Menu

Monthly Archives: December 2017

LinuxSecurity.com: An update for cfme, cfme-appliance, and cfme-gemset is now available for CloudForms Management Engine 5.7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Cryptocoins robbed at gunpoint
User ‘Gross Negligence’ Leaves Hundreds of Lexmark Printers Open to Attack
DOJ confirms Uber is under criminal investigation
Bitcoin FOMO or FOJI?
Watch out – fake support scams are alive and well this Christmas
Two critical and unpatched flaws identified in vBulletin
30% off APC 1500VA Compact UPS Battery Backup & Surge Protector
Zero Trust networks and enterprise security strategy | Salted Hash Ep 12
News agencies demand Facebook and Google pay for their stories
Bitfinex cryptocurrency exchange hit by “heavy DDoS” attack again
Malware Decompiler Tool Goes Open Source
Firefox users are ticked after Mozilla secretly installed Mr. Robot add-on

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Windows 10 bundles a briefly vulnerable password manager
No hack needed: Anonymisation beaten with a dash of SQL
Chinese woman unlocks colleague’s iPhone X through Face ID

LinuxSecurity.com: It was discovered that there was a command-injection vulnerability in kildclient, a “MUD” multiplayer real-time virtual world game. For Debian 7 “Wheezy”, this issue has been fixed in kildclient version

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

Lazarus group conducting malware attacks to steal Bitcoins

security update

Russian oil pipeline computer hacked to mine Monero coins

LinuxSecurity.com: The package tor before version 0.3.1.9-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

LinuxSecurity.com: The package openssl-1.0 before version 1.0.2.m-1 is vulnerable to multiple issues including information disclosure and denial of service.

LinuxSecurity.com: The package chromium before version 63.0.3239.108-1 is vulnerable to cross-site scripting.

Dune! Game App Leaking Sensitive Data of Millions of Android Users
Keeper Password Manager in Windows 10 Exposed Saved Passwords
Hackers steal 19M California voter records after holding database for ransom
Everything you need to know about virtual private networks (VPN)

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update is now available for JBoss Core Services on RHEL 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update is now available for JBoss Core Services on RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update is now available for Red Hat JBoss Core Services. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Merry Xmas, fellow code nerds: Avast open-sources decompiler

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

IDG Contributor Network: 3 predictions for devsecops in 2018
New OSX.Pirrit Malware floods Mac devices with ads; spies on users

LinuxSecurity.com: Reportbug, a tool designed to make the reporting of bugs in Debian easier, was further enhanced to automatically detect bug reports for potential regressions caused by a security update. After user confirmation an additional email with a copy of the report will be

LinuxSecurity.com: It was discovered that there was a vulnerability in sensible-browser, a utility to start the most suitable web browser based on your environment or configuration.

Triton Malware Targets Industrial Control Systems in Middle East
Simple research tool detects 19 unknown data breaches
Hackers Deploy Triton Malware to Shut Down Power Station
How MP Nadine Dorries could have shared her passwords securely
New tool exposes websites that have suffered data breaches
We need to talk about mathematical backdoors in encryption algorithms
Business Email Compromise scammer sentenced to 41 months in prison
Russia could chop vital undersea web cables, warns Brit military chief

LinuxSecurity.com: An erlang TLS server configured with cipher suites using RSA key exchange, may be vulnerable to an Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) against RSA, which when exploited, may result in plaintext recovery of encrypted messages and/or a Man-in-the-middle (MiTM)

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

Brit film board proposed as overlord of online pr0nz age checks
Is source code inspection a security risk? Maybe not, experts say
FCC repeals net neutrality
To avoid phishing hooks don’t swim with the shoal

LinuxSecurity.com: Update to 0.18.6

LinuxSecurity.com: USN-3509-2 introduced a regression in the Linux HWE kernel for Ubuntu 14.04 LTS.

LinuxSecurity.com: USN-3509-1 introduced a regression in the Linux kernel for Ubuntu 16.04 LTS.

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any questions? Just ask. NC County Crippled by Ransomware Attack Recently, a county in North Carolina was the target of a […]

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 11.0 (Ocata). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 9.0 (Mitaka). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Synaptics Says Claims of a Keylogger in HP Laptops are False

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

Man gets friend kidnapped to steal $1.8 million worth of Ethereum

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Satellite 5.8 and Red Hat Satellite 5.8 ELS. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: libxml2 could be made to crash or run arbitrary code if it opened a specially crafted file.

What’s in your Android’s December security update?
Starbucks Wi-Fi hijacked customers’ laptops to mine cryptocoins
Permissions Flaw Found on Azure AD Connect

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

85 Credential-Stealing Apps Found on Google Play Store
19-Year-Old ROBOT Flaw Resurfaces to Haunt Popular Websites
Mr. Robot season 3 finale: shutdown -r
Fox-IT reveals hackers hijacked its DNS records, spied on clients’ files
Mirai botnet authors plead guilty
Cybersecurity Trends 2018: The costs of connection

To help the reader navigate through the maze of such threats, ESET’s thought leaders have zeroed in on several areas that top the priority list in our exercise in looking forward. The post Cybersecurity Trends 2018: The costs of connection appeared first on WeLiveSecurity

Bitfinex cryptocurrency exchange is back up after repeated DDoS
The Mirai botnet: three men plead guilty after weaponizing the Internet of Things

LinuxSecurity.com: An update for go-toolset-7 and go-toolset-7-golang is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

UK.gov delays biometrics strategy again – but cops will STILL USE the tech
NIST Releases New Cybersecurity Framework Draft
Smashing Security podcast #057: Mikko – live from the sauna – talks Bitcoin security

LinuxSecurity.com: The package quagga before version 1.2.2-1 is vulnerable to denial of service.

LinuxSecurity.com: The package qt5-webengine before version 5.10.0-1 is vulnerable to multiple issues including arbitrary code execution, cross-site scripting, access restriction bypass, content spoofing and information disclosure.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.