Risk Level: Very Low. Type: Trojan.
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: Security fix for CVE-2017-15698
This is aimed at improving security at the time of the handshake, which is when the key is being exchanged. As a result, WPA3 is poised to provide robust security even if short or weak passwords are used, i.e. those that don’t contain a combination of letters, numbers and symbols. The post How will WPA3 […]
LinuxSecurity.com: simplesamlphp, an authentication and federation application has been found vulnerable to Cross Site Scripting (XSS), signature validation byepass and using insecure connection charset.
LinuxSecurity.com: The mailman package has a Cross-site scripting (XSS) vulnerability in the web UI before 2.1.26 which allows remote attackers to inject arbitrary web script or HTML via a user-options URL
The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. New Variant of Scarab Ransomware With a few interesting changes to the original Scarab ransomware, Scarabey is […]
LinuxSecurity.com: A regression was detected in the previously issued fix for CVE-2018-6360. The patch released with DSA 4105-1 broke the feature of invoking mpv with raw YouTube ids. This update fixes this functionality issue. For reference, the relevant part of the original advisory text follows.
LinuxSecurity.com: An update that solves two vulnerabilities and has 17 fixes is now available.
security update
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
security update
security update
LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update that solves 9 vulnerabilities and has 68 fixes is now available.
LinuxSecurity.com: Several security issues were fixed in Django.
LinuxSecurity.com: Security fixes for CVE-2017-17485 and CVE-2018-5968.
According to US authorities, the enterprise aimed at becoming the premier destination for the buying and selling of stolen payment card data and forged identification documents. It is believed that the losses that the Infraud Organization had intended to cause were north of $2.2 billion. The post Global cybercrime behemoth busted, 36 people indicted appeared […]
LinuxSecurity.com: An update is now available for Red Hat JBoss Core Services. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.
LinuxSecurity.com: It was discovered that the webhook validation of Anymail, a Django email backends for multiple ESPs, is prone to a timing attack. A remote attacker can take advantage of this flaw to obtain a WEBHOOK_AUTHORIZATION secret and post arbitrary email tracking events.
security update
LinuxSecurity.com: A vulnerabilities has been found in the PostgreSQL database system: CVE-2018-1053
Type: Vulnerability. Adobe Flash Player is prone to an remote code-execution vulnerability; fixes are available.
LinuxSecurity.com: Two vulnerabilities were discovered in Libtasn1, a library to manage ASN.1 structures, allowing a remote attacker to cause a denial of service against an application using the Libtasn1 library.
LinuxSecurity.com: An update that solves two vulnerabilities and has 17 fixes is now available.
LinuxSecurity.com: Security fix for CVE-2017-17969 (from Debian)
LinuxSecurity.com: Security fix for CVE-2018-6381
LinuxSecurity.com: This update includes a rebase from 8.0.47 to 8.0.49.
LinuxSecurity.com: This is a security fix release that fixes a sandbox escape in the flatpak dbus proxy. This issue was found by Gabriel Campana of The Google Security Team. Major changes in 0.10.3 * Fix dbus proxy vulnerability in authentication phase * Make permission handling ignore unknown permissions for forwards compatibility * Removed incorrect error […]
Risk Level: Very Low. Type: Trojan.
The investigation showed that the tool, which required little technical knowledge to deploy, had over 8,600 users in 78 countries. Victims are believed to be in the thousands. The post UK-led police operation quashes Luminosity Link RAT appeared first on WeLiveSecurity
LinuxSecurity.com: Security fixes for CVE-2017-17485 and CVE-2018-5968.
LinuxSecurity.com: New kernel packages are available for Slackware 14.2 to mitigate the speculative side channel attack known as Spectre variant 2.
LinuxSecurity.com: It was discovered that mpv, a media player, was vulnerable to remote code execution attacks. An attacker could craft a malicious web page that, when used as an argument in mpv, could execute arbitrary code in the host of the mpv user.
Who doesn’t like a good mobile game? Especially a free one! They allow you to blow off steam while fine-tuning your skills, competing with others or maybe even winning bragging rights among friends. Free games can be fun to play, yet there are some common-sense guidelines to make sure these apps don’t surprise you with […]
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low.
Another template attempts to scare, rather than thrill, the recipients. Upon learning that “your IP address and other identifying information were used to commit multiple online crimes”, the mark is urged to contact the sender by phone immediately. The post FBI warns of email scams claiming to be from Bureau appeared first on WeLiveSecurity
