Menu

Monthly Archives: February 2018

LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which may allow execution of arbitrary code.

Google reveals Edge bug that Microsoft has had trouble fixing

LinuxSecurity.com: An update that solves 9 vulnerabilities and has 44 fixes is now available.

Dark Web’s worst pedophile sentenced to 32 years in prison

LinuxSecurity.com: Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the execution of arbitrary code.

LinuxSecurity.com: Several security issues have been corrected in multiple demuxers and decoders of the libav multimedia library. A full list of the changes is available at https://git.libav.org/?p=libav.git;a=blob;f=Changelog;hb=refs/tags/v11.12

LinuxSecurity.com: Bind could be made to crash if it received specially crafted network traffic.

Hackers made $3M on Jenkins server in one of biggest mining ops ever
Google drops new Edge zero-day as Microsoft misses 90-day deadline
Critical macOS Sierra disk image flaw leads to data loss
Millions bagged in two bank cyber-heists

This hack is said to be reminiscent of a particularly brazen bank cyber-heist from February 2016, in which hackers successfully pilfered $81 million from the account of the central bank of Bangladesh at the Federal Reserve Bank of New York. The post Millions bagged in two bank cyber-heists appeared first on WeLiveSecurity

‘Killer text bomb’ crashes iPhones, iPads, Macs, and Apple Watches
5 Proven Cyber Security Certifications That Will Boost Your Salary in 2018
Broadband network plagued by wheezy old cryptomining gadget
US and UK condemn Russia for NotPetya worm attack
Hackers sentenced for SQL injections that cost $300 million

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Ransomware: Do you pay the ransom? | Salted Hash Ep 19
Crims pull another SWIFT-ie, Indian bank stung for nearly US$2m
Australia’s new insta-pay scheme has insta-lookup of any user’s phone number
Hacker erase 1 terabyte of data from spyware developers server
Austria seeks Interpol’s help to bust Bitcoin scammers who stole $115M

security update

Monero Mining Malware Infecting Android Smart TVs & Smartphones
TrickBot Variant Steals Bitcoin by Hijacking Cryptocurrency Transactions
Man admits hacking former employer’s computer system for revenge
Global security crackdown, a host of code nasties, Brit cops mocked, and more
New EU Privacy Law May Weaken Security
Meltdown-Spectre flaws: We’ve found new attack variants, say researchers
Raw sockets backdoor gives attackers complete control of some Linux servers
Hands up who HASN’T sued Intel over Spectre, Meltdown chip flaws

security update

security update

LinuxSecurity.com: Several vulnerabilities have been discovered in Quagga, a routing daemon. The Common Vulnerabilities and Exposures project identifies the following issues:

LinuxSecurity.com: Krzysztof Sieluzycki discovered that the notifier for removable devices in the KDE Plasma workspace performed insufficient sanitisation of FAT/VFAT volume labels, which could result in the execution of arbitrary shell commands if a removable device with a malformed disk label is

LinuxSecurity.com: BIND, a DNS server implementation, was found to be vulnerable to a denial of service flaw was found in the handling of DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly with an

119,000 FedEx users​ ​passports, security ID & driving licenses exposed

security update

Mueller bombshell: 13 Russian ‘troll factory’ staffers charged with allegedly meddling in US presidential election
Apple Rushes Fix for Latest ‘Text Bomb’ Bug As Abuse Spreads

LinuxSecurity.com: The package irssi before version 1.1.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

Telegram IM security flaw – what you see is NOT always what you get

LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.

LinuxSecurity.com: Talosintelligence discovered a command injection vulnerability in the gplotMakeOutput function of leptonlib. A specially crafted gplot rootname argument can cause a command injection resulting in arbitrary

New IoT Botnet DoubleDoor Bypass Firewall to Drop Backdoor
Hackers who stole $300 million, hacked Citibank & Nasdaq are jailed
PM urged to protect data flows post-Brexit ahead of Munich speech
Google’s big plans for email will give it even more power
US forms dedicated office to help avert cyberattacks at infrastructure

The vulnerability of critical infrastructure, including energy grids, to cyberattacks has been a growing concern worldwide. Many nations have been scrambling to improve their defenses vis-à-vis threats faced by services that are critical to the continuity of our daily lives. The post US forms dedicated office to help avert cyberattacks at infrastructure appeared first on […]

UK.gov: Psst. Belgium. Buy these Typhoon fighter jets from us, will you?

LinuxSecurity.com: An update that solves 10 vulnerabilities and has three fixes is now available.

LinuxSecurity.com: An update that solves 16 vulnerabilities and has 12 fixes is now available.

Why Chrome’s ad filter isn’t an adblocker
Facebook accused of spamming 2FA phone numbers

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Winter Olympics Disrupted by Malware Attack The Winter Olympics are in full swing, and cybercriminals seem to […]

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: New irssi packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Russians behind bars in US after nicking $300m+ in credit-card hacks
Techno-senator tells Tinder to hook up its app with better security

LinuxSecurity.com: Several security issues were fixed in Quagga.

Former ICE top lawyer raided US govt database to steal aliens’ identities
Facebook wants you to install a VPN app accused of spying on users

LinuxSecurity.com: Several vulnerabilities have been discovered in Quagga, a routing daemon. The Common Vulnerabilities and Exposures project identifies the following issues:

Intel Expands Bug Bounty Program Post-Spectre and Meltdown

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

security update

security update

That terrifying ‘unfixable’ Microsoft Skype security flaw: THE TRUTH

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: – CVE-2018-1055 Remote arbitrary file disclosure vulnerability via WEBSERVICE formula

LinuxSecurity.com: Updated AppStream metadata

LinuxSecurity.com: This is an update to Mozilla’s CA certificates list version 2.22, which has been published as part of Mozilla NSS 3.35. For additional details, please refer to the NSS 3.35 release notes: https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.35_release_notes

Reported Critical Vulnerabilities In Microsoft Software On the Rise
Word-based Malware Attack Doesn’t Use Macros
How a Bitcoin phishing gang made $50 million with the help of Google AdWords
Hackers use Google Ads to steal $50 million of Bitcoin
Dell EMC squashes pair of VMAX virtual appliance bugs
Smashing Security #065: Cryptominomania, Poppy, and your Amazon Alexa
Essex black hat behind Cryptex and reFUD gets two years behind bars
Concerns about data breaches hitting all-time high

A record-high proportion of organizations worldwide (67%) said that they had been breached at some point, up from 56% in the report’s previous edition. The post Concerns about data breaches hitting all-time high appeared first on WeLiveSecurity

With Intel’s updated bug bounty program, you could earn big bucks for finding the next Meltdown
A potent botnet is exploiting a critical router bug that may never be fixed
Unsecured server exposed thousands of FedEx customer records
Hack the Air Force 2.0 uncovers over 100 vulnerabilities
Adding Encryption To printk()
Managing open-source mobile security and privacy for activists worldwide
You’ve heard the advice before: Whether you’re in the office or on the road, a VPN is one of the bes
Joke dating site matches people based on their passwords
Coinmining frenzy is making it hard for us to find aliens
Android ransomware in 2017: Innovative infiltration and rougher extortion

Ransomware in 2017 saw users and businesses across the globe trying to cope with campaigns such as Petya and WannaCryptor. Not to be outdone, Android ransomware had a year full of innovative infiltration and rougher extortion as highlighted by the latest ESET research whitepaper. The post Android ransomware in 2017: Innovative infiltration and rougher extortion […]

UK names and shames Russia as source of NotPetya
PCI Council and X9 Committee to combine PIN security standards

LinuxSecurity.com: It was discovered that jackson-databind, a Java library used to parse JSON and other data formats, did not properly validate user input before attempting deserialization. This allowed an attacker to perform code execution by providing maliciously crafted input.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

security update

Hate to ruin your day, but… Boffins cook up fresh Meltdown, Spectre CPU design flaw exploits
Lazarus Group is back, targeting Banks & Bitcoin users with phishing scam