Menu

Monthly Archives: January 2018

Children at ‘significant’ social media risk
Meltdown and Spectre Flaws in Intel CPUs: Collateral Damage to OS & Cloud Services Unavoidable
Researchers Discover Two Major Flaws in the World’s Computers
Cisco to release patches for Meltdown, Spectre CPU vulns, just in case
Enterprise IoT threatens to undermine cloud and IT security
Meltdown and Spectre CPU Vulnerabilities: What You Need to Know

The first few days of 2018 have been filled with anxious discussions concerning a widespread and wide-ranging vulnerability in the architecture of processors based on Intel’s Core architecture used in PCs for many years, and also affecting ARM processors commonly used in tablets and smartphones. The post Meltdown and Spectre CPU Vulnerabilities: What You Need […]

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst with a passion for all things security. Any questions? Just ask. Researchers Find Major Security Flaws in Modern Processors Newly discovered bugs, Meltdown and Spectre, exploit critical flaws in the architecture […]

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in denial of service, information leaks, privilege escalation or the execution of arbitrary code.

Woo-yay, Meltdown CPU fixes are here. Now, Spectre flaws will haunt tech industry for years

It can be daunting to step into the often unfamiliar world of security, where you can at times be inundated with technical jargon (and where you face real consequences for making the wrong decision). Employing an MSP or MSSP is oftentimes in best interest of small and medium businesses (SMBs). In a study performed by […]

LinuxSecurity.com: Multiple researchers have discovered a vulnerability in Intel processors, enabling an attacker controlling an unprivileged process to read memory from arbitrary addresses, including from the kernel and all other processes running on the system.

LinuxSecurity.com: An industry-wide issue was found in the way many modern microprocessordesigns have implemented speculative execution of instructions (a commonlyused performance optimization). There are three primary variants of theissue which differ in the way the speculative execution can be exploited.Variant CVE-2017-5715 triggers the speculative execution by utilizingbranch target injection. It relies on the presence of […]

LinuxSecurity.com: An update for microcode_ctl is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0023

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0029

Microsoft patches Windows to cool off Intel’s Meltdown – wait, antivirus? Slow your roll

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0030

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0008

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0013

Private Details of 240,000 DHS Employees Accessed after Data Breach
F**CKWIT – the video!
Vendors Share Patch Updates on Spectre and Meltdown Mitigation Efforts
Top 7 Cyber Forensic Tools
Bogus security apps in the Google Play store stole users’ info and tracked their location
US Homeland Security breach compromised personal info of 200,000+ staff
ESET Research: Wauchos now headed for extinction?

As Wauchos was sold on underground forums, there were various monetization schemes. One of them was to use the form grabber plugin to steal passwords for online accounts. The post ESET Research: Wauchos now headed for extinction? appeared first on WeLiveSecurity

Social media namer and shamer charged
New Android Malware Disguised as Uber App

LinuxSecurity.com: An update that solves 5 vulnerabilities and has 13 fixes is An update that solves 5 vulnerabilities and has 13 fixes is An update that solves 5 vulnerabilities and has 13 fixes is now available. now available.

Is your Spotify password up to scratch?

LinuxSecurity.com: An update that solves 17 vulnerabilities and has 13 fixes An update that solves 17 vulnerabilities and has 13 fixes An update that solves 17 vulnerabilities and has 13 fixes is now available. is now available.

LinuxSecurity.com: An update that solves 5 vulnerabilities and has 26 fixes is An update that solves 5 vulnerabilities and has 26 fixes is An update that solves 5 vulnerabilities and has 26 fixes is now available. now available.

32% off Kidde Carbon Monoxide Alarm with Display and 10 Year Battery – Deal Alert

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0014

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0012

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0007

Artificial Intelligence to listen for suicidal thoughts on social media
Spectre? Meltdown? F*CKWIT? Calm down and make yourself some tea

LinuxSecurity.com: It was discovered that there were two vulnerabilities in the imagemagick image manipulation program: CVE-2017-1000445: A null pointer dereference in the MagickCore

Meltdown, Spectre: The password theft bugs at the heart of Intel CPUs

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for linux-firmware is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for linux-firmware is now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

We translated Intel’s crap attempt to spin its way out of CPU security bug PR nightmare
Smashing Security podcast #059: An intro to Bitcoin and Blockchain

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Apple macOS so secure some apps can’t be easily deleted
Today’s CPU vulnerability: what you need to know
Attention, vSphere VDP backup admins: There is a little remote root hole you need to patch…
Intel In Security Hot Seat Over Reported CPU Design Flaw

LinuxSecurity.com: Upstream announcement: Welcome to **phpMyAdmin 4.7.7**, a regular maintenance release containing bug fixes and a security fix. The security vulnerability is a XSRF/CSRF flaw; you can read more at https://www.phpmyadmin.net/security/PMASA-2017-9/ As a result of this, we recommend all users upgrade immediately. A CVE-ID has been requested but not yet

The F*CKWIT Intel chip flaw. Ready yourself for patches
Security Flaws in GPS Trackers Puts Millions of Devices’ Data at Risk
F**CKWIT, aka KAISER, aka KPTI – Intel CPU flaw needs low-level OS patches
Multiple Intel Processors Generations Hit by Serious Security Flaw
Ad scripts track users via browser password managers
Your Nigerian Prince is a 67 year old from Louisiana
Teen girl facing up to 10 years for sending nude selfie
Bug-finders’ scheme: Tick-tock, this tech’s tested by flaws.. but who the heck do you tell?
Sensor data can be used to guess your PIN, unlock your phone

LinuxSecurity.com: Jason Crain discovered a overflow vulnerability in the poppler PDF rendering library. For Debian 7 “Wheezy”, this issue has been fixed in poppler version

Opera browser updated to stop crypto-currency mining
Facebook ditches fake news flag, admits it was making things worse
Ransomware to hit cloud computing in 2018, predicts MIT
Critical Flaw Reported In phpMyAdmin Lets Attackers Damage Databases
Driving Open Standards in a Fragmented Networking Landscape
Security catch-up: Nigerian prince email ring cops collar … Louisiana OAP?
Now is the best time to craft your breach response

Taking time to think logically and deliberately about your assets can help you determine what needs to be secured. Preparing for the worst can help you see the best course of action to prevent those emergencies in the present. The post Now is the best time to craft your breach response appeared first on WeLiveSecurity

LinuxSecurity.com: An update for eap7-jboss-ec2-eap is now available for Red Hat JBoss Enterprise Application Platform 7.0 for Red Hat Enterprise Linux 6 and Red Hat JBoss Enterprise Application Platform 7.0 for Red Hat Enterprise Linux 7.

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 7.0 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 7.0 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Brazil says it has bagged Royal Navy flagship HMS Ocean for £84m
Shopped in Forever 21? There was bank-card-slurping malware in it for, like, forever
Code for Satori malware posted on Pastebin
MacOS LPE Exploit Gives Attackers Root Access
VMware Issues 3 Critical Patches for vSphere Data Protection
Kernel-memory-leaking Intel processor design flaw forces Linux, Windows redesign
The mysterious case of the Linux Page Table Isolation patches
Windows Hello face recognition spoofed with photographs
Forever 21 Says PoS Systems Exposed Customer Data for 8 Months
A desperate YouTube moderator scam spam
IP address errors lead to wrongful arrests
Iranians resist internet censorship amid deadly street protests
Automatic autofill of your username and password? Not a good idea
15-year-old Unpatched Root Access Bug found in Apple’s macOS
Multiple-guess quiz will make Brit fliers safer, hopes drone-maker DJI
Tuesday review – the hot 8 stories of the week

LinuxSecurity.com: It was discovered that wireshark, a network protocol analyzer, contained several vulnerabilities in the dissectors for CIP Safety, IWARP_MPA, NetBIOS, Profinet I/O and AMQP, which result in denial of dervice or the

Smartphone sensors can leak the four-digit PIN code to hackers
Reddit user leaks alleged Game of Thrones Season 8 script pages
2017’s Top hacks and data breaches