Menu

Monthly Archives: March 2018

ICANN meets as internet overseers weigh website owner privacy
Brit police forces spend peanuts on cybercrime training
Leading by example: UK.gov’s secure server setup is patchy at best
UK’s National Lottery urges millions of players to change their passwords

The lottery’s operator has found that attackers probably used an automated method known as ‘credential stuffing’ to access up to 150 customer accounts. The post UK’s National Lottery urges millions of players to change their passwords appeared first on WeLiveSecurity

You need an ‘I’ve been hacked’ plan for your cloud
Apple moves on HSTS abuse in Safari

LinuxSecurity.com: The package lib32-libcurl-gnutls before version 7.59.0-1 is vulnerable to multiple issues including denial of service and information disclosure.

LinuxSecurity.com: The package libcurl-gnutls before version 7.59.0-1 is vulnerable to multiple issues including denial of service and information disclosure.

LinuxSecurity.com: The package lib32-libcurl-compat before version 7.59.0-1 is vulnerable to multiple issues including denial of service and information disclosure.

LinuxSecurity.com: The package libcurl-compat before version 7.59.0-1 is vulnerable to multiple issues including denial of service and information disclosure.

LinuxSecurity.com: The package lib32-curl before version 7.59.0-1 is vulnerable to multiple issues including denial of service and information disclosure.

LinuxSecurity.com: The package curl before version 7.59.0-1 is vulnerable to multiple issues including denial of service and information disclosure.

LinuxSecurity.com: The package clamav before version 0.99.4-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

1 in 5 Michigan state staffers fail phishing test but that’s OK apparently
Researchers Show How Popular Text Editors Can Be Attacked Via Third-Party Plugins
Social media accounts of Cambridge Analytica whistleblower suspended
BOOM! Cambridge Analytica explodes following extraordinary TV expose

security update

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves 7 vulnerabilities and has one errata is now available.

Facebook Data Privacy Policies Bashed By Critics After Cambridge Analytica Incident
How to Keep Your Customers Safe Online – 2018
A Mirai Botnet Postscript: Lessons Learned
Coverity Scan code checker’s systems crypto-jacked to run cheeky mining op
Prilex ATM Malware Modified to Clone Chip-and-Pin Payment Cards

LinuxSecurity.com: The package firefox before version 59.0.1-1 is vulnerable to arbitrary code execution.

Modified BlackBerrys sold to drug dealers, five indicted

LinuxSecurity.com: The package libvorbis before version 1.3.6-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

Russia accused of burrowing into US energy networks
This Android malware redirects calls you make to your bank to go to scammers instead
Facebook loses control of 50 million users’ data, suspends analytics firm
Facebook Secretly Provided Analytic Firm Access to Million of Profiles
Facebook suspends account of Cambridge Analytica whistleblower

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Multiple vulnerabilities have been found in KDE Plasma Workspaces, the worst of which allows local attackers to execute arbitrary commands.

LinuxSecurity.com: Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Gentoo’s JabberD 2.x ebuild, the worst of which allows local attackers to escalate privileges. [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in Oracle’s JDK and JRE software suites, the worst of which may allow execution of arbitrary code. [More…]

Cambridge Analytica’s grab of 50 million Facebook users’ data

LinuxSecurity.com: Multiple vulnerabilities were found in cURL, an URL transfer library: CVE-2018-1000120

LinuxSecurity.com: The package ntp before version 4.2.8.p11-1 is vulnerable to multiple issues including arbitrary code execution, content spoofing and denial of service.

security update

security update

security update

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

Facebook confirms Cambridge Analytica stole its data; it’s a plot claims former director

security update

security update

The Pirate Bay is down – Here are its best alternatives

LinuxSecurity.com: Richard Zhu and Huzaifa Sidhpurwala discovered that an out-of-bounds memory write when playing Vorbis media files could result in the execution of arbitrary code.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Hackers Hide Monero Cryptominer in Scarlett Johansson’s Picture
5 Protective Ps to help you prevent network takeovers [VIDEO]
Microsoft bug bounty program: $250k for reporting Meltdown & Spectre type flaws
AMD security flaw saga, browsers broken, Lamo dead at 37, and more
Hacker Adrian Lamo who tipped off FBI about Chelsea Manning dies at 37

LinuxSecurity.com: Huzaifa Sidhpurwala discovered that an out-of-bounds memory write in the codebook parsing code of the Libtremor multimedia library could result in the execution of arbitrary code if a malformed Vorbis file is opened.

security update

New Microsoft Bug Bounty Program Looks To Squash The Next Spectre, Meltdown

LinuxSecurity.com: Richard Zhu discovered that an out-of-bounds memory write in the codeboook parsing code of the Libvorbis multimedia library could result in the execution of arbitrary code.

PS4 Firmware 4.55 Modified to Be Compatible with Firmware 5.50
Crooks opt for Monero as crypto of choice to launder ill-gotten gains
The ‘Perfect Storm’ of Disinformation and Hacking
Pre-installed malware on Android devices made $115k revenue in 10 days
Scarlett Johansson’s face lands starring role in database hack
Intel Details CPU ‘Virtual Fences’ Fix As Safeguard Against Spectre, Meltdown Flaws
Poisoned BitTorrent client kickstarted malware outbreak that tried to infect 400,000 PCs
The Chrome extension that knows its you by the way you type

LinuxSecurity.com: Some vulnerabilities have been found in ClamAV, an open source antivirus engine:

LinuxSecurity.com: An update that fixes 27 vulnerabilities is now available.

YouTuber jailed after shooting boyfriend dead in failed prank
yescrypt – modern KDF and password hashing scheme
Why a hard drive RAID array can save your bacon
Linus Torvalds slams CTS Labs over AMD vulnerability report
Facebook: we won’t share data with WhatsApp (yet)
Tricks that cybercriminals use to hide in your phone

Malware in the official Google store never stops appearing. For cybercriminals, sneaking their malicious applications into the marketplace of genuine apps is a huge victory. The post Tricks that cybercriminals use to hide in your phone appeared first on WeLiveSecurity

The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Global Gas Station Software Found Unsecured Researchers have recently discovered a vulnerability that would allow anyone to […]

Ugh, of course Germany trounces Blighty for cyber security salaries
FYI: There’s a cop tool called GrayKey that force unlocks iPhones. Let’s hope it doesn’t fall into the wrong hands!

Risk Level: Very Low. Type: Worm.

Risk Level: Very Low. Type: Trojan.

We’re Putin our foot down! DHS, FBI blame Russia for ongoing infrastructure hacks

LinuxSecurity.com: Several security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors and other implementation errors may lead to the execution of arbitrary code, denial of service or information disclosure.

GandCrab Ransomware Crooks Take Agile Development Approach
Walmart Jewelry Partner Exposes Personal Data Of 1.3M Customers

LinuxSecurity.com: An update that fixes 8 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: This update upgrades Firefox to version 52.7.0 ESR. * Mozilla: Memory safety bugs fixed in Firefox 59 and Firefox ESR 52.7 (MFSA 2018-07) (CVE-2018-5125) * Mozilla: Buffer overflow manipulating SVG animatedPathSegList (MFSA 2018-07) (CVE-2018-5127) * Mozilla: Out-of-bounds write with malformed IPC messages (MFSA 2018-07) (CVE-2018-5129) * Mozilla: Mismatched RTP payload type can trigger memo […]

LinuxSecurity.com: This update upgrades Firefox to version 52.7.0 ESR. * Mozilla: Memory safety bugs fixed in Firefox 59 and Firefox ESR 52.7 (MFSA 2018-07) (CVE-2018-5125) * Mozilla: Buffer overflow manipulating SVG animatedPathSegList (MFSA 2018-07) (CVE-2018-5127) * Mozilla: Out-of-bounds write with malformed IPC messages (MFSA 2018-07) (CVE-2018-5129) * Mozilla: Mismatched RTP payload type can trigger memo […]

security update

security update

Smart home devices can be hacked within minutes through Google search
Hyperbole Swirls Around AMD Processor Security Threat

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0527

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0526

LinuxSecurity.com: Several security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors and other implementation errors may lead to the execution of arbitrary code or denial of service.

LinuxSecurity.com: An update for ceph is now available for Red Hat Ceph Storage 3.0 for Ubuntu 16.04. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,