK/IGTK reinstallation of WNM-Sleep Mode cases (CVE-2017-13078,

LinuxSecurity.com: xserver 1.19.5 —- Update to xserver 1.19.4, multiple stability fixes.

LinuxSecurity.com: Update to 1.4.15. Fixes CVE-2017-8911

LinuxSecurity.com: 6.9.9-19

LinuxSecurity.com: 6.9.9-19

LinuxSecurity.com: Security fix for CVE-2017-13720 and CVE-2017-13722

LinuxSecurity.com: This is security update fixing possible buffer overflow in loadbuf function.

LinuxSecurity.com: Update to Open vSwitch 2.8.1 Includes security fix for CVE-2017-14970

LinuxSecurity.com: New upstream version

Never mind the WPA2 drama… Details emerge of TPM key cockup that hits tonnes of devices
Google isn’t saying Microsoft security sucks but Chrome for Windows has its own antivirus
Here’s a timeless headline: Adobe rushes out emergency Flash fix after hacker exploits bug
Factorization Flaw in TPM Chips Makes Attacks on RSA Private Keys Feasible

Risk Level: Very Low. Type: Trojan.

Wi-Fi at risk from KRACK attacks – here’s what to do
How the Waltham cyberstalker’s reign of fear was ended
Adobe Patches Flash Zero Day Exploited by Black Oasis APT
Brit intel fingers Iran for brute-force attacks on UK.gov email accounts
KRACK Attack Devastates Wi-Fi Security
Apple co-founder Steve Wozniak Launches ‘Woz U’ Online Tech Education Platform
National Cybersecurity Awareness Month Twitter Chats

We’ve gathered our own thoughts on the topics chosen each week for this short series of blogs that will be published twice a week. The post National Cybersecurity Awareness Month Twitter Chats appeared first on WeLiveSecurity

Chrome smoked by Edge in browser phishing test
Customers cheesed off after card details nicked in Pizza Hut data breach
DoubleLocker Android ransomware explained

The infection mechanism works well – which is crucial for determining how big of a deal a piece of malware is. The post DoubleLocker Android ransomware explained appeared first on WeLiveSecurity

Remember how you said it was cool if your mobe network sold your name, number and location?
WPA2 KRACK attack smacks Wi-Fi security: Fundamental crypto crapto

LinuxSecurity.com: Mathy Vanhoef of the imec-DistriNet research group of KU Leuven discovered multiple vulnerabilities in the WPA protocol, used for authentication in wireless networks. Those vulnerabilities applies to both the access point (implemented in hostapd) and the station (implemented in wpa_supplicant).

WPA2 security issues pose serious Wi-Fi safety questions

‘KRACK’ or Key Reinstallation AttaCK, as it has been labeled, means third parties could eavesdrop on a network meaning private conversations would no longer be private. The post WPA2 security issues pose serious Wi-Fi safety questions appeared first on WeLiveSecurity

Linus Torvalds lauds fuzzing for improving Linux security
Learn the ins and outs of Europe’s General Data Protection Regulation (GDPR)
‘Open sesame’… Subaru key fobs vulnerable, says engineer
WPA2 security in trouble as KRACK Belgian boffins tease key reinstallation bug

security update

Sounds painful: Audio code bug lets users, apps get root on Linux

LinuxSecurity.com: Fix CVE-2017-2887

LinuxSecurity.com: A vulnerability found in Shadow may allow remote attackers to cause a Denial of Service condition or produce other unspecified behaviors.

LinuxSecurity.com: A null pointer dereference in GnuTLS might allow attackers to cause a Denial of Service condition.

LinuxSecurity.com: 3.94 and patch for CVE-2017-15056

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

Hundreds Of websites mining cryptocurrency without user consent

LinuxSecurity.com: update to upstream release 0.3.1.7 —- update to upstream release 0.2.9.12 (SECURITY) (#1494860)

LinuxSecurity.com: Security fix for buffer overflow due to long input filenames [see Bug 1422550 and 1422545]

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

An oil industry hacker facing jail, a $20m damages bill, and claims of counter-hacking
New Android Ransomware Permanently Changes PIN, Demands Ransom
Cyberespionage Group Steps Up Campaigns Against Japanese Firms
What is a firewall?
500 million PCs are being used for stealth cryptocurrency mining online

LinuxSecurity.com: Multiple vulnerabilities have been found in WebkitGTK+, the worst of which may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Graphite, the worst of which could lead to the remote execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Puppet Agent, the worst of which could result in the execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in GNU Libtasn1, the worst of which may allow remote attackers to execute arbitrary code.

US Congress mulls first ‘hack back’ revenge law. And yup, you can guess what it’ll let people do

LinuxSecurity.com: Multiple vulnerabilities have been found in elfutils, the worst of which may allow remote attackers to cause a Denial of Service condition. [More…]

LinuxSecurity.com: Security fix for buffer overflow due to long input filenames [see Bug 1422550 and 1422545]

IT at sea makes data too easy to see: Ships are basically big floating security nightmares
Google Home Mini Secretly Recorded Conversations Due to “Flawed Touch Panel”
Pulitzer-winning website Politifact hacked to mine crypto-coins in browsers
Hackers steal restricted information on F-35 fighter, JDAM, P-8 and C-130
Kiss Goodbye to Privacy: Microsoft Introduces Cortana for Skype

Risk Level: Very Low. Type: Trojan.

Hyatt Hit By Credit Card Breach, Again

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. Rigzone Founder Caught Stealing Data Over the last few months, officials have been piecing together the […]

Google Busy Removing More Malicious Chrome Extensions from Web Store
Chris Brook Says Farewell to Threatpost
Android ransomware DoubleLocker encrypts data and changes PINs
Legacy Office Feature Used In Novel Document Attacks