Menu

Monthly Archives: February 2018

In the past, security awareness training for user education—i.e. empowering users to make more savvy IT decisions in their daily routines—was considered a “nice to have,” not a necessity. The decision to adopt user education was typically passed over because of budget, lack of in-house expertise, and the general lack of availability of high-quality, low-cost, […]

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

Unprotected AWS Bucket Exposes 50.4 GB of Financial Giant’s Data

LinuxSecurity.com: quagga: Double free vulnerability in bgpd when processing certain forms of UPDATE message allowing to crash or potentially execute arbitrary code (CVE-2018-5379) SL7 x86_64 quagga-0.99.22.4-5.el7_4.i686.rpm quagga-0.99.22.4-5.el7_4.x86_64.rpm quagga-debuginfo-0.99.22.4-5.el7_4.i686.rpm quagga-debuginfo-0.99.22.4-5.el7_4.x86_64.rpm quagga-contrib-0.99.22.4-5.el7_4.x86_64. [More…]

LinuxSecurity.com: It was discovered that the Net::FTP module did not properly process filenames in combination with certain operations. A remote attacker could exploit this flaw to execute arbitrary commands by setting up a malicious FTP server and tricking a user or Ruby application into downloading files with specially crafted names using the Net::FTP module. (CVE-2017-17405) […]

Misconfigured Memcached Servers Abused to Amplify DDoS Attacks

security update

security update

security update

LinuxSecurity.com: An update for ruby is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: create a separate user for dnsmasq.

LinuxSecurity.com: The textbook ElGamal implementation is not secure. PyCrypto and some other implementations use the wrong algorithm, which may lead to some information disclosure simply by looking at the encrypted text. For a full description, see https://github.com/dlitz/pycrypto/issues/253 This update includes a fix for this problem backported from pycryptodome.

LinuxSecurity.com: Use default RPM build flags and configure parameters (#1539097) Remove group writable bit from some config files (#1528445)

Single Sign-On authentication – the bug that lets you logon as someone else
If any phone can be hacked, should we give up on security? [VIDEO]
Brit spooks slammed over ‘gentlemen’s agreement’ with telcos to get mass comms data
New Android malware record voice calls for extortion & blackmailing
Irish eyes are sighing: Data protection office notes olagoanin’* up 79%
Intel Releases Updated Spectre Fixes For Broadwell and Haswell Chips
Let’s talk about PCI-DSS
Got that itchy GandCrab feeling? Ransomware decryptor offers relief

LinuxSecurity.com: An update is now available for CloudForms Management Engine 5.8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

“Misguided” hacking bill threatens to ice security researchers, say critics
Researchers unveil Veil to make ‘private browsing more private’

The blinding server randomly adds some nonsense code to every webpage. This ‘code obfuscation’, according to the academics, has no effect on what the actual page looks like, but it drastically changes the appearance of the underlying source file. The post Researchers unveil Veil to make ‘private browsing more private’ appeared first on WeLiveSecurity

ISIS recruiter caught by Facebook screenshot
Making private browsing more private
Apple co-founder Steve Wozniak scammed by Bitcoin fraudster

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0350

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0349

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0349

Cryptocurrency scams on Android: do you know what to watch out for?

The recent rise in cryptocurrency scams appearing on the Android platform in disguise has shown that such incidents are not exclusive to PCs and also highlight the importance of knowing what to look out for so you do not unintentionally take part. The post Cryptocurrency scams on Android: do you know what to watch out […]

XM-hell strikes single-sign-on systems: Bugs allow miscreants to masquerade as others
Dutch name authority: DNSSEC validation errors can be eliminated

LinuxSecurity.com: The package mbedtls before version 2.7.0-1 is vulnerable to arbitrary code execution.

Popular cache utility exploited for massive reflected DoS attacks
Intel gives Broadwells and Haswells their Meltdown medicine
Phone-cracking firm advertises that it can unlock any iPhone
NSA boss: Trump won’t pull trigger for Russia election hack retaliation
Massive Malspam Campaign Targets Unpatched Systems
iTunes will no longer work on old PCs & 1st Generation Apple TV

LinuxSecurity.com: An update that solves 9 vulnerabilities and has 40 fixes is now available.

LinuxSecurity.com: Two vulnerabilities have been found in Solr, a search server based on Lucene, which could result in the execution of arbitrary code or path traversal.

LinuxSecurity.com: Kelby Ludwig and Scott Cantor discovered that the Shibboleth service provider is vulnerable to impersonation attacks and information disclosure due to incorrect XML parsing. For additional details please refer to the upstream advisory at

LinuxSecurity.com: Joonun Jang discovered several problems in wavpack, an audio compression format suite. Incorrect processing of input resulted in several heap- and stack-based buffer overflows, leading to application crash or potential code execution.

WordPress Users Warned of Malware Masquerading as ionCube Files

LinuxSecurity.com: From upstream announcement: **Security fix: phpMyAdmin 4.7.8 is released** Welcome to phpMyAdmin 4.7.8, a security releaes also containing regular maintenance bug fixes. The security fix relates to a self-XSS vulnerability in the central columns feature that is reported as PMASA-2018-1 https://www.phpmyadmin.net/security/PMASA-2018-1/. Thanks to Mayur Udiniya

Remote Code Execution Bug Patched in Adobe Acrobat Reader DC
Mirai Variant ‘OMG’ Turns IoT Devices into Proxy Servers for Cryptomining
Can the FBI really unlock ANY iPhone in existence?
Cellebrite’ Hacking Tool Unlocks Any iOS Devices Including iPhone X
Use of HTTPS among top sites is growing, but weirdly so is deprecated HTTP public key pinning
Apple Tackles Cellebrite Unlock Claims, Sort Of
MS Word Maybe Used for Cryptojacking Attacks
Oops! Apple repair center making around 20 false emergency calls a day
Unsecured AWS led to cryptojacking attack on LA Times
SEC says insider trading is not the right response to cyber risk
GDPR deadline looms: The price and penalties | Salted Hash Ep 20
Fender’s ‘smart’ guitar amp has no Bluetooth pairing controls
Opt-in cryptomining script Coinhive ‘barely used’ say researchers
RAT king thrown in the slammer for peddling NanoCore PC nasty
You get a criminal record! And you get a criminal record! Peach state goes bananas with expanded anti-hack law
Developer of NanoCore RAT that targeted Canada, US & Steam jailed

LinuxSecurity.com: A flaw was found in the AWT component of OpenJDK. An untrusted Java application or applet could use this flaw to bypass certain Java sandbox restrictions. (CVE-2018-2641) * It was discovered that the LDAPCertStore class in the JNDI component of OpenJDK failed to securely handle LDAP referrals. An attacker could possibly use this flaw […]

LinuxSecurity.com: An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: gcab: Extracting malformed .cab files causes stack smashing potentially leading to arbitrary code execution (CVE-2018-5345) SL7 x86_64 gcab-debuginfo-0.7-4.el7_4.i686.rpm gcab-debuginfo-0.7-4.el7_4.x86_64.rpm libgcab1-0.7-4.el7_4.i686.rpm libgcab1-0.7-4.el7_4.x86_64.rpm gcab-0.7-4.el7_4.x86_64.rpm libgcab1-devel-0.7-4.el7_4.i686.rpm libgcab1-devel-0.7-4.el7_4.x86 [More…]

Revamp of ‘Pwned Passwords’ Boosts Privacy and Size of Database

LinuxSecurity.com: An update for gcab is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: It was discovered that there was an arbitrary command execution vulnerability in the Go programming language. The “go get” implementation did not correctly validate “import path”

Insecure CCTV feeds of kids at school are being streamed live online
Facebook bug reveals identity of page admin via email
Chrome OS Will Soon Start Supporting Linux Applications
Teen Exposes T-Mobile Flaw Allowing Mass Hijacking of User Accounts
NanoCore’s author didn’t hack anyone, but he was imprisoned anyway
Form W-2 data thefts are rocketing, warns FBI
Over 40% of online login attempts are attackers trying to invade accounts

Bots that traverse the internet on behalf of their human operators can fulfill both legitimate and malicious automated tasks. Statistics indicate that bot-driven internet traffic, by helper and harmful bots combined, surpasses human traffic. The post Over 40% of online login attempts are attackers trying to invade accounts appeared first on WeLiveSecurity

US border agents haven’t verified e-passport data for over 10 years
‘In Fraud We Trust’ – Cybercrime org bust shows we’re fighting pros

LinuxSecurity.com: An update that fixes 12 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 12 vulnerabilities is now available.

Privacy by Design: Can you create a safe smart home?

The Internet of Things (IoT) can be a network of connected convenience but this should not come at the expense of safeguarding your privacy and the personal data that connected devices collect and share. The post Privacy by Design: Can you create a safe smart home? appeared first on WeLiveSecurity

Private browsing isn’t: Boffins say smut-mode can’t hide your tracks
Cisco NFV controller is a bit too elastic: It has an empty password bug

LinuxSecurity.com: This update updates QtWebEngine to the 5.10.1 bugfix and security release. QtWebEngine 5.10.1 is part of the Qt 5.10.1 release, but only the QtWebEngine component is included in this update. This update includes: * Security fixes from Chromium up to version 64.0.3282.140. Including: CVE-2017-15407, CVE-2017-15409, CVE-2017-15410, CVE-2017-15411, CVE-2017-15415, CVE-2017-15416,

LinuxSecurity.com: New upstream version Security fix for upstream issue 35 https://github.com/milkytracker/MilkyTracker/issues/35

LinuxSecurity.com: New upstream version Security fix for upstream issue 35 https://github.com/milkytracker/MilkyTracker/issues/35

LinuxSecurity.com: CVE-2017-13194 Fix for a flaw in libvpx related to odd frame width, which may lead to a denial of service.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: Multiple vulnerabilities have been found in the Drupal content management framework. For additional information, please refer to the upstream advisory at https://www.drupal.org/sa-core-2018-001

Russia hacked Winter Olympics & framed N.Korea in false-flag attack: US

LinuxSecurity.com: It was discovered that there was a remote denial of service vulnerability in the imagemagick graphics library via a specially- crafted TIFF file.

Top The Pirate Bay Alternatives – Best Torrent Download Sites (2018)

LinuxSecurity.com: This update includes the changes in tzdata 2018c for the Perl bindings. For the list of changes, see DLA-1291-1. For Debian 7 “Wheezy”, these problems have been fixed in version

LinuxSecurity.com: This update includes the changes in tzdata 2018c. Notable changes are: – S?o Tom? and Pr?ncipe switched from +00 to +01. – Brazil’s DST will now start on November’s first Sunday.

Use 1Password’ ‘pwned password’ to verify if your password was leaked
Stunning infosec tips from Uncle Sam, furries exposed, Chase bank web leak, and more
Tor pedo’s torpedo torpedoed: FBI spyware crossed the line but was in good faith, say judges

LinuxSecurity.com: The package lib32-wavpack before version 5.1.0-2 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package unixodbc before version 2.3.5-1 is vulnerable to arbitrary code execution.