Menu

Monthly Archives: February 2018

Risk Level: Very Low. Type: Trojan.

New Tech Support Scam Freezes Chrome, Firefox & Brave Browser
Corpse! of! Yahoo! drags! emails! of! the! dead! case! to! US! Supreme! Court!
Apple’s iOS source code leak – what you need to know

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Chinese police get facial recognition glasses
Robot’s revenge – the CAPTCHA that stops humans

LinuxSecurity.com: Security fix for CVE-2017-15698

How will WPA3 improve WiFi security?

This is aimed at improving security at the time of the handshake, which is when the key is being exchanged. As a result, WPA3 is poised to provide robust security even if short or weak passwords are used, i.e. those that don’t contain a combination of letters, numbers and symbols. The post How will WPA3 […]

LinuxSecurity.com: simplesamlphp, an authentication and federation application has been found vulnerable to Cross Site Scripting (XSS), signature validation byepass and using insecure connection charset.

LinuxSecurity.com: The mailman package has a Cross-site scripting (XSS) vulnerability in the web UI before 2.1.26 which allows remote attackers to inject arbitrary web script or HTML via a user-options URL

The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. New Variant of Scarab Ransomware With a few interesting changes to the original Scarab ransomware, Scarabey is […]

VMware sticks finger in Meltdown/Spectre dike for virtual appliances
Wish you could log into someone’s Netgear box without a password? Summon a &genie=1

LinuxSecurity.com: A regression was detected in the previously issued fix for CVE-2018-6360. The patch released with DSA 4105-1 broke the feature of invoking mpv with raw YouTube ids. This update fixes this functionality issue. For reference, the relevant part of the original advisory text follows.

LinuxSecurity.com: An update that solves two vulnerabilities and has 17 fixes is now available.

security update

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Apple Downplays Impact of iBoot Source Code Leak
WordPress denial-of-service attacks – how real is the problem? [VIDEO]
iOS ‘iBoot’ source code posted online, Apple issues DMCA takedown notice

security update

security update

Insurance Customers’ Personal Data Exposed Due to Misconfigured NAS Server
Now that’s taking the p… Sewage plant ‘hacked’ to craft crypto-coins

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update that solves 9 vulnerabilities and has 68 fixes is now available.

LinuxSecurity.com: Several security issues were fixed in Django.

LinuxSecurity.com: Security fixes for CVE-2017-17485 and CVE-2018-5968.

From July, Chrome will name and shame insecure HTTP websites
Uber data breach aided by lack of multi-factor authentication
Gojdue Variant Eludes Microsoft, Google Cloud Protection, Researchers Say
Global cybercrime behemoth busted, 36 people indicted

According to US authorities, the enterprise aimed at becoming the premier destination for the buying and selling of stolen payment card data and forged identification documents. It is believed that the losses that the Infraud Organization had intended to cause were north of $2.2 billion. The post Global cybercrime behemoth busted, 36 people indicted appeared […]

Deepfake porn videos banned by Reddit, Twitter, Pornhub
Facebook HOAX! New algorithm will NOT only show you 26 friends

LinuxSecurity.com: An update is now available for Red Hat JBoss Core Services. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

12 Common Threat Intelligence Use Cases
Swisscom data breach exposes 800,000 customers
DDoS attacks: How an 18-year-old got arrested for trying to knock out systems
CyberThreat18: 2 days of bughunting, techie chat and code lockdown
Apple’s top-secret iBoot firmware source code spills onto GitHub for some insane reason
Intel adopts Orwellian irony with call for fast Meltdown-Spectre action after slow patch delivery
New strife for Strava: Location privacy feature can be made transparent
PSA: If your security starts and ends with bug bounties, you’re gonna have a bad time
Unlucky 13 collared by cops hunting cyber-crew who stole up to $2.2bn
WordPress users – do an update now, and do it by hand!
Smashing Security #064: So just a ‘teeny tiny’ security issue then?
Google Expands Play Marketplace Bug Bounty Program

LinuxSecurity.com: It was discovered that the webhook validation of Anymail, a Django email backends for multiple ESPs, is prone to a timing attack. A remote attacker can take advantage of this flaw to obtain a WEBHOOK_AUTHORIZATION secret and post arbitrary email tracking events.

security update

LinuxSecurity.com: A vulnerabilities has been found in the PostgreSQL database system: CVE-2018-1053

Type: Vulnerability. Adobe Flash Player is prone to an remote code-execution vulnerability; fixes are available.

LinuxSecurity.com: Two vulnerabilities were discovered in Libtasn1, a library to manage ASN.1 structures, allowing a remote attacker to cause a denial of service against an application using the Libtasn1 library.

LinuxSecurity.com: An update that solves two vulnerabilities and has 17 fixes is now available.

LinuxSecurity.com: Security fix for CVE-2017-17969 (from Debian)

LinuxSecurity.com: Security fix for CVE-2018-6381

LinuxSecurity.com: This update includes a rebase from 8.0.47 to 8.0.49.

LinuxSecurity.com: This is a security fix release that fixes a sandbox escape in the flatpak dbus proxy. This issue was found by Gabriel Campana of The Google Security Team. Major changes in 0.10.3 * Fix dbus proxy vulnerability in authentication phase * Make permission handling ignore unknown permissions for forwards compatibility * Removed incorrect error […]

Hotspot Shield Vulnerability Could Reveal ‘Juicy’ Info About Users, Researcher Claims

Risk Level: Very Low. Type: Trojan.

WordPress update stopped WordPress automatic updates from working. So update now
UK-led police operation quashes Luminosity Link RAT

The investigation showed that the tool, which required little technical knowledge to deploy, had over 8,600 users in 78 countries. Victims are believed to be in the thousands. The post UK-led police operation quashes Luminosity Link RAT appeared first on WeLiveSecurity

Reddit users, beware its evil twin
YouTube Kids hasn’t cleaned up its act

LinuxSecurity.com: Security fixes for CVE-2017-17485 and CVE-2018-5968.

Alleged Kelihos botmaster and spam king extradited to US
Boffins crack smartphone location tracking – even if you’ve turned off the GPS
Abusing X.509 Digital Certificates for Covert Data Exchange
Hacking suspect Lauri Love wins landmark appeal against US extradition
Australian cops to enter kindergartens to teach kids not to cyber
Malware Exploiting Spectre, Meltdown Flaws Emerges
Beware the looming Google Chrome HTTPS certificate apocalypse!
Uber quits GitHub for in-house code after 2016 data breach
Registrar Namecheap let miscreants slap spam, malware on customers’ web domains willy-nilly

LinuxSecurity.com: New kernel packages are available for Slackware 14.2 to mitigate the speculative side channel attack known as Spectre variant 2.

Amazon explained ‘Key’ crack before it shipped fix, says hacker who found the hole
Web analytics outfit Mixpanel slurped surfers’ passwords

LinuxSecurity.com: It was discovered that mpv, a media player, was vulnerable to remote code execution attacks. An attacker could craft a malicious web page that, when used as an argument in mpv, could execute arbitrary code in the host of the mpv user.

Who doesn’t like a good mobile game? Especially a free one! They allow you to blow off steam while fine-tuning your skills, competing with others or maybe even winning bragging rights among friends. Free games can be fun to play, yet there are some common-sense guidelines to make sure these apps don’t surprise you with […]

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low.

Leaky Amazon S3 Bucket Exposes Personal Data of 12,000 Social Media Influencers
Adobe: Two critical Flash security bugs fixed for the price of one
Safer Internet Day 2018 [VIDEO]
All Ledger hardware wallets vulnerable to man in the middle attack
Uber and Waymo clash in court over driverless technology
Firefox 59’s privacy mode plugs leaky referrers
MacUpdate Hacked to Distribute Mac Cryptocurrency Miner
Cisco Issues New Patches for Critical Firewall Software Vulnerability
Early Google, Facebook employees band together to tame tech addiction
One year later, the UK’s Active Cyber Defence is seeing good results
Security hole meant Grammarly would fix your typos, but let snoopers read your private writings
Keeping kids safe online – trying to practice what I preach
FBI warns of email scams claiming to be from Bureau

Another template attempts to scare, rather than thrill, the recipients. Upon learning that “your IP address and other identifying information were used to commit multiple online crimes”, the mark is urged to contact the sender by phone immediately. The post FBI warns of email scams claiming to be from Bureau appeared first on WeLiveSecurity

Spectre and Meltdown | Salted Hash Ep 17
How I Got Paid $0 From the Uber Security Bug Bounty
Why cops won’t need a warrant to pull the data off your autonomous car