Menu

Monthly Archives: January 2018

New Android Malware records audio, video & steals WhatsApp messages

Type: Vulnerability. Multiple CPU Hardwares are prone to an information-disclosure vulnerability; fixes are available.

Potent Skygofree Malware Packs ‘Never-Before-Seen’ Features

LinuxSecurity.com: Rebase `osc` and `osc-source_validator` to new versions for security fixes for CVE-2017-9274

LinuxSecurity.com: Rebase `osc` and `osc-source_validator` to new versions for security fixes for CVE-2017-9274

Mozilla Joins U.S. Attorneys General In Bid to Restore Net Neutrality
4 Malicious Chrome Extensions Put 500k Users at Risk of Click Fraud
Former Santander bank manager pleads guilty to computer misuse crimes
Fighting cyber attacks with nuclear weapons
Carphone Warehouse faces hefty fine for 2015 breach

The attackers gained access to a range of customer data such as names, addresses, phone numbers, dates of birth, and marital status. Making matters worse, the historical payment card details of some 18,000 customers were also compromised. The post Carphone Warehouse faces hefty fine for 2015 breach appeared first on WeLiveSecurity

Firefox locks down its future with HTTPS ‘secure contexts’
Twitter denies claims that it snoops on your private messages
Hawaii’s missile alert agency keeps its password on a Post-it note
Mental Models & Security: Thinking Like a Hacker
Android security: This newly discovered snooping tool has remarkable spying abilities
Spectre and Meltdown patches causing trouble as realistic attacks get closer
Biggest vuln bombshell in forever and storage industry still umms and errs over patches
CES 2018: Blockchain will solve everything

The first obvious candidate was banking, a sector that has been hard at work trying to implement blockchain to secure the vast troves of digital transactions that happen every microsecond of every day. The post CES 2018: Blockchain will solve everything appeared first on WeLiveSecurity

Man charged with selling billions of breached records on LeakedSource
Wanna motivate staff to be more secure? Don’t bother bribing ’em
Another round of click-fraud extensions pulled from Chrome Store
Beware! A new bug can crash iOS and macOS with a single text message

LinuxSecurity.com: Multiple vulnerabilities have been found in rsync, the worst of which could allow remote attackers to bypass access restrictions.

BIND comes apart thanks to ancient denial-of-service vuln

security update

Hospital injects $60,000 into crims’ coffers to cure malware infection
It’s raining fake missiles: Japan follows Hawaii with mistaken alert

LinuxSecurity.com: An update for microcode_ctl is now available for Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 6.2 Advanced Update Support, Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, Red Hat Enterprise Linux 6.6 Advanced Update Support, Red

LinuxSecurity.com: The Check Point Research Team discovered that the XBMC media center allows arbitrary file write when a malicious subtitle file is downloaded in zip format. This update requires the new dependency libboost-regex1.49.

LinuxSecurity.com: An update for linux-firmware is now available for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.2 Telco Extended Update Support, Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions, and Red Hat Enterprise Linux 7.3

LinuxSecurity.com: Jayachandran Palanisamy of Cygate AB reported that BIND, a DNS server implementation, was improperly sequencing cleanup operations, leading in some cases to a use-after-free error, triggering an assertion failure and crash in named.

Google Chrome Once Again Target of Malicious Extensions

LinuxSecurity.com: An update that solves 14 vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: Transmission could be made to run arbitraty code.

LinuxSecurity.com: An update is now available for Red Hat CloudForms 4.0. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Lenovo Patches Networking OS Vulnerability Dating Back to 2004
BlackWallet hacked: Hackers replace DNS server, steal $400k in Stellar

security update

LinuxSecurity.com: Qtpass password generation had a bug where only a 1000 different passwords where possible https://github.com/IJHack/QtPass/issues/338 —- Upstream release

LinuxSecurity.com: Qtpass password generation had a bug where only a 1000 different passwords where possible https://github.com/IJHack/QtPass/issues/338

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that solves 7 vulnerabilities and has three fixes is now available.

Risk Level: Very Low. Type: Trojan.

FBI expert calls Apple ‘jerks’ as encryption tension simmers
Android snoopware Skygofree can pilfer WhatsApp messages
New BitTorrent Flaw Puts Linux & Windows devices at risk of hacking
UK’s Just Eat faces probe after woman tweets chat-up texts from ‘delivery guy’
Smart card forwarding with Fedora
Man charged over fatal “Call of Duty” SWATting
Hawaii missile alert triggered by one wrong click
Scammers and jobhunters

It’s easier to have scruples about how you earn your living when you’re not one of millions of people chasing just a few thousand jobs. The post Scammers and jobhunters appeared first on WeLiveSecurity

New Mirai botnet species ‘Okiru’ hunts for ARC-based kit
Congress Renews Warrantless Surveillance-And Makes It Even Worse
The “Doublespeak” of Responsible Encryption
Wi-Fi Alliance announces WPA3 to secure modern networks
How I’ve captured all passwords trying to ssh into my server
Cybersecurity quiz winners rewarded with malware-infected USB sticks

LinuxSecurity.com: This release does a complete update of the CA list. This includes removing the StartCom and WoSign certificates to as they are now untrusted by the major browser vendors.

LinuxSecurity.com: New kernel packages are available for Slackware 14.0 and 14.2 to fix security issues.

LinuxSecurity.com: A vulnerability has been discovered in GraphicsMagick, a collection of image processing tools, which may result in a denial of service.

Canada charges chap alleged to run stolen data-mart Leakedsource
Bad benchmarks bedevil boffins’ infosec efforts
Operator of hacked password service Leakedsource.com arrested
Netflix phishing campaign goes after your login, credit card, mugshot and ID

LinuxSecurity.com: An update is now available for Red Hat CloudForms 4.5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update is now available for Red Hat CloudForms 4.2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update is now available for Red Hat CloudForms 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Police distributed malware infected USBs as cybersecurity quiz prizes

LinuxSecurity.com: It was discovered that multiple integer overflows in the GIF image loader in the GDK Pixbuf library may result in denial of service and potentially the execution of arbitrary code if a malformed image file is opened.

security update

LinuxSecurity.com: Several security issues were fixed in GDK-PixBuf.

Now Meltdown patches are making industrial control systems lurch

LinuxSecurity.com: David Sopas discovered that Kohana, a PHP framework, was vulnerable to a Cross-site scripting (XSS) attack that allowed remote attackers to inject arbitrary web script or HTML by bypassing the strip_image_tags protection mechanism in system/classes/Kohana/Security.php. This issue

House votes for six more years of warrantless surveillance
OnePlus denies checkout page hack amid credit card fraud reports
Typosquatting and the risks of one wrong keystroke
How to set up 2FA on your Facebook account
More SCADA app vulnerabilities found
Inside Uber’s $100,000 Payment to a Hacker, and the Fallout
Are mass transit systems the next cybersecurity target? | Salted Hash Ep 14
Customers reporting credit card fraud after using OnePlus webstore
CES 2018: Why doesn’t everyone use VR already?

One side effect of slower than expected uptake of VR is that virtual reality application developers have been slow to invest in creating content. In this sort of chicken-and-egg cycle, growth tends to be slow, not explosive. The post CES 2018: Why doesn’t everyone use VR already? appeared first on WeLiveSecurity

iPhone’s Apple Health data used as evidence in murder trial
Your Facebook News Feed is getting an overhaul
UK.gov denies data processing framework is ‘sinister’ – but admits ICO has concerns
Meltdown/Spectre fixes made AWS CPUs cry, says SolarWinds
Hawaii’s ballistic missile false alarm and a user interface failure

LinuxSecurity.com: Multiple vulnerabilities have been found in PolarSSL, the worst of which may allow remote attackers to execute arbitrary code.

Oracle still silent on Meltdown, but lists patches for x86 servers among 233 new fixes

LinuxSecurity.com: Multiple vulnerabilities have been found in Xen, the worst of which could allow for privilege escalation.

LinuxSecurity.com: Philip Huppert discovered the Shibboleth service provider is vulnerable to impersonation attacks and information disclosure due to mishandling of DTDs in the XMLTooling XML parsing library. For additional details please refer to the upstream advisory at

LinuxSecurity.com: The package qtpass before version 1.2.1-1 is vulnerable to private key recovery.

security update

LinuxSecurity.com: Tavis Ormandy discovered a vulnerability in the Transmission BitTorrent client; insecure RPC handling between the Transmission daemon and the client interface(s) may result in the execution of arbitrary code if a user visits a malicious website while Transmission is running.

Intel puts security on the todo list, Tavis topples torrent tool, and more
Let’s Encrypt plugs hole that let miscreants grab HTTPS web certs for strangers’ domains
Feds may have to explain knowledge of security holes – if draft law comes into play
How to Protect Your Personal Data in 3 Simple Ways