Menu

Monthly Archives: November 2017

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: The system could be made to crash or run programs as an administrator.

LinuxSecurity.com: Samba could be made to expose sensitive information over the network.

LinuxSecurity.com: formail could be made to crash or run programs if it processed specially crafted mail.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

How one man could have deleted any image on Facebook
Hackers can Exploit Load Planning Software to Capsize Balance of Large Vessels
Researchers Convert Human Bacteria into World’s Tiniest Tape Recorder
What keeps IT administrators up at night? Ransomware, for one | Salted Hash Ep 8
Newly Published Exploit Code Used to Spread Mirai Variant
Facebook tool will reveal if you were fooled by Russian propaganda
Imgur breached back in 2014, wasn’t storing your passwords properly
Looking for scrubs? Nah, NHS wants white hats – the infosec techie kind
Don’t shame idiots about their idiotically weak passwords
Facebook flaw allowed unauthorised users to delete any photo
Imgur hackers stole 1.7 million email addresses and passwords

LinuxSecurity.com: An update for samba is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for samba is now available for Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 6 and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

.GIF garage Imgur plugs 1.7 million-subscriber creds breach
Exim-ergency! Unix mailer has RCE, DoS vulnerabilities
Anonymous Muslim Group Confusing ISIS with Porn and Fake News

LinuxSecurity.com: An update that solves one vulnerability and has 5 fixes is An update that solves one vulnerability and has 5 fixes is An update that solves one vulnerability and has 5 fixes is now available. now available.

Fake Symantec Blog Caught Spreading Proton macOS Malware

LinuxSecurity.com: An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three fixes is now available. fixes is now available.

Imgur was hacked in 2014; affecting 1.7M users

LinuxSecurity.com: **Update** – Fixed chain-build – Remove hard dependency of bash-completion from fedpkg **rpkg** – Ignore TestModulesCli if openidc-client is unavailable (cqi) – Port mbs-build to rpkg (mprahl) – Add .vscode to .gitignore (mprahl) – Fix TestPatch.test_rediff in order to run with old version of mock (cqi) – Allow to specify alternative Copr config file […]

LinuxSecurity.com: **Update** – Fixed chain-build – Remove hard dependency of bash-completion from fedpkg **rpkg** – Ignore TestModulesCli if openidc-client is unavailable (cqi) – Port mbs-build to rpkg (mprahl) – Add .vscode to .gitignore (mprahl) – Fix TestPatch.test_rediff in order to run with old version of mock (cqi) – Allow to specify alternative Copr config file […]

“ProtonMail Contacts” world’s first encrypted contacts manager is here

LinuxSecurity.com: An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now available. errata is now available.

LinuxSecurity.com: An update that solves 33 vulnerabilities and has 7 fixes is An update that solves 33 vulnerabilities and has 7 fixes is An update that solves 33 vulnerabilities and has 7 fixes is now available. now available.

security update

security update

A gargantuan all-seeing eye is watching you on popular websites

LinuxSecurity.com: An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three fixes is now available. fixes is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

Alleged HBO hacker is an Iranian the FBI can’t arrest
MS Office’ Default Function Can Be Used to Create Self-Replicating Malware

Risk Level: Very Low. Type: Trojan, Worm.

Risk Level: Very Low. Type: Trojan, Worm.

Risk Level: Very Low. Type: Trojan, Worm.

Blockchain Wallet CoinPouch Hacked; Verge Coins Stolen
SAML Post-Intrusion Attack Mirrors ‘Golden Ticket’
3 simple tips to stay off the hook this phishing season
Seek ‘passion’ and tech skills will follow, say recruiting security chiefs
New reality in European banking looming large: the lowdown

At the heart of the regulation is the requirement for banks to allow licensed third-party providers (TPPs) of financial services to access securely their customer-account data, as long as the customer has given their prior consent. The post New reality in European banking looming large: the lowdown appeared first on WeLiveSecurity

UK emergency crews get 4G smartmobes as monkeys attempt to emerge from Reg’s butt
EU’s data protection bods join the party to investigate Uber breach
Cloud storage for password managers – are you for or against?
‘Treat infosec fails like plane crashes’ – but hopefully with less death and twisted metal
Busy Browsers attract Black Friday Burglars

Just as in past decades when cash drawers and bank vaults were targeted for theft, today’s e-shops and online banks have fallen under the scope of cybercriminals. Their “digital-focus” is just an evolutionary step beyond robbing stagecoaches in the Wild West, and banks in the 20th century. The post Busy Browsers attract Black Friday Burglars […]

Linus Torvalds on security: ‘Do no harm, don’t break users’
Firefox to warn users who visit p0wned sites

LinuxSecurity.com: An update that solves three vulnerabilities and has two An update that solves three vulnerabilities and has two An update that solves three vulnerabilities and has two fixes is now available. fixes is now available.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in impersonation of Kerberos services, denial of service, sandbox bypass or HTTP header injection.

LinuxSecurity.com: Two vulnerabilities were discovered in the Open Ticket Request System which could result in disclosure of database credentials or the execution of arbitrary shell commands by logged-in agents.

Alleged HBO hacker identified, charged and indicted

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available.

security update

Firefox to collaborate with HaveIBeenPwned to alert users on data breach

LinuxSecurity.com: **Update** – Fixed chain-build – Remove hard dependency of bash-completion from fedpkg **rpkg** – Ignore TestModulesCli if openidc-client is unavailable (cqi) – Port mbs-build to rpkg (mprahl) – Add .vscode to .gitignore (mprahl) – Fix TestPatch.test_rediff in order to run with old version of mock (cqi) – Allow to specify alternative Copr config file […]

LinuxSecurity.com: **Update** – Fixed chain-build – Remove hard dependency of bash-completion from fedpkg **rpkg** – Ignore TestModulesCli if openidc-client is unavailable (cqi) – Port mbs-build to rpkg (mprahl) – Add .vscode to .gitignore (mprahl) – Fix TestPatch.test_rediff in order to run with old version of mock (cqi) – Allow to specify alternative Copr config file […]

Tether hits back after $31m cryptocurrency hack

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: update to 9.5.10, per release notes http://www.postgresql.org/docs/9.5/static/release-9-5-10.html

LinuxSecurity.com: Tobias Schneider discovered that libspring-ldap-java, a Java library for Spring-based applications using the Lightweight Directory Access Protocol, would under some circumstances allow authentication with a correct username but an arbitrary password.

LinuxSecurity.com: update to 9.6.6 per release notes: https://www.postgresql.org/docs/9.6/static/release-9-6-6.html

LinuxSecurity.com: An update that solves three vulnerabilities and has two An update that solves three vulnerabilities and has two An update that solves three vulnerabilities and has two fixes is now available. fixes is now available.

Tips for Making Your Business Secure from Digital Crimes
Royal Navy destroyer leaves Middle East due to propeller problems
‘Data is the new oil’: F-Secure man on cartels, disinformation and IoT
Worries over Intel’s Mangement Engine grow after new flaws found
Androids caught secretly reporting location data regardless of opt-out
World’s top websites record all your browsing movements
Mr. Robot eps3.6_fredrick+tanya.chk – the security review
Smartphone adoption among older Americans continues growth spurt

Some three-quarters of users up to 34 years of age reported that they “definitely” or “probably” use their phone too much. Almost half (47 percent) of all ages said they make a conscious effort to pare back their mobile phone time, most commonly by keeping their devices in their bag or pocket or by switching […]

US indicts alleged culprit of HBO hack-and-extort campaign

Between approximately July 23 and 29, Mesri reportedly engaged in his blackmail campaign. After the TV network didn’t pay the required $6 million in digital cryptocurrency, he began leaking portions of the stolen data on July 30. The post US indicts alleged culprit of HBO hack-and-extort campaign appeared first on WeLiveSecurity

To fix Intel’s firmware fiasco, wait for Christmas Eve or 2018
Samba needs two patches, unless you’re happy for SMB servers to dance for evildoers
Devs working to stop Go math error bugging crypto software
Smashing Security podcast #053: Game of Thrones, a major Amazon cloud leak, and web tracking gone crazy

LinuxSecurity.com: An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

security update

security update

3 Cybersecurity Predictions for 2018
What we know about Uber (so far, anyway) [VIDEO]
HP to Patch Bug Impacting 50 Enterprise Printer Models

Risk Level: Very Low. Type: Trojan.

Black Friday shopping? “A little delay goes a long way!”
Permissionless data slurping: Why Google’s latest bombshell matters
You’re such a goober, Uber: UK regulators blast hushed breach
Google and Twitter turn their backs on Russian media over fake news
Uber Paid Hackers $100k to Hide Massive Theft of 75M Accounts
Possible cut to British F-35 order considered before Parliament
Girls Inc. in the spotlight: Nonprofit Pitch Fest contest grand prize winner

Girls Inc. of San Diego County was founded 50 years ago as a local affiliate of the national Girls Inc. The national organization was started as the Girls Club of America more than 150 years ago, to help young women who had migrated from rural communities in search of job opportunities. The post Girls Inc. […]

Chromebook exploit earns researcher second $100k bounty