Menu

Monthly Archives: March 2018

LinuxSecurity.com: Jesse Schwartzentruber discovered a use-after-free vulnerability in Firefox, which could be exploited to trigger an application crash or arbitrary code execution.

security update

Hackers pwn Baltimore’s 911 system?! Quick, someone call 91– doh!

LinuxSecurity.com: Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues:

LinuxSecurity.com: It was discovered that a use-after-free in the compositor of Firefox can result in the execution of arbitrary code. For the oldstable distribution (jessie), this problem has been fixed

Alleged Mastermind Behind Carbanak Crime Gang Arrested

LinuxSecurity.com: An update that solves 9 vulnerabilities and has four fixes is now available.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

Did the FBI engineer its iPhone encryption court showdown with Apple to force a precedent? Yes and no, say DoJ auditors

security update

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0592

Facebook Cracks Down On Data Misuse With Expanded Bug Bounty Program
GoScanSSH Malware Targets SSH Servers, But Avoids Military and .GOV Systems
Hackers spread password stealer malware from YouTube comment section

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: A vulnerability in PLIB may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in BusyBox, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: It was discovered that there was an issue in the irssi IRC client where certain nick names could result in out-of-bounds access when printing theme strings.

LinuxSecurity.com: It was discovered that there was a heap corruption vulnerability in the net-snmp framework which exchanges server management information in a network.

LinuxSecurity.com: An update for python-paramiko is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: The package bchunk before version 1.2.2-4 is vulnerable to denial of service.

Exploit kit development has gone to sh$t… ever since Adobe Flash was kicked to the curb
US government gets its hand on $15,000 iPhone cracking device
US Cops Using Dead Suspects’ Fingerprints to Unlock iPhones
The Last Windows XP Security White Paper

Using the strategies and procedures we present in our paper could help prevent an attacker from taking control of your computer The post The Last Windows XP Security White Paper appeared first on WeLiveSecurity

HOAX ALERT: Can you really verify your Facebook account security with a comment?
Biggest pirate in the US sentenced to 5 years
Cobalt/Carbanak bank malware gang’s alleged leader arrested
3 of Facebook’s dumbest hoaxes

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

Of course Facebook logs calls and texts – people gave it permission
Why IoT security should keep you up at night
Oil & gas industry in Middle East found lagging in security

The oil and gas industry is the target of as much as one-half of all cyberattacks in the Middle East The post Oil & gas industry in Middle East found lagging in security appeared first on WeLiveSecurity

GCHQ’s infosec crew plans to ‘scale up’ Web Check to improve uk.gov site security
Police arrest members of billion-dollar banking cybercrime gang
Cash-machine-draining €1bn cybercrime kingpin suspect cuffed by plod
Police arrest members of cybercrime gang

ATM jackpot gang is thought to have infiltrated over 100 financial firms in 40 countries costing banks more than one billion dollars. The post Police arrest members of cybercrime gang appeared first on WeLiveSecurity

How a QR code can fool iOS 11’s Camera app into opening evil.com rather than nice.co.uk

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: Richard Zhu and Huzaifa Sidhpurwala discovered that an out-of-bounds memory write when playing Vorbis media files could result in the execution of arbitrary code.

Hurrah! TLS 1.3 is here. Now to implement it and put it into software
Android Malware in QR Reader apps on Play Store downloaded 500k times
Political ad campaign biz AggregateIQ exposes tools, DB logins online

LinuxSecurity.com: slf4j: Deserialisation vulnerability in EventData constructor can allow for arbitrary code execution (CVE-2018-8088) SL7 noarch slf4j-1.7.4-4.el7_4.noarch.rpm slf4j-javadoc-1.7.4-4.el7_4.noarch.rpm slf4j-manual-1.7.4-4.el7_4.noarch.rpm – Scientific Linux Development Team

Sanny Malware Updates Delivery Method

LinuxSecurity.com: Bas van Schaik and Kevin Backhouse discovered a stack-based buffer overflow vulnerability in librelp, a library providing reliable event logging over the network, triggered while checking x509 certificates from a peer. A remote attacker able to connect to rsyslog can take

LinuxSecurity.com: An update for slf4j is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

ATM hacker behind $1 billion malware heists arrested in Spain

LinuxSecurity.com: The package thunderbird before version 52.7.0-1 is vulnerable to multiple issues including arbitrary code execution and access restriction bypass.

Facebook Woes Continue as FTC Opens Data Privacy Probe
Facebook death hoax: Captain Kirk says, “I’ve not boldly gone yet!”
FBI: Iranian Firm Stole Data In Massive Spear Phishing Campaign
UK.gov unveils cyber security export strategy – only thing missing is the strategy
Mozilla Tests DNS over HTTPS: Meets Some Privacy Pushback
Police use dead man’s fingers to try to unlock his iPhone
Critical Infrastructure Interview with David Harley

WeLiveSecurity sat down with David Harley to get a better understanding of Critical Infrastructure and the role he has played in the area throughout his career. The post Critical Infrastructure Interview with David Harley appeared first on WeLiveSecurity

Shodan and passwords sitting in a tree, S-H-O-W-I-N-G!
Facebook collected users’ call and SMS logs with “their permission”

LinuxSecurity.com: An update for rh-ruby23-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-mysql57-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

YouTube isn’t for kids

LinuxSecurity.com: An update for rh-mysql56-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-ruby24-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Why Spectre demands more elegantly coded software

LinuxSecurity.com: An update for rh-ruby22-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Craigslist personals, some subreddits yanked after passage of FOSTA

LinuxSecurity.com: An update for rh-maven35-slf4j is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

We need to go deeper: Meltdown and Spectre flaws will force security further down the stack
Hey Siri! Read me this locked iPhone’s hidden messages…
Tumblr troll-ban follows February indictments

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

LinuxSecurity.com: Daniel P. Berrange and Peter Krempa of Red Hat discovered a flaw in libvirt, a virtualization API. A lack of restriction for the amount of data read by QEMU Monitor socket can lead to a denial of service by exhaustion of memory resources.

Five year old vulnerability used for Monero mining on Linux servers

security update

LinuxSecurity.com: Wojciech Regu?a discovered that Freeplane, a program for working with mind maps, was affected by a XML External Entity (XXE) vulnerability in its mindmap loader that could compromise a user’s machine by opening a specially crafted mind map file.

Microsoft to lock out Windows RDP clients if they are not patched against hijack bug
9 Iranian hackers charged with hacking universities & stealing secrets

LinuxSecurity.com: Samba could be made to crash if it received specially crafted input.

LinuxSecurity.com: An update that solves 10 vulnerabilities and has 70 fixes is now available.

Guccifer 2.0 outed, Kaspersky slammed, Oz radio hacker in the slammer, and more

LinuxSecurity.com: An update that fixes one vulnerability is now available.

World celebrates, cyber-snoops cry as TLS 1.3 internet crypto approved
Elon Musk deletes Tesla & Space X Facebook pages for #DeleteFacebook
Senate Gives Nod To Controversial Cross-Border Data Access Bill
Nine Iranians accused of cyber-swiping 30TB+ of blueprints from unis, biz on Tehran’s orders

security update

security update

LinuxSecurity.com: Sharutils could be made to execute arbitrary code if it opened a specially crafted file.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: It was discovered that there was a server-side request forgery exploit in adminer, a web-based database administration tool. Adminer allowed unauthenticated connections to be initiated to arbitrary

On Dark Web Your Facebook ID is worth $5.20 & Gmail ID just $1
Crooks infiltrate Google Play with malware in QR reading utilities
A Closer Look at APT Group Sofacy’s Latest Targets
Ransomware Attack Cripples Several Atlanta City Systems
British doctor says his laptop was hacked & led to Aleppo hospital airstrike
The bug that made free money
AMD announces Ryzen patch timeline as disclosure controversy rages
Guccifer 2.0’s schoolboy error reveals he’s hacking from Moscow