Menu

Monthly Archives: March 2018

Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft ASP.NET is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft .NET is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.

New POS Malware PinkKite Takes Flight
How diversity in cybersecurity contributes to your company

Diverse background can contribute to your organization’s security. Here are some tips to get more diversity in security perspectives. The post How diversity in cybersecurity contributes to your company appeared first on WeLiveSecurity

LinuxSecurity.com: This update fixes CVE-2017-18196. —- This update backports security fixes for CVE-2018-3836, CVE-2018-7186 and CVE-2018-7247.

LinuxSecurity.com: This update fixes CVE-2017-18196. —- This update backports security fixes for CVE-2018-3836, CVE-2018-7186 and CVE-2018-7247.

Android malware HenBox hits Xiaomi devices & minority group in China

Risk Level: Very Low.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Ex-Equifax exec charged with insider trading after selling $1 million worth of stock before data breach disclosure
Ex-Equifax exec charged with insider trading after bagging 1 MEEELLION dollars in stock sale
WhatsApp agrees not to share user info with the Zuckerborg… for now
Google to ban cryptocurrency and ICO ads from June 2018
Harden your JBoss EAP 7.1 Deployments with the Java Security Manager
Critical Flash update. Patch now!
Don’t fall for Fortnite invite scams!
Mr. Robot S03E05: A Runtime Error, Credential Theft and New Easter Eggs

The latest episode of this series marks the halfway point in the third season and, in addition to some amazing camerawork there are several examples of actions related to IT security that crop up throughout the episode. The post Mr. Robot S03E05: A Runtime Error, Credential Theft and New Easter Eggs appeared first on WeLiveSecurity

Ex-GCHQ boss: All the ways to go after Russia. Why pick cyberwar?
Flippy the burger-flipping robot too good, fired after one day
Speakers can be used to jump air-gapped systems

LinuxSecurity.com: The package postgresql before version 10.3-1 is vulnerable to privilege escalation.

Samba settings SNAFU lets any user change admin passwords
Let’s Encrypt updates certificate automation, adds splats
Dangerous malware stealing bitcoin hosted on Download.com for years

ESET researchers dicovered that Trojanized applications used to steal bitcoin were hosted inadvertently by the popular website download.cnet.com. The post Dangerous malware stealing bitcoin hosted on Download.com for years appeared first on WeLiveSecurity

Russian anti-antivirus security tester pleads guilty to certifying attack code

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Hackers allegedly steal confidential reports from Police server
OK, deep breath, relax… Let’s have a sober look at these ‘ere annoying AMD chip security flaws
Microsoft Patches 15 Critical Bugs in March Patch Tuesday Update

LinuxSecurity.com: The package calibre before version 3.19.0-1 is vulnerable to arbitrary command execution.

LinuxSecurity.com: The package dovecot before version 2.3.0.1-1 is vulnerable to multiple issues including information disclosure and denial of service.

LinuxSecurity.com: Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the execution of arbitrary code.

It’s March 2018, and your Windows PC can be pwned by a web article (well, none of OURS)
AMD Investigating Reports of 13 Critical Vulnerabilities Found in Ryzen, EPYC Chips
Is the financial sector the most vulnerable to cyber attacks?

LinuxSecurity.com: mailman: Cross-site scripting (XSS) vulnerability in web UI (CVE-2018-5950) SL6 x86_64 mailman-2.1.12-26.el6_9.3.x86_64.rpm mailman-debuginfo-2.1.12-26.el6_9.3.x86_64.rpm i386 mailman-2.1.12-26.el6_9.3.i686.rpm mailman-debuginfo-2.1.12-26.el6_9.3.i686.rpm – Scientific Linux Development Team

LinuxSecurity.com: mailman: Cross-site scripting (XSS) vulnerability in web UI (CVE-2018-5950) SL7 x86_64 mailman-2.1.15-26.el7_4.1.x86_64.rpm mailman-debuginfo-2.1.15-26.el7_4.1.x86_64.rpm – Scientific Linux Development Team

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for 389-ds-base is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for libreoffice is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

APT15 Hackers Hit UK Govt Contractor to Steal Military Technology Secrets

Risk Level: Very Low. Type: Trojan.

Samba Patches Two Critical Vulnerabilities in Server Software
Calendar 2 app pulled from Mac App Store after cryptomining controversy
SecurEnvoy SecurMail, you say? Only after this patch is applied, though
China-Linked APT15 Used Myriad of New Tools To Hack UK Government Contractor
Hackers can steal data from Air-Gapped PCs with microphones & speakers
Mozilla wants to seduce BOFHs with button-down Firefox
Cryptocurrency exchange announces bounty on hackers

The attack itself unfolded within the span of two minutes on March 7. Hackers made a flurry of automated transactions that involved the digital currencies Viacoin (VIA) and Bitcoin (BTC). The post Cryptocurrency exchange announces bounty on hackers appeared first on WeLiveSecurity

Firefox turns out the lights on two privacy-sucking features
‘Hacked’ Facebook taunt leads to 1-star restaurant reviews
Tweet thieves suspended by Twitter
Cryptomining isn’t going to make you rich
How Creative DDOS Attacks Still Slip Past Defenses

LinuxSecurity.com: Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues:

OceanLotus ships new backdoor using old tricks

To smuggle the backdoor onto a targeted machine, the group uses a two-stage attack whereby a dropper package first gains a foothold on the system and sets the stage for the backdoor itself. This process involves some trickery commonly associated with targeted operations of this kind. The post OceanLotus ships new backdoor using old tricks […]

Know who hacked the Binance cryptocurrency exchange? Earn $250,000
CEO of smartmobe outfit Phantom Secure cuffed after cocaine sting, boast of murder-by-GPS

security update

Yahoo! Can’t! Toss! Hacking! Lawsuit!

LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, Red Hat Enterprise Linux 6.6 Advanced Update Support, Red Hat Enterprise Linux 6.6 Telco Extended Update Support, and Red Hat Enterprise

Air gapping PCs won’t stop data sharing thanks to sneaky speakers

We live in the future. Not one with teleportation, time travel, or flying cars, but one where talking to inanimate objects is the “normal,” even “cool” thing to do. According to The Smart Audio Report from NPR and Edison Research, 39 million people now own an interactive, voice-activated smart speaker and, in just a few […]

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.7, 3.6, 3.5, 3.4, and 3.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: dhcp: Buffer overflow in dhclient possibly allowing code execution triggered by malicious server (CVE-2018-5732) * dhcp: Reference count overflow in dhcpd allows denial of service (CVE-2018-5733) SL7 x86_64 dhclient-4.2.5-58.el7_4.3.x86_64.rpm dhcp-common-4.2.5-58.el7_4.3.x86_64.rpm dhcp-debuginfo-4.2.5-58.el7_4.3.i686.rpm dhcp-debuginfo-4.2.5-58.el7_4.3.x86_64.rpm dhcp [More…]

LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.2 Telco Extended Update Support, Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions, and Red Hat Enterprise Linux 7.3 Extended Update Support.

LinuxSecurity.com: Update to latest version. Security-Fixes TROVE-2018-001, TROVE-2018-002,

LinuxSecurity.com: An update for dhcp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Life is cheap! Well it is on Dark Web where your entire identity is for sale

Risk Level: Very Low. Type: Trojan.

FireEye’s Marina Krotofil On Triton and ICS Threats
China ALTERED its public vuln database to conceal spy agency tinkering – research
CCleaner Attackers Intended To Deploy Keylogger In Third Stage
Keep Your Home Warm with this cryptomining heater
UK’s air accident cops are slurping data from pilots’ fondleslabs
Controversial age checks to access online porn delayed in UK
Join SC Media for their 12th annual cybersecurity conference, RiskSec, in New York!
With 4 months to switch on HTTPS, are web hosting companies ready?

LinuxSecurity.com: Updated Red Hat Enterprise Messaging, Realtime, and Grid (MRG) Realtime packages that fix multiple security issues and add one enhancement are now available for Red Hat Enterprise MRG 2.5. Red Hat Product Security has rated this update as having Moderate security

LinuxSecurity.com: An update that solves 8 vulnerabilities and has 14 fixes is now available.

Fake news travels faster than truth on Twitter, and we can’t blame bots