Menu

Monthly Archives: December 2017

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

OK, OK, MIRA-I DID IT: Botnet-building compsci kid comes clean

LinuxSecurity.com: An update that solves three vulnerabilities and has three An update that solves three vulnerabilities and has three An update that solves three vulnerabilities and has three fixes is now available. fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

Hackers behind Mirai botnet & DYN DDoS attacks plead guilty
19-Year-Old TLS Vulnerability Weakens Modern Website Crypto

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer are prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office Outlook is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to an information-disclosure vulnerability; fixes are available.

LinuxSecurity.com: An update for eap7-jboss-ec2-eap is now available for Red Hat JBoss Enterprise Application Platform 7.1 for Red Hat Enterprise Linux 6 and Red Hat JBoss Enterprise Application Platform 7.1 for Red Hat Enterprise Linux 7.

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 7.1 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 7.1 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: A regression was added by the patch introduced in version 0.5.0-2+deb7u2 to fix CVE-2017-16927: xrdp-sesman started to segfault in libscp. For Debian 7 “Wheezy”, these problems have been fixed in version

LinuxSecurity.com: An update for rh-java-common-lucene5 is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for rh-java-common-lucene is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Fix to directory traversal attacks (CVE-2017-17042).

LinuxSecurity.com: Update to 2.1 —- Update to 2.0, Initial support for aarch64 images and associated SBCs

Break the Internet: a last ditch attempt to save net neutrality
Banker jailed for helping criminals who stole millions using Dridex malware
Netflix sparks privacy row after making fun of users of Twitter
Barclays employee sentenced for aiding Dridex money launderers
Massive Uber data scraping and secret servers exposed in Waymo suit
Memes: the explanation of nearly everything – including computer viruses

We still don’t have a solid scientific theory of memes; nonetheless, they already allow us to understand why certain things happen the way they do. Memes are “alive”; they reproduce, mutate, and evolve according to Darwinian laws. The post Memes: the explanation of nearly everything – including computer viruses appeared first on WeLiveSecurity

Apple plugs IoT HomeKit hole
File with 1.4 Billion Hacked and Leaked Passwords Found on the Dark Web
Newly Revealed Flaw in Intel Processors Allows Undetectable Malware
Australian airport hack was ‘a near miss’ says government’s cybersecurity expert
One per cent of all websites probably p0wned each year, say boffins
Up to ‘ONE BEEELLION’ vid-stream gawpers toil in crypto-coin mines
Put down the eggnog, it’s Patch Tuesday: Fix Windows boxes ASAP
Intel to slap hardware lock on Management Engine code to thwart downgrade attacks
I, Robot? Aiiiee, ROBOT! RSA TLS crypto attack pwns Facebook, PayPal, 27 of 100 top domains

Risk Level: Very Low. Type: Trojan.

Tenable’s response to folks upset at AWOL features: A 150-emails-a-minute spam storm
It’s time to patch your Microsoft and Adobe software again against vulnerabilities
What is the cyber kill chain?
Kaspersky dragged into US govt’s trashcan as weaponized blockchain agile devops mulled
Microsoft December Patch Tuesday Update Fixes 34 Bugs
Argy-bargy Argies barge into Starbucks Wi-Fi with alt-coin discharges

security update

Sophisticated ‘MoneyTaker’ group stole millions from Russian & US banks
New Spider Ransomware Comes With 96-Hour Deadline

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2017:3402

iOS jailbreak exploit published by Google
Bitfinex cryptocurrency exchange hit by massive DDoS attacks​
Ransom email scam from ‘hitman’ demands: pay up or die
Man apologizes after photo of ‘racist’ woman goes viral
Brrr! It’s a snow day and someone has pwned the chuffin’ school heating
Cryptocurrency in kilowatt hours: Counting the costs of anonymous transactions

The energy costs are not the only charges in a transaction: the bitcoin network itself levies a charge which, according to a blog from Valve, the gaming provider behind the Steam network, has skyrocketed from $0.20 in 2016 to $20 per transaction today The post Cryptocurrency in kilowatt hours: Counting the costs of anonymous transactions […]

Coinbase: don’t expect to trade your cryptocurrency at busy times
This Fidget spinner app is sending other apps data to Chinese server

It has been a turbulent year of devastating ransomware attacks (e.g. NotPetya) and gut-wrenching breaches (e.g. Equifax). Undoubtedly, the question on everyone’s mind is, “what’s in store for us in the New Year?” Webroot’s top 10 cybersecurity predictions for 2018 covers everything from ransomware and breaches to mobile, cryptocurrency, and government.We’ve grouped our predictions to […]

Spies are watching… on LinkedIn
Watch: How to Pick a Lock
Dyn Inc. DDoS anniversary, and the truth about the Reaper botnet

LinuxSecurity.com: New release (1:12.2.2-1), security fix for CVE-2017-16818

LinuxSecurity.com: Fix omapi SD leak (#1523547)

LinuxSecurity.com: * CVE-2017-1000256: libvirt: TLS certificate verification disabled for clients (bz #1503687) * Fix qemu image locking with shared disks (bz #1513447)

LinuxSecurity.com: Fix to directory traversal attacks (CVE-2017-17042).

LinuxSecurity.com: This is an update fixing denial of service (CVE-2017-16944). —- This is an update fixing use-after-free (CVE-2017-16943).

LinuxSecurity.com: Upstream annoucement: [WordPress 4.9.1 Security and Maintenance Release](https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and- maintenance-release/)

LinuxSecurity.com: Update to latest version. Contains security fixes for CVE-2017-15090, CVE-2017-15092, CVE-2017-15093 and CVE-2017-15094

LinuxSecurity.com: * Ver. 19.3.6.4

LinuxSecurity.com: The simplesamlphp package in wheezy is vulnerable to multiple attacks on authentication-related code, leading to unauthorized access and information disclosure.

LinuxSecurity.com: Several vulnerabilities have been discovered in the chromium web browser. CVE-2017-15407

Why bother cracking PCs? Spot o’ malware on PLCs… Done. Industrial control network pwned
Enterprise security spend to continue to trend higher

A breakdown of the ‘spending pie’ shows that the ‘security services’ segment is projected to make up nearly 60% of the total IT security budgets, followed by the ‘infrastructure protection’ segment on a little over 18%. The post Enterprise security spend to continue to trend higher appeared first on WeLiveSecurity

LinuxSecurity.com: An update for org.ovirt.engine-root is now available for Red Hat Virtualization Manager version 4.1. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

Google’s Project Zero reveals Apple jailbreak exploit
Archive of 1.4 BEEELLION credentials in clear text found in dark web archive
HP leaves accidental keylogger in laptop keyboard driver

security update

Type: Vulnerability. Microsoft Excel is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft PowerPoint is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.