Menu

Monthly Archives: March 2018

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

42 Android Models infected with data stealing banking trojan

LinuxSecurity.com: Several vulnerabilities have been discovered in the Dovecot email server. The Common Vulnerabilities and Exposures project identifies the following issues:

LinuxSecurity.com: Multiple heap buffer over reads were discovered in freexl, a library to read Microsoft Excel spreadsheets, which could result in denial of service.

Equifax Adds 2.4 Million More People to List of Those Impacted By 2017 Breach
In Wake of ‘Biggest-Ever’ DDoS Attack, Experts Say Brace For More
Malware steals data directly from the device to hack Facebook account
RedDrop nasty infects Androids via adult links, records sound, and fires off premium-rate texts
US Navy gives Lockheed Martin $150m big frickin’ laser cannon contract
GitHub knocked briefly offline by biggest DDoS attack ever

At its peak, inbound traffic reached a staggering 1.35 terabits per second (Tbps), outflanking the previously record-setting assault of 1 Tbps at French web hosting provider OVH in September 2016. The post GitHub knocked briefly offline by biggest DDoS attack ever appeared first on WeLiveSecurity

Beware; rTorrent Client Exploited to Mine Monero Cryptocurrency
Chi*a ce*sors the letter ‘N’ from the i*ter*et for a day
20,000 web certificate private keys outed in “business tiff”
Facebook’s see yourself bald app: extreme hackers or extreme hoax?
The rise of AI needs to be controlled, report warns

The experts urge policy-makers to work closely with technical researchers, computer scientists and the cybersecurity community to investigate, understand and prepare for possible malicious uses of AI. The post The rise of AI needs to be controlled, report warns appeared first on WeLiveSecurity

LinuxSecurity.com: Several vulnerabilities have been discovered in SimpleSAMLphp, a framework for authentication, primarily via the SAML protocol. CVE-2016-9814 & CVE-2016-9955

Apple issues advice on how to spot App Store and iTunes phishing scams
Can emojis save you from a terrible password?
Don’t fall for fake iTunes and App Store messages
Memcached servers can be hijacked for massive DDoS attacks
How to start analyzing the security of your IoT devices

The big challenge with IoT devices is that they are all different: Each manufacturer has its own firmware, uses different protocols, and designs its own architecture. So, the first step before carrying out any analysis is to understand the architecture, find out what components are involved, and how they interact and communicate among themselves. The […]

Train to become an expert cyber crime fighter

The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Thanatos Ransomware Causing Major Damage for Victims A new ransomware variant has recently appeared and is proving […]

Github hit by 1.35 Tbps DDoS attack; the largest ever

security update

LinuxSecurity.com: New ntp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Microsoft lobs Skylake Spectre microcode fixes out through its Windows

LinuxSecurity.com: New dhcp packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues.

Bug in HP Remote Management Tool Leaves Servers Open to Attack
HTTPS cert flingers Trustico, SSL Direct go TITSUP after website security blunder blabbed

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Equifax reveals additional 2.4 million users impacted from 2017 breach
Machine learning self defence: how to not shoot yourself in the foot
Sophisticated RedDrop Malware Targets Android Phones

LinuxSecurity.com: An update for quagga is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: This is the One-Year notification for the retirement of Red Hat Enterprise Linux 6.4 Advanced Mission Critical (AMC). This notification applies only to those customers subscribed to the Advanced Mission Critical (AMC) channel for Red Hat Enterprise Linux 6.4.

LinuxSecurity.com: – Update to 2.7.0 Release notes: https://tls.mbed.org/tech- updates/releases/mbedtls-2.7.0-2.1.10-and-1.3.22-released Security Advisory: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security- advisory-2018-01

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Hackers can compromise Memcached Servers for DDoS attacks
Ad Network Circumvents Ad-Blocking Tools To Run In-Browser Cryptojacker Scripts
Smashing Security #067: Cyber stalking and gun control
Equifax finds ANOTHER 2.4 million Americans hit by breach
Personal Data of 21,426 US Marine Force Reserve Personnel Leaked
Equifax peeks under couch, finds 2.4 million more folk hit by breach
Mobile World Congress: Introducing 5G

If we look back at previous incarnations of mobile networks, 1G, 2G and so on, there have been major changes to the technology. The next generation, 5G, delivers, greater speed and lower latency, but also has the advantage of being able to connect many more devices concurrently. The post Mobile World Congress: Introducing 5G appeared […]

1 in 50 publicly readable Amazon buckets are also writable – and that’s a data disaster waiting to happen
27% of under-18s have been sexted, and it’s on the rise
Russia behind compromise of seven states’ voter registration systems
Microsoft still refusing to hand over private email data stored in Ireland
Why Blockchain Will Serve New IT Purposes in 2018
Right to be Forgotten requests stagnate, Google refuses most anyway
Major reform of cybersecurity policies in France

This document, which is described by its authors as a “real white paper on cyber-defense”, is divided into three parts, followed by approximately 20 priority recommendations summarizing the central elements of the document. The post Major reform of cybersecurity policies in France appeared first on WeLiveSecurity

Spectre haunts Intel’s SGX defense: CPU flaws can be exploited to snoop on enclaves

LinuxSecurity.com: An update for rh-dotnet20-dotnet, rh-dotnetcore10-dotnetcore, and rh-dotnetcore11-dotnetcore is now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact

German government confirms hackers blitzkrieged its servers to steal data
23,000 HTTPS certs will be axed in next 24 hours after private keys leak

LinuxSecurity.com: Kelby Ludwig and Scott Cantor discovered that the Shibboleth service provider is vulnerable to impersonation attacks and information disclosure due to incorrect XML parsing. For additional details please refer to the upstream advisory at