Menu

Monthly Archives: February 2018

LinuxSecurity.com: The package wavpack before version 5.1.0-2 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package phpmyadmin before version 4.7.8-1 is vulnerable to cross- site scripting.

security update

LA Times website hacked to mine Monero cryptocurrency
Drupal Patches Critical Bug That Leaves Platform Open to XSS Attack
NPM update changes critical Linux filesystem permissions, breaks everything

security update

security update

Man Sues Feds For Installing Surveillance Camera on his Property

LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. CVE-2017-5715

LinuxSecurity.com: It was discovered that there was an issue in the CUPS printer framework where remote attackers could execute arbitrary commands by sending POST requests to the CUPS daemon in conjunction with DNS rebinding.

LinuxSecurity.com: Several security issues were fixed in WavPack.

LinuxSecurity.com: This update doesn’t fix a vulnerability in GCC itself, but instead provides support for building retpoline-enabled Linux kernel updates. For the stable distribution (stretch), this problem has been fixed in

2,000 Colorado DOT computers infected with SamSam Ransomware
FBI Warns of Spike in W-2 Phishing Campaigns
Hacking these IoT baby monitors is child’s play, researchers reveal
Bitcoin exchange founder charged with covering up hack
Supporters of Net Neutrality Vow to Fight Rule Changes
Rancher sues Feds for sneaking a spy camera on to his land
3,000 Databases with 200 Million Unique accounts found on Dark Web
5 signs you may be talking to a bot
Hacker claims spyware maker Retina-X has been breached, again
Six tips to help you avoid targeted marketing

If you get sick of shopping sites sending you “I see you stared at this item, here’s some similar stuff” messages, you may be able to modify your subscriptions or notifications to make this stop. The post Six tips to help you avoid targeted marketing appeared first on WeLiveSecurity

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Intel didn’t tell CERTS, govs, about Meltdown and Spectre because they couldn’t help fix it

The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Hackers Run Linux OS On Nintendo Switch When gaming consoles get hacked, it’s usually by someone who […]

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

OpenBSD releases Meltdown patch

LinuxSecurity.com: On February 22, fixes for CVE-2017-5715 were released into the Ubuntu Xenialkernel version 4.4.0-116.140. This CVE, also known as “Spectre,” is caused by flaws in the design of speculative execution hardware in the computer’sCPU, and could be used to access sensitive information in kernel memory. [More…]

LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.

security update

LinuxSecurity.com: Several vulnerabilities have been discovered in Squid3, a fully featured web proxy cache. The Common Vulnerabilities and Exposures project identifies the following issues:

Hackers spread Android spyware through Facebook using Fake profiles

LinuxSecurity.com: It was discovered that there where a number of vulnerabilities in irssi, the terminal based IRC client: – CVE-2018-7050: Null pointer dereference for an “empty” nick.

That microchipped e-passport you’ve got? US border cops still can’t verify the data in it

LinuxSecurity.com: An update that solves 8 vulnerabilities and has 19 fixes is now available.

Cryptojacking Attack Found on Los Angeles Times Website
How to protect your browser from Unicode domain phishing attacks

LinuxSecurity.com: The package libmspack before version 1:0.6alpha-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

Over 50,000 baby monitors can be hacked but its vendor is AWOL
Survey shows sloppy password habits among young Brits

Young people were singled out as increasingly likely victims of internet-borne fraud, including because of their penchant for liberal sharing of personal information. The post Survey shows sloppy password habits among young Brits appeared first on WeLiveSecurity

How one guy could have taken over any Tinder account (but didn’t)
Tesla cryptojacked by currency miners
LA Times homicide website throttles cryptojacking attack
Friendly warnings left in unsecured Amazon S3 buckets which expose private data
Another baby monitor is allowing strangers to spy on children

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: An update for rh-maven35-jackson-databind is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

uTorrent file-swappers urged to upgrade after PC hijack flaws fixed
Hey, you. App dev. You like secure software? Let’s learn from Tinder, Facebook’s blunders
Smashing Security #066: Passwords, pirates, and postcards

LinuxSecurity.com: The package strongswan before version 5.6.2-1 is vulnerable to denial of service.

Guys, you’re killing us! LA Times homicide site hacked to mine crypto-coins on netizens’ PCs

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Guess who else Spectre is haunting? Yes, it’s AMD. Four class-action CPU flaw lawsuits filed
uTorrent Users Warned of Remote Code Execution Vulnerability
Intel Issues Updated Spectre Firmware Fixes For Newer Processors
Life-saving Pacemakers, Defibrillators Can Be Hacked and Turned Off
New BEC Spam Campaign Targets Fortune 500 Businesses
Cyber Aware – are passwords past it? (Hint: no.) [VIDEO]
Coldroot Mac Malware Silently Performs System-Wide Keylogging

LinuxSecurity.com: Security fix for CVE-2018-6942.

LinuxSecurity.com: New upstream release, including security fixes for CVE-2016-10713, CVE-2018-6951, CVE-2018-6952.

“Wire bank transfer” malware phishing scam hits SWIFT banking system
Intel hurls Spectre 2 microcode patch fix at world
Apple defuses ‘text bomb’ bug

A number of text-based apps crashed, became unresponsive or entered an endless bootloop when attempting to show the otherwise little-used character from a language that is spoken by some 75 million people. The post Apple defuses ‘text bomb’ bug appeared first on WeLiveSecurity

JDK approach to address deserialization Vulnerability
Is your child a victim of identity theft?
Flight simulator comes bundled with password stealing stowaway
World’s cyber attacks hit us much harder in past year – major infosec chief survey
Artificial intelligence reads privacy policies so you don’t have to
Read the 200,000 Russian Troll tweets Twitter deleted
Bad news: 43% of login attempts ‘malicious’ Good news: Er, umm…
Hackers Compromise Tesla Cloud Server to Mine Cryptocurrency

LinuxSecurity.com: It was discovered that there was a uncontrolled memory allocation issue in zziplib, a ZIP archive library. Remote attackers could leverage this vulnerability to cause a denial of service via a specially-crafted file.

Flight Sim Labs’ ‘Heavy Handed’ Anti-Piracy Tactics Raise Hackles

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

security update

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that solves 10 vulnerabilities and has two fixes is now available.

Hackers Exploite Tegra Chipset Flaw to Run Linux OS on Nintendo Switch
Flight Sim Lab installed Chrome passwords stealer in piracy check tool
Cybercrime weighs most heavily on financial service firms

A further breakdown of the overall figures shows that, in all, the actual cost hinges on a number of variables. The factors that enter heavily into the equation include attack types and their frequency, along with the organization’s size and even the country in which an organization is based. The post Cybercrime weighs most heavily […]

Facebook SMS spam risks spoiling adoption of 2FA
Year-Old Coldroot RAT Targets MacOS, Still Evades Detection
Facebook to verify election ad buyers by snail mail
UK local gov: 37 cyber attacks a minute but little mandatory training
Apple fixes that “1 character to crash your Mac and iPhone” bug

The way people shop has changed drastically over the last 10 years. E-commerce continues to boom. In fact, 80% of Americans made an online purchase in the past month, according to the Omni-Channel Retail Report from BigEcommerce. Because what’s not to love about shopping online, receiving your items in just two days, and not having […]

Apple fixes ‘killer text bomb’ vulnerability with new update for iOS, macOS, watchOS, and tvOS
Facebook told to stop tracking users that aren’t logged in
Oracle open-sources DTrace under the GPL
Year-old vuln turns Jenkins servers into Monero mining slaves

LinuxSecurity.com: A vulnerability in LibreOffice might allow remote attackers to read arbitrary files.

LinuxSecurity.com: A vulnerability has been found in Ruby which may allow for arbitrary command execution.

LinuxSecurity.com: Multiple vulnerabilities were found in MySQL, the worst of which may allow remote execution of arbitrary code.