Menu

Monthly Archives: March 2018

FBI: we don’t want a backdoor; we just want you to break encryption
SparkyLinux 5.3 Rolling Linux OS Debuts Based on Debian GNU/Linux 10 “Buster”
Cavalry riding to the rescue of DDoS-deluged memcached users
Suspicious cert-sellers give badware a good name for just a few thousand bucks
$250k bounty for anyone exposing hackers behind Binance attempted attack

security update

LinuxSecurity.com: **PHP version 7.1.15** (01 Mar 2018) **Apache2Handler:** * Fixed bug php#75882 (a simple way for segfaults in threadsafe php just with configuration). (Anatol) **Date:** * Fixed bug php#75857 (Timezone gets truncated when formatted). (carusogabriel) * Fixed bug php#75928 (Argument 2 for `DateTimeZone::listIdentifiers()` should accept `null`). (Pedro Lacerda) * Fixed

Sauna security camera hacked; nude videos of Dutch Women’s Handball Team leaked

LinuxSecurity.com: Bjorn Bosselmann discovered that the umount bash completion from util-linux does not properly handle embedded shell commands in a mountpoint name. An attacker with rights to mount filesystems can take advantage of this flaw for privilege escalation if a user (in particular

State Spy Programs, espionage & Monero mining – fingers point at Sandvine
Robots can be hacked with ransomware & curse at customers

LinuxSecurity.com: It was discovered that there were multiple vulnerabilities in the “zsh” shell: * CVE-2014-10070: Fix a privilege-elevation issue if the

Israeli Rabbi arrested for hacking CCTV cameras at women’ bathing suit shop
Cyber Espionage Campaign ‘Slingshot’ Targets Victims Via Routers

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0378

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0377

Auto manufacturers are asleep at the wheel when it comes to security

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0414

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0406

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0418

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0395

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0469

How Dutch Police Busted Hansa Dark Web Marketplace
Less than half of paying ransomware targets get their files back
Slingshot malware uses cunning plan to find a route to sysadmins
Citizen Lab says Sandvine network gear aids government spyware

LinuxSecurity.com: Several security issues were fixed in ClamAV.

LinuxSecurity.com: Several security issues were fixed in Zsh.

Sofacy APT Adopts New Tactics and Far East Targets
New traces of Hacking Team in the wild

Since being founded in 2003, the Italian spyware vendor Hacking Team gained notoriety for selling surveillance tools to governments and their agencies across the world. The capabilities of its flagship product, the Remote Control System (RCS), include extracting files from a targeted device, intercepting emails and instant messaging, as well as remotely activating a device’s […]

Security Camera Found Riddled With Bugs
New FlawedAmmyy RAT steals data and intercepts audio chat
Cryptomining versus cryptojacking – what’s the difference?
Unidentified hax0rs told not to blab shipping biz Clarksons’ stolen data
Vulnerability in Robots Can Lead To Costly Ransomware Attacks
Facebook says “let me get that for you”, secures your links
Rift keels over after Oculus forgets to renew security certificate
How to Rename Multiple Files on Linux
DVLA denies driving licence processing site is a security ‘car crash’
FBI again calls for magical solution to break into encrypted phones
Homeland Security’s IT security continues to fall short
Amazon’s trying to get Alexa to stop laughing at us
One in five healthcare employees willing to sell patient data, study finds

The problem was particularly acute among provider organizations, as opposed to payer organizations (21% vs. 12%). Also, and perhaps counterintuitively, staff with more frequent cybersecurity training were more inclined to such practices. The post One in five healthcare employees willing to sell patient data, study finds appeared first on WeLiveSecurity

LinuxSecurity.com: An update for dhcp is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Windows 10 flaw allowed attackers to open malicious websites… even if your PC was locked

LinuxSecurity.com: The system could be made to expose sensitive information.

The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. MoviePass Subscription Service Tracks More Than Your Viewing Habits The CEO of MoviePass recently revealed the full […]

Google, PlayStation & NRA suffered DDoS attacks via Memcached servers
Carnegie Mellon makes network security guru Jahanian president
Hansa down, this is cool: How Dutch cops snatched the wheel of dark web charabanc

LinuxSecurity.com: dhcp: Buffer overflow in dhclient possibly allowing code execution triggered by malicious server (CVE-2018-5732) * dhcp: Reference count overflow in dhcpd allows denial of service (CVE-2018-5733) SL6 x86_64 dhclient-4.1.1-53.P1.el6_9.3.x86_64.rpm dhcp-4.1.1-53.P1.el6_9.3.x86_64.rpm dhcp-common-4.1.1-53.P1.el6_9.3.x86_64.rpm dhcp-debuginfo-4.1.1-53.P1.el6_9.3.i686.rpm dh [More…]

LinuxSecurity.com: An update that solves 10 vulnerabilities and has four fixes is now available.

You are not alone Blizzard & EA servers are down in multiple regions

security update

Will the defendant please rise? Utah State Bar hunts for sender of topless email

LinuxSecurity.com: Several functions were extremely slow to evaluate certain inputs due to catastrophic backtracking vulnerabilities in several regular expressions.

Surprise: Norks not actually behind Olympic Destroyer malware outbreak – Kaspersky

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Web Server 3.1 for RHEL 6 and Red Hat JBoss Web Server 3.1 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Web Server 3.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Kill Switch Can Mitigate Massive DDoS Attacks Via Memcached Servers

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Olympic Destroyer: A False Flag Confusion Bomb
Lookout: Dark Caracal Points To APT Actors Moving To Mobile Targets
UK data watchdog raids companies suspected of 11 million nuisance texts
Android P promises new security and privacy features
Bitcoin Price Drops 10% Amid Binance Exchange Hacking Rumors
Facebook Onavo VPN app collects user data even when its off
New DDoS attack method breaks record again, adds extortion

DDoS mitigation service Arbor Networks has announced that an undisclosed US company has suffered an attack fueled by internet-facing Memcached servers that clocked in at 1.7 terabits per second (Tbps), beating the previous record of 1.35 Tbps. The post New DDoS attack method breaks record again, adds extortion appeared first on WeLiveSecurity

Your entire ID is worth £820 to crooks on dark web black market
Download Kali Linux from Microsoft Store and use on Windows 10
Smart traffic lights cause jams when fed spoofed data
Spyware maker shuts down surveillance services after hacks
Hope Hicks hacked
Ad-Blocker Ghostery Just Went Open Source-And Has a New Business Model
Memcached DDoS: This ‘kill switch’ can stop attacks dead in their tracks
How women are helping to fight cybercrime
Chrome 65 rolls out: You’re getting a stronger redirect blocker, 45 security fixes
Open-source Exim remote attack bug: 400,000 servers still vulnerable, patch now
MoviePass removes ‘unused’ location feature that tracked cinema-goers’ movements