Menu

Monthly Archives: January 2018

What are “WannaMine” attacks, and how do I avoid them?

LinuxSecurity.com: Several security issues were fixed in curl.

Windows Defender will strap pushy scareware to its ass-kicker machine

security update

Lizard Squad is alive and continuing activities as BigBotPein: Report
New click-to-hack tool: One script to exploit them all and in the darkness TCP bind them
Google Booted 700,000 Bad Apps From Its Marketplace in 2017

Risk Level: Very Low. Type: Trojan.

Terror law expert to UK.gov: Why backdoors when there’s so much other data to slurp?
Georgia bill poses potential threat to cybersecurity researchers
Johnny Hacker hauls out NSA-crafted Server Message Block exploits, revamps ’em
Hacker compromised user data & illegally used car sharing service 33 times
Multiple Critical Flaws Found in Zoho’s ManageEngine
Google smashed over 700,000 bad Android apps last year

Google says that it is getting better than ever at protecting Android users against bad apps and malicious developers. The post Google smashed over 700,000 bad Android apps last year appeared first on WeLiveSecurity

Flaws in Gas Station Software Let Hackers Change Prices, Steal Fuel, Erase Evidence
Bitcoin payments used to unmask dark web users
Camera makers resist encryption, despite warnings from photographers
Ban Facebook Messenger for Kids, urge children’s health advocates
Oracle point-of-sale system vulnerabilities get Big Red cross
My cryptocoin startup vanished and all I got was this lousy penis

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHBA-2018:0169

Torvalds Releases Linux 4.15 With Improved Meltdown, Spectre Patches
Forget cyber crims, it’s time to start worrying about GPS jammers – UK.gov report

LinuxSecurity.com: openSUSE: openSUSE Leap 42.2 has reached end of SUSE support

Most Threatening DNS Security Risks And How To Avoid Them
Bitcoin hijack steals from both ransomware authors AND their victims
To hack Australia and learn its secrets, buy second-hand furniture
Ransomware makes it into the Oxford English Dictionary

LinuxSecurity.com: The package zathura-pdf-mupdf before version 0.3.2-2 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package mupdf-tools before version 1.12.0-2 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package libmupdf before version 1.12.0-2 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package mupdf-gl before version 1.12.0-2 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package mupdf before version 1.12.0-2 is vulnerable to arbitrary code execution.

Tor Proxy Used By Cybercriminals To Initiate Bitcoin Theft

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

I’ll torpedo Tor weirdos, US AG storms: Feds have ‘already infiltrated’ darknet drug souks
Unsanitary Firefox gets fix for critical HTML-handling hijack flaw

LinuxSecurity.com: An update for collectd is now available for Red Hat OpenStack Platform 12.0 Operational Tools for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Car-share biz GoGet became data share biz after 2017 hack attack

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code, denial of service or URL spoofing. For the oldstable distribution (jessie), these problems have been fixed

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: An update for erlang is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for openstack-nova is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Ethereum Startup Leaves Penis for Investors & Vanishes with $11
Kremlin social media trolls aren’t actually that influential, study finds
Cisco Patches Critical VPN Vulnerability
Attackers can Bypass Fingerprint Authentication in Lenovo devices
Scammers become the scammed: Ransomware payments diverted with Tor proxy trickery
Stop dilly-dallying. Block all ads on YouTube
Are organizations prepared for the ransomware threat?
Secret Service warning: Jackpotting ATM attacks reach the US
Deepfakes AI celebrity porn channel shut down by Discord

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

Privacy of fitness tracking apps in the spotlight after soldiers’ exercise routes shared online
Bitcoin exchange robbed by real-life bank robbers with real-life guns
Keylogger found on thousands of WordPress-based sites
F-35 flight tests are being delayed by onboard software snafus
Secret military bases revealed by fitness app Strava
Maybe you should’ve stuck with NetWare: Hijackers can bypass Active Directory controls
Crooks make US ATMs spew million-plus bucks in ‘jackpotting’ hacks
Ugly, perfect ten-rated bug hits Cisco VPNs

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

Jackpotting attacks hit U.S. ATMs; spit out cash in seconds
Ploutus.D Malware Variant Used in U.S.-based ATM Jackpotting Attacks
Intel alerted Chinese cloud giants ‘before US govt’ about CPU bugs

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

$500m cryptocoin heist could be biggest cybertheft ever
What do you press when flaws in Bluetooth panic buttons are exposed?
Phishing Scam: Hackers Steal $150,000 in Ethereum from Experty ICO
Strava’s Global Heat Map Exposes User Locations Including Military Bases
UK infrastructure firms to face £17m fine if their cybersecurity sucks
Thar she blows: Strava heat map shows folk on shipwreck packed with 1,500 tonnes of bombs
Cop buys mobile spyware, says he can’t remember why
Researchers warn of invisible attacks on electrical sensors
Lyft investigates allegations of employees snooping on riders
Ready for the EU’s GDPR compliance deadline? Many companies aren’t | Salted Hash Ep 16

LinuxSecurity.com: The package lib32-glibc before version 2.26-11 is vulnerable to privilege escalation.

LinuxSecurity.com: The package glibc before version 2.26-11 is vulnerable to privilege escalation.

You can’t ignore Spectre. Look, it’s pressing its nose against your screen
You publish 20,000 clean patches, but one goes wrong and you’re a PC-crippler forever
Microsoft works weekends to kill Intel’s shoddy Spectre patch
All your base are belong to us: Exercise app maps military sites, reveals where spies jog
CrossRAT keylogging malware targets Linux, macOS & Windows PCs

security update

security update

LinuxSecurity.com: An update that fixes 24 vulnerabilities is now available.