Menu

Monthly Archives: January 2018

Don’t just grab your CPU bug updates – there’s a nasty hole in Office, too
Teach citizens IoT dangers, engineering students cybersecurity, Uncle Sam suggests
Microsoft January Patch Tuesday Update Fixes 16 Critical Bugs
FBI says it can’t unlock 8,000 encrypted devices, demands backdoors for America’s ‘public safety’

security update

security update

Locked out? Don’t worry, here’s the hardcoded password for your WD My Cloud NAS device

LinuxSecurity.com: A vulnerability has been found in LibXfont and LibXfont2 which may allow for arbitrary file access.

LinuxSecurity.com: PySAML2 could allow authentication without a password.

LinuxSecurity.com: Fixes https://bitcointalk.org/index.php?topic=2702103.0 Changelog: https://github.com/spesmilo/electrum/blob/master/RELEASE-NOTES —- Fixes https://bitcointalk.org/index.php?topic=2702103.0

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0061

Anti-Virus Updates Required Ahead of Microsoft’s Meltdown, Spectre Patches
Critical Vulnerability in Electrum Bitcoin Wallets Finally Addressed
Barracuda snags email security biz ahead of private equity plunge
AI-Powered Search Engine Ella Searches Security Footage with Keywords
Aadhaar breaches fuelled by rogue admin accounts
Apple issues Spectre fix with iOS 11.2.2 update
ESET research: Appearances are deceiving with Turla’s backdoor-laced Flash Player installer

In order to establish persistence on the system, the installer tampers with the operating system’s registry. It also creates an administrative account that allows remote access. The post ESET research: Appearances are deceiving with Turla’s backdoor-laced Flash Player installer appeared first on WeLiveSecurity

US tightens rules on border search
How are the shares, Bry? Intel chief cops to CPU fix slowdowns
Spyware user tracked boyfriend to have him killed by hitman

LinuxSecurity.com: An update that fixes 46 vulnerabilities is now available.

Facebook bug could have exposed your phone number to marketers
Ouch! Microsoft’s Spectre security update bricks some AMD-powered PCs
Until your anti-virus adds this Registry key, you aren’t getting any more Windows security updates
Hackers target Winter Olympics with new custom-built fileless malware
How to hack public Wi-Fi to mine for cryptocurrency
Is a Good Offense the Best Defense Against Hackers?
With WPA3, Wi-Fi will be secure this time, really, wireless bods promise
IBM melts down fixing Meltdown as processes and patches stutter

LinuxSecurity.com: New irssi packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Apple fixes the Meltdown and Spectre flaws in Macs, iPhones, and iPads
Meltdown, Spectre bug patch slowdown gets real – and what you can do about it

Type: Vulnerability. Microsoft Office is prone to a memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Word is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft .NET Framework is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft .NET Framework is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft ASP.NET Core is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a memory-corruption vulnerability; fixes are available.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

LinuxSecurity.com: Several vulnerabilities were found in PHP, a widely-used open source general purpose scripting language: CVE-2017-11142

VTech hack fallout: What is a kid’s privacy worth? About 22 cents – FTC

LinuxSecurity.com: Several vulnerabilities were found in PHP, a widely-used open source general purpose scripting language: CVE-2017-11144

Apple Releases Spectre Patches for Safari, macOS and iOS

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves 32 vulnerabilities and has 7 fixes is now available.

security update

New adware attack bombard phones & prevent users from disabling ads

LinuxSecurity.com: Opencv 3.3 and earlier has problems while reading data, which might result in either buffer overflows or integer overflows.

New Rules Announced for Border Inspection of Electronic Devices

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

More stuff broken amid Microsoft’s efforts to fix Meltdown/Spectre vulns
Facebook needs fixing, says Mark Zuckerberg
Star Wars: The Last Jedi – the security review
New Malware Campaign Launched to Disrupt Winter Olympics 2018
Ex-NSA hacker builds AI tool to hunt hate groups’ symbols online
DJI’s bounty problems and video surveillance programs | Salted Hash Ep 13
First shots at South Korea could herald malware campaign of Olympic proportions
Your connection is not Brexit… we mean private: Tory party lets security cert expire
Hundreds of Android Gaming Apps are Tracking Your TV Viewing Habits
MADIoT – The nightmare after XMAS (and Meltdown, and Spectre)

It is not feasible, in fact not even possible, to replace all CPUs in all devices. It would be too costly, besides the success rate for unsoldering and resoldering pin-throughs in multi-layer boards will never be 100%. The post MADIoT – The nightmare after XMAS (and Meltdown, and Spectre) appeared first on WeLiveSecurity

Monday review – the hot 15 stories of the week
Smartphones’ security enhancements just make them more dangerous
It gets worse: Microsoft’s Spectre-fixer bricks some AMD PCs

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Experts Weigh In On Spectre Patch Challenges

LinuxSecurity.com: Updated to version 3.1.1 Fixes https://bitcointalk.org/index.php?topic=2702103.0 —- Updated to version 3.1

Risk Level: Very Low. Type: Trojan.

Fake Android apps caught dropping Coinhive miner

LinuxSecurity.com: openSUSE: openSUSE 11.3 has reached end of SUSE support

BlackBerry Mobile Website hacked to mine Monero via Coinhive
Who the Hell Is This ‘Crypto-Genius?’
Spectre and Meltdown: What you need to know going forward
Security hole in AMD CPUs’ hidden secure processor code revealed ahead of patches
Qualcomm joins Intel, Apple, Arm, AMD in confirming its CPUs suffer hack bugs, too
How to hack Wi-Fi for fun and imprisonment with crypto-mining inject

LinuxSecurity.com: An update that solves 14 vulnerabilities and has three An update that solves 14 vulnerabilities and has three An update that solves 14 vulnerabilities and has three fixes is now available. fixes is now available.

security update

Type: Vulnerability. Multiple CPU Hardwares are prone to an information-disclosure vulnerability; fixes are available.

LinuxSecurity.com: The package linux-hardened before version 4.14.11.a-1 is vulnerable to multiple issues including access restriction bypass, denial of service, privilege escalation and information disclosure.

LinuxSecurity.com: The package linux-zen before version 4.14.11-1 is vulnerable to multiple issues including access restriction bypass, denial of service, privilege escalation and information disclosure.

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

How a USB could become security risk for your device

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 9.0 (Mitaka). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 11.0 (Ocata). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: The package linux-lts before version 4.9.74-1 is vulnerable to multiple issues including denial of service, privilege escalation and information disclosure.

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

How to Protect your Device from Meltdown and Spectre?
Dell EMC patches 3 zero-days in Data Protection Suite
Microsoft could soon be “password free”
Google Play Removes 22 Malicious ‘LightsOut’ Apps From Marketplace
JPMorgan doesn’t trust YouTube to keep its ads out of sketchy channels

LinuxSecurity.com: The package linux before version 4.14.11-1 is vulnerable to multiple issues including access restriction bypass, denial of service, privilege escalation and information disclosure.

LinuxSecurity.com: An update that solves 5 vulnerabilities and has 19 fixes is An update that solves 5 vulnerabilities and has 19 fixes is An update that solves 5 vulnerabilities and has 19 fixes is now available. now available.

LinuxSecurity.com: An update that solves 5 vulnerabilities and has 35 fixes is An update that solves 5 vulnerabilities and has 35 fixes is An update that solves 5 vulnerabilities and has 35 fixes is now available. now available.