Menu

Monthly Archives: January 2018

LinuxSecurity.com: Rebased to 1.37.0.

Hacker demands ransom in Bitcoin after taking over hospital servers

security update

Cisco’s new tool will detect malware in encrypted traffic
Lenovo removes backdoor present in networking switches since 2004
60 Android apps for kids found infected with Pornographic malware
Fruitfly malware spied on Mac users for 13 years – man charged

LinuxSecurity.com: Philip Huppert discovered the Shibboleth service provider is vulnerable to impersonation attacks and information disclosure due to mishandling of DTDs in the XMLTooling XML parsing library. For additional details please refer to the upstream advisory at

Intel AMT Loophole Allows Hackers to Gain Control of Some PCs in Under a Minute
Attackers Exploit Oracle WebLogic Flaw to Mine $266K in Monero

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has 5 fixes is now available.

Boffins split on whether Spectre fix needs tweaked hardware
Critical Intel AMT Flaw Lets Attackers Hack Laptops in Mere Seconds
Cryptocurrency as the lure, an ISO as the attachment – why not open it?
Intel AMT security locks bypassed on corp laptops – research

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst with a passion for all things security. Any questions? Just ask. Exploitable Backdoor Found in Western Digital NAS Drives Western Digital has recently released numerous patches for the vulnerabilities that were […]

Man charged with spying on thousands of Mac users for 13 years
Data protection is best managed from the centre
Apps Exposing Children to Porn Ads Booted From Google Play
WhatsApp Vulnerability Lets Anyone Spy on Group Chats
‘Mummy, what’s felching?’ Tot gets smut served by Android app
Bitcoin conference won’t let you pay with Bitcoin
Malware infected fake Telegram Messenger app found in Play Store

LinuxSecurity.com: It was discovered that gifsicle, a tool for manipulating GIF image files, contained a flaw that could lead to arbitrary code execution. For the oldstable distribution (jessie), this problem has been fixed

Police give out infected USBs as prizes in cybersecurity quiz
Let’s Encrypt disables TLS-SNI-01 validation
Linux vs Meltdown: Ubuntu gets second update after first one fails to boot
FBI chief claims encryption is an ‘urgent public safety issue’
Security event in Taiwan ‘rewards’ quiz winners with malware-laden USB drives

The distribution of the USB sticks was halted on December 12 after some of the quiz’s successful entrants reported that their rewards had been flagged by their security software as containing malware. The post Security event in Taiwan ‘rewards’ quiz winners with malware-laden USB drives appeared first on WeLiveSecurity

Intel’s Meltdown fix freaked out some Broadwells, Haswells

LinuxSecurity.com: Security fix for CVE-2017-1000501

Brace yourselves for the ‘terabyte (sic) of death’, warns US army IT boss

security update

LinuxSecurity.com: Multiple vulnerabilities have been found in icoutils, the worst of which may lead to arbitrary code execution.

LinuxSecurity.com: Multiple vulnerabilities have been found in TigerVNC, the worst of which may lead to arbitrary code execution.

LinuxSecurity.com: A vulnerability in PySAML2 might allow remote attackers to bypass authentication.

LinuxSecurity.com: The package intel-ucode before version 20180108-1 is vulnerable to access restriction bypass.

Man used Fruitfly Mac malware to spy on US citizens for 13 years
House Votes to Reauthorize Controversial Spy Provision, Section 702
FBI director says ‘unbreakable encryption is a public safety issue’
WhatsApp Downplays Damage of a Group Invite Bug
Facebook settles after 14-year-old sues over nude image reposting
Drunk droning could cost you jail time in New Jersey
Everything running smoothly at the plant? *Whips out mobile phone* Wait. Nooo…
Warbiking in Perth – how does Wi-Fi security stack up these days?
WhatsApp flaw could allow anyone to sneak into your private group chat

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Ming: CVE-2017-11732

FBI supports & blames encryption for 7,800 devices it can’t unlock
Fedora 28 Looking To Replace Glibc’s libcrypt With libxcrypt
Adobe patches information leak vulnerability
CES 2018: The price of tech is dropping, kids can do this!

Row after row of startup tech here has tiny modules designed to be mashed up into the next big thing if their founders have anything to say about it, and the trend continues. The post CES 2018: The price of tech is dropping, kids can do this! appeared first on WeLiveSecurity

Smashing Security #060: Meltdown, Spectre, and personal devices in the White House

LinuxSecurity.com: Stephan Zeisberg discovered that poco, a collection of open source C++ class libraries, did not correctly validate file paths in ZIP archives. An attacker could leverage this flaw to create or overwrite arbitrary files.

Ohio coder accused of infecting Macs, PCs with webcam, browser spyware for 13 years

security update

Risk Level: Very Low. Type: Trojan.

Android Malware written in Kotlin found on Play Store stealing data

security update

Leaky credit report biz face massive fines if US senators get their way

Type: Vulnerability. Microsoft Office is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Outlook is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Word is prone to a memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Access is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Outlook is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Word is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Word is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Word is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Word is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Word is prone to a remote code-execution vulnerability; fixes are available.

FBI Director Calls Smartphone Encryption an ‘Urgent Public Safety Issue’

Risk Level: Very Low. Type: Trojan.

Netgear’s New Gaming Router Offers Protection Against DDoS Attacks
Wi-Fi security overhaul coming with WPA3
Marketing ads, soon to be screening on your car dashboard
Tank-traps versus trappings in virtual currencies: A cybersecurity minefield

Bitcoin, the progenitor of the entire cryptocurrency boom and still the most popular virtual currency, experienced a truly heady run-up in value. Its price surge was punctuated with a crescendo midway through December, when a single bitcoin approached $20,000. The post Tank-traps versus trappings in virtual currencies: A cybersecurity minefield appeared first on WeLiveSecurity

Best Encrypted Email Services for 2018
Post-hack, VTech has to pay $650,000 in FTC settlement – but doesn’t have to admit any wrongdoing
Smart-toymaker VTech fined over charges of violating child privacy law

LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Taiwanese cops give malware-laden USB sticks as prizes for security quiz
Russia claims it repelled home-grown drone swarm in Syria

LinuxSecurity.com: The system could be made to expose sensitive information.

IBM’s complete Meltdown fix won’t land until mid-February
Intel, Microsoft confess: Meltdown, Spectre may slow your servers

LinuxSecurity.com: The system could be made to expose sensitive information.

Facebook has open-sourced encrypted group chat

LinuxSecurity.com: Microcode update for AMD cpus

LinuxSecurity.com: Security fix for CVE-2017-1000456.

LinuxSecurity.com: Security fix for CVE-2017-17784 CVE-2017-17785 CVE-2017-17786 CVE-2017-17787 CVE-2017-17788 CVE-2017-17789

Risk Level: Very Low. Type: Trojan.

CPU bug patch saga: Antivirus tools caught with their hands in the Windows cookie jar
CoffeeMiner project lets you hack public Wi-Fi to mine cryptocoins