Menu

Monthly Archives: November 2017

Parity: The bug that put $169m of Ethereum on ice? Yeah, it was on the todo list for months
Oracle Issues Emergency Patches for ‘JoltandBleed’ Vulnerabilities

LinuxSecurity.com: Rod Widdowson of Steading System Software LLP discovered a coding error in the OpenSAML library, causing the DynamicMetadataProvider class to fail configuring itself with the filters provided and omitting whatever checks they are intended to perform.

LinuxSecurity.com: Rod Widdowson of Steading System Software LLP discovered a coding error in the “Dynamic” metadata plugin of the Shibboleth Service Provider, causing the plugin to fail configuring itself with the filters provided and omitting whatever checks they are intended to perform.

security update

security update

Oracle scrambles to sew up horrid security holes in PeopleSoft’s Tuxedo
Another preinstalled app found on OnePlus that could collect user data
Drone maker DJI left its private SSL, firmware keys open to world+dog on GitHub FOR YEARS
White House Releases VEP Disclosure Rules
Ransomware via RDP – how to stay safe! [VIDEO]
A Boeing 757 was hacked remotely while it sat on the runway
Pawnbroker pwnd: Cash Converters says hacker slurped customer data
Forever 21 clothing stores hit by credit card data breach after encryption failure
Security is from Mars, Developers are from Venus……or ARE they?
New, revamped Terdot Trojan: It’s so 2017, it even fake-posts to Twitter
Woman scammed for $60,000 through fake Police website
Think you deleted that embarrassing WhatsApp message you sent? Think again

LinuxSecurity.com: It was discovered that jackson-databind, a Java library used to parse JSON and other data formats, improperly validated user input prior to deserializing: following DSA-4004-1 for CVE-2017-7525, an additional set of classes was identified as unsafe for deserialization.

DJI bug bounty NDA is ‘not signable’, say irate infosec researchers
YASAT – A Simple Security Auditing Tool
After a year of intensely investigating password theft, here’s what Google found
Deleted WhatsApp sent messages might not be gone forever
Homeland Security team remotely hacked a Boeing 757
Forever 21 informs customers of a potential data breach
Apple’s Face ID security fooled by simple face mask
Does UK high street banks’ crappy crypto actually matter?
Smashing Security podcast #052: Facebook tackles vengeful scumbags, and a sex toy privacy boob

LinuxSecurity.com: An update for openstack-aodh is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Q: Why are you running in the office? A: This is my password for El Reg

security update

The four problems with the US government’s latest rulebook on security bug disclosures
Cisco Warns of Critical Flaw in Voice OS-based Products
Crouching cyber Hidden Cobra: US warns Nork hackers are at it again with new software nasty
US govt’s ‘foreign’ spy program that can snoop on Americans at home. Sure, let’s reauth that…
Amazon Echo and Google Home Devices Vulnerable to BlueBorne Attack

Type: Vulnerability. Microsoft Office is prone to a cross-site request-forgery vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft ASP.NET Core is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to a memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft ASP.NET Core is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft ASP.NET Core is prone to an open-redirection vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft ASP.NET Core is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

LinuxSecurity.com: Update to 6.20170925 * https://hackage.haskell.org/package/git- annex-6.20170925/changelog Security fix for CVE-2017-12976.

Microsoft Patches 17-Year-Old Office Bug
Ransomware-spreading hackers sneak in through RDP
Confusion reigns over crypto vuln in Spanish electronic ID smartcards
Hackers mimicking little kids can fool voice recognition systems
Shadow Brokers cause ongoing headache for NSA
Got an Amazon Echo or Google Home? Patch ’em or face bite of Bluetooth-linked vuln
10-year-old kid uses his face to unlock mom’s iPhone X with Face ID
The 5 types of cyber attack you’re most likely to face

As a consultant, one of the biggest security problems I see is perception: The threats companies think they face are often vastly different than the threats that pose the greatest risk. For example, they hire me to deploy state-of-the-art public key infrastructure (PKI) or an enterprise-wide intrusion detection system when really what they need is […]

DHS says it remotely hacked a Boeing 757 sitting on a runway
11% off August Smart Lock Pro With Connect Bundle – Deal Alert
Coming live to a warzone near you: Army Truck Driver for Xbox!
Multi-stage malware sneaks into Google Play

In all the cases we investigated, the final payload was a mobile banking trojan. Once installed, it behaves like a typical malicious app of this kind: it may present the user with fake login forms to steal credentials or credit card details. The post Multi-stage malware sneaks into Google Play appeared first on WeLiveSecurity

LinuxSecurity.com: ‘shamger’ and Carlo Cannas discovered that a programming error in Varnish, a state of the art, high-performance web accelerator, may result in disclosure of memory contents or denial of service.

US rules on reporting cybersecurity flaws set to change according to source

Currently the US government employs an inter-agency review, created under former President Barack Obama. Known as the Vulnerability Equities Process, it is tasked with deciding what happens to any cybersecurity flaws that is discovered by the National Security Agency (NSA). The post US rules on reporting cybersecurity flaws set to change according to source appeared […]

10 best Linux distros for privacy fiends and security buffs in 2017
US Government issues alert about North Korean “Hidden Cobra” cyber attacks
Using bots to scam the scammers

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

10-year-old kid succeeds in unlocking his mum’s iPhone X, with just a glance
Uncle Sam to strap body sensors to hackers in nuke lab security study

LinuxSecurity.com: An update for php is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

How can airlines stop hackers pwning planes over the air? And don’t say ‘regular patches’
It’s 2017 – and your Windows PC can be forced to run malware-stuffed Excel macros
What do Vegas hookers, Colombian government, and 30,000 other sites have in common? Crypto-jacking miners

security update

There is a Pre-Installed Backdoor in OnePlus 5, 3 and 3T Devices
Microsoft Patches 20 Critical Vulnerabilities

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for jboss-ec2-eap is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

security update

Debugging Tool Left on OnePlus Phones, Enables Root Access
Texas National Guard secretly installed spying devices on surveillance aircrafts
Google study reveals how criminals break into Gmail accounts
Adobe Patches Flash Player, 56 Bugs in Reader and Acrobat