Menu

Monthly Archives: January 2018

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: It was discovered that PHP5 was vulnerable to a reflected cross-site scripting (XSS) attack on the PHAR 404 error page by manipulating the URI of a request for a .phar file. This issue is only exploitable if the web server is configured to handle phar files using PHP5.

Android Malware in gaming apps on Play Store downloaded 4 million times
Crackas with Attitude’ hacker posed as CIA Chief to access secret data
State-Sponsored Malware Campaign Hits Users Across 21 Countries
Rogue Chrome, Firefox Extensions Hijack Browsers; Prevent Easy Removal
Mozilla mandates that new Firefox features rely on encrypted connections
Unlocked: The hidden love note on the grave of America’s first crypto power-couple

“How to buy Bitcoin” dominated Google how-to searches in 2017, ranking third overall. With the hype surrounding cryptocurrency at a palpably all-time high, now is a better time than ever to cover the essentials of keeping cryptocurrencies safe. If you are just getting into the crypto space or you’ve known what ‘HODL’ means for a […]

Opponents Vow to Continue the Fight after Trump Reauthorizes Domestic Spying Law
America restarts dodgy spying program – just as classified surveillance abuse memo emerges
OnePlus website hacked; credit card data of 40,000 users stolen

security update

OnePlus Confirms Credit Card Breach Impacted Up to 40,000 Customers

Type: Vulnerability. Microsoft Office for MAC is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

New Dridex Variant Emerges With An FTP Twist
Apple Preps ChaiOS iMessage Bug Fix for Next Week
Facebook Hacking Android Malware GhostTeam Found in 53 Play Store Apps

The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any questions? Just ask. Hospital Pays Ransom to Restore Systems, Despite Having Backups In the first cyberattack of 2018 to hit […]

There are other, legal ways to nab Microsoft emails, privacy groups remind Supremes
The Google Play “Super Antivirus” that’s not so super at all… [REPORT]
90% of Gmail users could improve their security easily, but don’t
Virtual reality porn app SinVR exposes details of 20,000 customers
“Give me a job or else!” approach fails to land IT job
Man Admits to Directing DDoS Attacks Across the US
Does your credit card need a tinfoil hat to keep it safe on the train?

LinuxSecurity.com: It was discovered that there was a denial-of-service attack in the libgd2 image library. A corrupt file could have exploited a signedness confusion leading to an infinite loop.

LinuxSecurity.com: It was discovered that there was an injection vulnerability in the rsync file-copying tool. For Debian 7 “Wheezy”, this issue has been fixed in rsync version

Are mobile devices insecure by nature?

Granted, not all that glitters is gold, and mobiles also come with some drawbacks in terms of the protection of information. There are a number of risks that users may face when trying to secure their information on mobiles and tablets. The post Are mobile devices insecure by nature? appeared first on WeLiveSecurity

Delve into the hidden corners of security at CyberThreat18

LinuxSecurity.com: The cPanel Security Team discovered that awstats, a log file analyzer, was vulnerable to path traversal attacks. A remote unauthenticated attacker could leverage that to perform arbitrary code execution.

Two things will survive a nuclear holocaust: Cockroaches and crafty URLs like ғасеьоок.com

security update

LinuxSecurity.com: Tavis Ormandy discovered a vulnerability in the Transmission BitTorrent client; insecure RPC handling between the Transmission daemon and the client interface(s) may result in the execution of arbitrary code if a user visits a malicious website while Transmission is running.

LinuxSecurity.com: The package bind before version 9.11.2.P1-1 is vulnerable to denial of service.

LinuxSecurity.com: The package perl-xml-libxml before version 2.0130-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package nrpe before version 3.2.1-3 is vulnerable to arbitrary command execution.

LinuxSecurity.com: The package transmission-cli before version 2.92-8 is vulnerable to arbitrary command execution.

LinuxSecurity.com: The package irssi before version 1.0.6-1 is vulnerable to denial of service.

You get a lawsuit! And you get a lawsuit! And you! Now Apple sued over CPU security flaws
Sprawling Mobile Espionage Campaign Targets Android Devices

LinuxSecurity.com: An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Fix permissions on rootsh log directory to limit it to root.

Sad-sack Anon calling himself ‘Mr Cunnilingus’ online is busted for DDoSing ex-bosses
6 years jail time for ‘one of the largest’ dark web drug dealer
Google Awards Record $112,500 Bounty for Android Exploit Chain

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0094

LinuxSecurity.com: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0093

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0093

LinuxSecurity.com:

LinuxSecurity.com: This is new version of irssi. It contains security fixes for CVE-2018-5205 CVE-2018-5206 CVE-2018-5207 CVE-2018-5208 .

LinuxSecurity.com: – Resolves: #1510351 – CVE-2017-14992 – built docker @projectatomic/docker-1.13.1 commit 584d391 – built docker-novolume-plugin commit 385ec70 – built rhel-push-plugin commit af9107b – built docker-lvm-plugin commit 8647404 – built docker-runc @projectatomic/docker-1.13.1 commit 1c91122 – built docker-containerd @projectatomic/docker-1.13.1 commit 62a9c60 – built

chaiOS “Text Bomb” Can Freeze & Crash Your iPhone

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Someone is touting a mobile, PC spyware platform called Dark Caracal to governments
Intel Says Firmware Fixes for Spectre and Meltdown Affecting Newer Chips
Researcher reports how to hack Facebook account with Oculus Integration
Less than 10% of Gmail users have enabled two-factor authentication
F-35 ‘incomparable’ to Harrier jump jet, top test pilot tells El Reg
Virtual Reality (VR) Porn App Exposed Personal Data of 20k Users
Google fuels up Chromecast Wi-Fi flooding fix
And Oracle E-biz suite makes 3: Package also vulnerable to exploit used by crytpo-currency miner
CES 2018 cybersecurity: Now in every single ‘whatchamacallit’

Not content anymore to just have a bed made of soft plushy stuff, now you can adjust everything about the bed, from electronically sitting up in bed to the lighting surrounding your nap: connected digital technology everywhere. The post CES 2018 cybersecurity: Now in every single ‘whatchamacallit’ appeared first on WeLiveSecurity

Yes, Hawaii emergency management stuck a password on a sticky note
Hijackers DM @realDonaldTrump from former Fox News hosts’ accounts
The first lawsuits to save net neutrality have been filed
BlackWallet cryptocurrency site loses users’ money after DNS hijack
Trends 2018: Personal data in the new age of technology and legislation

The depth of data collected from our online habits could easily allow profiles to be constructed, showing what may be considered extremely personal interests, drawing on information that we don’t realize someone is collecting. The post Trends 2018: Personal data in the new age of technology and legislation appeared first on WeLiveSecurity

SkyGoFree malware spies on your Android phone and your messages
Smashing Security #061: Fallout over Hawaii missile false alarm
VTech fondleslabs for kids ‘still vulnerable’ despite sanctions
Mozilla edict: ‘Web-accessible’ features need ‘secure contexts’
North Korea’s finest spent 2017 distributing RATs, wipers, and phish
Industrial systems scrambling to catch up with Meltdown, Spectre

LinuxSecurity.com: Security fix for CVE-2018-5702 (Mitigate dns rebinding attacks against daemon)

LinuxSecurity.com: – Update to 52.5.3 – Patched for mozilla bug-1427870 (spectre mitigation)

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: – Update to 52.5.3 – Patched for mozilla bug-1427870 (spectre mitigation)

New macOS malware hijacks DNS settings and takes screenshots
Attackers Use Microsoft Office Vulnerabilities to Spread Zyklon Malware

LinuxSecurity.com: New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

Who’s using 2FA? Sweet FA. Less than 1 in 10 Gmail users enable two-factor authentication

LinuxSecurity.com: It was discovered that multiple encryption key classes in the Librariescomponent of OpenJDK did not properly synchronize access to their internaldata. This could possibly cause a multi-threaded Java application to applyweak encryption to data because of the use of a key that was zeroed out.(CVE-2018-2579)Note: If the web browser plug-in provided by the icedtea-web […]

Oracle Ships 237 Fixes in Latest Critical Patch Update

security update

HTML5 may as well stand for Hey, Track Me Longtime 5. Ads can use it to fingerprint netizens